Velaru Standards · Sovereign Behavioral Evidence · v2.0
POSS-1 proved behavioral outcomes reconcile. POSS-2 names why lone generators cannot cryptographically prove completeness, distinguishes completeness classes, and specifies the quorum-aware architecture Velaru implements for EPL, carrier underwriting, and EU AI Act Art. 12 evidence.
| Class | Domain | Invariant | Example |
|---|---|---|---|
| Class A | Multiset / trading lifecycle | XOR: every attempt = exactly one terminal event | Order signal → fill; GEN_ATTEMPT = GEN + DENY + ERROR |
| Class B | Process / behavioral governance | Σ attempts = GEN + DENY + ERROR + SILENCE + unclosed | Hiring AI: permitted, refused, errored, silent, or pending |
Class A and Class B are not competing standards. They answer different questions. Trading audit proves execution events. POSS-2 proves governance behavior — including refusals, silence, and pre-incident policy locks.
A lone generator — the same party that produces AI output — cannot cryptographically prove that no unlogged generation occurred. Any internal log can omit entries. Zero-knowledge proofs cannot fix this without external observers.
IETF draft-kamimura-scitt-refusal-events-03 (VeritasChain, Aug 2026) states explicitly: "This demonstrates that a refusal was logged. It does not prove that no unlogged generation occurred." POSS-2 is the honest architecture that follows from that admission.
Reference: draft-kamimura-scitt-refusal-events-03 §5.3 · draft-noa-scitt-ai-agent-receipt-00 §9 (policy-replay out of scope)Velaru implements impossibility-aware completeness with independent observers:
| Tier | Requirements |
|---|---|
| POSS-2 Crypto | Ed25519 + hash chain + /verify pass + DRP-1 deontic binding |
| POSS-2 Complete | Crypto + Class B invariant holds (unclosed = 0) |
| POSS-2 Sovereign | Complete + external anchor + Handler Receipt + BYOK or Tri-Receipt |
| POSS-2 Causal | Sovereign + TCB Counterfactual Receipt bound to frozen Handler Receipt |