{"block_close_oss.c33fd1fe9c":"Community and ecosystem","core-extras.96d330537a":"Base IR","core-extras.bee831a169":"Substrate","core-extras.61a0822826":"Apps on Core","core-extras.15438cc098":"not supported","core-extras.ad565d9d01":"Feature","core-extras.0155bf03e5":"Segment legend","core-extras.8b7110078e":"Algorithm groups by data type","core-extras.25ab4276a6":"Scrollable capability matrix","open-source-ledger.4ba3c461c8":"Decision certificates","open-source-ledger.ac9835d4bd":"Execution transcripts","open-source-ledger.24f43d4446":"Syntax trees","open-source-ledger.55c6923a1e":"Knowledge governance that uses Ledger as its audit spine.","open-source-ledger.4a86080d67":"Spindle","open-source-ledger.fe0a091fdb":"Products","open-source-ledger.2274740521":"Parse source into trees with content-addressed nodes.","open-source-ledger.188fb5d6cf":"Reed","open-source-ledger.6cc3364a24":"Replayable event history","open-source-ledger.3810849650":"Execution transcripts inside a sandbox. Ledger captures what happened; Selvedge captures how it executed.","open-source-ledger.de6848949f":"Selvedge","open-source-ledger.814ca45595":"Reasoning-step certificates inside a single decision, not event provenance across a system.","open-source-ledger.df84637182":"AION","open-source-ledger.d5d6e83bf2":"Continue exploring","open-source-ledger.75e393a1ac":"Explore the project","open-source-ledger.f9743247fa":"Read the documentation","open-source-ledger.db52af1cb6":"Ask about the release","open-source-ledger.49343426a7":"Ledger publishes in the second round of Dweve's foundation release programme; once it does, point the build at your storage backend and inspect your first append, hash check and replay in one local run.","open-source-ledger.6141184964":"Every event. Hash-chained. Queryable.","open-source-ledger.90e40d5043":"Get started","open-source-ledger.1aa2f31ee7":"Ledger","open-source-ledger.650fabe787":"Replayable event history","open-source-ledger.29416cbc87":"Ledger / event provenance","open-source-ledger.13f71ffcde":"No external service","open-source-ledger.9e50bc5c66":"Append · hash · replay","open-source-ledger.182522a199":"Tamper-evident integrity primitives","open-source-ledger.6fd867ddde":"BLAKE3 + Ed25519","open-source-ledger.635948a509":"Hash-chained typed event log","open-source-ledger.cd0a445053":"Dweve Ledger","open-source-ledger.40730fd594":"Operator surface","open-source-ledger.a010de5c61":"Fabric","open-source-ledger.85592d5c8c":"Knowledge governance","open-source-ledger.30dfe1814b":"Multi-agent traces","open-source-ledger.485a04fef4":"Nexus","open-source-ledger.4bb7bcd8d1":"Code-agent receipts","open-source-ledger.af0854de67":"Aura","open-source-ledger.63184e5ed2":"How Ledger plugs in","open-source-ledger.a4ca6bdccd":"STACK BINDING","open-source-ledger.5f5cdfd63a":"SERVICE","open-source-ledger.d4407b4ee1":"SIDECAR","open-source-ledger.9652018eda":"C ABI","open-source-ledger.803a250cd3":"CRATE","open-source-ledger.e2c457dbac":"Ledger ships as a Rust crate, a C ABI, a sidecar process, and a service binary. The sidecar pattern is the most common production deployment. The same event format flows through every variant.","open-source-ledger.2a8296e2ea":"Sidecar. Service. Tiered.","open-source-ledger.044a65f2af":"Embedded.","open-source-ledger.081c04bf3d":"Integration and posture","open-source-ledger.3f91f2b2c4":"Same chain integrity","open-source-ledger.e416b48a20":"Same log shape","open-source-ledger.9ed422d1bf":"Archival, WORM bucket","open-source-ledger.d2481bc5c9":"One interface, five backends","open-source-ledger.45556c8c92":"EventStore trait","open-source-ledger.2c385ff8b8":"Production, indexed","open-source-ledger.c590abf597":"Postgres","open-source-ledger.9f714e5484":"Embedded, single file","open-source-ledger.9f09ccbd1c":"SQLite","open-source-ledger.b4f37d52e8":"Portable, grep-friendly","open-source-ledger.db35ca65d0":"JSONL","open-source-ledger.fc9a6caaea":"Tests, ephemeral","open-source-ledger.89c8a2851d":"Memory","open-source-ledger.dbc12b5774":"Pick per scale and audit need","open-source-ledger.418b97ed32":"STORAGE