Measured and anchored every day.
Each day the instrument takes its own picture and writes it into the public log: the counts it stands on, the head of a living pool of test items nobody is shown, and a sealed commitment to its own state. A day is written that day or never — the base refuses any other — so what you see here could not have been added afterwards, and nobody can catch up with it in a few days.
| Day | Snapshot digest | Line | Anchor | Pool | Human verdicts | Protocols | Marks standing |
|---|---|---|---|---|---|---|---|
| 2026-10-11 | 09b89d30cd0e… | 79 | pending root of 2026-10-11 | 0 · e3b0c44298fc… | 0 | 0 · 0 closed | 0 |
| 2026-10-10 | 7d8d87e7cc5c… | 51 | pending root of 2026-10-11 | 0 · e3b0c44298fc… | 0 | 0 · 0 closed | 0 |
Our own proof runs are counted in no figure here. Each day's instrument state is committed by its digest in the line, and not shown.
What a day holds
- 1
The counts
Human verdicts received, by where they came from; items judged; protocols registered and closed; marks standing and withdrawn; the specifications and signing keys in force, by their digest. Counts only — never a formula, never anything a person said.
- 2
The living pool
Test items that grow and are never shown. Each is committed by a salted digest; the commitments are the leaves of a tree whose head — size and root — is a line of its own. An item is a reference to a human verdict of someone who chose to be asked, never their words; if they leave, its salt goes and it can never be opened again, while every past head stays true.
- 3
The instrument, sealed
The state the measurement ran on that day is committed by its digest alone, its salt kept sealed. Revealed later, it recomputes to that digest or it does not: the instrument of a past day can never be redescribed.
- 4
The anchor
Both lines sit in the public log, chained to every line before them and carried by the day's root on OpenTimestamps. The base refuses a snapshot on any day but its own, refuses to change one once written, and refuses a pool head that is not the root of its leaves.
Verifying it without us
Each day has two lines in the public log, written that day and never after: a `pool` line (the living pool's head) and an `evolution` line whose payload is the day's snapshot. 1 · The snapshot digest: SHA-256 of the `evolution` payload as canonical JSON (keys sorted at every depth, compact). It must equal the line's digest and the digest printed for the day. The payload carries the public part in clear and only the digest of the private part. 2 · Its place: recompute the chain from that line to the daily root that covers it, and check the root's OpenTimestamps proof with the public `ots` client. 3 · The pool head: the payload names the day's `pool` line; its root is the RFC 9162 root (SHA-256) of the first `size` leaves, each leaf a salted commitment to an item never shown; each day's head extends the one before — the consistency proofs are served with the timeline. 4 · The private part is a commitment made like a pool item: SHA-256 of the 32-byte salt, then the instrument's state as canonical JSON, the moment it was taken and its class, each as UTF-8 preceded by its length on four bytes big-endian. When it is revealed, salt and state recompute this digest exactly; until then it says nothing, and the instrument of that day can never be redescribed. A day missing from the timeline was not measured: the base refuses a snapshot written on any other day than its own.
The timeline, with each day's line, its anchor and the consistency proofs, is at /api/lumen/v1/evolution. The whole log, and its daily roots, are on the public log.