Phase B.7 — Canonical Version Locking v1.0

PBTG Sovereign Verification Architecture · Doctrine Artifact
Issuing Authority: Point Break Trading Group LLC
Constitutional Anchor: fa39bbe8 · Genesis Block: b1c57f72
Watermark: PBTG-PB7-v1.0-CANONICAL

Preamble

A canonical artifact whose live serving state is not continuously verified against its anchored state is a canonical artifact in name only. Phase B.7 defines the discipline that converts cryptographic anchoring from a moment in time into a continuously enforced contract: every publicly served byte under PBTG sovereignty is bound, by deterministic mechanism, to its anchored canonical state. Drift is detected, not tolerated. Sovereignty is defined by what cannot drift unobserved.

Article 1 — Scope

Phase B.7 governs all canonical artifacts registered under /opt/pbtg/canonical/registry/. Each registered artifact has a live serving surface, a canonical residence, a SHA-256 hash, and a Bitcoin OTS receipt. The drift detector continuously verifies that the live serving surface matches the canonical hash. Artifacts not registered are not under Phase B.7 protection.

Article 2 — The Five Invariants

I1 — Canonical Existence: Every registered artifact must have its canonical bytes present at the canonical path.
I2 — Live Reachability: The live serving surface must respond. Unreachability is a warning, not a pass.
I3 — Hash Coupling: Live SHA-256 must match canonical SHA-256. Any difference is drift.
I4 — OTS Witness: The OTS receipt must be present alongside the canonical bytes.
I5 — Version Coherence: Manifest-declared version must match the registry-locked version.

Article 3 — Severity Ladder

GREEN: all invariants pass. WARN: I2 fails (transient unreachability). ERROR: I4 fails (missing OTS receipt). CRITICAL: I1, I3, or I5 fails. CRITICAL events trigger fail-closed escalation per Sovereign Law 5.

Article 4 — Version Progression

A registered artifact's canonical hash is immutable. Modification of a live artifact is treated as a new version (v1.0 → v1.1 → v1.2 ...). Each new version requires fresh atomic ratification + OTS anchor. The prior version's anchor remains valid as a historical record. There is no in-place mutation under Phase B.7.

Article 5 — Detection Cadence

The drift detector runs at minimum every hour. Each cycle produces a JSON drift report and a compact log line. Reports are append-only. The detector itself runs under systemd timer genesis-drift-detector.timer, fail-closed on registry corruption.

Article 6 — Sovereign Laws Enforced

Phase B.7 enforces Determinism Supremacy (deterministic hashes), Structural Impossibility (hash collisions are computationally infeasible), Governance Before Mechanism (registry is authoritative), No Runtime Authority Drift (anchored bytes are immutable), Fail Closed Always (any invariant failure halts the cycle and escalates), and Sovereignty By Architecture (Bitcoin chain is the witness, not PBTG-controlled infrastructure).

Article 7 — Public Verifiability

The canonical registry is published at /.well-known/canonical-registry.json. Any third party can fetch the live surfaces, compute SHA-256, and verify against the registry without PBTG cooperation. The OTS receipts at /opt/pbtg/canonical/<artifact>/anchors/ are independently verifiable against the Bitcoin blockchain.

Article 8 — Licensing Tiers (Forward Architecture)

Tier 1 (Public Lock): self-service, free. Tier 2 (Institutional Lock): managed registry, anchored on behalf of the customer. Tier 3 (Sovereign Lock): full doctrine binding, custom registry, dedicated OTS anchor cadence, cryptographic SLA. Pricing surface forthcoming at /verification-tax.