STACK","open-source-ledger.5e121445b0":"POSTGRES","open-source-ledger.798e0a809a":"SQLITE","open-source-ledger.f4b1c471ce":"MEMORY","open-source-ledger.3f75dd1229":"Memory for tests. JSONL for portability. SQLite for embedded. Postgres for query power. S3 for archival. The log shape and hash chain are identical across all five. Migration between tiers is a copy operation, not a re-encoding.","open-source-ledger.d69fbd45e7":"One log shape.","open-source-ledger.610680fe1d":"Five backends.","open-source-ledger.ab1557ec70":"Storage backends","open-source-ledger.22b7d7e676":"Versioned","open-source-ledger.6dbc1edb99":"Typed schema","open-source-ledger.e3c29b4cbe":"SbomGenerated, AttestationCompleted.","open-source-ledger.04fd7b048c":"Attestation","open-source-ledger.382e79e997":"AiIncidentDetected.","open-source-ledger.5e326b17d2":"Incidents","open-source-ledger.b107c6be6a":"Consent, DPIA, erasure, subject rights.","open-source-ledger.f106ba472b":"Data rights","open-source-ledger.1b594960b2":"Session and replay, plus checkpoint.","open-source-ledger.033df3d297":"Lifecycle","open-source-ledger.80e0dd52b3":"Requested, granted, denied.","open-source-ledger.3cbad8e97e":"Gate events","open-source-ledger.d73aa8728c":"ToolCall, ToolResult.","open-source-ledger.2ae8c3a073":"Tool events","open-source-ledger.7fb3b92f84":"9 categories, 23 variants","open-source-ledger.dba2ceac3a":"EVENT LADDER","open-source-ledger.63d55e50dd":"CUSTOM","open-source-ledger.0a7b77e1bf":"SECURITY","open-source-ledger.7b46d2f3cc":"AI ACT","open-source-ledger.a5b7d57a85":"GDPR","open-source-ledger.29d43743c4":"SYSTEM","open-source-ledger.3c2c55d3e3":"ARTIFACT","open-source-ledger.97efc8640f":"APPROVAL","open-source-ledger.16de25af88":"CODE","open-source-ledger.a3a1644f1e":"TOOL","open-source-ledger.80e6284561":"Tool calls, approvals, artifacts, policy checks, and system changes each keep their own typed shape. That makes the history precise enough to query without flattening every event into an ambiguous log line.","open-source-ledger.883782af96":"9 categories.","open-source-ledger.f2ab62cc23":"23 variants.","open-source-ledger.ed5a89b5a7":"Event taxonomy","open-source-ledger.33a8f2def6":"Figures are an in-memory benchmark snapshot from the supplied Ledger source, not a published SLA. Run the included harness before sizing a workload.","open-source-ledger.c68f437468":"Snapshot, 100 events, BLAKE3 integrity.","open-source-ledger.d0295f339d":"Chain verify","open-source-ledger.db23c994b2":"139 us","open-source-ledger.60ea181e8d":"In-memory snapshot, ledger_append_event.","open-source-ledger.a313bc7f88":"Single append","open-source-ledger.606497be6f":"2.4 us","open-source-ledger.9430f8c53c":"Memory, JSONL, SQLite, Postgres, S3.","open-source-ledger.85a4325174":"Across 9 typed categories.","open-source-ledger.54398265bf":"Event variants","open-source-ledger.10e7f2f495":"Typed, hash-chained, and queryable.","open-source-ledger.9fe381468b":"Ledger by the numbers","open-source-ledger.2895f84277":"Replayable end-to-end","open-source-ledger.acaaaf846b":"Tamper-evident","open-source-ledger.ac27ed38ab":"Walk to a timestamp, rebuild state.","open-source-ledger.fb1bbd1f19":"Linear walk","open-source-ledger.321252ba5f":"Five backends","open-source-ledger.f6976847fa":"Trust anchors seal a segment.","open-source-ledger.ed36a1a142":"Ed25519 anchor","open-source-ledger.c0fb1b2f0d":"Each entry folds in the previous hash.","open-source-ledger.0c95e0b5c6":"BLAKE3 link","open-source-ledger.d76f47eec4":"One of 23 typed variants is added to the tail.","open-source-ledger.5a7f106ecc":"Typed entry","open-source-ledger.98d4944aa2":"Append to replay","open-source-ledger.1c4fd778bd":"EVENT PIPELINE","open-source-ledger.4e250b4fde":"REPLAY","open-source-ledger.34512fba1d":"PERSIST","open-source-ledger.6c516a9cdc":"SIGN","open-source-ledger.2d533b9d9f":"HASH","open-source-ledger.025e07020e":"APPEND","open-source-ledger.515be2e1fe":"Events are typed, BLAKE3-hashed, Ed25519-signed at trust anchors, and persisted to a backend of your choice. The pipeline is the same regardless of storage. Hover a stage to read its