{"space":"killinchu","khipu_root":null,"count":0,"signing_available":true,"keyid":"szlholdings-cosign","slsa":"L1","doctrine":"v11","pub_fingerprint_sha256":"a4d73120c312d94bdd6cbdfa6f3d629cfff4b85e7addde5f9c3fd4c02341eb30","verify_key_url":"/cosign.pub","nodes":[],"citations":[{"claim":"Merkle-DAG provenance build","status":"PROVEN","lutar_theorem":"Lutar.DPI.MerkleDAGBuild","lutar_url":"https://github.com/szl-holdings/lutar-lean/blob/main/Lutar/DPI/MerkleDAGBuild.lean","standard":"RFC 6962 Merkle transparency; Sigstore Rekor (Apache-2.0)","arxiv":"RFC 6962"},{"claim":"DPI / provenance soundness","status":"PROVEN","lutar_theorem":"Lutar.DPI.TH6_DPI_Soundness","lutar_url":"https://github.com/szl-holdings/lutar-lean/blob/main/Lutar/DPI/TH6_DPI_Soundness.lean","standard":"in-toto/DSSE; SLSA provenance framework","arxiv":"arXiv:2406.10109"},{"claim":"Composition soundness (W3C trace continuity)","status":"PROVEN","lutar_theorem":"Lutar.Composition.TH1_Composition","lutar_url":"https://github.com/szl-holdings/lutar-lean/tree/main/Lutar/Composition","standard":"W3C Trace Context (traceparent)","arxiv":"arXiv:2406.10109"}],"citation_note":"Provenance/ledger tabs cite real in-tree lutar-lean theorems plus the public standard / arXiv they map to. All cited entries are kernel-verified (PROVEN).","anchor_health_at":"/api/killinchu/uds/v1/rekor/health","honesty":"DSSE signatures are REAL ECDSA-P256-SHA256 cosign sigs when the SZL_COSIGN_PRIVATE_PEM runtime secret is present (else UNSIGNED, labelled). DAG is in-memory per Space (non-persistent across restart). SLSA L1 honest; L2 roadmap via Wire D (signed provenance) — NOT L3 (no hardened CI yet)."}