---
title: "The Interveil Engine: Core Technology for Evidence That Holds Its Shape"
subtitle: "An epistemic engine, an enrichment layer, and instruments you choose"
author: "Dietrick Hardwick, Founder & Chief Technologist, Interveil Labs"
version: "1.0 — supersedes the Alpha white papers of 17–18 August 2026"
date: "2026-08-18"
status: "Public. Alpha in preparation."
notice: "External claims carry citations. Interveil synthesis is marked [PROPOSAL] or [INFERENCE]. Figures from the two Alpha encodings are reported separately and never blended."
---

# The Interveil Engine

## Core technology for evidence that holds its shape

### Abstract

Provenance standards have solved a real problem well: they can establish that a file has not been altered and that a named signer stood behind it. They say—often in their own normative text—nothing about whether the signed assertions are correct.

The failure now doing the damage sits above the bytes. It is the routine fusion of four distinguishable things: the event, the record of the event, the evidentiary weight of that record, and the meanings later assigned to it. Once fused, repetition is indistinguishable from corroboration, a missing origin is indistinguishable from concealment, and a superseded reading is indistinguishable from a current one. Language models did not introduce this failure. They compress its cycle from decades to milliseconds, because generated inference re-enters the corpus as apparent attestation.

The **Interveil Engine** is the core technology built for that failure. It is an epistemic engine: it holds records in a form that cannot silently collapse, computes what is actually supported and by how many independent roots, keeps loss and unknowns as structured entries rather than blank cells, versions meaning instead of overwriting it, and makes every rendered answer reversible to its evidence.

Two further layers sit above it. **Authentic Intelligence** is the enrichment and interface schema—how a person's own material is captured, governed, disclosed, and kept theirs. **Instruments** are the evidence-based presentation surfaces a person selects: a reader, an inspector, a forensic view, a studio, an API. The Engine does the work. The enrichment layer decides what meets the person. The instruments decide how it looks.

This paper consolidates and supersedes the separate Alpha white papers. It reports two independent Alpha encodings—one on a contested mid-century crash narrative, one on a contested 1990 photograph—built by different teams from the same doctrine. They agree on every principle and diverge on vocabulary in ways that are themselves the most useful result the project has produced.

## 1. The layer that was missing

### 1.1 Five things, never fused

The Engine's entire design follows from one rule:

> Asset provenance ≠ claim provenance ≠ evidentiary support ≠ semantic interpretation ≠ truth.

The first four are representable chains. The fifth is never computed. Every schema decision below traces back to keeping those five apart.

The collapse they guard against has a signature at the level of vocabulary. A witness may be entirely accurate about luminance, azimuth, motion, and duration—and catastrophically wrong at the level of the noun. *Craft* imports a builder. *Occupant* imports intent. *Landed* imports a destination. The noun is not an observation; it is a compressed theory applied at the moment of speech, and from that moment it is typographically indistinguishable from what was seen.

The same collapse runs through clinical case histories, procurement records, incident reports, archival finding aids, and family memory. The domain changes. The failure does not.

### 1.2 Three governing truths

**Reality exceeds representation.** Every descriptor is a projection and every projection is lossy. The loss is not a defect to engineer away; it is a structural property of describing anything. *Obligation:* loss is recorded as a quantity—what was discarded, at what confidence, under whose vocabulary, at what date.

**Lineage is not veracity.** Signature validity, hash agreement, and custody continuity are each establishable, and none bears on whether the originating assertion was correct. A perfectly preserved falsehood remains false. *Obligation:* integrity and epistemic weight occupy permanently separate fields, and no rule may map one onto the other.

**Meaning is contextual and revisable.** The same source supports a forensic reading, a historical reading, and a legal reading. Trouble begins when a reading conceals its frame and presents itself as the source. *Obligation:* interpretations are versioned, attributable, and superseded—never overwritten.

Condensed to an operating instruction: **preserve the thing, expose the chain, version the meaning.**

### 1.3 Why the loop closes faster now

An interpretation is published. It is indexed. The indexed interpretation is cited as corroboration. Corroboration is counted as weight. Weight is read as evidence. At no step did anything enter from the world.

