Custodia · Trust and verification
Different kinds of trust must not be confused.
A seal can express institutional approval. It cannot substitute for metadata integrity, a checksum, a cryptographic signature, or an identity record.
Six distinct layers
- Visual seal
- An institutional mark. It is decorative and declarative, not cryptographic proof.
- Institutional approval
- A recorded decision that Triluna accepts responsibility for a stated publication status.
- Archive metadata
- Identifier, version, date, lifecycle, visibility, canonical status, source project, and supersession context.
- Checksum integrity
- A digest that can detect whether a specific public file has changed. No checksum is currently issued for an institutional Library record; testnet protocol hashes do not change that publication status.
- Cryptographic signature
- Proof made with a managed private key and verifiable public key. Triluna has no institutional signing ceremony or production key policy; the separate active chain testnet uses disposable simulated keys only.
- Identity reference
- A Renkan ID reference to the responsible person or action where private workflows later require it; the reference does not confer project privileges.
Present method
Metadata first; testnet cryptography remains non-authoritative.
Stable archive fields and canonical URLs remain the basis of institutional publication verification. The active, explicitly non-production triluna-testnet-2 laboratory tests canonical encoding, hashes, simulated signatures, and append-only proofs without making its test events institutional records or production authority. Institutional signing will be added only after key generation, custody, rotation, revocation, recovery, and verification procedures are documented and practicable.
Archive identifiers
The general form is FT-YYYY-NNN. Optional branch-aware forms remain reserved. An identifier locates a record; it does not prove that the record is public, canonical, approved, or cryptographically signed.
Public verification boundary
No example record currently qualifies for public Library output. Private, semi-public, keyed, and example-only records remain outside the public build rather than relying on an unlinked URL for protection. The testnet verifier checks public proof objects and pasted disclosure bundles locally in the browser; private disclosure content is not uploaded and no analytics are used.