ميزانMIZAN
VTR-1 · governance · §6 era law

The rules that bind
the standard's own author.

A verification standard is only worth what its worst-case operator cannot do. The engine that issues credentials evolves; governance exists so that no issuer, including this one, can retroactively change what a past credential means. These are not policies that can be revised at convenience — they are §6 of the specification, and an implementation that breaks them is non-conforming by definition.

Era law — the four rules

1
A credential names its judge.It commits the image hash of the engine era that produced it. The credential does not say "verified by MIZAN"; it says which exact program judged it, and the verifier checks that hash against its own copy.
2
Eras are superseded, never revoked.A changed engine is a new era with a new hash. Old credentials verify against their own era permanently — including ones issued before a flaw was known. Nothing is withdrawn from the record.
3
A changed judge is a new judge.Any change reaching the compiled proving program is, by definition, a new era. There is no such thing as a small patch to a live judge.
4
Weakness is disclosed, not rewritten.A soundness gap in a frozen era is published as status, with the credential remaining checkable. The reader, not the issuer, decides what it is worth. An implementation that quietly patches a soundness break has revoked a credential without saying so, which §6 forbids.

Versioning of the specification

The specification is versioned under the discipline it defines. The current normative version is 1.1, frozen 1 August 2026. Future versions supersede but never invalidate credentials issued under prior versions. Requirement identifiers R-01 to R-41 are permanent: a retired requirement keeps its number and is marked retired, so a citation never silently changes meaning. Version history and resolved findings: the errata register →

Reporting a soundness break

A conforming implementation MUST publish a route by which a suspected soundness break can be reported, and MUST disclose a confirmed break as era status. For this specification and its reference implementation that route is [email protected]. A report will be acknowledged, and a confirmed break published, whether or not the finder wishes to be named, and whether or not the finding flatters the standard. The affected era is marked, not rewritten.

What this governance does not yet have

An independent body. Today the standard is stewarded by its author. Era law constrains what the steward can do to past credentials, and the open licence means anyone may implement without permission — but there is no external party with a vote. That is a real limitation and it is stated here rather than implied away. A VTR Standards Council of five seats — an allocator, an implementer, a cryptographer, a verification professional, and one open seat — is designed and unfilled. No seat has been offered or accepted, and no external party has endorsed this standard. When that changes, this page changes, and the errata register records when.
What the open licence already removes. VTR-1 is published under CC BY 4.0. Anyone may implement it, forever, with attribution — including competitors of its steward, and including anyone who believes the steward is governing it badly. A standard nobody can fork is a product; the fork right is the check that exists today while the council does not.
MIZAN · governance of VTR-1 · §6 era law · the standard · errata register · implementers & conformance · verify anything offline
Research and verification artifacts. Not investment advice; no offer or solicitation.
Prove the edge. Never reveal the strategy.