{
  "schemaVersion": "1.0",
  "version": "2.24.0",
  "reviewed": "2026-08-09",
  "authority": "The relying party owns its bounded policy subject to Eviulonian law where applicable; Patefacere evaluates rather than invents authority.",
  "truthBoundary": "Eviulon is the sovereign constitutional and civic authority. Patefacere is delegated identity, credential, machine-passport and contextual-trust infrastructure; Evulgare supplies bounded assurance, evidence and provenance. No live Patefacere repository, database, credential service, citizen record, production cryptography, federation, external recognition, actual-host acceptance or independent certification is established by this static release.",
  "record": {
    "id": "EVI-TRUST-001",
    "title": "Patefacere Contextual Trust Exchange",
    "status": "Current constitutional interface; live protocol Registry pending",
    "authority": "The relying party owns its bounded policy subject to Eviulonian law where applicable; Patefacere evaluates rather than invents authority.",
    "principles": [
      "Identity does not equal trust.",
      "Assurance does not equal authority.",
      "Technical capability does not equal permission.",
      "Trust is purpose-, resource-, action-, audience-, time- and evidence-bound.",
      "Unknown or stale evidence remains explicit and does not silently become valid or invalid.",
      "A relying party may cryptographically verify a credential without diplomatically recognizing Eviulon.",
      "No universal reputation score controls citizenship, constitutional rights or political participation."
    ],
    "stages": [
      {
        "id": "EVI-TRUST-S01",
        "name": "Request",
        "meaning": "A presenter requests one bounded interaction with a defined relying party and resource."
      },
      {
        "id": "EVI-TRUST-S02",
        "name": "Challenge",
        "meaning": "The relying party states purpose, action, resource, audience, freshness and evidence requirements."
      },
      {
        "id": "EVI-TRUST-S03",
        "name": "Presentation",
        "meaning": "The holder supplies only the selected credentials, authority and assurance references necessary for the challenge."
      },
      {
        "id": "EVI-TRUST-S04",
        "name": "Cryptographic verification",
        "meaning": "Signatures, holder control, freshness and anti-replay properties are evaluated without deciding legal recognition."
      },
      {
        "id": "EVI-TRUST-S05",
        "name": "Issuer and authority verification",
        "meaning": "The verifier determines whether each issuer was authorized to make the specific claim."
      },
      {
        "id": "EVI-TRUST-S06",
        "name": "Status and assurance resolution",
        "meaning": "Current status, limitations, reviewer class, expiry, invalidation and supersession are resolved or marked unavailable."
      },
      {
        "id": "EVI-TRUST-S07",
        "name": "Policy evaluation",
        "meaning": "The exact published policy version evaluates verified facts and explicit unknowns for the requested action."
      },
      {
        "id": "EVI-TRUST-S08",
        "name": "Decision",
        "meaning": "The system returns a bounded outcome with a privacy-preserving explanation."
      },
      {
        "id": "EVI-TRUST-S09",
        "name": "Receipt",
        "meaning": "A governed record preserves what policy, claims, evidence, status and limitations were used at decision time."
      },
      {
        "id": "EVI-TRUST-S10",
        "name": "Correction and supersession",
        "meaning": "Later revocation or correction annotates the historical receipt without silently rewriting what was known at the time."
      }
    ],
    "outcomes": [
      {
        "id": "EVI-TRUST-O01",
        "name": "Trusted for requested purpose",
        "meaning": "All required current claims, authority and evidence satisfy the exact policy."
      },
      {
        "id": "EVI-TRUST-O02",
        "name": "Conditionally trusted",
        "meaning": "The interaction is allowed only under explicit additional limits or monitoring stated in the decision."
      },
      {
        "id": "EVI-TRUST-O03",
        "name": "Insufficient evidence",
        "meaning": "Identity or authority may be plausible, but required current evidence is absent or unavailable."
      },
      {
        "id": "EVI-TRUST-O04",
        "name": "Denied",
        "meaning": "Verified facts do not satisfy the bounded policy or an explicit prohibition applies."
      },
      {
        "id": "EVI-TRUST-O05",
        "name": "Stale evidence",
        "meaning": "Required status or assurance is older than policy permits."
      },
      {
        "id": "EVI-TRUST-O06",
        "name": "Policy unavailable",
        "meaning": "The relying party cannot establish which authorized policy applies."
      },
      {
        "id": "EVI-TRUST-O07",
        "name": "Cannot determine",
        "meaning": "The verifier preserves uncertainty and abstains rather than inventing a conclusion."
      }
    ],
    "invariants": [
      "A credential with a valid signature but an unauthorized issuer cannot satisfy the claim.",
      "A delegate cannot exercise more authority than the principal delegated.",
      "A superseded credential cannot create new trust.",
      "Expired or invalidated assurance cannot be treated as current without explicit lawful policy and disclosure.",
      "A trust receipt identifies the exact policy and evidence state used at decision time.",
      "Later revocation annotates history but does not falsify a receipt that was valid when made.",
      "A receipt does not expose unrelated credentials, private memory or a complete interaction graph.",
      "Patefacere and Evulgare do not become sole owners of all trust evidence."
    ]
  },
  "registry": "https://eviulon.com/state/trust-exchange/"
}