Historiography has always insisted that multiple attestation counts only where independence holds, and that independence must itself be adjudicated rather than assumed. Text-reuse scholarship supplies the computational analogue: reprint-cluster methods developed for nineteenth-century newspaper corpora show that apparently independent publications frequently resolve to one upstream text. Intelligence practice encodes the same discipline differently—the Admiralty system grades source reliability and information credibility on separate axes, reserving its highest credibility grade for confirmation by genuinely independent sources. A wire story republished twice is one source.

Machine systems compress that loop to nothing. Work on attributed generation finds that even strong systems produce citations that do not support the sentences attached to them, and that *partially supportive*—evidence bearing on part of a claim but not the whole—is both the most common case and the hardest to classify.

Two failure shapes follow, and they need different countermeasures:

1. **Unsupported fluency.** The sentence is coherent; the cited source does not bear on it. Countermeasure: span-level entailment between generated text and source passages.
2. **Laundered repetition.** Every citation is real, every source says what is claimed—and all of them descend from one root. Countermeasure: dependency structure beneath the citation edges.

Entailment checking cannot detect the second, because nothing in it is false. The Engine exists for the second. **[INFERENCE]**

## 2. The stack

```text
INSTRUMENTS
Inspector · Reader · Forensic view · Studio · Evidence API
Selectable, swappable, none canonical

AUTHENTIC INTELLIGENCE
Capture · consent · disclosure · sovereignty · human-as-author
Provenance carried into the interface rather than stripped at it

INTERVEIL ENGINE
Record Plane: append-only typed epistemic graph
Lens Plane: declared, reversible rendering
Echo collapse · Loss Ledger · frontiers · assessment · receipts

STANDARDS SUBSTRATE
C2PA · W3C PROV-O · SCITT · Nanopublications · RO-Crate
```

The division of labour is worth stating plainly:

- The **Engine** keeps the *record* honest. It is indifferent to who is reading and why.
- **Authentic Intelligence** keeps the *relationship* honest. It governs what is taken from a person, what is disclosed back, and who remains the author.
- **Instruments** decide only *how it looks*. They are views. None is the record, and switching views changes nothing underneath.

A system can have excellent provenance and still extract from the person using it. A system can be scrupulous about consent and still launder repetition into evidence. These are different failures with different remedies, which is why they are different layers. **[PROPOSAL]**

## 3. The Engine

### 3.1 Two planes and a one-way membrane

**The Record Plane** is append-only and content-addressed. It holds referents, artifacts, observations, atomic claims, evidence relations, actors, instruments, contexts, transformations, loss events, provenance frontiers, independence clusters, and revisions. Nothing in it is mutated. Corrections arrive as new nodes bearing supersession edges.

**The Lens Plane** is a declared, reproducible rendering layer. It produces summaries, narratives, and views for particular audiences and purposes. Lenses read the record. They never write to it.

Interpretation is a view, not a schema. This is the load-bearing engineering claim: store pre-interpretive, render on request. The era's vocabulary, the discipline's assumptions, and the reader's purpose become query parameters rather than storage decisions. Every archive that baked its epoch's categories into its schema is now primarily a record of that epoch rather than of its subject. **[PROPOSAL]**

Between the planes runs a **one-way membrane**: observations may inform interpretations; interpretations may never be re-ingested as observations. This is enforced as a type-check on edge endpoints, not as a guideline. Policy erodes at exactly the moment the distinction becomes inconvenient. A constraint that holds only when nobody minds is not a constraint.

### 3.2 What the Engine refuses

| Forbidden collapse | Engine rule |
|---|---|
| Interpretation → Observation | Nothing downstream of an interpretation may serve as an observation |
| Signature → truth | A valid signature may raise source integrity and nothing else. A perfectly authenticated lie remains a lie. |
| Repetition → corroboration | Corroboration counts distinct independent roots, never citations |
| Missing provenance → deception | An unresolved origin is typed `unknown`, full stop |
| Overwrite → revision | Supersession is the only revision mechanism; predecessors stay legible |
| Consensus → evidence | A consensus record may not bear on its own referent-level claim |
| Partial → full | Partial support may never be aggregated or rendered as full support |
| Undeclared context → neutral context | Absent context surfaces as absent, not as no context |

One invariant governs the commercial temptation more than any other: **no truth score.** The schema defines no aggregate field. Any weighting applied in an interface is a declared lens, never schema.

