Vaara Vaara

Vaara Conformance Results

Every suite, every verdict, and everyone who checked it themselves.

Each suite below ships an independent checker that imports no Vaara code and recomputes its verdicts from the bytes of its own case files. This page is generated from the runner's report, so it says what the checkers did rather than what a document claims they do.

46suites
43passed
0failed
3skipped
75cases

generated 2026-08-21T13:35:08Z

Run it yourself

Nothing here needs Vaara installed. The checkers use the standard library plus cryptography and rfc8785.

git clone https://github.com/vaaraio/vaara
cd vaara
pip install cryptography rfc8785
python scripts/conformance_runner.py

Point --vectors-dir at a directory laid out the same way and it grades those bytes instead. The runner collects; the checkers decide.

What a pass does not establish

These vectors are Vaara's and there is no ratification process behind them. The maintainer adds the cases and decides what a verdict means, and nobody else has a vote. That is a real limit on any neutrality claim and it is stated here rather than argued around.

What the corpus does give is narrower and checkable: every case recomputes from committed bytes with no Vaara import, so anyone can disagree with an expected result and show their work. Recompute is checkable by strangers. Authorship is not.

Independent reproductions

Parties other than the maintainer who ran the checkers and reported the outcome in public. Claims are quoted as each party scoped them. Everyone here asked to be listed, knowing the entry is permanent. To add your own run, open a row request. Row numbers are permanent and each listed party gets its own badge, carrying that number, the date and the commit. A badge says the party ran the checkers at that commit on that date. It never says currently passing, and it is not a certification.

Checking a badge without trusting this page

Each badge carries the digest of its own row inside the SVG, and the row it commits to is served as JCS-canonical bytes (RFC 8785) next to it. The file holds those bytes and nothing else, so verifying a badge is one command and needs no parser, no canonicaliser and no Vaara installed.

curl -s https://vaara.io/badge/<slug>.json | sha256sum
curl -s https://vaara.io/badge/<slug>.svg | grep digest

python scripts/vcr_chain.py            # nothing removed from the table

The two agree or the badge is not describing that row. This is the same property the corpus runs on, applied to the badge itself: a claim that recomputes from bytes, checkable by someone who trusts neither the party nor Vaara.

Terms for a listed party, version 2026-08-21

Stated before there is anything to sell, so that anyone deciding whether to be listed can read the commercial position at the moment they decide rather than learn it afterwards.

#1 2026-08-19 babyblueviper1 (invinoveritas) invinoveritas

40 passed, 0 failed, 3 skipped, 49 cases

Suites
acp_checkout_v0, agent_decision_v0, agent_identity_v0, ap2_v0, article12_fold_v0, atlas_threat_v0, attestation_result_v0, audit_summary_v0, authorization_v0, build_bundle_v0, bundle_doc_v0, bundle_set_v0, capability_scope_v0, class_gate_v0, conformance_statement_v0, contiguity_v0, credential_binding_v0, credential_grant_v0, crewai_enforcement_v0, cross_org_handoff_v0, cross_stack_revocation_v0, data_locality_v0, decision_pairing_v0, enforcement_attestation_v0, enforcement_set_v0, evidence_bundle_v0, evidence_ref_v0, execution_receipt_v0, external_evidence_v0, fallback_projection_v0, governance_decision_v0, handoff_set_v0, ingest_v0, key_rotation_v0, normalize_v0, pq_hybrid_v0, qualified_time_v0, record_conformance_v0, record_set_v0, sep2787_attestation_v0, tap_v0, transparency_consistency_v0, x402_settlement_v0
At commit
cc5df5d2938cb9a26e820c1b8b5ac3b7d398ab1e
Their scoping
Ran the independent checkers exactly as documented (git clone, pip install cryptography rfc8785, python scripts/conformance_runner.py) in an isolated venv, no Vaara install. Establishes that the checkers reproduce their own stated verdicts against the shipped case files at this commit. Does not establish interoperability between Vaara's proofs and our own (invinoveritas) proof format.
Record
record
Listed under terms
2026-08-15
Row digest
sha256:2682d581d86fc18156386c716c38d9c63ea34264ecb2dc31938ae30d20a55693
over /badge/babyblueviper1-invinoveritas.json
Badge
VCR row 1
[![Vaara Conformance Results row 1](https://vaara.io/badge/babyblueviper1-invinoveritas.svg)](https://vaara.io/conformance.html)
Certificate
printable sheet

Suites

SuiteVerdictNote
acp_checkout_v0PASS
agent_decision_v0PASS
agent_identity_v0PASS
ap2_v0PASS
article12_fold_v0SKIPchecker validates a passed-in bundle zip, not a bare case directory
atlas_threat_v0PASS
attestation_result_v0PASS
attribute_attestation_v0PASS
attribute_attestation_zk_v0PASS
audit_summary_v0PASS
authorization_v0PASS
build_bundle_v0PASS
bundle_doc_v0PASS
bundle_set_v0PASS
capability_scope_v0PASS
class_gate_v0PASS
conformance_statement_v0PASS
contiguity_v0PASS
credential_binding_v0PASS
credential_grant_v0PASS
crewai_enforcement_v0PASS
cross_org_handoff_v0PASS
cross_stack_revocation_v0PASS
data_locality_v0PASS
decision_pairing_v0PASS
enforcement_attestation_v0PASS
enforcement_set_v0PASS
evidence_bundle_v0PASS
evidence_ref_v0PASS
execution_receipt_v0PASS
external_evidence_v0PASS
fallback_projection_v0PASS
governance_decision_v0PASS
handoff_set_v0PASS
ingest_v0PASS
key_rotation_v0PASS
normalize_v0PASS
pq_hybrid_v0SKIPpq_hybrid_v0 needs an optional dependency not installed: dilithium_py (pip install 'vaara[pq]')
qualified_time_v0SKIPqualified_time_v0 needs an optional dependency not installed: asn1crypto (pip install 'vaara[timeanchor]')
record_conformance_v0PASS
record_set_v0PASS
release_condition_v0PASS
sep2787_attestation_v0PASS
tap_v0PASS
transparency_consistency_v0PASS
x402_settlement_v0PASS