Skip to content
Trust Spine · /claims

Claims registry

Core PAI claims and ecosystem claims are separated. Core claims carry scope, maturity, immutable evidence, limitations, and promotion criteria under an active promotion freeze.

Download reviewer packet
Site status legend
  • LivePublicly operational right now.
  • SimulatedBrowser/demo execution only — not real enforcement.
  • DocumentedArchitecture or behavior is described, but not exposed as a live public runtime.
  • PlannedExplicit future work that is not yet exposed.
  • Sign-inAvailable only behind authenticated or protected flows.
  • LockedIntentionally restricted from public interaction.
Promotion freeze · active — core assurance claims cannot move upward while the receipt, verifier, witness, and clean-clone proof chain is being repaired. Corrections, demotions, and added limitations remain allowed.
Core thesis · PAI claims

These claims decompose Governance Before Execution and its proof surfaces into bounded, falsifiable records. Status and implementation maturity are independent dimensions.

PAI-001Documentedmaturity · Specified

On the scoped Project-AI execution path, governance reaches a terminal decision before an effect is dispatched.

The claim is limited to effect paths that are explicitly integrated with the Project-AI governance boundary; it does not cover privileged host actions or callers that bypass that boundary.

TRYRun the gate orderExercise the documented pre-effect sequence in the guided simulation.
Subject
IAmSoThirsty/Project-AI@9fc3c93e6abd02a14bd141fab4d3ef772fa090bf
Public surfaces
/
Limitations
  • The pinned documentation does not itself prove that every effect-producing call site is integrated with the gate.
Promotion criteria
  • open · A fresh-clone harness enumerates the scoped effect paths and proves that none dispatch before a terminal governance decision.
PAI-002Unverifiedmaturity · Specified

The named nine-gate Project-AI path is non-bypassable for every effect within its declared scope.

Only the nine named gates and effect paths registered in a future executable coverage manifest are in scope.

CHALLENGEAttempt a bypassUse the standing capability-gate challenge; complete path coverage remains unverified.
Subject
IAmSoThirsty/Project-AI@9fc3c93e6abd02a14bd141fab4d3ef772fa090bf
Public surfaces
/defense
Evidence
Limitations
  • No pinned call-site inventory or bypass test demonstrates complete nine-gate coverage at this revision.
Promotion criteria
  • open · Publish a machine-readable gate and effect-path inventory with deterministic bypass tests for every registered path.
PAI-003Unverifiedmaturity · Planned

Project-AI interposes policy enforcement at the operating-system syscall boundary.

The claim is limited to a pinned, executable Linux interposition implementation and excludes architectural descriptions or user-space simulations.

OPEN DEBTNo syscall proof yetInspect the missing executable interposition evidence and promotion criterion.
Subject
IAmSoThirsty/Project-AI@9fc3c93e6abd02a14bd141fab4d3ef772fa090bf
Public surfaces
/defense
Evidence
Limitations
  • No pinned eBPF, LSM, seccomp, or hypervisor implementation and runtime trace is linked by this registry.
Promotion criteria
  • open · A clean environment loads the interposition mechanism and a test proves that denied syscalls do not reach the protected effect.
PAI-004Unverifiedmaturity · Specified

The OctoReflex containment path is strictly faster than the cognition path it constrains.

The bound must name the measured reflex and cognition paths, hardware, workload, percentile, sample count, and confidence interval.

CHALLENGETest the latency claimReview the containment-speed challenge; measured cross-path proof remains open.
Subject
IAmSoThirsty/Project-AI@9fc3c93e6abd02a14bd141fab4d3ef772fa090bf
Public surfaces
/doctrine
Evidence
Limitations
  • The registry has no pinned benchmark artifact establishing a quantified latency bound.
Promotion criteria
  • open · Publish a reproducible benchmark and raw results proving the scoped latency inequality under declared conditions.
PAI-005Unverifiedmaturity · Planned

A versioned Project-AI receipt bundle specifies the exact signed bytes and hash inputs required for interoperable verification.

