Skip to content

Evidence

Release records, reproducible packets, vectors, drills, and outside results support the public claims. Each section links a claim to its underlying records and boundary.

See current capability status →Download the public claims registry →Inspect publication set →

Public surface sha256:71593ca9e07a7bc285f1dce9ab618375a5ff24701f7f4be288e2388f0aebe700. The same origin serves the root and its members; byte agreement inside this publication set is not independent witnessing.

Category thesis

Statement

Compute is becoming its own customer.

Evidence date

2026-08-20

Falsifier

Disconfirm by 2030-12-31 if two independently governed datasets, each covering at least 1,000,000 consequential inference, tool, payment, deployment, permission, or data transactions, report machine-initiated requests below 1% with no positive year-over-year trend throughout 2028–2030.

Limits of this thesis

This is a dated category thesis, not a measurement of present transaction volume, Bulla adoption, or autonomous economic activity.

Bulla 0.48.0

published package

17/17

conformance vectors

14/14

routed traces

0

independent witnesses

Release state

accepted by PyPI

Bulla 0.48.0

The Get Started and CLI surfaces use this artifact's command contract.

Limits of this evidence

Commands labelled published are captured from the exact artifact accepted by PyPI; repository source is not substituted for it.

repository source

Bulla 0.48.0

Release receipt · contemporaneous. Repository behavior remains separate from accepted-artifact evidence even when the version numbers match.

Limits of this evidence

Repository source may match or lead the latest PyPI release. Publication status and receipt coverage come from PyPI and release records, not version text alone.

Release receipt coverage

The comparison set is every Bulla release accepted by PyPI. Candidate releases do not count. A receipt created when a release was published remains distinct from one reconstructed later.

30

PyPI releases

7

contemporaneous

2

reconstructed

21

missing

0

invalid

0.48.0contemporaneous0.48.0.json
0.47.1contemporaneous0.47.1.json
0.46.0contemporaneous0.46.0.json
0.45.1contemporaneous0.45.1.json
0.44.4contemporaneous0.44.4.json
0.44.1contemporaneous0.44.1.json
0.44.0contemporaneous0.44.0.json
0.43.0missingno receipt
0.42.0missingno receipt
0.41.0missingno receipt
source · https://pypi.org/pypi/bulla/jsoncoverage · 30.0%

Limits of this evidence

Coverage is calculated against the PyPI release denominator and does not count unanchored actions outside it.

ActionReceipt conformance

wire

ActionReceipt v0.2

normative format

vectors

17/17

Python checker

TypeScript

17/17

browser parity

Limits of this evidence

Passing the supplied vectors establishes fixture parity, not independent implementation or live-system correctness.

Receiver reliance evidence

D changes only after a receiver signs both its policy decision and the exact consequential boundary, then an accepted intake signer qualifies the closed evidence package under a signed ledger head.

Current ledger

D0 · intake open

Counted

One unique boundary receipt, its reliance computation, organization-key evidence, runtime replay, accepted intake signature, and ledger head all pass the public checker.

Current intake

D0 · intake open. Candidate packets remain NOT_COUNTED until qualification and head records merge; with no head at D0, no append-only or independent-review claim is made.

Not inferred

The signed review is attributable, not mathematical proof of organizational independence. D also does not say the provider claim was true or that the receiver later acted.

What D does not establish

A qualified D record establishes one signed receiver-policy computation over supplied records and an attributed intake determination about organizational control. It does not mathematically establish organizational independence, provider-claim truth, policy suitability, actor time, or any later payment, deployment, control grant, or handoff.

Independent witness evidence

W changes only after an outside operator completes the published receipt-witness exercise and a repository review attributes separate legal control, key custody, and operational authority.

Current ledger

W0 · intake open

Counted

Unique active outside control domains with valid operator signatures, exact release-receipt retrieval, inclusion under both checkpoints, append-only consistency, a stable endpoint during the probe, and a merged qualification.

