Trust model

Security claims stop where evidence stops.

Enforced by SPACLY

  • Candidate release ref is read from a verified same-origin manifest.
  • Every candidate route response body is SHA-256 matched to that manifest.
  • Candidate paths are same-deployment relative paths.
  • Ordinary assessments are immutable; decisive READY/BLOCKED outcomes cannot be resampled.
  • Challenge evidence is independently fetched before consuming a bounded route challenge slot.
  • Owners cannot challenge their own READY candidate.
  • Authorization binds a deterministic evidence root.

Not claimed

  • A release ref is not proven to be a Git commit unless the deployment pipeline itself publishes that relationship in the manifest.
  • Semantic model explanations are not necessarily identical across validators; only consequential status/provenance fields are consensus-bound.
  • Personalized/A-B content, provider correlation and transient web behavior remain residual risks.
  • Live Studionet performance/finality/fees are not claimed before funded-wallet proof.

Accepted is not finalized. Finalized is not execution success until the receipt says so and finalized contract state is re-read.