Trusted source ingress is not the same as a hash

Current target state: NONE. This page describes an internal factual-control gate, not a claim that any target's private sources have been authenticated.

What EA requires

After the governing document set is defined, each material current-value source needs an accepted provenance basis: a governed repository object/version, authenticated delivery channel, system-of-record audit trail, direct canonical public acquisition path, or verified digital signature with signer-identity basis.

What a hash proves

A hash alone can show that bytes match a previously recorded digest. It does not prove who supplied those bytes or how they entered the workflow.

Digital signature boundary

A digital signature can provide stronger integrity and origin/signatory authentication when the signature and signer identity are properly verified. EA does not require digital signatures universally and does not call ordinary repository provenance cryptographic authentication.

Fail closed

If ingress provenance is unproved, the source may remain historical/context evidence or the dependent fact may be delivered as an explicit unknown. It cannot support a current factual value merely because the file exists or hashes correctly.

Not included

No legal authenticity opinion, chain-of-custody opinion, notarization, non-repudiation, factual-truth guarantee, credit decision, buyer-system access or private-data authorization is created.

Download the internal machine-readable proof