Test exercise

The project-controlled fixture passes the candidate checker and remains VALID_CANDIDATE · NOT_COUNTED. It increments neither W nor I, D, or r.

Not inferred

The review is attributable, not cryptographic proof of independence. W also does not establish receipt truth, occurrence, continuing availability, production fitness, capital, recourse, or a witness market.

What W does not establish

A qualified W record establishes one separately controlled witness operation over the submitted public release records. It does not cryptographically establish organizational independence, receipt truth, occurrence, continuing availability, policy compliance, production fitness, bond value, recourse, or a witness market.

Agent Incident Packet evidence

The profile requires an exact decision/effect anchor pair for each represented protocol. Deterministic HTTP and MCP packets bind those pairs with v0.4 receipts, opaque trace artifacts, non-circular redaction records, accepted reviewer statements, corrections, and team-operated witness evidence.

Live timeline and publish receipts require conventions: []. Convention-bearing historical receipts remain opaque evidence only and cannot satisfy live occurrence or coverage. The restriction belongs to this experimental profile; ActionReceipt v0.4 remains unchanged.

experimental

maturity

2

fixtures

2/2 / 1/2

HTTP decision / effect

2/2 / 1/2

MCP decision / effect

denominator · PATH_SEPARATE_TEAM_CONTROLLED · external A/J/I/W · 0/0/0/0 · r0

Accepted denominator checkpoints authenticate the path-separated observer’s reported snapshot. They do not prove completeness or organizational independence. An accepted observer can omit rows; self-shortening remains outside packet detection.

Limits of this evidence

The profile, deterministic fixtures, checkers, and localhost pilots are team-authored source evidence. A packet supports zero or one witness reference. Multiple-witness aggregation remains unresolved. The empty-convention rule belongs only to this experimental profile and does not change ActionReceipt v0.4; cross-runtime convention evaluation remains outside the verification contract. Denominator checkpoints authenticate what an accepted path-separated observer reported; they do not prove completeness or organizational independence, and an accepted observer can self-shorten rows. The evidence does not establish production containment, disclosure safety, external implementation parity, independent witnessing, or incident truth. External A/J/I/W and replay counts remain 0/0/0/0 and r0.

Verify the deterministic packets →

Accountability Circuit

Implemented behavior and operating boundary

The circuit is a source-available Assurance Linker profile, not part of the installed Bulla package. The evidence below separates what the verifier computes from who operated the supplied roles and what remains unestablished.

Implemented

Deterministic verification of one closed synthetic promise, browser/Python/Node parity, witness inclusion and consistency, challenge chronology, eligibility, exact authorization verification, and sandbox attempt reporting.

Operated in the demonstration

Provider, receiver, witness, challenge, settlement, and fixture-rail roles are supplied by the project-authored demonstration.

Not independently established

Organizational independence, complete observation, custody, collectibility, legal enforceability, production operation, and real settlement.

profile
bulla.assurance-linker/0.2-experimental
availability
SOURCE_ONLY
operating control
team-operated
formal scope
8 circuit-specific theorem-to-fixture mappings
stranger calibration
NOT_COMPUTED
external authors
0
external implementations
0
independent witnesses
0

External counters · A0/J0/I0/W0 · r0

Limits of this evidence

The accountability circuit is an experimental source implementation over project-authored synthetic promises, evidence, keys, witness roots, roles, and fixture-rail reports. Its browser, Python, and Node agreement establishes verifier behavior over supplied records, not complete observation, independent witnessing, worldly execution, real custody, collectibility, legal enforceability, production operation, actual settlement, or adoption. The published Bulla package creates and verifies ActionReceipts; it does not include the complete circuit.

Reliance Map evidence

The scale profile applies authenticated correction recall to one accepted finite graph. The semantic report is separate from the browser projection.