contract.","open-source-ledger.8a32a688e1":"Hash. Sign. Replay.","open-source-ledger.f2903e2088":"Append.","open-source-ledger.b040b4179b":"Architecture","open-source-ledger.23f15552e8":"Hash chain is evidence","open-source-ledger.f8d8991f8b":"Logs are not evidence","open-source-ledger.9e0b3bf5b1":"Cannot reconstruct state from the log alone.","open-source-ledger.b90a38ae7f":"No replay","open-source-ledger.f61882a2ca":"Multi-process clocks drift. No canonical order.","open-source-ledger.fa8cb10473":"Out of order","open-source-ledger.4dc0a92aed":"no integrity","open-source-ledger.c501736247":"Tail-truncate, log-rotate, easy to alter.","open-source-ledger.07ca44c83d":"Mutable","open-source-ledger.91f1447d0b":"no schema","open-source-ledger.a98ec2c84a":"Free-text, grep-only, ambiguous fields.","open-source-ledger.5ffffa9c4a":"Unstructured","open-source-ledger.2d833ba488":"Four observed gaps","open-source-ledger.9db2289885":"WHY LOGS FAIL","open-source-ledger.5d693aa68b":"NO INTEGRITY","open-source-ledger.b4dee9d399":"NO REPLAY","open-source-ledger.1a5065e6a6":"UNSTRUCTURED","open-source-ledger.4c25e3fbac":"Most AI systems write unstructured text logs that nobody can replay. SIEM dashboards summarise, but they cannot reconstruct a decision. Auditors are left with prose.","open-source-ledger.8635d531a1":"are not evidence.","open-source-ledger.fd0f035ee7":"AI logs today","open-source-ledger.8a9400005c":"Logs cannot replay a system","open-source-ledger.b13e136af4":"EU origin","open-source-ledger.2513a48834":"No broker or hosted event service.","open-source-ledger.562de5e6e7":"Edition 2021","open-source-ledger.e2ae20d9ae":"Rust","open-source-ledger.52149322c8":"Linear walk, no solver dependency.","open-source-ledger.c0f85d6679":"Replay","open-source-ledger.ebc75cd71f":"O(n)","open-source-ledger.6e1f3db0ab":"Mem, JSONL, SQLite, PG, S3.","open-source-ledger.b3776d63ad":"Backends","open-source-ledger.43c9eac60a":"Across 9 categories.","open-source-ledger.e0c97bd053":"What ships","open-source-ledger.6f19d16ea8":"PROJECT STAT","open-source-ledger.949b542842":"O(n) REPLAY","open-source-ledger.a063f9f012":"One command. The replay walks every event in order, verifies the BLAKE3 chain, and rebuilds the state at any timestamp. The figures below are an in-memory benchmark snapshot from the supplied Ledger source, not a published SLA. Run the harness on your own hardware.","open-source-ledger.e701c3712a":"Every decision reconstructed.","open-source-ledger.3e6df79cba":"ledger replay","open-source-ledger.acb04fe99d":"The query","open-source-ledger.1e41ef2a5f":"No re-platforming","open-source-ledger.0bd1a67d1a":"Move freely","open-source-ledger.a520bde95d":"Cut off from the internet, for the most sensitive records.","open-source-ledger.cd36883cc4":"Fully sealed off","open-source-ledger.1752e07df4":"A cloud region pinned to a European country, under European rules.","open-source-ledger.b477a9ed0e":"A cloud in Europe","open-source-ledger.b9b2bbbc78":"It runs on the computers your own team manages, inside your walls.","open-source-ledger.b43a584c45":"In your building","open-source-ledger.2e1278ae29":"One record, no rebuild","open-source-ledger.cf4c21c3a7":"THREE POSTURES","open-source-ledger.b69bf7e246":"SEALED OFF","open-source-ledger.492c0dbda6":"EU CLOUD","open-source-ledger.8bd5f943bf":"EU cloud. Sealed off.","open-source-ledger.fbefed778b":"Your building.","open-source-ledger.1d197d39c5":"Where it runs","open-source-ledger.dffeefde83":"Project properties and supported deployment modes; not a service-level or capacity claim.","open-source-ledger.65759c0439":"Built in the Netherlands.","open-source-ledger.44ab85a252":"Origin","open-source-ledger.c82d1b09cf":"EU","open-source-ledger.e4e490c7ce":"Your building, EU cloud, or sealed off.","open-source-ledger.5e41344d14":"Ways to run it","open-source-ledger.cf7caf33ce":"None required to append, verify, or replay.","open-source-ledger.1ef1565eea":"External brokers","open-source-ledger.835da6eae7":"One chain across every supported backend.","open-source-ledger.fef8e889dc":"History model","open-source-ledger.6b5eb5323e":"Append · hash · replay","open-source-ledger.c900b782e4":"A record designed to move with the