The claim covers receipt serialization, hash input, signature input, key identifier, previous-hash semantics, and bundle versioning.

OPEN DEBTExercise the current receipt contractRun the current browser-local checks; interoperable clean-clone proof remains open debt.
Subject
IAmSoThirsty/creative-blossom-tool-6976969a@381057ba00af4ac5b7ac4eab474947e46357eb6f91fff498247e21b5ef88edcf
Evidence
Limitations
  • The receipt-v1 implementation and local fixtures are checksum-bound, but no fresh-clone CI artifact or deployed receipt has yet been accepted as promotion evidence.
  • The contract proves receipt integrity only; it does not establish RFC 3161 time, ledger membership, or the semantic correctness of a recorded decision.
Promotion criteria
  • open · Publish the receipt schema, canonical serialization, exact signed bytes, and valid and tampered test vectors.
PAI-006Unverifiedmaturity · Implemented

Receipt signer identity and the public trust-root surface derive key identifier, algorithm, public key bytes, and fingerprint from one registry.

The claim covers the declared key identifier, Ed25519 algorithm, complete SPKI and raw public key bytes, and SPKI SHA-256 fingerprint; it excludes undeclared validity, rotation, and revocation state.

VERIFYInspect the trust rootCompare the declared key id, SPKI fingerprint, algorithm, and public bytes.
Subject
IAmSoThirsty/creative-blossom-tool-6976969a@486587a4e3c031979838ad4d41bba8ff93e65a0bfc6f12e7227aa3c492df653e
Public surfaces
/keys
Evidence
Limitations
  • The signer now rejects a configured private key whose public half differs from the registry, but the deployed secret-to-public-key pairing has not been probed.
  • No validity window, revocation feed, verified rotation history, or external trust-anchor ceremony is declared.
Promotion criteria
  • open · Signer and public key pages derive from one registry and a fixture proves key-id, fingerprint, and signature resolution.
PAI-007Unverifiedmaturity · Implemented

The public browser verifier locally validates receipt-v1 schema, hashes, Ed25519 signatures, signer identity, timestamp syntax, and supplied previous-hash continuity.

Verification is deterministic for a supplied strict receipt-v1 bundle and optional expected previous hash; successful JSON parsing alone is not treated as verification.

VERIFYRun the local verifierExecute the exact bounded checks in-browser against a supplied receipt bundle.
Subject
IAmSoThirsty/creative-blossom-tool-6976969a@9fdbd3169d7d5cba07e583b7a3ab85162a2075790f5b7e13cd803e73d144e2da
Evidence
Limitations
  • The verifier establishes receipt integrity for supplied bytes; it does not establish ledger membership, timestamp freshness, or the semantic correctness of a decision.
  • No production-browser probe or immutable clean-clone execution artifact has yet been accepted as promotion evidence.
Promotion criteria
  • open · Valid, tampered, unknown-key, expired-key, malformed-timestamp, and broken-chain fixtures pass with fail-closed results.
PAI-008Documentedmaturity · Specified

A receipt bundle can deterministically reproduce the original governance verdict from pinned inputs and policy.

Replay requires a versioned receipt bundle, exact policy and input artifacts, a pinned runtime, and a declared comparison of reproduced output.

OPEN DEBTInspect replay requirementsOpen the documentary replay packs; end-to-end deterministic replay remains unverified.
Subject
IAmSoThirsty/creative-blossom-tool-6976969a@2fc328c4d3bcf214c47f9521c432bb227c8468ab
Public surfaces
/reproduce
Evidence
Limitations
  • The current evidence is a replay guide, not an executed deterministic replay artifact.
Promotion criteria
  • open · A fresh-clone replay command reproduces fixture verdicts byte-for-byte and emits a signed comparison report.
PAI-009Unverifiedmaturity · Implemented

An unauthenticated Witness surface returns a privacy-redacted newest-first receipt-v1 suffix whose disclosed receipt-hash signatures can be checked locally and whose disclosed chain order and link equality can be inspected structurally.

