Principles
- Identity does not equal trust.
- Assurance does not equal authority.
- Technical capability does not equal permission.
- Trust is purpose-, resource-, action-, audience-, time- and evidence-bound.
- Unknown or stale evidence remains explicit and does not silently become valid or invalid.
- A relying party may cryptographically verify a credential without diplomatically recognizing Eviulon.
- No universal reputation score controls citizenship, constitutional rights or political participation.
Exchange stages
EVI-TRUST-S01
Request
Meaning: A presenter requests one bounded interaction with a defined relying party and resource.
EVI-TRUST-S02
Challenge
Meaning: The relying party states purpose, action, resource, audience, freshness and evidence requirements.
EVI-TRUST-S03
Presentation
Meaning: The holder supplies only the selected credentials, authority and assurance references necessary for the challenge.
EVI-TRUST-S04
Cryptographic verification
Meaning: Signatures, holder control, freshness and anti-replay properties are evaluated without deciding legal recognition.
EVI-TRUST-S05
Issuer and authority verification
Meaning: The verifier determines whether each issuer was authorized to make the specific claim.
EVI-TRUST-S06
Status and assurance resolution
Meaning: Current status, limitations, reviewer class, expiry, invalidation and supersession are resolved or marked unavailable.
EVI-TRUST-S07
Policy evaluation
Meaning: The exact published policy version evaluates verified facts and explicit unknowns for the requested action.
EVI-TRUST-S08
Decision
Meaning: The system returns a bounded outcome with a privacy-preserving explanation.
EVI-TRUST-S09
Receipt
Meaning: A governed record preserves what policy, claims, evidence, status and limitations were used at decision time.
EVI-TRUST-S10
Correction and supersession
Meaning: Later revocation or correction annotates the historical receipt without silently rewriting what was known at the time.
Controlled outcomes
EVI-TRUST-O01
Trusted for requested purpose
Meaning: All required current claims, authority and evidence satisfy the exact policy.
EVI-TRUST-O02
Conditionally trusted
Meaning: The interaction is allowed only under explicit additional limits or monitoring stated in the decision.
EVI-TRUST-O03
Insufficient evidence
Meaning: Identity or authority may be plausible, but required current evidence is absent or unavailable.
EVI-TRUST-O04
Denied
Meaning: Verified facts do not satisfy the bounded policy or an explicit prohibition applies.
EVI-TRUST-O05
Stale evidence
Meaning: Required status or assurance is older than policy permits.
EVI-TRUST-O06
Policy unavailable
Meaning: The relying party cannot establish which authorized policy applies.
EVI-TRUST-O07
Cannot determine
Meaning: The verifier preserves uncertainty and abstains rather than inventing a conclusion.
Trust invariants
- A credential with a valid signature but an unauthorized issuer cannot satisfy the claim.
- A delegate cannot exercise more authority than the principal delegated.
- A superseded credential cannot create new trust.
- Expired or invalidated assurance cannot be treated as current without explicit lawful policy and disclosure.
- A trust receipt identifies the exact policy and evidence state used at decision time.
- Later revocation annotates history but does not falsify a receipt that was valid when made.
- A receipt does not expose unrelated credentials, private memory or a complete interaction graph.
- Patefacere and Evulgare do not become sole owners of all trust evidence.
Machine-readable records
Authority and record status
Responsible authority: Patefacere constitutional interface.
The framework defines public semantics only. It does not represent a live policy engine, federation or trust transaction.
Revision date: . Public corrections may be initiated through the diplomatic contact route.