### 3.3 Truth Objects

The Engine's unit is a **Truth Object**: a versioned evidence packet, named with the standing warning that it contains structured approaches to truth and not truth itself.

A Truth Object declares a bounded question with explicit inclusions and exclusions, then carries: a neutral referent identifier; artifacts with content hashes where bytes exist; observations held at the lowest available interpretive altitude; claims separated from observations; evidence as an evaluated *bearing* with method, scope, and limitations rather than as a synonym for artifact; competing hypotheses with their assumptions and discriminating predictions; interpretations bound to declared lenses; a Loss Ledger; provenance frontiers with logged resolution attempts; dimensioned assessment; and a complete revision genealogy.

### 3.4 Echo collapse

Corroboration strength is the count of **independent roots**, not of sources. Evidence and artifacts join an independence cluster whose shared root names the common upstream origin; members contribute one to any corroboration count.

The clustering method is itself recorded, and—critically—independence assessability admits the value **not assessable**. *We cannot judge whether these sources are independent* is a legal, first-class verdict. The alternative, which citation-counting systems routinely take, is to assume independence silently.

At scale this is a detection problem: near-duplicate detection over shingled text for lexical reuse, embedding similarity for paraphrase, feeding a human adjudication queue. Detection proposes; people adjudicate. That division does not change with scale.

### 3.5 The Loss Ledger and provenance frontiers

Ordinary provenance records what happened. The Loss Ledger records what ceased to be available, what was never captured, and what cannot be recovered.

A **loss event** carries its type—destroyed, redacted, suppressed, inaccessible, not captured, degraded—together with what it affects, who recorded it, when, and a recoverability note. A **provenance frontier** marks the last verified node in a lineage and carries its logged resolution attempts, each with method, date, and result.

A frontier is a null with a shape. A blank invites authorship and cannot record that it was authored; a structured unknown resists filling and states what was tried. It makes absence visible without converting absence into suspicion—and the Engine must be as disciplined about unfair doubt as about unfair belief.

### 3.6 Assessment, not score

Every claim-family node carries a multi-dimension assessment. Both Alpha encodings independently settled on **seven dimensions**: source integrity, chain completeness, claim-evidence fit, source independence, alternative coverage, context sensitivity, and unresolved loss. Each dimension is itself an attributed, timestamped mini-assertion with a written rationale and a calibrated value.

There is no aggregate, and the schema defines no field where one could live. A vector is harder to read than a number—that is the point. The number's readability comes entirely from discarding the information that would let a reader disagree with it.

Two mature practices independently reject scalar confidence. IPCC calibrated language holds *confidence*—a function of evidence and agreement—distinct from *likelihood* expressed as calibrated probability. ICD 203 separates analytic confidence from estimative language, requires source quality to be described, and requires assumptions to be distinguished from judgments. The Calvine encoding recommended renaming the field *assessment* in Beta so “confidence” does not import probability connotations it does not carry. That recommendation is adopted here.

### 3.7 Consensus as a derived record

A consensus record is invalid without five facets: **cohort** (who), **method** (how agreement was measured), **denominator** (out of how many), **independence** (assessed, including shared-root analysis), and **as-of date**.

Its referent is the *population's belief-state*, never the underlying event. Popularity may not flow backwards through the graph to inflate the quality of originating evidence. This permits a structurally important state: a claim may be `disputed` at the referent level while being the subject of a well-supported consensus at the population level, with no contradiction. Those are facts about different things.

A consensus record may also validly state that consensus **was not measured**. That is a finding, not a gap.

## 4. Two Alpha encodings

The strongest evidence the project has produced is not either packet. It is that two teams, working from the same doctrine on different material, arrived at nearly the same machine.

