{
  "schema": "csoai.population-door/0.1",
  "kind": "preview",
  "id": "claim-watch",
  "title": "Claim-maintenance registries",
  "population": "one row per published claim registry (a vendor's public claims captured, hashed, source-cited, each with a measurement plan), with the file's digest, its digest-reproducibility and its .ots state read from bytes",
  "state": "INDEXED",
  "n": 78,
  "n_unit": "claims captured across the published registries",
  "as_of": "2026-09-23",
  "source": [
    "/spec/claim-maintenance/register.json",
    "/claims/claimreg-ai-assurance-and-settlement-2026-09-23.json",
    "/claims/claimreg-ai-assurance-and-settlement-2026-09-23.json.ots",
    "/claims/claimreg-ondo-chainlink-2026-09-22-rev2.json",
    "/claims/claimreg-ondo-chainlink-2026-09-22-rev2.json.ots",
    "/claims/claimreg-ondo-chainlink-2026-09-22.json",
    "/claims/claimreg-ondo-chainlink-2026-09-22.json.ots"
  ],
  "reason": null,
  "unmeasured": [
    "25 of 78 claim rows across the published registries are CLAIM_MEASURED, 9 remain CLAIM_CAPTURED and 44 are UNMEASURED or UNCHECKABLE — counted from the served bytes at request time, not typed here. A measured claim carries its method, window, denominator and sources. No claim of falsity is made about any entry."
  ],
  "head": {
    "registries": [
      {
        "registry_id": "claimreg-ai-assurance-and-settlement-2026-09-23",
        "schema": "csoai.claim-registry/0.3",
        "created_utc": "2026-09-23",
        "supersedes": null,
        "merkle": {
          "algorithm": "RFC 9162 §2.1.1 Merkle Tree Hash",
          "root": "6bbb10ac1a67640480593e6e39a7746b2f3045f67933f1a741cc7704f618e356",
          "n_leaves": null
        },
        "file": "/claims/claimreg-ai-assurance-and-settlement-2026-09-23.json",
        "file_sha256": "0fb10e73e325485c96e29d828b27ebe776364ed620303b15e90e49bd3c7c58ac",
        "registry_digest": "c80ae3e64a6df0504c2c410dfd534282af6fac2cc85560e958e23d0d4f9c5020",
        "registry_digest_reproducible": true,
        "registry_digest_rule": "sha256 over compact sorted-key UTF-8 integer-only canonical JSON, omitting registry_digest; v0.3 rule, recomputed from served bytes",
        "subjects": [
          "16939677",
          "vanta.com",
          "credo.ai",
          "holisticai.com",
          "armilla.ai",
          "arize.com",
          "langfuse.com",
          "galileo.ai",
          "traceloop.com",
          "helicone.ai",
          "anthropic.com",
          "mistral.ai",
          "549300DTUYXVMJXZNY75",
          "sebi.gov.in",
          "github.com/NVIDIA-NeMo/Guardrails",
          "github.com/NVIDIA/garak",
          "github.com/guardrails-ai/guardrails",
          "github.com/microsoft/PyRIT",
          "github.com/meta-llama/PurpleLlama",
          "github.com/invariantlabs-ai/invariant",
          "github.com/Giskard-AI/giskard-oss"
        ],
        "claims_per_subject": {
          "16939677": 4,
          "vanta.com": 4,
          "credo.ai": 3,
          "holisticai.com": 3,
          "armilla.ai": 2,
          "arize.com": 3,
          "langfuse.com": 5,
          "galileo.ai": 2,
          "traceloop.com": 3,
          "helicone.ai": 3,
          "anthropic.com": 2,
          "mistral.ai": 2,
          "549300DTUYXVMJXZNY75": 4,
          "sebi.gov.in": 3,
          "github.com/NVIDIA-NeMo/Guardrails": 4,
          "github.com/NVIDIA/garak": 3,
          "github.com/guardrails-ai/guardrails": 2,
          "github.com/microsoft/PyRIT": 1,
