Status. This edition presents the trust model for FORAY wire 4.2 and the batch-anchoring layer, derived from the accepted amendment lineage; where this page summarizes, the cited instrument governs. The earlier attestation-and-trust-model document remains served as the 4.1-era record. Sections are marked PROTOCOL INVARIANT (true of every conforming implementation) or DEPLOYMENT POLICY (parameters of the reference deployment or an engagement).
Protocol invariant
What FORAY proves
FORAY proves integrity: that submitted content has not changed since submission; that a record existed no later than its anchor's block time; continuity of registered streams; and annotated meaning under dispute. Every tier of the pipeline is mechanical.
It does not prove legitimacy, authorization, or truth of claims; completeness against reality; attestor competence; or the accuracy of claimed in-record timestamps beyond the anchor bound. In-record timestamps are submitter assertions, verified by no one. An anchor of a lie is the same lie, faithfully preserved, with proof that nobody edited it afterward. (Batch-anchoring amendment §13; anchor-assurance amendment §7.)
Protocol invariant
The claim ladder
Each rung states exactly what its artifact demonstrates — never more:
- A record hash proves the bytes are unchanged since hashing.
- An anchor proves those bytes existed no later than the anchor's block time, with the strength of the non-tampering guarantee graded by the substrate's assurance class.
- A validation PASS attests conformance to the ruled 4.2 shape — never truth of content.
- Residue (F25) is recorded and hashed — tamper-evident, not Root-validated. Compliance flags there are the author's recorded assertions, never verified compliance.
- A salted formula identifier (F18) proves definition retention — which formula was declared and that it is unaltered since. It does not prove the formula ran, or ran correctly. FORAY makes the originating system's declarations tamper-evident; it does not make them true. The controls for that boundary live outside the protocol — the field-map sheet, the conformance suite, and, where execution verification ever matters, attestation of the computing system.
- A salted identity (F3, party digests) proves nothing by itself: with the salt, the holder can demonstrate what they committed to; without it, nothing leaks from the record.
Protocol invariant — residual risks, stated in the open
Omission, delay, completeness
Three critiques recur from careful reviewers, and each has a specific, disclosed answer. These remain true after every shipped mitigation, and stating them here is deliberate (the residual-risk register is normative disclosure — batch-anchoring amendment §14, with the mechanisms of its §7).
Selective omission — "what about the record that was never anchored?" Inclusion never implies completeness. An unregistered anchor proves a record was included; it proves nothing about siblings that were not. The answer is registered streams: a consumer declares a stream and a continuity commitment; records carry monotonic sequence numbers and previous-hashes; segment ranges are anchored in every covering header. Within a registered stream, completeness becomes provable structure — an auditor's continuity walk returns CONTINUOUS, or names the missing sequence range (GAP), or exposes two records claiming one slot (FORK), with both anchor references cited. Forks are evidence, not options. Outside registered streams, omission is undetectable by design, and the protocol says so rather than implying otherwise.
Delay — "how late can a record be backdated?" Each lane registers a declared worst case (T_max) — contractual, and the number every analysis must use; typical latency is never quoted as a bound. In unregistered streams, backdating room is bounded only by T_max — disclosed, and irreducible without trusted time hardware. In registered streams two mechanisms shrink it: a record claiming a timestamp from a period whose covering anchors already closed must carry a late_recorded marker with a declared reason — permitted, never silent, and flagged in audit output (the accounting posture for late journal entries); and reference chronology is a tripwire — a record claiming Monday that references anything first anchored Wednesday betrays itself (INVALID-CHRONOLOGY). Invisible backdating room in a disciplined stream is thereby the current anchor interval, not T_max at large. The difference between the two postures is a reason to register streams, and evaluators should see both statements.
Completeness against reality — "does the audit trail show everything that happened?" Permanently out of scope, and stated as such. FORAY proves what was recorded is intact and when it existed; whether reality was recorded at all is a claims-versus-truth boundary no anchoring protocol can cross. The controls that address it are organizational: registered-stream commitments, engagement terms, and auditors doing what auditors do — now with continuity structure to walk.
One further register entry: submitter-key compromise has a bounded detection-and-dispute window, not elimination — revocations and disputes are themselves anchored, so a contested header verifies cryptographically but returns DISPUTED, its meaning annotated rather than erased.
Protocol invariant
Attestations — position reserved, layer unformalized
The wire reserves an optional attestations envelope position, and that is deliberately all it does today. The attestation layer — attestor identity, signatures, credentials, revocation — is not formalized in FORAY: identity attestation is the adjacent identity substrate's layer, and FORAY's attestation vocabulary stays exactly as thin as that substrate's shipped state. Attestations, where carried, record claims, not truth; their interior is not Root-validated. This gap is a recorded decision, not an oversight.
Deployment policy
Where trust parameters are set
The invariants above hold for every conforming implementation. What varies by deployment and engagement: the anchoring substrate and its assurance class (Kaspa is the first reference substrate, not constitutive); lane windows and each lane's declared T_max; whether a stream registers and its continuity commitment; custody arrangements for proof material (retention periods, dual-write independence, retention-attestation cadence) — a lost salt or body makes an anchor an unprovable commitment, and that risk is managed in custody terms, not in the wire; and the verification outcome vocabulary's service wrapper. The verifier's mandatory checks and outcome taxonomy (VALID / INVALID / DISPUTED / MATERIAL_UNAVAILABLE / PROVISIONAL / UNSUPPORTED / LEGACY) are protocol; which services run them for you is policy.
Records of this edition
Sources and authorities
Derived from: the batch-anchoring amendment (temporal semantics, registered streams, the residual-risk register, verification taxonomy), the anchor-assurance amendment (substrate assurance and what no anchor class claims), the F-Wire Migration Amendment (the 4.2 wire this model attaches to), and the 4.1-era attestation and trust-model record. Where this page and any instrument could be read to differ, the instrument governs.