**Packet A—the Trinity encoding.** A contested mid-century crash narrative. 114 nodes; 40 claim-family assertions; 17 node types; 21 relations partitioned so no edge is both a derivation and an epistemic bearing; 9 invariants and 8 forbidden collapses; 3 independence clusters, one marked *not assessable*; 5 loss events; 2 provenance frontiers; seven assessment dimensions; a 12-question evaluation returning **9 pass · 3 partial · 0 fail** with 12 logged failure items. This is the packet running in the public working model.

**Packet B—the Calvine encoding.** A contested 1990 photograph with a surviving print, official parliamentary records, and conspicuous breaks in provenance. 87 nodes; 66 links; 12 atomic claims; 1 counterclaim; 9 observations; 6 evidence records; 3 hypotheses; 5 loss events; 3 frontiers; 7 assessments; 3 lenses; 2 summary revisions; 18 node types; 25 relations; 15 machine-checked invariants; 12 evaluation questions.

**Where they agree:** the two-plane separation; one-way membrane; evidence as an evaluated bearing rather than an artifact; independence as scoped rather than binary; loss split from recoverability; frontiers as first-class; seven assessment dimensions; supersede-not-erase; no truth score; consensus as a derived record; and refusal to identify the referent in either case.

**Where they diverge:** 17 versus 18 node types, 21 versus 25 relations, 8 versus 15 named invariants. Packet B adds an explicit `ConfidenceAssessment` node and a root `TruthObject` type where Packet A treats both as structure rather than nodes. Packet A adds `IndependenceCluster` as a node where Packet B carries dependency clustering on links.

Neither divergence is a contradiction. Both are the “which vocabulary generalizes” data the roadmap asks for, arriving earlier than expected. The unification rule going forward: **a concept earns a node type only where two independent packets both needed it as a node.** By that rule the merged core is roughly 17 types, with the remainder demoted to properties pending a third packet.

**What neither packet proves:** that the vocabulary generalizes beyond contested-testimony and contested-image cases; that users answer better with the Engine than with a conventional summary; that invariants hold under adversarial input; or that any of it scales. Packet B's automated validator is ahead: it machine-checks identifiers, endpoints, type and relation allowlists, symmetric independence, sentence receipts, assessment dimensions, consensus fields, preserved revisions, and evaluation coverage. Merging that validator into the Engine core is the first Beta task.

## 5. The standards substrate

The Engine consumes the provenance stack rather than competing with it. Terminology already defined by these standards is reused, not reinvented.

**C2PA / Content Credentials.** Reused: the manifest, assertion, claim and claim-signature structures; ingredient assertions; hard versus soft bindings; `c2pa.actions` edit history; and the editorial/non-editorial transformation distinction. Of particular value is the redaction pattern: content can be withheld, but the withholding cannot be hidden. Not expressed: whether a signed assertion is correct. C2PA's principles decline to judge whether provenance data is good or bad, only whether assertions validate as correctly formed, bound to the asset, and untampered. The Alpha memo cited C2PA v2.2 (May 2025); the current paper supersedes that reference with **v2.4 (April 2026)** while retaining the earlier citation in the revision record.

**W3C PROV-O.** Reused verbatim: `prov:Entity`, `prov:Activity`, `prov:Agent`, and derivation relations such as `wasDerivedFrom`, `wasQuotedFrom`, `hadPrimarySource`, `wasRevisionOf`, `wasAttributedTo`, `wasGeneratedBy`, `used`, and `specializationOf`. PROV describes how entities came to be and is silent on what bearing they have; that silence is the seam the Engine occupies.

**IETF SCITT (RFC 9943).** Reused: signed statements, receipts, transparency services, append-only verifiable data structures, and multiple issuers making conflicting statements about one subject. Registration establishes issuance by an identified issuer—not correctness.

**Nanopublications.** Reused: assertion, provenance, and publication-information separation; content-hash identifiers; one atomic claim per publication; supersede-not-mutate.

**RO-Crate.** Reused: JSON-LD packaging over schema.org, the data/contextual-entity distinction, and profiles for portable, citable evidence bundles.