system","open-source-ledger.166eb69e89":"The facts that decide it","open-source-ledger.3cd8d4d21e":"Sealed when it happened","open-source-ledger.e2bd284bd9":"Not reconstructed later","open-source-ledger.e5fd4cede4":"Software bill of materials and attestation, recorded.","open-source-ledger.71be2d60c9":"What did you ship?","open-source-ledger.f76595e93b":"Requested, granted or denied, recorded in order.","open-source-ledger.d710f0b42e":"Who approved it?","open-source-ledger.425fb3def6":"AI Act","open-source-ledger.865009b6ca":"An AI incident is recorded the moment it is detected.","open-source-ledger.1e13b0d411":"When did you know?","open-source-ledger.3f8e051fe7":"Consent, DPIA, erasure and subject rights, each a typed event.","open-source-ledger.c6c5ed859b":"Was there consent?","open-source-ledger.d7b66b1801":"And the recorded event","open-source-ledger.aea6c8ea58":"WHAT A REVIEW ASKS","open-source-ledger.70f62d383e":"TOOL USE","open-source-ledger.f142bd1ae8":"SUPPLY CHAIN","open-source-ledger.d2534cffa4":"APPROVALS","open-source-ledger.380f063397":"EU AI ACT","open-source-ledger.20096140dd":"already on record.","open-source-ledger.e097bea376":"The answer is","open-source-ledger.8632e0b3b5":"When the auditor asks","open-source-ledger.e8c8a3c34a":"Lower risk","open-source-ledger.81d162731e":"Lower cost","open-source-ledger.68f6d4f41b":"Replay any window directly from the recorded events.","open-source-ledger.1607989434":"State you cannot rebuild","open-source-ledger.3bd957e109":"Approval events keep the actor, scope, and outcome together.","open-source-ledger.f6501ca9a2":"Missing approval context","open-source-ledger.ba9c8b0db0":"Hash links make every deletion, reorder, or mutation visible.","open-source-ledger.e5b4d87593":"Mutable snapshots","open-source-ledger.bf6e232a97":"One typed record replaces forensic joins across partial logs.","open-source-ledger.200a9fd9ea":"Fragmented evidence","open-source-ledger.0e45b2afd8":"And how this answers it","open-source-ledger.a25c8ddbe9":"WHAT A REVIEW WORRIES ABOUT","open-source-ledger.f812284999":"QUERYABLE","open-source-ledger.a3c32681d8":"TAMPER-EVIDENT","open-source-ledger.cdd26a8dc9":"REPLAYABLE","open-source-ledger.5b116da2ea":"ONE RECORD","open-source-ledger.70107051b1":"start with the answer","open-source-ledger.a29e5f15cd":"Stop rebuilding evidence","open-source-ledger.676ffa603b":"What it saves, what it de-risks","open-source-ledger.638edaf1ce":"Keep the same event shape in memory, SQLite, Postgres, S3, or your backend.","open-source-ledger.cfab3eb33f":"Choose the backend","open-source-ledger.e5d9e31cc5":"Reconstruct state from the events instead of trusting a snapshot.","open-source-ledger.eb9e736e5f":"Replay any window","open-source-ledger.de76a935ea":"Every entry extends the chain, so quiet changes fail verification.","open-source-ledger.bab9bef065":"Tamper-evident chain","open-source-ledger.cb750ef123":"New events are appended without rewriting earlier history.","open-source-ledger.416878d0ae":"Append each event","open-source-ledger.9a4e0aabc1":"Four operating properties","open-source-ledger.87c873497e":"THE RECORD AT A GLANCE","open-source-ledger.2531ed636c":"YOUR STORAGE","open-source-ledger.3115880727":"REPLAYABLE","open-source-ledger.c968638a6e":"HASH-CHAINED","open-source-ledger.825b742371":"TYPED EVENTS","open-source-ledger.91c120e5c6":"answers every audit","open-source-ledger.3d1e7bdec2":"One event history","open-source-ledger.47101bdd55":"What you are buying into","open-source-ledger.8cdd8d74d1":"The hardest moment is when an auditor or regulator asks a pointed question and the team has to go digging. Ledger answers a different way: the things a review asks about, consent, incidents, approvals, supply chain, tool use, are each recorded as their own sealed event when they happen. Pick a question below and see which recorded event already holds the answer.","open-source-ledger.2bb7852ca2":"The other question a review asks is where the software is allowed to run. The same record format and the same storage choices work in your own building, in a European cloud region, or fully sealed off from the internet. Moving between them is