ReleaseProof
A proof-carrying release lifecycle for document-driven autonomous work. Human review survives only when the same logical finding still reproduces from equivalent source-grounded evidence under the rules frozen when that authority was granted.
Public CI: Python 3.11-3.13.
PASS
Processor OCR/flatten canonicalization, Data Extraction grounding, canonical page isolation, page SHA-256 and explicit coordinate-space provenance all executed against hosted Nutrient services.
PASS
A byte-different non-material revision preserved the targeted authority. A material Shipment ID revision invalidated that authority and returned the packet to REVIEW_REQUIRED.
HTTP 400
The current Processor account rejected /sign. An isolated retry with a Processor-normalized synthetic PDF reproduced HTTP 400, so signing is kept separate from the accepted core invention path.
Differential Reverification
Hosted v2 evidence now exercises the same mechanism against canonical Processor renditions and Data Extraction grounding. The current packet always receives a new manifest.
DWS-native v2 boundary
Processor owns canonical OCR/flatten/page operations. Data Extraction owns source grounding. ReleaseProof owns cross-document reconciliation, frozen human authority and differential invalidation. The hosted core path is accepted. Viewer review execution remains UNRUN. Processor /sign remains a separately documented HTTP 400 limitation.
The human decision carries its own rules of continued validity
evidence-equivalence/1, its bbox tolerance, value-normalization version and bbox metric. Differential Reverification evaluates that review under its historical policy, so runtime defaults cannot silently reinterpret it.Controlled CI proves that a review granted at tolerance 2.0 is still invalidated after a 4px evidence move even if a later runtime passes tolerance 10.0. Unknown policy versions fail closed to review. This is an auditability and deterministic replay mechanism, not a regulatory certification claim.
Hosted proof chain
Historical Processor proof: run 32215337912. Current DWS-native v2 core proof: run 33296171708, with 5 Processor canonicalizations, 5 Data Extraction calls, 5 canonical page isolations and both differential-reverification assertions reached before the optional signing gate. Isolated signing diagnostic: run 33296422243, Processor normalization PASS and signing HTTP 400. Live calls are disabled on this public surface.
Evidence ledger
Choose a proof path above.