{"slug":"proof-of-coverage","verification":{"valid":true,"entries":11,"head":"3edb4dfa764793b867984ddd18e3a893c34bed7604e52e863ffa53f1db932c69"},"count":11,"sources":[{"id":"s1","type":"reference","title":"W3C PROV-DM: The PROV Data Model","publisher":"W3C","url":"https://www.w3.org/TR/prov-dm/","quote":"PROV-DM is a data model for provenance that describes the entities, activities and agents involved in producing a piece of data or thing in the world.","summary":"The standard vocabulary for saying who did what to which thing. It models the pass. It does not model the universe, so it cannot express coverage.","accessed_at":"2026-07-27T00:00","claim_ids":["c8"],"prev":"genesis","hash":"8c775f5d952802bf3db493a44c7e5849717c96af7fb88e1e57da4a2084080258"},{"id":"s2","type":"github","repo":"in-toto/attestation","title":"in-toto attestation framework: signed statements about software artifacts","url":"https://github.com/in-toto/attestation","summary":"A signed statement binds a predicate to a subject identified by cryptographic digest. This is the shape a pass record needs: the claim is bound to the hash of the exact thing examined, not to its name.","accessed_at":"2026-07-27T00:00","claim_ids":["c4"],"prev":"8c775f5d952802bf3db493a44c7e5849717c96af7fb88e1e57da4a2084080258","hash":"2124d27220fe8178b478d688013d609039c992ad5c656cb9e7256e31efa1eb37"},{"id":"s3","type":"reference","title":"SLSA v1.0 provenance specification","publisher":"slsa.dev","url":"https://slsa.dev/spec/v1.0/provenance","quote":"The provenance attestation describes how an artifact was produced, including the builder identity, the build definition, and the resolved dependencies.","summary":"Builder identity plus resolved inputs plus an externally produced record. Same three parts a model pass needs, applied to build systems instead of inference.","accessed_at":"2026-07-27T00:00","claim_ids":["c4"],"prev":"2124d27220fe8178b478d688013d609039c992ad5c656cb9e7256e31efa1eb37","hash":"82e399fc614846ea7202acd4886a5e81deeb80ae8d602bd463b3c738f7882598"},{"id":"s4","type":"reference","title":"OpenTelemetry tracing specification","publisher":"OpenTelemetry","url":"https://opentelemetry.io/docs/specs/otel/trace/api/","summary":"Records operations and their causal relationships across services. Spans are sampled and expire, and nothing declares how many spans should have existed, so a trace cannot answer a coverage question.","accessed_at":"2026-07-27T00:00","claim_ids":["c8"],"prev":"82e399fc614846ea7202acd4886a5e81deeb80ae8d602bd463b3c738f7882598","hash":"df7628c336d037c2cc2d694284358fbaeb13f885712a1d80eb405d2d65fa4051"},{"id":"s5","type":"reference","title":"OpenLineage object model","publisher":"OpenLineage","url":"https://openlineage.io/docs/spec/object-model","summary":"Datasets, jobs and runs, tracked across pipelines. Lineage at dataset granularity: it says a job read a table, not which of the table's rows were evaluated.","accessed_at":"2026-07-27T00:00","claim_ids":["c8"],"prev":"df7628c336d037c2cc2d694284358fbaeb13f885712a1d80eb405d2d65fa4051","hash":"ae35669d3b719559bf9aea5abb4713c877a1904b817baf57583788aef064a480"},{"id":"s6","type":"reference","title":"Cloudflare D1 pricing — rows written, rows read, storage","publisher":"Cloudflare","url":"https://developers.cloudflare.com/d1/platform/pricing/","quote":"Rows written: first 50 million / month included + $1.00 / million rows. Rows read: first 25 billion / month included + $0.001 / million rows. Storage: first 5 GB included + $0.75 / GB-mo.","summary":"The rates used in the cost arithmetic below. Page last updated 2026-04-21.","accessed_at":"2026-07-27T00:00","claim_ids":["c7"],"prev":"ae35669d3b719559bf9aea5abb4713c877a1904b817baf57583788aef064a480","hash":"42840db3431c48cfb0957033249cc7161e52528a1fbe540a310fe98ecab8e18d"},{"id":"s7","type":"model","model":"GPT-5.6","surface":"web app","vendor":"OpenAI","object":"claim:coverage-needs-a-denominator","passes":1,"title":"GPT-5.6 on the declared universe","quote":"Without the declared universe, “the AI checked everything” is unverifiable.","verdict":"Agreed — coverage requires a declared denominator","accessed_at":"2026-07-27T00:00","claim_ids":["c1"],"prev":"42840db3431c48cfb0957033249cc7161e52528a1fbe540a310fe98ecab8e18d","hash":"0dc65990e9176fe5d5ceb8ce2177db26d63b377a4429f5b3bcb546d12938ab41"},{"id":"s8","type":"model","model":"Kimi","surface":"kimi.com web app","vendor":"Moonshot","object":"claim:coverage-needs-a-denominator","passes":1,"title":"Kimi, given the same question and none of the first answer","quote":"Your “one door” is only as good as your proof that nothing slipped through it.","verdict":"Agreed — same conclusion, independent pass","accessed_at":"2026-07-27T00:00","claim_ids":["c1"],"prev":"0dc65990e9176fe5d5ceb8ce2177db26d63b377a4429f5b3bcb546d12938ab41","hash":"e61852e926fbb6e8ddd3d88e46e299d61e57a44c682c6ab31b1a80072cf243f3"},{"id":"s9","type":"model","model":"GPT-5.6","surface":"web app","vendor":"OpenAI","object":"claim:model-narration-is-proof","passes":1,"title":"GPT-5.6 refuses the self-report","quote":"Model self-report is not proof. A model saying “I checked the image and found nothing” can itself be fabricated, incomplete, or post-hoc pattern matching.","verdict":"Refuted — the environment must produce the record, not the model","accessed_at":"2026-07-27T00:00","claim_ids":["c4"],"prev":"e61852e926fbb6e8ddd3d88e46e299d61e57a44c682c6ab31b1a80072cf243f3","hash":"e232898b2b524219946ea9edaded18c0c2c2bc79f5ce8aaed6db539dd68d22ff"},{"id":"s10","type":"model","model":"Kimi","surface":"kimi.com web app","vendor":"Moonshot","object":"claim:finite-shapes","passes":2,"title":"Kimi on how few shapes there are","quote":"Payments: Stripe, Square, PayPal, Plaid — same shape, different field names.","verdict":"Agreed — a new system is a classification, not an integration","accessed_at":"2026-07-27T00:00","claim_ids":["c6"],"prev":"e232898b2b524219946ea9edaded18c0c2c2bc79f5ce8aaed6db539dd68d22ff","hash":"daa3fe75852ee4fafeacf0028e5e15af0b75ccf938945947d00de7b5cc4ceb2c"},{"id":"s11","type":"model","model":"GPT-5.6","surface":"web app","vendor":"OpenAI","object":"claim:coverage-proves-correctness","passes":1,"title":"The strongest objection on the page","quote":"Execution correctness: every intended object was processed under the intended procedure. World correctness: the resulting judgment was actually true. Ten models can consistently make the same error.","verdict":"Partially refuted — coverage proves the first only","accessed_at":"2026-07-27T00:00","claim_ids":["c9"],"prev":"daa3fe75852ee4fafeacf0028e5e15af0b75ccf938945947d00de7b5cc4ceb2c","hash":"3edb4dfa764793b867984ddd18e3a893c34bed7604e52e863ffa53f1db932c69"}]}