The server validates each full receipt core before redaction. The public response is limited to contract version, sequence, receipt hash, previous hash, signature, and key identifier; sequence gaps are valid, and publication stops at the first invalid or legacy row, duplicate or non-descending chain_seq, or broken prev_hash link.

VERIFYInspect the witness suffixFetch the public redacted suffix and run its disclosed receipt checks locally.
Subject
IAmSoThirsty/creative-blossom-tool-6976969a@d070f2ba06e47f252e189389350764427134b17daf49c4179c69ad9b3358dd38
Public surfaces
/witness
Evidence
Limitations
  • The browser verifies the signature over the disclosed receipt_hash, but redaction prevents it from recomputing the full signed core hash; disclosed contract_version, chain_seq, and prev_hash are therefore not independently cryptographically bound for the browser.
  • Client continuity checks are structural only: unique, strictly descending chain_seq values and disclosed prev_hash equality, not consecutive numbers. Sequence gaps are valid and may reflect bounded or redacted publication; the suffix does not prove ledger membership, timestamp freshness or authority, deployed-key pairing, or continuity before the oldest disclosed row.
  • Live database migration state and the existence of a publishable receipt-v1 suffix have not yet been established in the production backend.
Promotion criteria
  • open · An unauthenticated browser and HTTP test can retrieve a redacted Witness fixture, verify each disclosed receipt_hash signature, and fail closed on malformed order or disclosed link equality without exposing private fields.
PAI-010Partialmaturity · Implemented

The TSCG-B codec packs and unpacks its bounded frame format with deterministic integrity checks.

The claim covers only the committed TSCG-B pack and unpack implementation and its pinned codec and property tests; it does not imply compiler, signing, or Code Store integration.

TRYRun the bounded codecExercise the TSCG surface and inspect deterministic input and output behavior.
Subject
IAmSoThirsty/Project-AI@9fc3c93e6abd02a14bd141fab4d3ef772fa090bf
Public surfaces
/defense
Evidence
Limitations
  • The canonical codec source and two test modules are pinned on current public master, but this portal gate has not recorded a fresh-clone execution artifact and makes no compiler, signing, or Code Store claim.
Promotion criteria
  • open · Run the pinned codec and property tests from a fresh clone and publish the command, environment, result, and artifact digest.
PAI-011Unverifiedmaturity · Planned

The canonical policy compiler emits TSCG-B as an integrated production output.

The claim requires a pinned compiler entry point, emitted artifact, conformance test, and declared mapping from source policy to TSCG-B bytes.

OPEN DEBTCompiler integration not provedUse the playground for the current surface; canonical compiler output remains planned.
Subject
IAmSoThirsty/Project-AI@9fc3c93e6abd02a14bd141fab4d3ef772fa090bf
Public surfaces
/defense
Evidence
Limitations
  • The pinned evidence identifies a loader and frame, not a canonical policy compiler emitting TSCG-B.
Promotion criteria
  • open · A pinned compiler command emits a TSCG-B fixture and a conformance test proves its decoded policy matches the source policy.
PAI-012Unverifiedmaturity · Planned

TSCG-B policy artifacts are signed under a published, versioned signing contract.

The claim covers signature algorithm, exact signed bytes, key identifier, public key record, verification command, and tampered-artifact behavior.

OPEN DEBTSigning contract not publishedInspect the open criterion for versioned signed TSCG-B policy artifacts.
Subject
IAmSoThirsty/Project-AI@9fc3c93e6abd02a14bd141fab4d3ef772fa090bf
Public surfaces
/defense
Evidence
Limitations
  • No pinned source, key record, or test vector currently proves TSCG-B artifact signing.
Promotion criteria
  • open · Publish valid and tampered signed TSCG-B fixtures and demonstrate offline verification against the canonical key registry.
PAI-013Unverifiedmaturity · Planned

The execution runtime loads and enforces signed TSCG-B policy from the Constitutional Code Store.

