Developers
Two verifiers, written separately, check the same bundle offline.
JSON Schemas define the canonical objects. The verifiers, one in Python and one in TypeScript, check a bundle against its registry entry and the trust registry with no network access. Both run over a shared conformance corpus and are compared on structure, integrity and the schema contract.
Rules
What every implementation must get right.
A registry entry carries no evidence content. Hashes and identifiers are its only link to the bundle.
A verification report lists the levels it checked. A report that stops at L2 has not failed L3; that check was not requested.
Without a pinned trust root, a verifier reports REVIEW at best, never PASS.
Repositories
One repository per component.
Each carries a release label; the implementation status page lists them. None is on a package registry yet, and there is no hosted API yet.
Before integrating
An integration would rest on closed schemas and offline checks.
Engineering
Share the first workflow you would integrate.
Tell us which policy it applies and what evidence it needs, and name any optional registry-entry fields it would use.