a copy, not a costly rebuild, so the decision is never final.","open-source-ledger.4f2181750c":"A procurement review asks two plain questions: what does this save, and what does it de-risk? Ledger keeps teams from stitching evidence together across partial logs during an incident. Its append-only chain also exposes any attempt to alter history after the fact.","open-source-ledger.d51c7888f5":"Applications change, providers move, and storage gets replaced. Ledger keeps one typed event history across those changes, with every entry linked to the one before it. Operations can trace an incident, answer an audit, or rebuild state without stitching together partial logs.","open-source-ledger.7fb327c2ad":"No machine far away","open-source-ledger.ef75f99a25":"No bill that grows","open-source-ledger.e70136dad1":"The record and its plain format belong to you, to read back anytime.","open-source-ledger.bfaea2b631":"Yours to read","open-source-ledger.2bce51f60a":"It stays beside the system it remembers, without another account or dashboard in the way.","open-source-ledger.aa4a69c684":"No extra account","open-source-ledger.e804a6ae6f":"It can sit on a computer in your own building, not a stranger’s far away.","open-source-ledger.04f45276cd":"It stays close","open-source-ledger.57f4ea40bb":"Three plain answers","open-source-ledger.a6c72c056a":"THE PRACTICAL FACTS","open-source-ledger.34d387a45c":"YOURS TO READ","open-source-ledger.1cd222daa7":"NO EXTRA ACCOUNT","open-source-ledger.1914767b52":"IN YOUR BUILDING","open-source-ledger.e7920fda1c":"always within reach.","open-source-ledger.cc6e2e2a7f":"Close to home,","open-source-ledger.b6e77c24ce":"Where it lives","open-source-ledger.4c5bd0c2c1":"Already written down","open-source-ledger.10fc3853d2":"Nothing to set up","open-source-ledger.e905ada6fb":"It can stay on a computer in your own building, close to home.","open-source-ledger.5154d8d8b9":"On a far-off machine?","open-source-ledger.c4fc1a8fb0":"It tells the very same story on every computer, every time.","open-source-ledger.7e90a6d522":"Different elsewhere?","open-source-ledger.e8df15e484":"You can read it back from any moment, like rewinding a home video.","open-source-ledger.33a6361a1d":"What if I forget?","open-source-ledger.4dc95e4d71":"Each line is sealed to the one before, so a quiet change shows itself.","open-source-ledger.fdef66504e":"Could it be changed?","open-source-ledger.f9d61136da":"And the plain answer","open-source-ledger.d8be0496de":"WHAT PEOPLE WONDER","open-source-ledger.22b3558123":"CLOSE TO HOME","open-source-ledger.690da68068":"SAME EVERYWHERE","open-source-ledger.a302a940cf":"NEVER FORGOTTEN","open-source-ledger.7353de3bd3":"CANNOT BE CHANGED","open-source-ledger.3f18109144":"answered plainly.","open-source-ledger.4f46bc1bd1":"The quiet worries,","open-source-ledger.52e04b202a":"One less thing to worry about","open-source-ledger.f4739e4d5f":"Always answerable","open-source-ledger.4a0026798c":"Quiet and honest","open-source-ledger.fc35b25566":"Wonder later what happened, or when? It is written down for you.","open-source-ledger.5107894be3":"You can ask","open-source-ledger.f5a6b2697b":"Read it back on any computer and you get the very same story.","open-source-ledger.d30d63ea2a":"It stays put","open-source-ledger.b4183aaf6c":"That line is sealed to the line before it, so no one can quietly change it.","open-source-ledger.30c3a4e634":"It is locked","open-source-ledger.4fa84929cd":"When the AI does anything, one new line gets noted down.","open-source-ledger.bc6201a929":"It is written","open-source-ledger.70a51df743":"Four simple steps","open-source-ledger.bbe874d679":"THE WHOLE STORY","open-source-ledger.c4f5f05c42":"YOU CAN ASK","open-source-ledger.8dc644d429":"IT STAYS THE SAME","open-source-ledger.50242c14ed":"IT GETS LOCKED","open-source-ledger.0821bdc099":"SOMETHING HAPPENS","open-source-ledger.7ba6a992cb":"start to finish.","open-source-ledger.6ff33bb387":"Four everyday moments,","open-source-ledger.41d7edc25a":"What it does for you","open-source-ledger.24c8566438":"Nothing to install for you","open-source-ledger.e019421780":"No computer