Evidence

Evidence for Private Notes Without a Global Pool

Current certification, independently reproducible public evidence, explicit non-claims, and the date this boundary was last reviewed.

Boundary reviewed 18 Aug 2026 — 2d ago ← The post

This page separates three kinds of evidence that should not be collapsed:

  1. the current Relation V6 milestone certification at canonical implementation commit 7af3558b96448ac0991f241b2ed2a88151ad65e3;
  2. material a reader can inspect in the pinned public export, v0.4.4; and
  3. target work for the remaining funding period.

The v0.4.4 public export includes a reviewed Relation V6 boundary summary and supporting source, but deliberately does not publish the raw V6 artifact package. The V6 rows below report reviewed current implementation truth; that raw package is not represented as independently reproducible from the public tree.

Current Relation V6 certification

claimresultlimit that travels with it
Real canonical Relation V6 proofPASSA real proof is not, by itself, settlement or wallet acceptance.
Authenticated verifier, gate, and exact canonical settlementPASSLocal BCH VM conformance is not relay acceptance or chain inclusion.
Real wallet proof capabilityPASSThe capability is process-local and cannot be replaced by a caller’s success flag.
Configured-node chain capabilityPASSThis is authority over evidence from the wallet-selected validating node, not a new source of consensus truth.
Authenticated Recovery V1PASSRecovery produces wallet-private candidates; Recovery is not spendability.
Point-in-time wallet acceptancePASSAcceptance does not record or persist wallet state.
Relation V6 handoff to the private-transition input shapePASSFormat and semantic compatibility do not execute a private hop.

The reviewed program record marks the Relation V6 task list complete and the Proof Notes console aligned with these same lifecycle boundaries. “Complete” there refers to the Relation V6 program’s current task list, not to full APNT or successive private transfer.

Canonical settlement measurement

measurementvalue
serialized size99,950 bytes
SHA-2562ae95c94910ee9adb49e37a668871b9913231da6f513f164d7649fe36ef80770
shape12 inputs / 21 outputs
standard-size margin50 bytes
local BCH-2026 consensus VMPASS
local BCH-2026 standard VMPASS

This exact settlement has not established relay acceptance or live Chipnet inclusion. The earlier chain-confirmed import in the public v0.4.4 release is a different path and a different transaction; it must not be used to fill this gate by analogy.

The original research question, decomposed

Can private value move through successive owners using ordinary BCH UTXOs as authoritative single-use state, while note ownership and value relationships remain hidden, without a global mutable privacy pool or trusted sequencer?

partcurrent answer
Ordinary BCH UTXOs as authoritative single-use backing/stateESTABLISHED for the import/current-state acceptance path
Hidden private semantics, value/linkage shielding, and exact conservationESTABLISHED in Relation V6 and its proof path
No global mutable private-value poolPRESERVED
No trusted sequencer or aggregator authorityPRESERVED
Recipient Recovery plus independent point-in-time acceptanceESTABLISHED
Durable wallet ownership and spendabilityNOT ESTABLISHED
Successive private owner transitionNOT YET DEMONSTRATED

Phase 3 funding map

The original funding request named four milestones. The table records how the current result relates to them without declaring every literal historical acceptance criterion complete.

funded milestonecurrent result
Beaconless Import Funding and ML-KEM RecoveryRecovery V1 is authenticated and dispatches wallet-private recovered candidates. The mechanism evolved; this row does not certify every original criterion.
Wallet and Chain IntegrationReal proof authentication, configured-node chain authentication, and point-in-time wallet acceptance are integrated. Recording, persistence, reorg-safe lifecycle, and spendability remain open.
Initial Multi-User AggregationAggregation remains the privacy-default assembly path and the aggregator remains non-authoritative. No production anonymity or complete literal milestone acceptance is claimed here.
Chain-Backed Private Note Design and Proof RoadmapThe work progressed beyond a roadmap into frozen Relation V6 semantics, exact conservation, real proof construction, and an authenticated settlement and acceptance path. Current-path live Chipnet inclusion remains open.

At the time of the request, private conservation was described as the crucial unsolved problem. Relation V6 closes that question for the import/current-state acceptance path. It does not close successive ownership.

Pinned public evidence

The v0.4.4 public release contains the reviewed current boundary and material that supports the architecture and earlier import history:

The public release preserves APNT, BCH Cloak, bchcloak:, package names, relation names, statement magics, and commitment-domain strings where they are protocol or artifact identity. The repository and project containing those artifacts are published externally as Proofnote.

Privacy properties and public residue

The current path keeps participant identity, payer-to-recipient linkage, private-note amounts, note correspondence, bundle partitions, note-to-cell assignments, private change ownership, Recovery plaintext, openings, and private proving material out of public results. Recovery does not introduce a reusable recipient marker.

Public transaction shape, counts, fees, timing, BCH metadata, category lineage, backing-cell shape, and other settlement structure remain correlation surfaces. No production anonymity is claimed.

Current non-claims

claimstate
live inclusion of the current canonical fresh-category pathNOT ESTABLISHED
recordingNOT ESTABLISHED
persistenceNOT ESTABLISHED
durable reorg-safe lifecycleNOT ESTABLISHED
spendabilityNOT ESTABLISHED
Bob → CharlesNOT IMPLEMENTED
successive private-hop transferNOT IMPLEMENTED
full end-to-end APNTNOT CLAIMED
production anonymityNOT CLAIMED

Deliberately not published

This site does not publish private milestone documents, proving witnesses, private note plaintext, openings, wallet secrets, ML-KEM secret keys, private assignments, operator material, prover orchestration, or unpublished economics and product internals. The public repository remains a curated export rather than a copy of the private implementation tree.

Remaining funding-period target

accepted note
  → durable, reorg-safe wallet state
  → spendability
  → Bob privately sends to Charles
  → Charles independently recovers and accepts

This is a target for the remaining period, not a guarantee and not a current capability claim.