The claim requires a pinned load path, signature and hash validation before activation, fail-closed rejection tests, and an execution trace tied to the loaded policy digest.

OPEN DEBTRuntime enforcement not provedInspect the open criterion for loading and enforcing signed policy artifacts.
Subject
IAmSoThirsty/Project-AI@9fc3c93e6abd02a14bd141fab4d3ef772fa090bf
Public surfaces
/defense
Evidence
Limitations
  • A TSCG-B loader exists for the bounded SWR specification, but signed Constitutional Code Store activation on the execution path is not proven.
Promotion criteria
  • open · A fresh-clone test loads a valid signed policy and rejects unsigned, tampered, unknown-key, and stale policy artifacts before any effect runs.
Ecosystem claims · EC records

Existing repository and ecosystem observations remain separately tracked for backward compatibility.

IdClaimStatusEvidenceSourcePinnedReplayLimitations
EC-001Thirsty-Lang 0.9.0 is published on PyPI and declared in the pinned Python release metadata.Verifiedpackage_metadataIAmSoThirsty/Thirsty-lang · pyproject.tomlb09bbfc3dda4/thirsty-lang/proofPyPI publication was checked separately on 2026-09-09. Alpha maturity; package publication is not independent runtime acceptance or a matching container release.
EC-006Thirsty-Lang 0.9.0 documents dotted/nested context normalization and retains the 0.8.6 context repairs. The historical critical Competence Register findings remain pending independent acceptance.Partialstatus_registerIAmSoThirsty/Thirsty-lang · docs/STATUS.mdb09bbfc3dda4/thirsty-lang/securityThe pinned status register keeps its critical FAIL entries and positive-authority restrictions until independent acceptance. Portal tests do not clear them.
EC-007Thirsty Skill Library documents 79 specialist skills sharing one constitutional baseline, built and validated by CI on every push.DocumenteddocumentationIAmSoThirsty/Thirstys-Skills · README.md68281a5809cd/systems/skill-libraryPer-skill maturity ranges from UNASSESSED to STABLE; the aggregate skill count is a documented claim, not independently recounted by this portal.
EC-002TAAR first swarm is report-only and explicitly rejects repository mutation actions.DocumenteddocumentationIAmSoThirsty/TAAR · README.md7b51966317f6/systems/taarThe website did not independently execute TAAR workflows in this update.
EC-003Cerberus currently describes four guardian types and pre-alpha package maturity.Verifieddocumentation+metadataIAmSoThirsty/Cerberus · README.md + pyproject.toml4d3400c3e2de/systems/cerberusCoverage and test counts are documented from repository text and not re-run by this portal.
EC-004Thirstys Waterfall production readiness remains partial and acceptance-gated under Standard v3.Verifiedacceptance_matrixIAmSoThirsty/Thirstys-waterfall · docs/operations/README_CLAIM_ACCEPTANCE.md2fb49e673fc9/systems/waterfallAcceptance matrix itself identifies unresolved external target deployment evidence.
EC-005The /verify route performs bounded browser-local receipt-v1 cryptographic checks on a supplied bundle, while /reproduce remains a documentary replay guide.Documentedchecksum_bound_local_artifactIAmSoThirsty/creative-blossom-tool-6976969a · content/assurance/evidence/PAI-007.manifest.json9fdbd3169d7d/verifyThe browser verifies a user-supplied receipt's internal cryptographic consistency; it does not prove ledger membership, timestamp freshness or authority, deployed-key pairing, or decision correctness.
EC-008DICPS documents a zero-knowledge attribute-verification architecture (identity registry, ZK circuit engine, proof generator/verifier, revocation registry).DocumenteddocumentationIAmSoThirsty/Digital-Identity-Capability-Proof-Service · README.md586915be5cf0/systems/dicpsFormal security proofs and threat-model documents are the maintainer's own write-up; this portal did not independently re-verify the cryptographic claims.
