K06 assurance and procurement architecture
Offline Currentness Import
Direct answer
The K06 importer validates a caller-supplied canonical JSON payload, source-snapshot hashes, SHA-256 digest, detached RSA-SHA256 signature, stable IDs, status vocabulary, safe paths, and offline-only declarations. It performs no network retrieval.
Authority and evidence boundary. K06 publishes reference architecture, source review, machine-checkable dependencies, procurement scope, and test-evidence formats. These records do not certify a facility, award a contract, authorize an operation, prove deployment, establish current operation, or transfer regulatory or command authority.
Verified reference fixture
BundleBUNDLE-K06-CURRENTNESS-001
StatusACCEPTED_FOR_REVIEW
SignatureVERIFIED
Snapshots6
Observations6
Transitions4
Correction proposals2
Review queue4
Payload SHA-256: 71c1453bbfd478a81d075758e3118c3566941b99704754c9bd447e978a459666
Receipt JSON · Bundle manifest · Canonical payload · Digest · Detached signature · Public key
Validation contract
- canonical UTF-8 JSON payload
- SHA-256 digest match
- detached signature verification
- unique stable IDs
- monotonic observation times
- known status vocabulary
- no path traversal
- no network retrieval
- receipt records every accepted and rejected item
Offline-only boundary
The importer has no retrieval code and rejects bundles that do not declare network retrieval prohibited. An accepted receipt enters a governed review queue; it does not automatically change public claim status.
- import does not prove source truth
- import is not public runtime monitoring
- signature proves signer control and payload integrity, not legal authority
- status transition requires review before public promotion