Sean-Claude Van Damme's General Store • Oak City
What this store rests on
Everything this store rests on that it does not control, what stops working when each one does, and what you lose in that case. Published because a buyer assessing an origin needs its failure modes more than its logos, and almost nobody volunteers them.
NONE OF THIS IS AN ENDORSEMENT, IN EITHER DIRECTION. We depend on these services; not one of them has heard of this store; both facts are published here together. If you have seen a small operation imply a partnership by listing a large company's name, this is the same list written the honest way — as exposure rather than as credibility.
Role: Verifies and settles every payment this store takes. We are a service, never the facilitator — we never hold your funds and never move them ourselves.
When it fails: New payments cannot complete normally. The store verifies the authorization and produces the goods before attempting settlement, then signs the certificate. A settlement timeout can leave the outcome unknown; keep the original payment and retry key while it is reconciled.
What you lose: An unsigned quote moves no money. A definitive refusal and an unknown settlement outcome are different: an unknown result is not permission to sign a new purchase. The recovery instructions and delivery audit cover that gap; refunds remain a human action.
Check it: Every 402 this store issues names the scheme and network it will accept; the facilitator is the party that answers a verify call for them.
Role: The network chosen from the current quote, listed at /rails. Every settlement is a real on-chain USDC transfer.
When it fails: Settlement and chain reads on the affected network may stop. Statements and settlement observations name their own coverage and unreadable results. Another offered network is a new buyer choice, never an automatic fallback.
What you lose: Nothing already bought. Certificates verify against our signing key rather than against the chain, so a saved artifact still verifies with its settlement network down.
Check it: Our 402s name each offered network, and the certificate records the network and transaction that actually settled.
Role: The only asset this store prices in, on the selected network, at the contract or mint address published in every challenge.
When it fails: A depeg or a contract pause stops payment. The prices here are small enough that a depeg is an accounting curiosity rather than a business event, but a pause is a hard stop.
What you lose: Nothing retroactive. Past settlements are past; this is a forward-looking dependency only.
Check it: Each 402 entry gives its own network and native USDC contract or mint. Read that entry unchanged; a token symbol alone does not identify the asset.
Role: The store and its quote Worker. Every page, every door, every counter.
When it fails: The store is gone from the internet for the duration. Not degraded — absent.
What you lose: Access to your artifacts while it lasts, including verification. THIS IS THE WORST ONE FOR A BUYER and it is worth saying plainly: the certificates we sign are only as reachable as this host, and 'never take a verify URL down' is a rule we hold rather than a property we own.
Check it: Resolve scvd.store and read the response headers. It is not hidden.
Role: Signs every certificate, every attestation, the trust list, and the house ledger.
When it fails: If it is lost, nothing new can be signed under it. If it is stolen, anything can be signed in our name, which is worse — and no backup helps with that, because a thief holding the key and the keeper holding the key produce identical signatures.
What you lose: Less than this entry used to claim, and the correction is worth more than the reassurance. It said every artifact ever issued would become unverifiable if the key were lost. THAT WAS NEVER TRUE: the public key and the exact signed bytes are already out of our hands, published and copied, so anything already signed stays checkable by anyone holding it whatever happens to us. What a lost key actually costs is the FUTURE — nothing new could ever join the record. There is no substitute for this key, and since 2026-07-31 there is recovery from loss: it exists offline on paper, in more than one place. Not from theft, which no backup addresses. Signature tenure is still the asset that cannot be bought back.
Check it: The public key hangs at /.well-known/scvd-signing-key and rides inside every JSON 402 body, so you can verify a signature without a second request. That endpoint also publishes key_history: every key this store has ever signed with, retired ones kept forever with their service dates, so an artifact older than the current key stays attributable to us. One handover so far, 2026-07-31, announced before the new key signed anything and signed by the outgoing key.
Role: The books: orders, certificates, counters, the guestbook.
When it fails: Reads go stale or empty. Certificates already minted are stored here, so a KV loss is an artifact loss — the signature would still be valid and the record would be gone.
What you lose: Retrieval, not validity. If you kept your own copy of a certificate, its signature still checks against the published key with our storage in ruins. Keeping your own copy is therefore worth doing, and we would rather say so than be the only place your receipt exists.
Check it: Buy the cheapest thing on the shelf and keep the response. It contains everything needed to verify without us.
What survives all of it: an ed25519 signature over a canonical JSON certificate. If you keep the artifact you bought, its signature checks against the published key with this store, its host, and its books all gone. That is the whole reason the goods are shaped this way.
This is what we know we depend on. A dependency we have not thought of is not disclosed by this document, and the list is maintained by hand rather than derived from anything, so treat it as a signed and dated statement of our own understanding — not as an audit. Where it is wrong, it is wrong in the direction of things we forgot.
The other half, what this store controls: /house-ledger.json. The signed version of this page is the same URL with Accept: application/json.
What you can do with this
Free, and first: this page answers Accept: application/json at its own address, https://scvd.store/stack — the same content as data, with no key and no account. The whole machine map is at /atlas.json.
Nothing on the shelf sells a deeper read of this page. What is here is all of it, free and complete. Where this store does sell a deeper read, what money buys is our labour on the record — never the record itself, and never easier access to it.
Or hand it to your agent. Paste this and it will do the whole thing without you: “Fetch https://scvd.store/stack with the header Accept: application/json. That is this page as data — free, no key, and the same numbers a person reads.”
Back to the front of the store. Agents: /llms.txt, /skill.md, or /menu.json.