Current as of 2026-08-01
What is available today.
Bulla is published software. ActionReceipt 0.2 is the current standard. The research profiles below are labeled separately because a working internal demonstration is not the same as outside validation.
Status files and deployment limits
reproducible snapshot: status.json · sources.json (input digests) · Bulla release lineage · no website.deploy candidate is generated · generation, public release, and attestation are BLOCKED_UNIMPLEMENTED · deployed-output binding is NOT_COMPUTED · public withdrawal record · historical receipt registry
Published
Bulla 0.47.1 is the package version recorded from PyPI evidence.
Normative
ActionReceipt 0.2 is the normative receipt format.
Experimental
12 source-only or experimental profiles remain outside the stable product contract.
External evidence
No qualifying external author, adjudicator, implementation, or witness record is currently established.
Technical capability ledger
| Capability | Maturity | Availability | Established | Not established | External A/J/I/W |
|---|---|---|---|---|---|
| ActionReceipt | released | PYPI RELEASED | Portable ActionReceipt v0.2 records, canonical hashing, cryptographic verification, and reference vectors. released implementation and reproducible fixtures | The worldly truth of the recorded claim or occurrence of the underlying event. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE | 0/0/0/0 · r0 |
| Authority and scope | released-draft | PYPI RELEASED | Opt-in v0.3 implementation binds issuer authorization, delegation, and structured scope checks. released draft with local conformance fixtures | The legality, legitimacy, or institutional sufficiency of the authored authority policy. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE | 0/0/0/0 · r0 |
| Strict receipt ingestion | released-draft | PYPI RELEASED | A single byte-oriented parser rejects duplicate members, non-finite values, off-schema closed objects, and declared size, depth, node, and string limits before cryptographic verification. published in Bulla 0.44.4 with internal adversarial fixtures | Independent hostile-input review or immunity to every parser implementation defect. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE | 0/0/0/0 · r0 |
| ActionReceipt v0.4 occurrence binding | released-draft | PYPI RELEASED | The draft separately authenticates content, one claimed occurrence, and its authority envelope under a portable integer-only canonical data model; Python and Node reference checkers agree on the fixed vector. opt-in draft published in Bulla 0.44.4 with internal cross-language reference checks | Worldly occurrence, witnessed time, cross-platform independent parity, or promotion over the normative v0.2 default. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE | 0/0/0/0 · r0 |
| Semantic invention | experimental | PYPI RELEASED | Finite FRSL-1 packages and negative certificates are independently replayable on the captive Golden corpus. internal captive benchmark | Foreign generality, open-world completeness, or a stable semantic API. TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · FINITE EXACT | 0/0/0/0 · r0 |
| Partial envelopes | experimental | PYPI RELEASED | Checked RELY and REFUSE regions preserve residual escalation under a declared finite closure warrant. internal formal and executable evidence | Completeness outside the declared model class or safety under an unmodeled closure expansion. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT | 0/0/0/0 · r0 |
| Semantic Finality | experimental | PYPI RELEASED | Replayable provisional, reserve, conflict, refinement, finalization, and stale-epoch transitions in a finite shadow model. internal state-machine and Golden evidence | Production settlement, real custody, collectibility, actuarial value, or institutional efficacy. TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · BOUNDED EXACT | 0/0/0/0 · r0 |
| Claim Flow v0.4 | experimental | PYPI RELEASED | Typed appraisal, forum, precedent, applicability, and settlement transitions with explicit authority provenance. internal formal and captive benchmark evidence | External legal validity, foreign applicability judgments, or automatic institutional authority. TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · BOUNDED EXACT | 0/0/0/0 · r0 |