**Micropublications and AIF.** Reused as prior art for typed claims, statements, data, methods, support, and challenge structure.

**NIST guidance.** IR 8387 supplies digital-evidence handling practice. AI 100-4 concludes that provenance may contribute to trustworthiness without guaranteeing it, and that no single technique is comprehensive—adopted as a design constraint rather than marketed away.

**schema.org ClaimReview** is supported as a deliberately lossy export only. Its single `reviewRating` is exactly the scalar collapse the Engine rejects.

### The gap finding

Three capabilities are absent across the substrate: **missingness and loss as first-class data**; **formal source independence**—near-duplicate detection finds lexical overlap, claim matching finds similarity, and neither establishes dependency direction; and **meaning-change history**, since versioned stores record that triples changed, not what the change means. Confidence is high on the structural facts and moderate on the negative claim of absence, which is a survey result rather than exhaustive proof.

## 6. Authentic Intelligence—the enrichment layer

The Engine is indifferent to who is reading. That indifference is correct for a record and wrong for a product. **Authentic Intelligence** is the layer where a system meets a person, and it carries its own obligations.

Its thesis: today's models are not minds from nowhere. They are predominantly human-sourced—pattern drawn from the record of human thought. The layer's job is to carry that provenance in the open, keep the human as the author, and disclose the substrate.

What it governs **[PROPOSAL]**:

- **Capture.** A person's reading, annotation, correction, voice, or attention enters only under explicit opt-in, attributed to the person as an Actor in the graph like any other.
- **Sovereignty.** Personal material stays home by default. The Engine can operate over a packet without the packet leaving the person's control; content addressing and local operation make that an architectural property.
- **Disclosure.** Every rendered answer carries what was selected, omitted, which lens governed, which model or tool participated, and whether a human reviewed it.
- **Authorship.** The human lends the meaning; the model lends the horsepower. AI proposals enter a review queue; a human accept or reject produces the signed revision. **No autonomous canonical writes.**
- **Restraint.** Prime, whisper, withdraw. Context arrives at the edge of the page when it helps and is gone when it does not.

The separation matters commercially as well as ethically. The Engine can be licensed, embedded, and audited as infrastructure. The enrichment layer is where product promises live—and where those promises most easily rot. Keeping them separate means a failure in one is diagnosable without indicting the other.

## 7. Instruments

An instrument is a selectable presentation surface over a packet. Instruments are views: none is canonical, and switching between them changes nothing in the Record Plane.

The Alpha working model ships five reference instruments:

1. **Summary**—sentences unfold into the atomic claims carrying them, each with a *why* chain running to traces, transformations, independent roots, counterlines, and retained unknowns.
2. **Claims and inspector**—every claim-family node, with supporting, partially supporting, and contradicting edges visible with their rationales.
3. **Source genealogy**—the transformation tree from the earliest retrievable root forward, with drift classes annotated on edges.
4. **Independence and echoes**—dependency clusters collapsed; corroboration counted by root.
5. **Loss ledger and frontiers**—what is missing, how that is known, and what was attempted.

The lens bar adds forensic, plain-language, and cultural renderings. Switching lenses visibly changes the reading while the graph beneath does not move, and nothing re-badges to `observed`.

The roadmap adds **Reader** for immersion-preserving context, **Studio** for reviewed authoring and adjudication, and the **Evidence API**, whose answer contract is the Engine's external face:

```json
{
  "answer": "bounded natural-language response",
  "packetRevision": "stable identifier",
  "claimIds": ["..."],
  "supportIds": ["..."],
  "dependencyClusters": ["..."],
  "assumptions": ["..."],
  "losses": ["..."],
  "frontiers": ["..."],
  "renderReceipt": {
    "model": "...",
    "lens": "...",
    "reviewedBy": "...",
    "generatedAt": "..."
  }
}
```

Two properties matter more than the field list. **Every answer must be reproducible from a named packet revision**—not from “the corpus,” which nobody can re-inspect. And **no source-count feature may ignore dependency clusters**; a system reporting “twelve sources agree” without collapsing echoes has reintroduced the failure it was built to prevent.