talk","open-source-ledger.3685090f6c":"Runs alongside the system it remembers.","open-source-ledger.9dd0e4773e":"To keep","open-source-ledger.75f527181b":"Local","open-source-ledger.0e4bc9b8a7":"The story never changes.","open-source-ledger.945bc77616":"Every computer","open-source-ledger.b76aee974c":"Same","open-source-ledger.6d2ce6abe7":"Tampering shows itself at once.","open-source-ledger.3350b6f9ce":"Each line","open-source-ledger.66c95e7fc7":"Sealed","open-source-ledger.2f0b41e256":"It only ever adds, never erases.","open-source-ledger.1c54132b8e":"Record","open-source-ledger.9caa367403":"Honest","open-source-ledger.2a4827eec7":"In your own words","open-source-ledger.a1ec2cb1d8":"WHY IT IS SAFE","open-source-ledger.d8ddbc8b42":"YOURS TO KEEP","open-source-ledger.613cfdac00":"ASK LATER","open-source-ledger.b00a146670":"SAME ANSWER","open-source-ledger.6d79977ebc":"A SEAL","open-source-ledger.5f66a7cfe6":"A DIARY","open-source-ledger.7ad81b6665":"Nothing more to learn.","open-source-ledger.a56f046c1a":"It is an honest notebook.","open-source-ledger.704869f20f":"In plain words","open-source-ledger.db827043b3":"The notebook stays with the system that uses it. There is no separate account to check and no distant dashboard to trust: your own team can read the same ordered story whenever a question comes up.","open-source-ledger.8ebc9746bb":"It is fair to wonder what happens if something goes wrong. What if the record gets changed? What if you forget? What if it says something different elsewhere? Pick a worry below and see, in plain words, how an honest record answers it, so there is one less thing to lie awake about.","open-source-ledger.843ca259fe":"You do not have to understand any of the machinery. Here is the whole thing, start to finish, as four everyday moments. Something happens, it gets written down and locked, it stays the very same on every computer, and you can always ask about it later.","open-source-ledger.0f2c633388":"Think of it as a notebook that an AI tool keeps for itself. Every time it does something, it writes one more line at the bottom, and it never goes back to erase what is already there. Flip through the plain-words pages below to see, with everyday pictures, what each part of that notebook is really doing for you.","open-source-ledger.1725b559bd":"On-prem, EU cloud, sealed off","open-source-ledger.fcde5c325d":"Runs","open-source-ledger.79073eaaf2":"The Netherlands","open-source-ledger.6eef664840":"None","open-source-ledger.ad1aeaa4e4":"Hosted broker","open-source-ledger.bf5dde2d06":"External service","open-source-ledger.70f8bb9a8a":"Home","open-source-ledger.68c2cc7f0c":"Model","open-source-ledger.cba0624eb5":"Procurement sheet","open-source-ledger.6f696724c6":"What it saves and de-risks","open-source-ledger.b9948940ab":"Ledger is an event record for AI systems. It keeps an append-only history that cannot be quietly edited, so when an auditor or regulator asks what happened, you have a straight answer. It is built in the EU and can run entirely on infrastructure you control: one record of who called what, who approved what, and what happened next.","open-source-ledger.69becbb1fa":" show what happened","open-source-ledger.1d5be5a0ce":" rebuild any state","open-source-ledger.6575475ce1":"Keep the event history","open-source-ledger.9309f6a730":"Ledger","open-source-ledger.5491bb3fc9":"Can stay in your building","open-source-ledger.0b081a8ef4":"Direct for your team","open-source-ledger.64ae43e8fe":"Access","open-source-ledger.15d881f52c":"Ask what happened, anytime","open-source-ledger.2689163255":"You can","open-source-ledger.96a647dcb0":"The same on every computer","open-source-ledger.d39907caf6":"It repeats","open-source-ledger.20dac02e6d":"So nothing is changed","open-source-ledger.4c10b31d42":"It seals","open-source-ledger.e3496de5b8":"One new line at a time","open-source-ledger.2ab05d7411":"It writes","open-source-ledger.b7b925c5fc":"An honest notebook","open-source-ledger.f8c94a3b4b":"What it is","open-source-ledger.0882392b0c":"Read it in plain words","open-source-ledger.06c805023d":"A history you can ask for","open-source-ledger.d390f8bbde":"Ledger is the