Public information
The record: capabilities and limits
Product reference. Read the supported work alongside its review requirements and limits.
Last updated September 22, 2026.
Capabilities
What leaves carries its proof
A format published so it can be re-implemented
ShippedA filing's manifest carries, per citation, the source's content hash, the verbatim language relied on, character offsets, and a named check's verdict. The published spec is enough to rebuild that verifier in any language, and has it recompute the coverage counts rather than read them.
Silence is not a pass
The verdict ladder runs in order, and the third rung carries the weight: an authority whose text was never opened records as advisory, never promoted. A quotation too short to be distinctive is not checkable, not passing. Source hashes cover bytes, quote checks text.
One shape for every machine decision
ShippedOne structure carries every machine decision once written in ten vocabularies: a citation verdict, a deadline derivation, an evidence-ledger entry, an intake field, a valuation input. Each names its check, a re-derivable result, and an unresolved verdict. One lane gates, one counts, one records.
A last gate that shows its working
Flag-gated· PROVENANCE_EGRESS_ATTESTATIONSeven clearance sub-gates already run before a document leaves, each throwing or staying quiet, so nothing shows an attorney what was decided on the way to cleared. The eighth composes what the seven computed and surfaces what nothing checked either way. It ships switched off.
Anyone can check it, with no account
A verifier that runs with the network off
ShippedMIT-licensed, carrying no dependencies, so anyone re-derives every verdict from a local file offline. The browser copy is generated from the module that built the manifest and held by a drift test. A live page tampers with a real bundle, reporting four verdict bands.
A digest lookup that answers a stranger
ShippedPaste a SHA-256 and get a verdict, the proof tier behind it in plain words, and the sentence that a receipt cannot show what was left out. No account, and no matter, party, title or filename. The proof file itself comes back from that address.
A link that opens a brief, never the matter behind it
A reader with no account opens the brief on a signed expiring link, the whole credential: no edit, no relink, no export, no matter behind it. Each click is decided anew, a source barred from leaving loses filename and passage, and opening is not checking.
A later revision cannot reach a link already sent
The token names the payload id, the brief's version at mint and a hash of the bytes served. Those bytes are written once, never rewritten, and a payload that will not hash to the token refuses. The firm learns a shared brief moved on.
Four ledgers, and what each one claims
Two kinds of evidence, never one tick
ShippedThe activity log, supervision attestations and prediction ledger are sequence-numbered hash chains, where omission and re-ordering are detectable. The eval runs are a digest over the whole set, catching a later edit but carrying no ordering evidence: strictly weaker, labelled as its own kind.
Three checks, each blind to what the others see
Three checks, each blind to the others: the database recomputes every row hash, a structural walk catches deletion and re-ordering, and the anchor fixes the tip in time. Only the anchor sees a truncation, so shortfall counts against the high-water receipt, matured or not.
Removals disclosed inside the chain
ShippedTwo ledgers were cut short on 2026-07-27, in a hand-run purge of a deep-test matter. Nothing was ever removed is false about them from now on, so the disclosure is a row in the firm's own anchored chain, and cover is counted per sequence number.
Committed before the outcome was known
A prediction timestamped when it was made
ShippedEvery prediction is committed to the anchored chain at the moment it is authored, so whether it preceded the outcome is a comparison between two timestamps the firm did not author. That is the property a scoreboard assembled afterwards cannot borrow.
A scoreboard written to refuse more readily than it reports
Flag-gated· PUBLIC_CALIBRATIONFour states, and three decline to show a number: not switched on, a chain whose verdict could not be established, a sample under the floor of ten resolved matters, and published. Figures come from chained rows only. It ships switched off, with nothing to publish.
Your file, on your way out
An export that is a migration, not a download
Backend onlyOne request streams every document's bytes, the interchange tables, the per-matter hash-chained audit trail, a SHA-256 manifest, and an OpenTimestamps proof over it, under Model Rule 1.16(d). The manifest names the three members it cannot cover, records omissions, and says pending rather than confirmed.
Your own AI, reading the record
Every read carries where it came from and how far it was checked
ShippedAn answer arrives with the provenance row ids behind it, a verification status, and the timestamp of the data rather than of the response, so a graph rebuilt in March reports March. Unknown is a first-class answer, and the roll-up takes its weakest member.
Four write tools, and not one of them acts
ShippedOnly one of the four tools proposes an action, filing it into the approval inbox the attorney's confirm cards land in, at the lowest rung of the trust ladder, executing nothing. An override flag is stripped and named, a matter caps at twenty-five undecided proposals.