Conventional retrieval finds strings and embedding neighbours. It cannot distinguish a first-hand measurement from its thousandth retelling, because at the level of tokens they are the same sentence. Retrieval over a typed graph can. **Provenance grep** searches ancestry: return every assertion whose support terminates in a single unwitnessed testimony; show claims that gained citation weight without gaining sensory support; identify nodes where an interpretation entered as an observation; trace this noun to the first document that used it; list assertions that collapse if one named source is removed. The last query is the structural signature of credibility laundering, and it is invisible to keyword tools. **[PROPOSAL]**

## 8. Roadmap

The Engine should scale by proving its distinctions survive new domains, multiple reviewers, adversarial inputs, and production constraints—not by expanding the ontology in anticipation of cases it has not met.

**Gate A—merge and ratify.** Reconcile both encodings under the two-packet rule; port Packet B's automated validator into the Engine core; conduct expert review and a twelve-participant comparative usability study. *Go/no-go:* at least 90% trace accuracy across the six core questions; no critical forbidden-collapse failure; median completion time no more than 1.5 times a conventional summary.

**Gate B—cross-domain replication.** A third and fourth packet outside contested testimony and imagery—scientific replication and a bounded public record—with blind dual encoding. *Go/no-go:* at least 0.75 inter-annotator agreement on primary epistemic role before adjudication; fewer than five new primary concepts; no domain-specific term added to the core where a profile can hold it.

**Gate C—provenance hardening.** C2PA manifest import with validation-result display; W3C Web Annotation selectors for quoted spans and regions; content-addressed snapshots; RO-Crate conformance; SCITT-compatible receipts; redaction and withdrawal semantics preserving accountable tombstones. *Go/no-go:* round-trip without semantic loss; compromised, expired, absent, and valid signatures displayed distinctly; test users do not infer that signature validity equals claim truth above a pre-registered threshold.

**Gate D—assisted authoring.** Source-grounded extraction with exact selectors; proposal queue; model, prompt, and tool receipts; uncertainty-preserving summarization; omission and qualification diffs. *Go/no-go:* no autonomous canonical writes; at least 95% of accepted summary sentences carry complete claim traces.

**Gate E—query service.** Packet registry and immutable version store; provenance-aware query API; subgraph receipt per answer; dependency-aware retrieval; embeddable inspector components.

**Gate F—federation and governance.** An application profile and conformance suite; institutional signer and reviewer roles; protected disagreement and appeals; packet merging without silent conflict resolution. *Go/no-go:* two external organizations independently produce conforming packets; conflicting packets can coexist and be compared; red-team review covers manipulation, reputation laundering, citation cascades, prompt injection, and abusive dossiers.

**Metrics that matter:** claim-trace completeness; forbidden-collapse rate; dependency-detection precision and recall; reviewer agreement and adjudication time; frontier resolution rate; correction latency; user accuracy on the six core questions.

**Vanity metrics to avoid:** raw node count, graph density, pages ingested, unqualified consensus counts.

**Do not lead with truth certification.** The value proposition is inspectability, source independence, defensible revision, and answers that show their work.

## 9. Limitations and honest unknowns

**Source independence has no formal metric.** The Engine's central computational claim—corroboration counts independent roots—rests on a determination nobody currently knows how to make automatically. *Not assessable* is an honest interface to an unsolved problem, not a solution to it.

**Packet A's invariants hold partly by discipline.** They are not yet a complete lint suite runnable over an arbitrary Truth Object. Packet B is ahead here and its validator is the merge target.

**Encoding cost is high and unmeasured.** The 114-node and 87-node packets required substantial manual work. Whether assisted authoring reduces that work without degrading accuracy is a Gate D question with no current answer.

**Both packets share a genre.** Contested testimony and a contested photograph are closer to each other than either is to a clinical trial or procurement record. Their agreement is real but should not be over-read.

**Dimensioned assessment may not survive contact with users.** Seven attributed dimensions are more honest and more work than one number. If readers reliably collapse the vector into an impression anyway, Interveil will have relocated the collapse rather than prevented it. The usability study is designed to detect this, and the project is committed in advance to reporting it.

