Executable synthetic proof bundle
Replay one synthetic treasury operating contract.
Macrovision’s v4 public fixture starts with 4 disclosed, accepted evidence-source preimages, assembles and content-addresses the exact normalised FIELD input, replays 1,000 deterministic coverage draws, and evaluates them against a fixture-signed Decision Contract. The resulting coverage and policy receipts are bound into the fixture-signed Decision Packet and its reopen condition. Every organisation, role, key and value is synthetic; FIELD remains shadow-uncalibrated, connector writes are simulated, and no customer or production authority is established.
Generated trace
The bundle traces accepted evidence into a signed policy result.
Source manifest → SOP Twin → candidate replay → accepted evidence preimages → FIELD input assembly → normalised FIELD input → coverage distribution → signed Decision Contract evaluation → Decision Packet → authorised reopen. A changed disclosed value breaks a content address, signature or binding.
| Sequence | Workflow step | Verifiable output | Authority boundary |
|---|---|---|---|
| 01 | Freeze the source manifest | Exact synthetic SOP and historical-case hashes | Sources are fixtures, not customer records |
| 02 | Build the SOP Twin | Source-cited declared and observed process | Candidate simulation confers no authority |
| 03 | Compile and replay the proposal | Plan, compiler receipt and matching virtual-clock trace | Eligibility still requires a separate customer ratification |
| 04 | Bind accepted evidence to FIELD | 4 source preimages, assembly receipt and exact normalised input | Synthetic evidence only; no customer records |
| 05 | Run FIELD and coverage | FIELD receipt, 1,000 coverage draws and coverage receipt | Shadow-uncalibrated method; no production authority |
| 06 | Evaluate the signed policy | Decision Contract domain hash, signature and policy receipt | Deterministic fixture key; no customer trust root |
| 07 | Simulate familiar-system routing | 4 outbox and reconciliation exchanges | No file, task, approval or archive provider is contacted |
| 08 | Seal and reopen the Case | Fixture-signed Decision Packet and coverage-flip baseline | No payment, trade, custody or asset operation |
Disclosed coverage and policy result
Read the exact values bound into the fixture-signed packet.
The generated kernels computed these fixture values. The public verifiers authenticate the disclosed inputs, outputs, pinned values, cross-asset bindings and fixture signatures; they do not rerun FIELD or independently recalculate the coverage arithmetic.
| Measure | Disclosed value | Contract or method boundary |
|---|---|---|
| Hard obligations | 9,000,000.00 | Due inside the 30-day decision horizon and at the binding date |
| Stressed available liquidity | 14,988,003.49 | FIELD target-survival output at the binding point |
| Stressed headroom | 5,988,003.49 | Available liquidity less hard obligations |
| Stressed coverage ratio | 1.665333721111 | Minimum Decision Contract ratio is 1 |
| Coverage probabilities | 0.001 breach; 0.999 survival | 1,000 deterministic draws; FIELD remains shadow_uncalibrated |
| Binding point | Day 8; 2026-08-11T00:00:00Z | Dominant dependency: bank-a |
| Signed policy thresholds | 1 minimum ratio; 0.05 maximum breach probability | Fixture-signed Decision Contract version 2 |
| Policy evaluation | within_policy; expected metric 1.665250937527869 | Valid fixture evaluation with 0.001 constraint-breach probability and no alerts |
| Reopen condition | obligation_coverage_flip | Armed baseline is the exact policy receipt hash |
Browser and offline verifier
Recompute the bundle and its receipt bindings.
The checker downloads 35 JSON assets, recomputes their JCS and domain-separated SHA-256 addresses, verifies all 4 evidence-source preimages and the exact normalised FIELD input, verifies the fixture-signed Decision Contract and Operating Contract authority acts, checks the coverage draws, policy result, receipts, packet and reopen baseline, and verifies the exact two Decision Packet signatures. The downloadable Node verifier performs the same 201-check contract offline. The manifest, verifier and keys are served together, so a pass proves reproducibility rather than independent assurance.
Not checked. Select “Verify v4 bundle” to recompute the public proof.
| Asset | Expected SHA-256 | Computed SHA-256 | Result |
|---|---|---|---|
| Bundle | Manifest not loaded | Not computed | Not checked |
Downloadable inputs and receipts
Inspect the exact files used by the executable proof.
The archive contains the manifest, offline verifier and every input and receipt. Individual files remain available for targeted review.
| Layer | Download | What it binds |
|---|---|---|
| Contract Studio | Candidate dossier | Source manifest, SOP Twin, conformance, compiler and replay |
| Proposal input | Candidate Operating Contract | Candidate authority, simulation mode, exact body digest and no financial execution |
| Fixture authority | Fixture-signed Operating Contract | Exact Operating Contract body plus fixture ratification and activation acts |
| Evidence to FIELD | Input assembly receipt | 4 accepted evidence-source preimages and their exact assembled FIELD input |
| Normalised input | Normalised FIELD input | Replayable value and SHA-256 address supplied to FIELD |
| FIELD | FIELD receipt | Shadow-uncalibrated method output and exact input/output addresses |
| Coverage draws | Coverage distribution | All 1,000 deterministic ratios, binding days and summary values |
| Coverage binding | Coverage receipt | FIELD, assembly, distribution and Case contract bindings |
| Signed policy | Fixture-signed Decision Contract | Minimum coverage, breach threshold, exact domain hash and fixture signature |
| Policy result | Decision Contract policy receipt | Domain-addressed evaluation, within_policy verdict and reopen ID |
| Replay | Candidate replay receipt | Exact plan, fixture and trace |
| Authority | Fixture authority receipts | Approval, reopen and trust-verification outputs |
| Connectors | Simulated exchanges | Outbox, idempotency and reconciliation identities |
| Decision Packet | Fixture-signed packet | Frozen Case version 1 evidence, analyses, decision and reopen conditions |
| Verifier | Offline verifier | Run node verify.mjs beside the extracted manifest and assets |
From fixture to institution
A customer engagement replaces synthetic evidence, roles and artefacts with the customer’s own governed inputs—then earns authority through replay, shadow operation and ratification.
This public case is a synthetic test fixture. FIELD remains shadow-uncalibrated, within_policy is a fixture-contract result, deterministic fixture keys establish no customer trust root, and all connector exchanges are simulated in memory. A verifier pass proves reproducibility, not independent assurance, customer authority or production fitness. The fixture is not investment advice, a customer decision, a production approval, financial performance evidence or permission for payment, trade, custody or asset transfer. V4 adds accepted evidence-source preimages, exact FIELD input assembly, coverage draws and a fixture-signed Decision Contract evaluation. The historical v3 manifest and v3 offline bundle, v2 manifest and v2 offline bundle, and legacy v1 digest fixture remain byte-immutable. V1 used an unsigned manifest served by the same site and did not execute the replay kernels.