Evidence semantics

Every device claim identifies its class, source, and limits.

VCM-1 carries four evidence classes that never blend: measured, derived, modeled, and declared. Assurance says how strongly the record is bound to the device; coverage says how much of its life was observed; neither changes what a claim is.

Measured · Derived · Modeled · Declared

The classification

Four evidence classes, kept separate.

The class is part of the claim and travels with it through every rendering. A signature records provenance; it does not promote a declaration, derivation, or model into a measurement.

MEASURED + DERIVED

Observed facts and deterministic functions over them.

  • Measured: read from a stated device or platform interface on a stated attempt
  • Derived: recomputable from measured inputs under a versioned, published function
  • Measured describes source, not assurance: a software-read value can still be A0
  • Rates, threshold distances, coverage, and the seven axes retain their derivation boundary
MODELED + DECLARED

Estimates and assertions remain visibly separate.

  • Modeled: a statistical estimate with stated uncertainty and a calibration snapshot
  • Modeled content is decision-inert and never enters a grade, axis, or covenant status
  • Declared: a party-signed assertion, recorded with attribution and never adjudicated

A declaration remains declared however long it stays consistent. Independent corroboration adds a separate record beside it; it does not reclassify it.

What the probe reads

Device evidence begins at named, vendor-supported interfaces.

The current live capture path is NVML on NVIDIA hardware. Raw reads are measured; rates, trajectories, distances, appraisals, and policy outcomes built from them are derived. Operator assertions enter through a separate declared lane.

01
M Read on a stated attempt

Device identity registers measured

modelUUIDserialPCI topology

Software-read identifiers establish operational identity at A0. Hardware authenticity begins only at A1 with challenge-fresh vendor attestation and every A1 prerequisite satisfied.

02
M Vendor-supported interface

Driver and VBIOS identity measured

driver versionVBIOSInfoROM

The raw identities are measured. Firmware and VBIOS gate outcomes are derived appraisals over admissible attestation evidence, never measurements themselves.

03
M Read directly from the device

ECC and memory state measured

ECCrow remapretirement state

Counts and states are measured. Rates, trajectories, and distance to version-pinned vendor thresholds are derived evidence.

04
M Device-boundary observation

Thermal and power sensors measured

temperaturepowerenergythrottle

Every figure retains its sensor identity and characterized cadence. Device telemetry cannot establish facility-side electrical exposure.

05
M Stated capture window

Clock and utilization state measured

clock residencyapplication clocksutilization

Covered duty and operating-state indicators may be derived from these reads. They do not establish future capacity or workload suitability.

06
M Current state against ceiling

PCIe and interconnect state measured

generationwidthreplay counterslink state

The read and its device ceiling remain visible. VCM-1 does not editorialize an idle-state reading into a performance or suitability claim.

07
M Device and driver interfaces

Configuration and event state measured

ECC modeMIGcompute modeXid

Configuration is measured; vendor events are measured when the source is present. An unread event source remains unread and never becomes a zero.

08
DEC Party-signed assertion

Operator declarations declared

locationcustodyreservation

Voltry checks signature, timestamp, schema, and internal consistency. It records attribution and never promotes an assertion into a measured fact or legal finding.

Provenance records such as the agent version, methodology stamp, and signature block describe the measurement apparatus. They are not device claims and therefore carry no evidence class.

Third-party verification

How independent verification works.

A relying party can verify a certificate without Voltry being online or cooperative, provided it retained the evidence bundle, keys and enrollment lineage, inclusion proof and signed root, and the exact versioned artifacts the certificate stamps.

  1. Signature check
    ECDSA P-384 over SHA-384 Check the signed evidence bundle against the signer's public key and retained enrollment lineage.
  2. Canonical bytes
    RFC 8785 recomputation Rebuild the exact canonical payload with the signature field omitted and confirm its digest.
  3. Ledger inclusion
    Inclusion proof + signed root Check the proof against the accepted root public key retained with the verification package.
  4. Specified replay final step
    Stamped versions + retained inputs Recompute the derivations defined by the published schema, methodology, manifests, and rubric where applicable.
  5. Result

    Integrity, provenance, and the specified derivations are independently checkable.

The truth of an A0 observation remains bounded by A0: software-read identifiers and signer continuity provide operational visibility, not a hardware-authenticity claim. Verification proves only what the retained bytes, signatures, proofs, and specified functions establish.

What travels with the record

Capture
Schema, methodology, probe, reference-manifest, and rubric versions where applicable
Integrity
Canonical signed bundle, signer key lineage, inclusion proof, and signed root
Context
Assurance class, coverage class, record tier, history basis, and explicit gaps
Models
Calibration snapshot only where a separate modeled block exists

What the record does not establish

  • A0 does not establish hardware authenticity or physical-silicon continuity.
  • C0 says nothing about the interval after the scan or between scans.
  • Device telemetry does not establish facility-side electrical exposure.
  • A declared ownership or custody claim is not title verification or adjudication.
Absence remains visible

A counter that was never read is not zero. Missing or unreadable evidence renders Not Assessed at the field or rule level; a policy without the evidence it needs renders Not Assessable. Neither outcome is silently converted into pass or fail.