VTR-1 · Governance · Era Law

The rules that bind the standard's own author.

A verification standard is only worth what its worst-case operator cannot do. The engine that issues credentials evolves; governance exists so that no issuer, including this one, can retroactively change what a past credential means. These are not policies to be revised at convenience — they are part of the specification, and an implementation that breaks them is non-conforming by definition.

§ 01Era law — the four rules

Four rules, none of them optional.

RULE 1
A credential names its judge.
It commits the image hash of the engine era that produced it. The credential does not say "verified by MIZAN"; it says which exact program judged it, and the verifier checks that hash against its own copy.
RULE 2
Eras are superseded, never revoked.
A changed engine is a new era with a new hash. Old credentials verify against their own era permanently — including ones issued before a flaw was known. Nothing is withdrawn from the record.
RULE 3
A changed judge is a new judge.
Any change reaching the compiled proving program is, by definition, a new era. There is no such thing as a small patch to a live judge.
RULE 4
Weakness is disclosed, not rewritten.
A soundness gap in a frozen era is published as status, with the credential remaining checkable. The reader, not the issuer, decides what it is worth. An implementation that quietly patches a soundness break has revoked a credential without saying so — which era law forbids.
§ 02Versioning of the specification

Frozen text changes by erratum, or not at all.

The specification is versioned under the discipline it defines. The current normative version is v1.1, frozen 2026-08-01. Future versions supersede but never invalidate credentials issued under prior versions. The 41 requirement identifiers (R-01 … R-41) are permanent: a retired requirement keeps its number and is marked retired, so a citation never silently changes meaning. Version history and resolved findings live in one place — the merged errata register.

Reporting a soundness break

A conforming implementation MUST publish a route by which a suspected soundness break can be reported, and MUST disclose a confirmed break as era status. For this specification and its reference implementation that route is [email protected]. A report will be acknowledged, and a confirmed break published, whether or not the finder wishes to be named, and whether or not the finding flatters the standard. The affected era is marked, not rewritten.

§ 03What this governance does not yet have

The council: designed, unfilled.

Today the standard is stewarded by its author. Era law constrains what the steward can do to past credentials, and the open licence means anyone may implement without permission — but there is no external party with a vote. That is a real limitation, and it is stated here rather than implied away. A VTR Standards Council of five seats is designed and unfilled:

An allocator
Seat open
An implementer
Seat open
A cryptographer
Seat open
A verification professional
Seat open
One open seat
Seat open
Stated plainly

No seat has been offered or accepted, and no external party has endorsed this standard. When that changes, this page changes — and the errata register records when.

§ 04The fork right

The check that exists while the council does not.

VTR-1 is published under CC BY 4.0. Anyone may implement it, forever, with attribution — including competitors of its steward, and including anyone who believes the steward is governing it badly. The fork right is not a courtesy; it is the enforcement mechanism of last resort, and it is already in force.

A standard nobody can fork is a product.

ENGINE v11 · 3ac3b10b… ● LIVE REGISTRY 77 CREDENTIALS · APPEND-ONLY VERIFY ~81 MS · OFFLINE · TRUSTING NO ONE ANCHOR BITCOIN #962,013 SPEC VTR-1 · FROZEN · CC BY ROOT 88298a2e…c6825a · MERKLE-COMMITTED