Know what has been verified.
Build on explicit trust boundaries instead of treating signatures, commitments, attestations, and proofs as interchangeable.
Match the claim to its evidence
A signature establishes authorization under a key. A digest establishes a commitment to bytes. Inclusion ties a record to a block. TEE verification adds hardware/workload-specific claims. Each has its own prerequisites and limits.
| Item | Details |
|---|---|
| Artifact commitment | Integrity and attribution; not automatic correctness, availability, or privacy. |
| Lumen receipt | Narrow sampled-commitment verification; not a proof of full model execution. |
| TEE attestation | Vendor, measurement, trust material, and policy must all be verified. |
| Zero knowledge | A roadmap boundary: current signed hash commitments are not a shipped Jolt verifier. |
A client should fail clearly
Verify chain identity before signing, preserve integer precision, bind nonces and authorization to the intended operation, and distinguish unsupported state from zero state. Never put a private signing key in a public web example or an RPC read form.
Audit claims need an audit record
Source availability and local tests are useful evidence, but they are different from an independent security audit or verification of a deployed revision. Use dated findings with explicit scope.