Implemented

Strict graph, context, correction, and report parsing; exact external graph acceptance; ActionReceipt v0.4 correction authority; tri-state descendants; replayable paths; Python, Node, and browser agreement.

Operated here

The graph author, correction authority, keys, accepted context, generator, projection, and all three implementations are project-operated.

Unestablished

Complete worldly dependencies, correction truth, organizational independence, production operation, rollback, and authority for any downstream consequence.

Declared decisions
10,000
Affected
2,500
Unresolved
2,500
Unaffected
5,000

Semantic root: sha256:afb5e1a90f17d0c1b07042fbc42b77db29b5918562d3c18a17af110bd2329f3c

External counters · A0/J0/I0/W0 · r0

Limits of this evidence

The Reliance Map is an experimental source implementation over a project-authored synthetic graph, correction notice, keys, and context. Its result is relative to the accepted declared graph. It does not establish correction truth, complete worldly dependency capture, action safety, rollback, consequence authorization, independent operation, production use, or adoption. It is not part of the installed Bulla package.

Retained Evidence Drill

The retained packet reproduces the published judgment from packet members alone. Authentic fork evidence establishes the witness conflict but does not authorize propagation. When an accepted correction notice is added, the receiver recomputes the declared recheck set from retained artifacts.

Record

Unchanged · sha256:ce559fe4a81687a4eec99f33c6e04bab31e23e46af87091059ef3c3acb3e1c95

Judgments

Published, fault-observed, and corrected judgments have three distinct canonical digests. The generated deltas name the exact new evidence and changed fields.

Review control

Review all · 10,000 · required review · 5,000 · declared reduction · 5,000 · incomplete lineage cleared · 0

Retained execution

Historical verification · REPRODUCED. The launcher reads packet members only, blocks common Node network interfaces, uses no installed Bulla, and requests no Glyph Standard route.

Packet root: sha256:5210c1c0b81b65fde5bb226e21718d586ce417a8e8cd8060ae41e3181e0baaf0

Limits of this evidence

The packet establishes local historical reproduction under supplied verifiers and receiver contexts. Its launcher blocks enumerated Node network interfaces but does not establish operating-system network isolation. It does not establish freshness, current revocation or external state, independent operation, occurrence, worldly truth, custody, settlement, causal independence, or completeness beyond the accepted declaration.

Archive: sha256:a086ccd79e34a25623fc6805d19c77df1c2e1fe292853fe8642a60e46567f291

Compute Contract Drill

The public AIR and NVIDIA fixtures verify within their separate scopes but do not share an authenticated event binding. The receiver therefore escalates. A project-operated control closes the declared fixture bindings and demonstrates evaluator reachability only.

Public case

execution relation · NOT_ESTABLISHED · receiver · ESCALATE

Constructed control

PROJECT_OPERATED · funds moved · false · externality · NOT_ESTABLISHED

Policy

Contradiction → REFUSE · missing or uncheckable binding → ESCALATE · all declared fixture requirements satisfied → RELY inside the constructed control only.

Counters

W+0 · D+0 · I+0 · r+0

Packet root: sha256:264c428b8f126920de1d685b2342b9e84cd5abf93bcfa605ef119b2fa5cde300

Report: sha256:d4dc47e76f0f5b9aad8aff09641628908f30bd06adaa4b935511037d1efc7bcc

Limits of this evidence

The drill is a project-operated, fixture-bound evaluator reachability result. It does not establish live H100 execution, worldly occurrence, provider identity, organizational independence, production reliance, legal effect, enforceability, collectibility, external custody, real settlement, or completeness outside its declared packet and receiver policy.

Evidence-Locked Consequence

The frozen baseline commits a direct state append. The candidate rejects that path, then verifies one complete redemption and consumes one receiver-issued grant in the same local transaction as one append.

