{"standfirst":"What 'verified' means at this store, stated before anything carries a badge: what gets checked, against which published criteria, what a verdict says, what it never says, and what happens when the thing changes. House rule 43 forbids any badge from shipping before this page exists. It exists now — and this page existing is not a badge, an endorsement, or a product. Nothing carries a badge today.","dated":"2026-08-10","what_a_badge_is":"A badge here would be a dated observation on a THING — a skill, a service, an endpoint — never a score on an actor. It says exactly this: as of a stated date, this artifact passed these named checks against this published criteria version. It is observation-shaped, never warranty-shaped. 'Ready' means the checks passed at that moment; it does not mean good, safe, reliable, or endorsed, and the copy on any badge this store ever ships is bound to that register by the same rule that wrote this page.","what_retires_a_badge":"Nothing retires a badge. It ages. A badge is not a live status to revoke — it carries its own expiry by carrying its own date, and a reader weighs an old observation the way they weigh any old fact. If the thing changes, the badge does not change with it: a newer observation supersedes an older one by being newer, never by taking the old one down. Nobody is chased to remove anything, and nobody who relied on a dated observation is owed a retraction of it — the date was the disclosure. The question an aging badge cannot answer is 'is this still true', and this store sells the instrument that answers it: re-observation, on the record, at the same URL. A badge never answers it.","never_a_score_on_an_actor":"No accumulating score on any operator, ours or anybody's, ever — that is rule 43's other half and it binds this page too. Individual dated observations may be published because each one is a fact; a ratio over them is withheld on purpose. Ready-in-eight-of-twelve is one division away from the data and it is a score on an actor wearing an observation's clothes, which is why the per-host history says out loud that it will not compute one.","who_pays_and_what_it_buys":"The party being watched is the party paying, which is the rating agency's model and carries its one famous defect: the rated pays the rater, and the rater drifts favorable. So the terms say it before any sale rather than after a dispute — payment buys FREQUENCY AND PERMANENCE, never outcome. The watch publishes what it observes. An endpoint that degrades while its operator is paying gets signed readouts saying so, in public, at the URL the operator paid for, for as long as the watch runs. Nothing here is bought, and a favorable history is worth reading only because an unfavorable one would have been published in the same place.","criteria_battery":{"version":"preflight-v1","url":"https://scvd.store/api/preflight/v1","note":"The published check battery. A criteria-governed check runs those checks and no others; a new battery is a new version, and the version is named on every artifact it produces."},"verdict_vocabulary":[{"verdict":"ready","means":"Every check in the named criteria version passed at the stated moment. Not an endorsement and not a prediction."},{"verdict":"not_ready","means":"One or more checks failed, and the failing checks are named on the artifact rather than collapsed into the label."},{"verdict":"unreachable","means":"The thing did not answer. A fact about one network path at one moment — it does not prove the endpoint is down."},{"verdict":"not_probed","means":"We did not look, and the record says so instead of saying nothing. Gaps are counted against the instrument, on the same page as the findings."}],"artifact_classes":[{"id":"certificate","name":"Certificates of purchase","trust_model":"Self-signed (in-process)","signs":"The canonical JSON of the certificate's own fields, in a fixed declared order: cert_id, item, patron_number, date, name, tip_usdc, note, win, tag, attests, made_by, paid_usdc, asset, network, payer, settlement_tx, cross_ref — every one of those that is present. DERIVED FROM THE SIGNING CODE, NOT TYPED BESIDE IT: this sentence was hand-written and had fallen a day behind by 2026-07-31, omitting made_by and then the five payment fields, on the page whose entire job is stating exactly what bytes a signature covers. paid_usdc is the TOTAL settled rather than the tip, payer is the paying wallet (chain-verifiable, unlike a chosen name), and settlement_tx is the on-chain transaction. The exact string is served as signed_payload on the verify response, so nothing has to be reconstructed.","does_not_prove":"That the goods were delivered, that they were any good, or that the buyer was who they said. It proves this store issued this certificate, with these fields, on this date.","verify_url":"https://scvd.store/api/verify/{cert_id}"},{"id":"settlement_attestation","name":"Settlement attestations (single, or each member of a sheaf)","trust_model":"Third-party observation","signs":"The whole observation object: the transaction hash asked about, what the chain said, the block height, the chain head at the time of reading, the confirmation count, and the moment of observation. A sheaf (attestation_bundle) is this artifact at volume — every member signed alone over the same fields, quotable alone.","does_not_prove":"That goods or services were delivered, that a NOT_FOUND will never settle later, or that the payment was legitimate. One RPC read of public state, at one moment, signed by a party with no interest in the answer.","verify_url":"https://scvd.store/api/verify/{cert_id}"},{"id":"standing_watch_probe","name":"Standing watch rows (the Night Watch)","trust_model":"Third-party observation","signs":"Each hourly row on its own: the watch id, the watched URL, the moment, the verdict, the names of any failed checks, and the status and latency where present — in the declared canonical order, so any single row can be quoted alone.","does_not_prove":"Anything about hours we did not probe. The gaps are derived at read and counted against us in the same history; a row is one look from one vantage, never an uptime figure. Nor is it bought. The watched party pays — the rating agency's model, whose one defect is that the rater drifts favorable — so the terms say it at spec level: payment buys frequency and permanence, never outcome. An endpoint that degrades while its operator is paying gets signed readouts saying so, in public, at the URL the operator paid for. The clause rides every watch history as who_pays_and_what_it_buys.","verify_url":"https://scvd.store/api/watch/{watch_id}"},{"id":"conformance_watch_pass","name":"Conformance