GRUNDNORM · WHAT IS REAL AND WHAT IS SCAFFOLDING
The limits, written down before you find them.
In a verification product the limits are the argument, not the small print. Everything below can be checked by running the published SDK, except one item that is marked as taken on our word, because you could not verify it and we would rather say so than let it pass.
Everything here refers to the demonstrator as the pinned version returns it: grundnorm==0.5.0. Later releases add fields and rename others.
The public corpus is a demonstrator, not an institutional deployment.
It seals five articles of one regulation. The system declares this itself, inside the signed response rather than in a footnote: the scope reads corpus demo, demoRecordsOnly true, sealedRecordCount 5. Nothing about it is a deployment for an institution, and no institution stands behind it.
The three signers are not independent of each other.
A sealed record in the demonstrator carries three valid signatures: the European Parliament and the Council of the EU as sovereign signers, and a legal reviewer as expert. Every one of them is named DEMO, every one is a pinned key, and the quorum is met. What the quorum measures is that three valid signatures exist, and they do. What it does not measure is whether three parties produced them.
Taken on our word, because you cannot check it: the three keys derive from a single seed. Cryptographically, a sealed demonstrator record is one party signing three times, not three institutions agreeing. What you can check is the consequence: the attestation says independence attested_multi rather than verified_multi, key_provenance pinned_demo, demo_keys true, and the verdict refuses to call itself authoritative.
The attestation declares its own custody, and it is not good.
custody unverified. ledger unanchored. classification not_present. Those three fields travel in every response. A verification layer whose first job is to tell you how far it can be trusted has to be willing to say this, and to say it in the payload rather than on a page nobody reads.
The absence proof is real, and it is bounded.
Ask for an identifier the demonstrator does not hold and the answer carries a cryptographic non-inclusion proof: absence proven. It does not prove that the article does not exist in EU law. It proves that within a declared and signed scope it is not there, which is why the field is called proves attributable_scope_statement.
Those are two separate axes on purpose. The proof can be valid while the statement is still not authoritative, and the SDK never collapses them into one field. A system that reported a single ok would have to choose which of the two facts to hide.
One property cannot be reproduced here, and we will not fake it.
The demonstrator holds five articles and six deontic atoms, and every one of them is in the state fixed. None is in needs_review or for_the_court. So the property we consider the most important, that genuine divergence between competent readings is recorded and handed to a court rather than resolved by the machine, is not something you can reproduce with what is published.
Sealing a divergent record on purpose would mean fabricating a disagreement the engine never found, which is the exact failure this product exists to prevent. Five articles chosen to show the pipeline do not produce real divergence, and we would rather leave the argument undemonstrated than demonstrate it with a lie.
What the epoch closes, and the three things it does not.
The non-inclusion proof shows that an identity is absent from the committed set. That is all it shows. It does not prove freshness: a record may have been superseded and the epoch will not tell you. It does not detect a deleted signature. And it does not close equivocation, where one signer commits to two different sets in front of two different readers. Closing that needs independent witnesses co-signing the head, which this version does not do. The bounds travel inside the response.
Two numbers that look like the same number.
sealedRecordCount counts sealed records within the scope you asked about. epoch.treeSize counts identities committed in the epoch. Today both read 5, which is a coincidence of this corpus rather than a rule. Seal a sixth record without republishing the epoch and they diverge. Cite either, but do not present them as one figure.
There is no accuracy figure, and there will not be one.
This is a position, not a task nobody has got to yet. A number measured on one body of rules, in one language, under one legal tradition, says nothing about another, and averaging across them produces a figure with no referent. Correctness is established per engagement, against that organisation's own corpus and by its own jurists. Treat any single accuracy number with suspicion, including one of ours if you are ever shown one.
Why this page exists at all
A page about honesty cannot be wrong even in the humble direction. An earlier draft of this one said the demonstrator was signed with a key we publish. It is not, and we corrected it before publishing, because confessing something false is as inaccurate as concealing something true, and here it is worse: a reader who checks would find that we overstated our own weakness, and would then have no reason to believe the rest.
Back to Grundnorm