Reach fixed at the key, never asked for in the request
ShippedA model cannot be trusted to set its own privilege flag, so the class sits on the key: a client-safe key forces the privilege-gated view whatever the request asks, minting an attorney-class key is firm-admin gated, and a key's matters only narrow its owner's reach.
Limits
- A digest is evidence about one artifact at one time. It is not evidence about what else the firm holds, and no surface here says otherwise.
- An anchor is an OpenTimestamps proof, and what it proves is a time of existence. There is no token in this product and no funds move.
- Attestation on every egress path ships switched off behind a named flag, and runs no queries while it is off.
- The public calibration scoreboard ships switched off behind a named flag and has nothing to publish: no prediction has been scored against a resolved outcome.
- The firm export runs on the backend today. No screen drives it yet, so a firm asks for it rather than clicking it.
- The per-key rate limit is counted inside one worker process, so a client spread across several can observe a higher ceiling than the refusal states.
- MCP sampling and the approval doorway keep their session state in one process. A restart loses that accelerant, never the durable approval row.
What BRON refuses
Say the record is whole.
A digest proves that one artifact existed at one time. It cannot prove that nothing was withheld, and the public route says so in the answer rather than in a footnote. Anchor a hundred documents, show a reader one, and the receipt still checks out.
Answer a ledger tip through the public door.
The four chain tips sit in the same table as the artifact receipts, and a distinguishing reply would turn the endpoint into an oracle: a caller could confirm a guessed tip and learn the ledger's state while holding nothing. A tip and a hash nobody has ever seen get the same answer.
Serve a proof file for a row the lookup will not acknowledge.
The proof endpoint re-derives the artifact kind rather than reading the stored proof straight out, because unknown answering 404 and a real ledger tip answering 200 would rebuild that same oracle out of the bytes.
Substitute a newer version into a link already sent.
The shared reader once re-read the brief live, so revising it changed what an unchanged URL served. No branch falls back to live content now. A link minted before pinning, a pinned payload that cannot be retrieved, and bytes disagreeing with the hash inside the token are three separate refusals, and not one of them shows a replacement.
Render a ledger short of rows as healthy.
A ledger missing rows it had already committed to is its own state, and it never renders the green of one that lost nothing. A disclosed removal is still a removal; what the disclosure changes is whether the shortfall is unexplained, and any part of it no disclosure names keeps the ledger broken.
Let yesterday's disclosure cover tomorrow's deletion.
A disclosure accounts only for evidence published before the removal it describes. A receipt published after it that no longer reproduces is a new break, and the ledger goes red again. A receipt that cannot be dated is never accounted for, because unknowable reads as unexplained rather than as fine.
Mark a filing that declares its own defect as a failed manifest.
The verdict answers whether the MANIFEST tells the truth, not whether the filing is good. A citation the manifest itself reports as misquoting its source, confirmed against that source, is the format working. Grading it as a failure would make omitting your defects the route to a clean report.
Call a grounded fact a verified one.
Grounded is a custody claim: this sentence came from that document, at that page. Verified means an independent pass checked the item against its cited source. Nothing in the read path promotes one to the other, and a verification lane that could not be read degrades the attestation to unknown rather than the read.
Hand a model a confirmation token.
The gate treats whoever holds a confirm nonce as the attorney, which is the property the whole stack is built to deny to a credential. The proposal seam mints nothing a caller could replay; the token is minted inside the gate, when a person taps approve and the stack is re-driven from the immutable row.
Publish a number over a ledger nobody can vouch for.
If the chain verdict cannot be established, or comes back bad, the scoreboard returns unverified and nothing else. A figure resting on a ledger nobody can check spends the credibility the ledger was built to earn.
Re-implement the hashing in the browser to look independent.
JavaScript and Postgres disagree about number precision and key collation, so an app-side twin of the row hash would raise tampering alarms on untouched ledgers. The recompute stays with the function that wrote the rows, and the independent half is a structural walk that needs no knowledge of the format at all.
Opposing counsel does not take my word for it. What can I hand them that does not require trusting me?
Give a recipient the files and citation evidence needed to check an export offline. Independent verification can establish what matches. Disclosed removals remain visible; a matching export does not establish that nothing was withheld.
Inputs
- Every draft, decision, prediction and posting
- The citation gate's verdicts
- The four hash-chained ledgers and their anchors
- Disclosed removals
Outputs
- Opposing counsel
- A court, a clerk or a carrier's auditor
- The client, when the file leaves
- The firm's own AI