part of an AI system that quietly keeps an honest notebook. Every time the AI does something, it writes one new line and seals it, so nothing can be changed behind your back. Read it tomorrow, or on a different computer, and you get the same story in the same order.","open-source-ledger.8fa28cb8b1":" in plain words.","open-source-ledger.4cc5134b16":" for your AI,","open-source-ledger.8d07898a9e":"Memory, JSONL, SQLite, Postgres, S3","open-source-ledger.9e092dda4f":"Storage","open-source-ledger.05a4ccce2e":"23 variants, 9 categories","open-source-ledger.0b420fa096":"Event types","open-source-ledger.1ebd45fcbe":"Signing","open-source-ledger.a304010ca5":"BLAKE3 (32-byte)","open-source-ledger.873507a022":"Hash","open-source-ledger.0ed5388e31":"Rust (Edition 2021)","open-source-ledger.89b86ab0e6":"Language","open-source-ledger.3229609e15":"History model","open-source-ledger.942587e61e":"Project sheet","open-source-ledger.d4a74b503a":"Read the docs","open-source-ledger.ab51bc7b84":"When a regulator asks what happened in your system, you need more than logs: you need an append-only event record where every entry extends a BLAKE3 chain, every type is strongly typed, and any window of history can be replayed to reconstruct state. Ledger is event provenance for systems: who called what, who approved what, who read what, in order, without the possibility of quiet edits. Unlike AION, which certifies the reasoning steps inside a single AI decision, Ledger records what events happened across an entire system. Unlike Selvedge, which captures execution transcripts inside a sandbox, Ledger captures provenance across multiple actors and services.","open-source-ledger.a738552599":"Every event,","open-source-ledger.3a78695388":"Home","open-source-ledger.f411a1fb62":"Simple","open-source-ledger.54b26f7d3d":"Yours","open-source-ledger.ed077f3d81":"Open","open-source-ledger.87ec4027e1":"Append","open-source-ledger.d781e3ddee":"No lock","open-source-ledger.9170a8b2fb":"EU","open-source-ledger.1dabba21cd":"✓","open-source-ledger.341f82d43e":"APPEND","open-source-ledger.c1fb44c726":"HASH","open-source-ledger.1e2f12a3eb":"SIGN","open-source-ledger.f2539f6819":"PERSIST","open-source-ledger.92d23f5381":"REPLAY","open-source-ledger.91b097d7d4":"TOOL","open-source-ledger.30b82cbe46":"APPROVAL","open-source-ledger.d621c1a716":"SYSTEM","open-source-ledger.803ac20b03":"GDPR","open-source-ledger.b7896e7fe4":"AI ACT","open-source-ledger.c3a409ae6f":"SECURITY","open-source-ledger.44d6a8a73e":"S3","open-source-ledger.00db09ab06":"PLAIN","open-source-ledger.35e0d0360a":"LIVE","open-source-ledger.ddd2c0300d":"CALM","open-source-ledger.36e65c39f8":"HOME","open-source-ledger.6e10953f3e":"OPEN","open-source-ledger.5d0b2f6bd4":"OBSERVED","open-source-ledger.cbd1224832":"ON RECORD","open-source-ledger.0cd291828b":"DEPLOY","open-source-ledger.8215b59ccb":"ENGINE","open-source-ledger.4fe467ac80":"ALL ON","oss-ledger.hero.eyebrow":"SECOND RELEASE ROUND","oss-ledger.hero.title.lead":"The record","oss-ledger.hero.title.accent":"you can hand over.","oss-ledger.hero.technical.lede":"A tamper-evident audit log in Rust for AI tool interactions. Ledger appends one typed event per action and links each entry to the previous one with BLAKE3 hashes. Ledger publishes in the second round of Dweve's foundation release programme, with its documentation at docs.dweve.com the same day.","oss-ledger.hero.business.lede":"Ledger is a tamper-evident audit log in Rust for AI tool interactions, publishing under Apache 2.0 terms in the second round of Dweve's release programme. Choose where Ledger stores the record, then hand it over when someone asks what happened.","oss-ledger.hero.consumer.lede":"Ledger is a tamper-evident audit log. When software uses it, the record can show what happened in order and link each note to the one before it.","oss-ledger.hero.action.primary":"Read the record","oss-ledger.hero.action.secondary":"Ask about the release","oss-ledger.hero.consumer.secondary":"Read the record","oss-ledger.hero.ledger.label":"DWEVE LEDGER","oss-ledger.hero.ledger.pill":"APACHE 2.0 / ROUND 