ON INDEPENDENCE

A log about yourself isn't evidence.

Every record an agent keeps about its own conduct is testimony from an interested party. It can be complete, tamper-proof, beautifully signed — and still be the keeper's own word about the keeper. The one thing a self-issued record cannot manufacture is a second signature from someone with nothing to win. That second signature, hash-chained and anchored so anyone can check it without trusting the keeper, is what Tersign is.

The challenge splits in two

When someone disputes your record, they ask two different questions.

Most "trust" products answer only the first. Answering the first without the second is why a self-hosted audit log, however tamper-evident, does not settle a dispute — the party asking already knows you kept it.

Question one — vantage

Is it independent?

Was the record made by someone outside the transaction? A third-party catalog or trust-score can clear this bar — it observed you from the outside. Vantage alone is cheap, and it is not enough.

Question two — evidence-grade

Can I verify it without trusting the keeper?

Is it counter-signed, hash-chained, complete against an unforgeable sequence, and anchored in time — so I can check every claim myself? A published score fails here: to believe it, I still have to trust whoever published it.

Tersign is the only answer that clears both: a neutral counter-signer that is outside your transaction, whose every record you — or a regulator, or the counterparty — can verify without trusting Tersign either. Independence of vantage and independence of verification.

Four properties structure supplies, and independence does not

What a second signature actually has to carry.

These are stated as evaluator-side disqualifications — what a record must not be read as — in the open compliance-fields extension (x402 #2853), and each is executable as a two-sided conformance vector anyone can run.

Independence

A signature from a non-party

A record composed and signed only by the payer, the payee, or their operators evidences the shape those parties assert — not that an outside observer would concur. Tersign counter-signs as a party to neither side.

Completeness

Omission is visible, not just ordering

An issuer-attested sequence proves ordering, never no-omission — quietly drop the failures and the record still looks clean. A counter-signed head over sequence 1..N makes any gap arithmetically visible to anyone.

Existence in time

The clock is not the keeper's to move

A signature proves integrity, not when a record came into being. Tersign anchors chain heads to Bitcoin: "existed no later than block N" is checkable with public tooling, and block time is not the keeper's to backdate.

/v1/anchors →
Phase separation

Funding is not delivery is not settlement

A record of one economic phase says nothing about a later one. A funding receipt is not proof of delivery; a delivery attestation is not proof of settlement. Tersign keeps them distinct so none is misread as another.

Why this is the demand, not a nicety

The obligation is increasingly to demonstrate, not to assert.

Disclosure and conduct rules tell you what you must do. A growing number then ask a second thing: show, to someone who does not have to take your word, that you did it. US broker-dealer record-keeping (SEC 17a-4, FINRA 4511) requires records that are tamper-evident and independently verifiable today. Assurance frameworks are converging on the same bar — independent verifiability, not self-attestation, is what separates a passing control from a claimed one.

A record you keep about yourself demonstrates your record-keeping. It cannot demonstrate the fact to a party who assumes you are interested — because you are.

Tersign closes exactly that gap: the demonstration a self-kept log structurally cannot provide. We are a data provider, not a law firm — an export pack is formatted for a named regime (Art 50 disclosure, VAT 226b, HK s.51C, MAS SAFR alignment), and its worth is that the reader can verify it independently, not that we certify anything.

Don't trust this page — run it

The genesis record is public. Verify it yourself.

One record on the ledger is public by design. Recompute its content address, recover its counter-signature, and confirm its Bitcoin anchor — no account, no trust in us:

npx tersign verify 0xe5874f1ffe87f0a6dd9eb157730f67b86ee4538b125fe30fcc4e165213dd3fc4 \
  --ledger https://tersign.ai

Or work from the raw bytes: curl /v1/genesis returns the record, and the stdlib-only conformance suite recomputes every digest — including the two-sided vectors for each property above — with no dependency on Tersign at all. Verify any receipt →

Independence is the one property structure cannot supply. If your evidence has to survive being held by an interested party, that party cannot be you.

See pricing →
Read on the evidence layer · the normative extension · conformance vectors · for agents