          "github.com/meta-llama/PurpleLlama": 3,
          "github.com/invariantlabs-ai/invariant": 3,
          "github.com/Giskard-AI/giskard-oss": 3
        },
        "claims": 62,
        "states": {
          "UNCHECKABLE": 10,
          "UNMEASURED": 32,
          "CLAIM_MEASURED": 20
        },
        "signature_state": "SIGNED BY SIDECAR. The signature is over these bytes, not inside them, because signed bytes are superseded and never edited (spec 9.4). See /claims/claimreg-ai-assurance-and-settlement-2026-09-23.signed.json, which pins this file by sha256 and carries the Ed25519 signature by did:web:csoai.org#board-attestation-1. A signature proves these bytes were signed at that time; it grades nothing, certifies nobody, and says nothing about any party named here (spec 9.5).",
        "ots": {
          "path": "/claims/claimreg-ai-assurance-and-settlement-2026-09-23.json.ots",
          "state": "PENDING",
          "bytes": 770,
          "sha256": "ffeb9b7765771ea0638178d69a182e9da7f7a977f7a50ddef9cd0c70452417fb"
        },
        "maintainer": "CSOAI Ltd — claim maintenance (measurement, never certification)",
        "notes": null
      },
      {
        "registry_id": "claimreg-ondo-chainlink-2026-09-22-rev2",
        "schema": "csoai.claim-registry/0.2",
        "created_utc": "2026-09-22",
        "supersedes": {
          "registry_id": "claimreg-ondo-chainlink-2026-09-22",
          "file": "/claims/claimreg-ondo-chainlink-2026-09-22.json",
          "sha256": "acc0f9ac2712f8b9cbc5c707142b4e7954d16e1582ddcdd5adb2afaf0e0908fe"
        },
        "merkle": {
          "algorithm": "RFC 9162 §2.1.1 Merkle Tree Hash",
          "root": "81d1b4d0eb671da534a4de471f03c02f2ed4ae2fa3d0a58f590a7ce7697be102",
          "n_leaves": 8
        },
        "file": "/claims/claimreg-ondo-chainlink-2026-09-22-rev2.json",
        "file_sha256": "4c8efe065cffbba0c7674907ddb882eb1d4144af543e263a16ac318b0cf2ca59",
        "registry_digest": "5edb8b0bb8c54daa04ab06a0a6a7738d12bf0bce54e72d6adf5162e2119bb0bb",
        "registry_digest_reproducible": true,
        "registry_digest_rule": "sha256 over Python sorted-indent-1 ASCII JSON omitting registry_digest; legacy rule, recomputed from served bytes",
        "subjects": [
          "chainlink",
          "ondo"
        ],
        "claims_per_subject": {
          "chainlink": 5,
          "ondo": 3
        },
        "claims": 8,
        "states": {
          "UNMEASURED": 2,
          "CLAIM_MEASURED": 5,
          "CLAIM_CAPTURED": 1
        },
        "signature_state": "SIGNED BY SIDECAR — the signature is over these bytes, not inside them. See /claims/claimreg-ondo-chainlink-2026-09-22-rev2.signed.json, which pins this file by sha256 and carries the Ed25519 signature by did:web:csoai.org#board-attestation-1. A signature proves these bytes were signed at that time; it grades nothing and certifies nobody.",
        "ots": {
          "path": "/claims/claimreg-ondo-chainlink-2026-09-22-rev2.json.ots",
          "state": "PENDING",
          "bytes": 635,
          "sha256": "dcf9b18fe25a2913763b195d07a8a68283a8da1084cad303c04648114f2ba4a1"
        },
        "maintainer": "CSOAI Ltd — claim maintenance (measurement, not certification)",
        "notes": "Second pass of claim maintenance on named subjects: every claim the public record allows was measured, each one states its window, denominator, method and sources, and each one states what it does not prove. Claims that could not be moved say why."