EC-009Civic Attest explicitly scopes its guarantees to origin authenticity and integrity, and explicitly disclaims truthfulness, intent, and coercion detection.DocumenteddocumentationIAmSoThirsty/civic-attest · README.md23db241029e1/systems/civic-attestCryptographic implementation was not independently audited by this portal.
EC-010Codex-workflow package version 1.0.0 is published and referenced in canonical pyproject metadata, exposing a codex-guardian console script.Verifiedpackage_metadataIAmSoThirsty/Codex-workflow · pyproject.toml372b920ec1b5/systems/codex-workflowGitHub Marketplace listing version may diverge from the pyproject-declared package version.
EC-011TS4-IIMP-001's normative standard reached version 1.1.0 on 2026-08-04, followed same-day by a 1.1.0-repository.1 packaging release that added real JSON Schema validation and a live conformance CI badge.VerifiedchangelogIAmSoThirsty/TS4-IIMP-001 · CHANGELOG.md6d21721a1d82/systems/ts4-iimpThis portal did not independently execute the conformance suite; the CI badge reflects the repository's own workflow run.
EC-012Mental Health Escalation Router's own status badge marks it 'Development', not production, despite marketing language elsewhere in the README describing it as production-grade.PartialdocumentationIAmSoThirsty/Mental-Health-Escalation-Router · README.mdea6cbab0d656/systems/mental-health-routerThis portal did not independently test detection accuracy, latency bounds, or the claimed 400+ test suite.
EC-013Thirstys-Projects-Miniature-Office's canonical README no longer badges the project Production Ready. Status is 'experimental prototype — not production-ready.' Independent in-repo audit at code pin fdd9762 scores 9 hold / 6 partial / 1 inflated / 3 false of 19. The February LIMITATIONS.md contradiction at 537c469 (32% vs 99%; codegen not operational vs a PRODUCTION READY badge) was repaired in-tree.Verifiedstatus_registerIAmSoThirsty/Thirstys-Projects-Miniature-Office · CLAIMS_AUDIT.mdfdd9762af2be/systems/miniature-officeThis portal verified README, LIMITATIONS.md, and CLAIMS_AUDIT.md text at code pin fdd9762 (src/tests trees identical through later docs-only HEAD 268058c). It did not re-run the 1,573 pytest suite in this update. Remaining product gaps — identity codegen, toy floors, optional HMAC, no WebXR, unhardened Docker — stay Partial in the in-repo ledger. Production-ready remains false.
EC-014Project-AI integrates TAAR as a report-only agent runner with hash-sealed evidence and an append-only audit spine; the first swarm cannot merge, push, or mutate inspected repositories.Verifiedlocal_integration+documentationIAmSoThirsty/Project-AI · packages/taar/README.md + packages/taar/registry/cb7f804ce4e8/systems/taarThe pinned source proves the integrated package and its declared boundaries; this portal does not execute the local TAAR runner in the browser.
EC-015Project-AI carries the standalone Thirstys Skills library as a tracked skills tree whose 79 catalog entries were checked one-to-one against vendored skill directories.Verifiedlocal_integration+catalog_integrityIAmSoThirsty/Project-AI · skills/CONTINUITY.md + skills/CATALOG.jsoncb7f804ce4e8/systems/skill-libraryThe source records catalog and directory integrity; this portal does not independently run the PowerShell validation and packaging pipeline.
EC-016Project-AI's security architecture combines standard-library-backed HMAC-SHA256, hashing, structured parsing, and bounded filesystem/process operations with dedicated security packages and test surfaces.Verifiedsecurity_architecture+stdlibIAmSoThirsty/Project-AI · docs/security.md + packages/security/ + tools/cb7f804ce4e8/securityThe source and implementation paths are pinned and inspectable; the portal has not run the complete Project-AI security suite as part of this page build.
Start verifying here