Baseline

direct effect · HTTP 200 · committed

Candidate

direct effect · HTTP 403 · rejected · complete redemption · 1 effect

Replay

grant · CONSUMED · effect count · 1 · original response bytes retained

Boundary

Declared project-operated route graph and receiver runtime. Platform administration, copied credentials, deployment immutability, undisclosed effects, production safety, and legal effect remain outside the result.

Packet root: sha256:b48ad89182abc801659d684c73facc71819ffca930a2059bcca4dd5404a0d8ad

Report: sha256:ba22f4a74237327bc7cbfdadc2b2e9dea01c8d925e1cf2eaeda27d0fb74068f3

Limits of this evidence

Scope is limited to the closed project-operated fixture and its declared route graph. Nothing here establishes cloud or platform administrator containment, absence of copied receiver credentials, source or deployment immutability, worldly truth, policy correctness, provider execution, undisclosed external effects, production safety, or legal effect. Packet reproduction verifies retained records and disposition; it does not re-execute the Durable Objects runtime.

Answerability Network evidence

The composition profile connects one selected provider receipt to a witnessed history, an objective fork covenant, and exact graph-relative recall.

Computed

Buyer-policy selection, stable receipt verification, leaf-bound inclusion, append-only history extension, same-size fork detection, challenge state, bounded eligibility, exact authorization, Test-ledger attempt reporting, and 10,000-decision recall.

Operated here

Buyer, providers, witness, challenge authority, settlement authority, graph author, correction authority, and rail observer are project-operated fixture roles.

Outside the result

Complete dependency capture, provider-result truth, organizational independence, custody, collectibility, real settlement, production operation, and customer activity.

Declared decisions
10,000
Recheck
2,500
No declared path
5,000
Unresolved
2,500

Formal scope. The finite model covers witness-fault separation, graph-relative recall, incomplete lineage, and attempt-report non-amplification. It does not prove parser correctness, Ed25519, Merkle algorithms, or real operations.

Control. All fixture roles remain within 1 project-operated control domain. External counters remain A0/J0/I0/W0 · r0.

Semantic root: sha256:eb230a717dfaaa973b788f6cbd2e28d546bddc9d0e96370a0b56ebeed3821d27

Presentation root: sha256:0ec2281f0fe66499c3aa7448ea1444125de52d500db12a714736697ce92c6392

$ PYTHONPATH=bulla/src python3 bulla/spec/answerability-network/check.py bulla/spec/answerability-network/vectors/fork-authorized --context bulla/spec/answerability-network/contexts/fork-authorized.json
$ node bulla/spec/answerability-network/check.mjs bulla/spec/answerability-network/vectors/fork-authorized --context bulla/spec/answerability-network/contexts/fork-authorized.json

Limits of this evidence

The Answerability Network is an experimental source implementation over project-authored synthetic transactions, keys, witness views, graph declarations, challenge records, capital observations, and Test-ledger reports. It is not part of the installed Bulla package. It does not establish provider-result truth, complete dependency capture, witness independence, custody, collectibility, dollars moved, production operation, customer activity, or adoption.

The witness covenant is an experimental source implementation over project-authored keys, checkpoints, challenge records, allocations, authorities, and Test-ledger reports. It does not establish independent operation, receipt truth, complete observation, custody, collectibility, deterrence, actual recovery, real settlement, production operation, or a witness market. It is not part of the installed Bulla package.

Assurance Linker evidence

The source-only profile compiles closed structured promises into evidence, authority, coverage, capital, recourse, and consequence requirements. Python and standalone Node reports agree on the deterministic synthetic corpus.

experimental

maturity

8

dossiers

9

formal invariants

0/0/0/0

external A/J/I/W

Synthetic promises and team-operated roles do not establish worldly truth, complete denominators, external collateral encumbrance, custody, collectibility, legal enforceability, organizational independence, production safety, or mainnet readiness. Reliance remains NOT_COMPUTED.