| Generalization Constitution v0.5 | experimental | SOURCE ONLY | Candidate, adoption, and applicability remain separate, with checked finite safe-scope frontiers and effect-laundering controls. internal formal and captive-control evidence | Foreign transfer, external applicability judgments, or a stable precedent API. TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · BOUNDED EXACT | 0/0/0/0 · r0 |
| Golden Gate qualification | experimental | PYPI RELEASED | The finite checker core supports typed abstention and reproducible qualification; benchmark packets add captive mutation, portability, custody, and control evidence. implemented methods with internal captive evidence | Reviewer-originated results, independent validation, production safety, or open-world completeness. TEAM AUTHORED · MACHINE PLANTED · INTERNAL REPRODUCIBLE · BOUNDED EXACT | 0/0/0/0 · r0 |
| Receipt-coupled dispatch | experimental | SOURCE ONLY | The reference boundary durably commits an authorized intent before external I/O, preserves uncertain outcomes, enforces committed adapter capabilities, and prevents duplicate effects under its captive verified-idempotency contract. internal exhaustive model, crash fixtures, and captive adapters | Distributed atomicity, production payment safety, external adapter conformance, or nonlocal integration value. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · BOUNDED EXACT | 0/0/0/0 · r0 |
| Agent Incident Packet v0.1 | experimental | SOURCE ONLY | The source profile requires an exact decision/effect anchor pair for each represented protocol and binds each reported denominator snapshot to a signed checkpoint whose issuer is accepted through external role context. Live timeline and publish receipts use ActionReceipt v0.4 with conventions: []; convention-bearing historical receipts remain opaque evidence artifacts only. Team-operated fixtures also bind non-circular redaction records and accepted reviewer statements, party statements, corrections, and witness evidence without collapsing their verification dimensions. team-operated deterministic fixtures and isolated localhost HTTP/MCP pilots | A packet supports zero or one witness reference. Multiple-witness aggregation remains unresolved. Cross-runtime convention evaluation, denominator completeness, organizational independence, production containment, disclosure safety, external implementation parity, independent witnessing, and incident truth also remain unestablished. The empty-convention rule narrows this experimental profile and does not change ActionReceipt v0.4. An accepted observer can self-shorten rows. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · NOT APPLICABLE | 0/0/0/0 · r0 |
| Recheckable Inference alpha | experimental | SOURCE ONLY | Two synthetic providers return byte-identical BACKUP artifacts. After both provider processes terminate, the retained, term-bound integer model reproduces one input-to-output relation while the opaque record supplies no model to rerun. Under the separately supplied buyer policy, the first relation is payment-eligible but not authorized or settled; the opaque response is refused. Adding one unmatched receiver effect leaves receipt integrity verified, changes coverage from 1/1 to 1/2, and makes payment ineligible. Project-authored Python, standalone Node, and browser verifiers reproduce these bounded reports. three deterministic bundles, team-operated localhost roles, project-authored Python, standalone Node, and browser parity, transient hostile mutations, and a finite abstract model | Historical provider execution, answer truth, model quality, complete receiver denominators, payment execution, external implementation parity, organizational independence, custody, collectibility, production clearing, or worldly truth. All roles and evidence remain synthetic and team-controlled. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT | 0/0/0/0 · r0 |
| Assurance Linker alpha | experimental | SOURCE ONLY | The source profile deterministically compiles a closed structured promise into explicit evidence, authority, coverage, capital, recourse, and consequence requirements. Python and standalone Node verifiers agree on eight team-authored dossiers. The checked fixture comparison shows that receipt integrity remains VERIFIED while a receiver-recorded bypass changes required coverage from COVERED to UNCOVERED and payment from ELIGIBLE to INELIGIBLE. The finite formal model checks eight assurance invariants. A Bitcoin Core 31.1 regtest adapter demonstrates synthetic rail mechanics while preserving the rail-neutral report. Trial 0.2-r5 preserves the r4 semantic root exactly and adds a deterministic publication bundle, two-mirror retrieval requirements, dimensional