The Anchored Receipts register now holds twenty-two families, twenty of them shipped, spanning thirty-three distinct claim types. A family is a small signed record of one thing that happened — consent given, data erased, authority delegated, a payment authorised, a model answer grounded — written in a wire format we locked before the first one shipped and have not broken since.
A receipt is not a log line. A log line is a claim your server makes to itself. A receipt is a signed envelope with a typed claim inside it, a subject it refers to, and a verification path someone outside your company can walk without asking you for anything.
Every family is one claim type and one set of rules for filling it in. APR says something was produced and by what. ACR says consent was given, modified, or withdrawn. ARR says data was erased, expired, held, anonymised, or archived. ADR says authority was delegated and, later, that it was revoked — without rewriting the record of the period when it was valid.
Provenance, consent, erasure, delegation, transfer, purpose, evaluation, attestation, lineage, notice, breach, subject rights, impact, tokenization, action, quality, guard, grounding. Eighteen of those carry chips on the public verification page; twenty-two exist in the register; two are built and waiting on a publish gate rather than on code.
The last four to arrive — action, quality, guard, grounding — are the agent-era ones. They exist because an agent that spends money, answers a question, refuses a request, or cites a source produces exactly the kind of event that is easy to assert and hard to prove afterwards.
A log line is a claim your server makes to itself. A receipt is a claim someone else can check.
The implementations are Apache 2.0 and MIT, the specification repository is CC0, and none of it is priced. We do not sell receipts. Revenue comes from Hub and miniterms, and the register is infrastructure we need to exist in order to build those honestly. A receipt format that only one company can read is not a receipt format.
That also settles the maintenance question in a way we find clarifying: the cross-family consistency tables are the single source of truth, and adding a family means updating every table in them. It is deliberately annoying to add a twenty-third.
Two families are built but behind a publish gate. The envelope's next version, which adds signature-algorithm agility for post-quantum work, is still a draft. And we hold an external cryptographic review as a hard gate before making any conformance or strength claim about the format in public — so this post describes what we built and how many, and deliberately claims nothing about how strong it is.
This post was drafted by an AI system from Dekimu's public engineering record and published with automated checks, without per-post human editing.
← Back to blog