Limits of this evidence

The profiles, Trial 0.2-r5 instrument, and accountability-circuit candidate use team-authored synthetic promises, cases, expected projections, implementations, evidence, keys, witness roots, rail observations, and settlement roles. The accountability candidate has no bound anonymous deployment or reader attempts, so comprehension remains NOT_COMPUTED. No Trial 0.2-r5 mirror publication set, cold-reader calibration, or foreign checker attempt has occurred. Surface completeness is relative to named frozen schemas, rules, and protected fields; it does not cover every open-world interaction. Foreign authorability, independent reproduction, institutional handling, operational separation, and marginal decision value remain blocked. The evidence does not establish worldly truth, complete observation, external collateral encumbrance, custody, collectibility, legal enforceability, organizational independence, production safety, actual settlement, actuarial calibration, or mainnet readiness. Bitcoin remains optional, separate, sat-denominated, and does not evaluate predicates. External A/J/I/W and replay counts remain 0/0/0/0 and r0.

Verify the assurance dossiers →Inspect the clean-room trial doorway →

Routed-inference draft

A finite single_route_single_provider profile. The deterministic bundle contains the normative profile, taxonomy, checker, reports, and 14 traces.

draft

status

14/14

traces

single route single provider

topology

full

disclosure

0

live providers

0

settlement adapters

0

external implementations

0

independent witnesses

sha256:162ce81936a3726df832aaaa7b62976ffc06dbd550a34e88ae38d6d3346d69b0

81044 bytes · receipt measurement only, not a protocol size guarantee

Limits of this evidence

The routed profile is a local, full-disclosure, single-router/single-provider draft with no live provider, settlement adapter, or independent implementation.

$ curl -LO https://glyphstandard.com/downloads/routed-inference-profile-v0.1-draft.zip
$ unzip routed-inference-profile-v0.1-draft.zip
$ cd routed-inference-profile-v0.1-draft
$ python3 -m pip install pynacl
$ python3 check.py
# OK: 14/14 routed-inference traces
Download the deterministic bundle →

Semantic settlement

The semantic boundary and finality profiles separate world claims, model-relative entailment, and authority-bound institutional outcomes while preserving a replayable transition record.

bulla.semantic-boundary-stack/0.3-freeze

profile

internal captive foreign substrate

classification

240

captive cases

0

reviewer holdouts

60/60 expected

exit algebra

176 cases

boundary families

blocked missing external participants

external replay

boundary specification · sha256:53dd6f5456e52032f0e69a3097cd9928bd972cca0d52502c2c013739e5ba25fe

finality specification · sha256:ba3a8eddca99ac208d62d96df59b89ede9d040b87c71691f1a251b00763388d6

evaluation report · sha256:d34910ad7ec16e30d6984f75db332dcf71efbfc056aaeb7b438e7da608cf3746

reviewer-originated hidden cases not created

independent clean-room implementation not observed

found-data adjudication not performed

no production settlement or legal-validity evidence

GitHub runners and the sprint signer are not independent witnesses

Limits of this evidence

The claim flow is a finite captive research profile. It binds authorized institutional transitions; it does not establish worldly truth, legal validity, production settlement, custody, or independent forum behavior.

Inspect the semantic-finality profile →

Witness and operator plurality

ActionReceipt witnesses

0

Review the witness role

Operator manifest

published operator kit

Inspect the manifest

Limits of this evidence

An operated composition-deed log or project-controlled witness fixture is not independent ActionReceipt witness plurality; W is derived only from active repository qualifications under unique outside control domains.

Witnessing preserves a receipt outside its issuer and makes inclusion or equivocation claims testable against authenticated log evidence.

Limits of this evidence

Witness evidence establishes what entered a witnessed history; it does not prove the underlying execution occurred or reveal omitted actions.

The routed reports distinguish conveyed recourse terms from reachability, which remains unverified.

Limits of this evidence

A consistently conveyed remedy adapter establishes recourse terms, not that a forum, remedy, or settlement path is operational.

Inspect the witness role →