K06 assurance and procurement architecture

Offline Currentness Import

Direct answer

The K06 importer validates a caller-supplied canonical JSON payload, source-snapshot hashes, SHA-256 digest, detached RSA-SHA256 signature, stable IDs, status vocabulary, safe paths, and offline-only declarations. It performs no network retrieval.

Authority and evidence boundary. K06 publishes reference architecture, source review, machine-checkable dependencies, procurement scope, and test-evidence formats. These records do not certify a facility, award a contract, authorize an operation, prove deployment, establish current operation, or transfer regulatory or command authority.

Verified reference fixture

BundleBUNDLE-K06-CURRENTNESS-001
StatusACCEPTED_FOR_REVIEW
SignatureVERIFIED
Snapshots6
Observations6
Transitions4
Correction proposals2
Review queue4

Payload SHA-256: 71c1453bbfd478a81d075758e3118c3566941b99704754c9bd447e978a459666

Receipt JSON · Bundle manifest · Canonical payload · Digest · Detached signature · Public key

Validation contract

  1. canonical UTF-8 JSON payload
  2. SHA-256 digest match
  3. detached signature verification
  4. unique stable IDs
  5. monotonic observation times
  6. known status vocabulary
  7. no path traversal
  8. no network retrieval
  9. receipt records every accepted and rejected item

Offline-only boundary

The importer has no retrieval code and rejects bundles that do not declare network retrieval prohibited. An accepted receipt enters a governed review queue; it does not automatically change public claim status.

  • import does not prove source truth
  • import is not public runtime monitoring
  • signature proves signer control and payload integrity, not legal authority
  • status transition requires review before public promotion

Payload schema · Importer contract