checker-source provenance, and interleaved recruitment. team-authored deterministic fixtures, team-authored checker parity, finite abstract-model checks, one local Bitcoin Core regtest execution, and a team-operated Trial 0.2-r5 publication-neutral checker doorway | No anonymous two-mirror publication set, cold-reader calibration, candidate round, or foreign checker attempt has occurred for Trial 0.2-r5; recruitment and blind execution remain unauthorized. Foreign authorability, independent checker reproduction, external institutional handling, operational separation, marginal decision value, economic adoptability, representative developer demand, worldly truth, complete denominators, external collateral encumbrance, custody, collectibility, legal enforceability, organizational independence, production safety, actuarial calibration, source-to-image correspondence, or mainnet readiness remain unestablished. Recruitment uses investigator-selected, uncompensated volunteers. The Bitcoin adapter is optional and does not evaluate predicates or replace the named settlement authority. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · FINITE EXACT | 0/0/0/0 · r0 |
| Executable recourse | experimental | SOURCE ONLY | A local receipt trace can open, acknowledge, evidence, decide, authorize, complete, route, expire, and close a challenge while keeping forum and remedy authority distinct. internal replay and authority-separation fixtures; reachability captive | A separately controlled forum, operational reachability, institutional efficacy, or automatic enforcement of a semantic finding. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · BOUNDED EXACT | 0/0/0/0 · r0 |
| Precedent compounding | research | RESEARCH ONLY | Compounding was observed in a team-authored, machine-planted, bounded-exact lineage benchmark and survives the declared captive controls. internal captive observation | Generalized compounding on foreign meanings, independent adjudication, or economic value. TEAM AUTHORED · MACHINE PLANTED · INTERNAL · BOUNDED EXACT | 0/0/0/0 · r0 |
| Public control-plane alpha candidate | experimental | SOURCE ONLY | Deterministic fixtures, source checkers, and local Cloudflare-runtime tests exercise one closed synthetic MCP authorization, receiver, denominator, witness, coverage, and packet-publication loop. team-authored deterministic fixtures and local Cloudflare-runtime tests | The generated control-plane evidence ledger reports whether a public endpoint has tracked deployment evidence. Customer authority, denominator completeness, organizational independence, production safety, and incident truth remain unestablished. TEAM AUTHORED · MACHINE CHECKED · INTERNAL REPRODUCIBLE · BOUNDED EXACT | 0/0/0/0 · r0 |
| Witness plurality | blocked | BLOCKED | A local checkpoint and inclusion-proof primitive is specified and tested. local fixture only | Independent witness operators, plurality, stake, or a production witness network. TEAM AUTHORED · MACHINE CHECKED · INTERNAL · NOT APPLICABLE | 0/0/0/0 · r0 |
| Risk and insurance | research | RESEARCH ONLY | The program contains mathematical ambiguity-reserve and worst-case exposure mechanisms under declared finite models. internal research architecture | Underwriter validation, actuarial calibration, product pricing, or real collateral custody. TEAM AUTHORED · NOT ADJUDICATED · INTERNAL · BOUNDED EXACT | 0/0/0/0 · r0 |
A/J/I/W means external authors, adjudicators, independent implementations, and witnesses; r counts external replays of supplied checkers, which never increment I. Internal agents, supplied checkers, and GitHub runners do not increment those counts.
What changes an external-evidence count
Each counter has one definition, and a counter changes only together with evidence that satisfies it. Canonical source: glyph/data/evidence-contract.json.
Outsider runs supplied checker on supplied artifacts
external replays
Outsider writes a second checker from the specification
implementations
Outsider authors previously unseen cases
authors
Outsider decides contested semantic cases
adjudicators
Separately controlled service retains receipts
witnesses
An external person reproduced the team's supplied procedure on the team's supplied artifacts. It does not establish an independent implementation.
Submit a case from your domain
Bring a consequential disagreement or workflow the project team did not write.
Review a specific claim
Choose a formal, implementation, domain, privacy, or authority claim and test it directly.