Device identity registers measured
Software-read identifiers establish operational identity at A0. Hardware authenticity begins only at A1 with challenge-fresh vendor attestation and every A1 prerequisite satisfied.
Evidence semantics
VCM-1 carries four evidence classes that never blend: measured, derived, modeled, and declared. Assurance says how strongly the record is bound to the device; coverage says how much of its life was observed; neither changes what a claim is.
The classification
The class is part of the claim and travels with it through every rendering. A signature records provenance; it does not promote a declaration, derivation, or model into a measurement.
Observed facts and deterministic functions over them.
Estimates and assertions remain visibly separate.
A declaration remains declared however long it stays consistent. Independent corroboration adds a separate record beside it; it does not reclassify it.
What the probe reads
The current live capture path is NVML on NVIDIA hardware. Raw reads are measured; rates, trajectories, distances, appraisals, and policy outcomes built from them are derived. Operator assertions enter through a separate declared lane.
Software-read identifiers establish operational identity at A0. Hardware authenticity begins only at A1 with challenge-fresh vendor attestation and every A1 prerequisite satisfied.
The raw identities are measured. Firmware and VBIOS gate outcomes are derived appraisals over admissible attestation evidence, never measurements themselves.
Counts and states are measured. Rates, trajectories, and distance to version-pinned vendor thresholds are derived evidence.
Every figure retains its sensor identity and characterized cadence. Device telemetry cannot establish facility-side electrical exposure.
Covered duty and operating-state indicators may be derived from these reads. They do not establish future capacity or workload suitability.
The read and its device ceiling remain visible. VCM-1 does not editorialize an idle-state reading into a performance or suitability claim.
Configuration is measured; vendor events are measured when the source is present. An unread event source remains unread and never becomes a zero.
Voltry checks signature, timestamp, schema, and internal consistency. It records attribution and never promotes an assertion into a measured fact or legal finding.
Provenance records such as the agent version, methodology stamp, and signature block describe the measurement apparatus. They are not device claims and therefore carry no evidence class.
Third-party verification
A relying party can verify a certificate without Voltry being online or cooperative, provided it retained the evidence bundle, keys and enrollment lineage, inclusion proof and signed root, and the exact versioned artifacts the certificate stamps.
Integrity, provenance, and the specified derivations are independently checkable.
The truth of an A0 observation remains bounded by A0: software-read identifiers and signer continuity provide operational visibility, not a hardware-authenticity claim. Verification proves only what the retained bytes, signatures, proofs, and specified functions establish.
A counter that was never read is not zero. Missing or unreadable evidence renders Not Assessed at the field or rule level; a policy without the evidence it needs renders Not Assessable. Neither outcome is silently converted into pass or fail.