Custodia · Trust and verification
Different kinds of trust must not be confused.
A seal can express institutional approval. It cannot substitute for metadata integrity, a checksum, a cryptographic signature, or an identity record.
Six distinct layers
- Visual seal
- An institutional mark. It is decorative and declarative, not cryptographic proof.
- Institutional approval
- A recorded decision that Triluna accepts responsibility for a stated publication status.
- Archive metadata
- Identifier, version, date, lifecycle, visibility, canonical status, source project, and supersession context.
- Checksum integrity
- A digest that can detect whether a specific public file has changed. No checksum is currently issued.
- Cryptographic signature
- Proof made with a managed private key and verifiable public key. Triluna has no signing ceremony or key policy yet.
- Identity reference
- A Ronova ID reference to the responsible person or action where private workflows later require it.
Present method
Metadata first, signing later.
Stable archive fields and canonical URLs are the present basis of verification. Cryptographic signing will be added only after key generation, custody, rotation, revocation, recovery, and verification procedures are documented and practicable.
Archive identifiers
The general form is FT-YYYY-NNN. Optional branch-aware forms remain reserved. An identifier locates a record; it does not prove that the record is public, canonical, approved, or cryptographically signed.
Public verification boundary
No example record currently qualifies for public Library output. Private, semi-public, keyed, and example-only records remain outside the public build rather than relying on an unlinked URL for protection.