Trust
Seal · Identity · Policy
These are implemented as separate layers in code. Marketing that collapses them into one green badge is wrong.
Optional transparency layers
- Local SCITT — offline transparency service under
~/.epi/local-scitt. Free. Not a public independent log. - Remote SCITT — hosted registration; requires Hosted plan or higher on the portal.
- RFC 3161 / OpenTimestamps — best-effort token collection at seal time (needs network; can fail open; token presence only, signature/chain/imprint not validated).
- Human review ledger — signed, append-only reviews bound to the sealed artifact.
Honesty notes
- Hosted PDF API is not implemented (CLI Annex PDF is free).
- The seal proves integrity after sealing, not capture completeness. In-process
record()is self-attestation; the gateway proxy is the stronger observation path. - Annex IV and AIUC-1 outputs are evidence input for those processes — not a conformity certificate or a certification anyone issued.
- EU notification helpers generate local signed payloads — not a live EU database client.
- See KNOWN_LIMITATIONS.md.