Draft 4 is open for reviewEvaluate with your platform team

Trust & conformance

A stranger surface can
verify your app offline.

Authenticity, scope, expiry, and accreditation resolve from one signed public file. No phone-home permission server. No discretionary trust.

OFFLINE REFRACTION FIELDSIGNED ENVELOPEissuer · scope · expiryCACHED TRUST LISTpublic root · local copyPROTECTEDreceiver-boundROOTFRESHISSUERSCOPESIGNATURESIGNED RECEIPT
A local lens checks root, freshness, issuer, scope, and signature before verifying the envelope offline.
VerificationOfflinesigned Trust List
Contract6 / 4MUST / MUST-NEVER
Key cadence≤180dautomatic expiry
Current production0published honestly

The conformance contract

Six obligations. Four red lines.

Every clause is observable, testable, and recorded as evidence—not interpreted as a value statement.

You MUST6 obligations
01
Validate every signature

Reject unsigned, expired, or unverifiable envelopes.

02
Seal to the receiver

Only the destination surface can open the payload.

03
Write an immutable receipt

Every accepted signal leaves reproducible evidence.

04
Publish live status

Keys, accreditation, and revocation stay inspectable.

05
Rotate keys ≤ 180 days

Stale trust fails closed on a fixed cadence.

06
Maintain independent assurance

Accredited tiers keep current audit evidence.

You MUST-NEVER4 red lines
01
Decrypt in transit

The carrier remains structurally blind.

02
Retain past delivery

Delivered transport copies are removed.

03
Cross-correlate families

Households cannot become an identity graph.

04
Re-identify minors

Receipts never attach a real child identity.

Two paths

Start today. Earn broader trust later.

The software stays the same. Only the independently verified scope of trust changes.

Path A · self-attested

Implementer

Publish a signed self-attestation with evidence. Exchange signals inside the implementer trust band immediately.

  • Free
  • Same-day
  • Evidence published
Open the implementation kit →

Live trust state

A mark is only as real as the registry entry behind it.

If the signed lookup fails, the claim fails with it.

OCSS TRUST LIST / DRAFTroot signature · valid
EntityTierKey stateScope
did:ocss:stewardSteward● validgovernance
Production entries0 listedpre-ratification

Conformance evaluation

Point the contract at a real endpoint.

Use the open harness to see how your current implementation behaves against the OCSS trust model.