watch passes (the Conformance Watch)","trust_model":"Third-party observation","signs":"Each daily pass on its own: the watch id, the watched URL, the moment, the verdict, the names of failed checks and of advisories — in the declared canonical order, so any single day can be quoted alone.","does_not_prove":"Anything about the hours between passes, or about days nobody checked — those are derived at read and counted against us. One pass a day is conformance cadence, never uptime. Nor is it bought. The watched party pays — the rating agency's model, whose one defect is that the rater drifts favorable — so the terms say it at spec level: payment buys frequency and permanence, never outcome. An endpoint that degrades while its operator is paying gets signed readouts saying so, in public, at the URL the operator paid for. The clause rides every watch history as who_pays_and_what_it_buys.","verify_url":"https://scvd.store/api/conformance-watch/{watch_id}"},{"id":"service_audit","name":"Service audit reports (the Once-Over)","trust_model":"Third-party observation","signs":"The whole report: the audited URL, the moment, the criteria version, the verdict, every check and advisory, and the report's evidence hash. The purchase certificate binds the same evidence hash in its attests field.","does_not_prove":"That the endpoint is endorsed, reliable, or up at any other moment. One GET against published criteria; an unreachable verdict is a fact about one network path at one moment.","verify_url":"https://scvd.store/api/service-audit/{audit_id}"},{"id":"settlement_reconciliation","name":"Settlement reconciliations (amount taken against ceiling in force)","trust_model":"Third-party observation","signs":"The whole observation: the transaction asked about, the USDC movement found, the ceiling in force, WHERE THAT CEILING CAME FROM, whether it was observed or merely declared, the headroom between the two, the chain head at read time, and the moment. cap_observed is a signed field in its own right, because the difference between a ceiling we read off Base and a ceiling somebody told us is the entire weight of this artifact.","does_not_prove":"That a DECLARED ceiling is real. Where cap_observed is false the number came from whoever commissioned the receipt — generally the party it benefits — and the signature covers only that we were told it, never that it is true. It also cannot see a ceiling granted in an earlier transaction: 'no cap observed' means 'not in this receipt'. And an over_cap on a declared ceiling is a fact about what the caller said, not about the chain.","verify_url":"https://scvd.store/api/reconciliation/{reconciliation_id}"},{"id":"bitcoin_anchor","name":"Patron Bitcoin anchors","trust_model":"Custody and timestamp only","signs":"Nothing directly on the record. Two independent bindings do the work: the purchase certificate signs the buyer's digest via its attests field, and the OpenTimestamps proof commits the same digest into a Bitcoin transaction — the store's dated word and Bitcoin's clock, separately checkable.","does_not_prove":"What the digest is a digest OF. The label is the buyer's own claim, stored verbatim and never checked; the proof establishes the digest existed by a Bitcoin block, nothing about the bytes behind it.","verify_url":"https://scvd.store/api/bitcoin-anchor/{anchor_id}"},{"id":"corpus_snapshot","name":"Corpus snapshots (the ecosystem record)","trust_model":"Third-party observation","signs":"The canonical snapshot: version, sequence, the moment taken, the previous entry's digest, the source, the week, and the whole ward round it freezes — hash-linked to the entry before it and OTS-stamped into Bitcoin.","does_not_prove":"That the observed services behave the same at any other moment, or that the record is complete. The chain proves WE did not rewrite our own history; it cannot prove we saw everything.","verify_url":"https://scvd.store/corpus.json"},{"id":"phantom_check","name":"Phantom checks","trust_model":"Third-party observation","signs":"The check id, the target URL, and the observation: whether it answered, with what status, how fast, and when we looked.","does_not_prove":"That the URL is up now, was up before, or will be up later. It is one look, from outside your infrastructure, about six hours after you asked, and unreachable is a finding rather than an error.","verify_url":"https://scvd.store/api/verify/{check_id}"},{"id":"context_anchor","name":"Context anchors","trust_model":"Custody and timestamp only","signs":"The anchor id, patron number, date, the summary exactly as the buyer wrote it, and the agent name if one was given.","does_not_prove":"Anything at all about whether the summary is true. The buyer wrote it; we filed it and dated it. We never read it as instructions and never will.","verify_url":"https://scvd.store/api/verify/{anchor_id}"},{"id":"stamp","name":"Visit stamps and Countermarks","trust_model":"Self-signed (in-process)","signs":"The stamp id, variant, ISO week, date, and where present the bearer's chosen name, the punched card, the consecutive-week count and the week's store condition.","does_not_prove":"That the bearer is any particular party. A name on a stamp is a name somebody chose.","verify_url":"https://scvd.store/api/verify/{stamp_id}"},{"id":"lucky","name":"Luckies","trust_model":"Self-signed (in-process)","signs":"The whole lucky record, including its status and any keeper's note about a status change.","does_not_prove":"Luck.","verify_url":"https://scvd.store/api/verify/{lucky_id}"},{"id":"gazette_issue","name":"Gazette issues","trust_model":"Self-signed (in-process)","signs":"The issue's markdown, exactly as printed. The copy you hold is the copy that went to press.","does_not_prove":"That anything reported in it is correct — only that it has not been altered since printing.","verify_url":"https://scvd.store/api/verify/gazette_{n}"}],"badges_today":"None. Nothing this store serves carries a badge, and this page existing changes that only by removing the gate rule 43 put in front of it.","attestation":"https://scvd.store/attestation","becoming":"https://scvd.store/becoming","limit":"This page is the contract for badges that do not exist yet. When the first badge class ships, it ships against these terms: the criteria version named on the artifact, the failing checks named on a miss, the date on everything, the gaps counted against us, and no score on any actor. If a badge this store issued ever violates a line on this page, the mailbox is free and the violation goes on /corrections with your name on it."}