      },
      {
        "registry_id": "claimreg-ondo-chainlink-2026-09-22",
        "schema": "csoai.claim-registry/0.1",
        "created_utc": "2026-09-22",
        "supersedes": null,
        "merkle": null,
        "file": "/claims/claimreg-ondo-chainlink-2026-09-22.json",
        "file_sha256": "acc0f9ac2712f8b9cbc5c707142b4e7954d16e1582ddcdd5adb2afaf0e0908fe",
        "registry_digest": "cbec2409cbce299326f8781d9c1b32095809c2ad38e219d61908c22fe17869e6",
        "registry_digest_reproducible": true,
        "registry_digest_rule": "sha256 over Python sorted-indent-1 ASCII JSON omitting registry_digest; legacy rule, recomputed from served bytes",
        "subjects": [
          "chainlink",
          "ondo"
        ],
        "claims_per_subject": {
          "chainlink": 5,
          "ondo": 3
        },
        "claims": 8,
        "states": {
          "CLAIM_CAPTURED": 8
        },
        "signature_state": "UNSIGNED — signer ceremony pending; OTS-anchored instead (no key required)",
        "ots": {
          "path": "/claims/claimreg-ondo-chainlink-2026-09-22.json.ots",
          "state": "PENDING",
          "bytes": 735,
          "sha256": "143108bfe12fa10b3ddedd06c19f48877e5507bdf3e7471ca5b0c297a4ef128f"
        },
        "maintainer": "CSOAI Ltd — claim maintenance (measurement, not certification)",
        "notes": "First live claim-maintenance pass executed permissionlessly from public pages/APIs. States: CLAIM_CAPTURED (hashed, timestamped, source-cited). CLAIM_MEASURED requires the harness runs queued in measurement_plan. No claim of falsity is made about any entry."
      }
    ],
    "claim_states_across_registries": {
      "UNCHECKABLE": 10,
      "UNMEASURED": 34,
      "CLAIM_MEASURED": 25,
      "CLAIM_CAPTURED": 9
    },
    "superseded_registry_ids": [
      "claimreg-ondo-chainlink-2026-09-22"
    ],
    "supersession_rule": "a superseding registry is a new file; the prior bytes are never edited and both remain served",
    "identification": "a claim is a sentence captured verbatim from the vendor's public page or API at the registry's created_utc, typed by kind, with the plan by which it could be measured; the file bytes are served unchanged and never edited"
  },
  "manifest": "https://csoai-org.pages.dev/api/pop/claim-watch/manifest",
  "buy": {
    "resource": "https://csoai-org.pages.dev/api/pop/claim-watch",
    "how": "GET the resource → 402 → pay accepts[] (x402) → retry with X-PAYMENT",
    "catalog": "https://csoai-org.pages.dev/api/x402",
    "all_doors": [
      "https://csoai-org.pages.dev/api/pop/stablecoins",
      "https://csoai-org.pages.dev/api/pop/swift",
      "https://csoai-org.pages.dev/api/pop/xrpl",
      "https://csoai-org.pages.dev/api/pop/x402-bazaar",
      "https://csoai-org.pages.dev/api/pop/mcp-registry",
      "https://csoai-org.pages.dev/api/pop/a2a",
      "https://csoai-org.pages.dev/api/pop/ots-proofs",
      "https://csoai-org.pages.dev/api/pop/layer0",
      "https://csoai-org.pages.dev/api/pop/corrections",
      "https://csoai-org.pages.dev/api/pop/claim-watch"
    ]
  },
  "rail": {
    "mode": "challenge-only",
    "pay_to_configured": true,
    "facilitator_configured": false,
    "note": "402 challenges are complete (asset, amount, payTo) but no facilitator is provisioned, so no receipt can settle and no paid artefact is granted. Nothing is charged. Verification stays free."
  }
}