**Lens governance is unsolved.** Lenses are declared and versioned; nothing prevents a lens from being tendentious. Who governs lens rules and how disputes are adjudicated is a live governance question, not a technical one.

**The doctrine applies to Interveil.** A system that cannot run its own operations on its founding metaphors is not a forensic instrument; it is a brand. Every structural claim marked **[PROPOSAL]** or **[INFERENCE]** here is Interveil synthesis, not a finding derived from cited standards. This paper supersedes earlier Interveil white papers; those papers are not deleted, and where they were wrong—a version citation, a set of figures reported without its packet—the correction is recorded with its reason.

**No priority claim.** This is a prior-art-aware implementation of a specific synthesis. It does not claim that no earlier knowledge graph, evidence model, provenance platform, or uncertainty system contains related concepts, and it makes no determination of inventorship, patentability, or ownership. Those require counsel and a prior-art search.

## 10. Conclusion

An information system need not choose between false certainty and unusable ambiguity. It can preserve the object of inquiry, show every known transformation, distinguish evidence from repetition, make loss explicit, and let meaning change in public view.

The Engine is deliberately modest in what it claims and specific about what it refuses. It computes no verdicts. It is not a debunking instrument—missing provenance is typed `unknown`, full stop. It requires no blockchain; append-only history is a Git-shaped problem and content addressing is a hash. It is not a universal ontology; the type ceiling is a working constraint, not a claim about the world.

What it offers is narrower and more useful: **a record that does not lie to itself**, and answers that remain useful while showing exactly how far they reach.

## References

- C2PA, [Content Credentials: C2PA Technical Specification v2.4](https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html), April 2026; [Guiding Principles](https://c2pa.org/principles/).
- W3C, [PROV-O: The PROV Ontology](https://www.w3.org/TR/prov-o/).
- Birkholz et al., [An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT), RFC 9943](https://www.rfc-editor.org/rfc/rfc9943.html).
- [Nanopublication Guidelines](https://nanopub.net/guidelines/working_draft/).
- [RO-Crate Specification v1.3](https://www.researchobject.org/ro-crate/specification/1.3/).
- Clark, Ciccarese & Goble, [Micropublications](https://pmc.ncbi.nlm.nih.gov/articles/PMC4530550/), 2014.
- NIST, [Digital Evidence Preservation, IR 8387](https://doi.org/10.6028/NIST.IR.8387).
- NIST, [Reducing Risks Posed by Synthetic Content, AI 100-4](https://doi.org/10.6028/NIST.AI.100-4).
- IPCC, [Guidance Note for Lead Authors on Consistent Treatment of Uncertainties](https://archive.ipcc.ch/pdf/supporting-material/uncertainty-guidance-note.pdf).
- Office of the Director of National Intelligence, [Intelligence Community Directive 203: Analytic Standards](https://archive.dni.gov/files/documents/ICD/ICD-203.pdf).
- UK Ministry of Defence, [Joint Doctrine Publication 2-00: Intelligence, Counter-intelligence and Security Support to Joint Operations, 4th ed.](https://assets.publishing.service.gov.uk/media/653a4b0780884d0013f71bb0/JDP_2_00_Ed_4_web.pdf), §§3.39–3.40.
- [Viral Texts](http://viraltexts.github.io/) reprint-cluster project.
- Rashkin et al., [Measuring Attribution in Natural Language Generation Models](https://openreview.net/pdf?id=VQ2aOIolZh).
- W3C, [Web Annotation Data Model](https://www.w3.org/TR/annotation-model/); [JSON-LD 1.1](https://www.w3.org/TR/json-ld11/).

---

*The Interveil Engine v1.0. This paper supersedes the Alpha white papers of 17–18 August 2026; superseded versions remain retrievable. Drafted in collaboration with AI tools, then reviewed and stood behind by D. Hardwick. Contested claims are flagged in the text. The record speaks.*

*Preserve the thing. Expose the chain. Version the meaning.*