2","oss-ledger.hero.ledger.license.label":"LICENCE","oss-ledger.hero.ledger.license.value":"Apache 2.0","oss-ledger.hero.ledger.language.label":"LANGUAGE","oss-ledger.hero.ledger.language.value":"Rust","oss-ledger.hero.ledger.what.label":"WHAT IT IS","oss-ledger.hero.ledger.what.value":"Tamper-evident audit log","oss-ledger.hero.ledger.format.label":"FORMAT","oss-ledger.hero.ledger.format.value":"JSON Lines or binary","oss-ledger.hero.ledger.chain.label":"CHAIN","oss-ledger.hero.ledger.chain.value":"BLAKE3","oss-ledger.hero.ledger.stores.label":"STORAGE","oss-ledger.hero.ledger.stores.value":"Memory, files, databases, S3","oss-ledger.shell.breadcrumb.open":"Open Source","oss-ledger.shell.close.label":"Get started","oss-ledger.shell.close.headline":"Keep the record","oss-ledger.shell.close.body":"When the repository publishes, choose a storage backend, append a first event and run an integrity check before adding another service. Publication is planned in fortnightly rounds; the repository and its documentation go live together.","oss-ledger.shell.next.eyebrow":"CONTINUE EXPLORING","oss-ledger.banner.engNumbers.body":"Tool calls, approvals, artefacts, sessions, replays, rights, incidents, attestations and custom entries keep their own shape. The record is precise enough to query without flattening every action into an ambiguous log line.","oss-ledger.banner.engNumbers.footer":"The categories are named so the record can be asked a question later","oss-ledger.banner.engNumbers.secondary.left":"The panel names Ledger's own vocabulary. It is not a scorecard: each kind gives a question a reliable shape before anyone starts searching through prose.","oss-ledger.banner.engNumbers.secondary.right":"The categories are real, and a selection runs over the entries themselves. Ask for denied approvals in March and the answer is a query over the record, not a reconstruction.","oss-ledger.banner.engClose.body":"Put two copies of one record on the table. Pull out line 61,208. The disagreement has a value, a position and a verdict that does not need the author standing beside it.","oss-ledger.banner.engClose.footer":"One line differs, and it has a number","oss-ledger.banner.engClose.secondary.left":"The figures in the panel are illustrative, but the comparison is not. Two copies can agree entry by entry until the first point at which one no longer produces the other.","oss-ledger.banner.engClose.secondary.right":"That point has a line number and two fingerprints. The reader can quote it, inspect it and keep the two copies without asking the person who issued either one.","oss-ledger.banner.bizHandover.body":"The other side can receive a JSON Lines file, its format, the chain rule and the licence. They can keep their own copy and check it with a compatible verifier, without a dashboard account.","oss-ledger.banner.bizHandover.footer":"Apache 2.0 terms once it publishes, checked, not believed","oss-ledger.banner.bizHandover.secondary.left":"The handover starts with the underlying file, not a report generated from it. A text editor opens JSON Lines; once the repository publishes, it includes the matching verifier.","oss-ledger.banner.bizHandover.secondary.right":"The checker can run against the copy that was handed over. The other side can retain that copy and compare it with a later one without access to your systems.","oss-ledger.banner.bizNumbers.body":"The audit subsystem can keep a separate hash-chained trail of authentications, authorisation decisions, reads, configuration changes and system events, with its own retention policy and integrity check.","oss-ledger.banner.bizNumbers.footer":"A trail over the trail, sealed the same way","oss-ledger.banner.bizNumbers.secondary.left":"The record of access is a second sealed chain because a review asks who touched the evidence as well as what the evidence says. It records reads, decisions and changes separately from the customer record.","oss-ledger.banner.bizNumbers.secondary.right":"That trail has its own check and a ninety-day default retention period. Per-entity policy can keep the operational trace proportionate to the actor it describes.","oss-ledger.banner.conRead.body":"A JSON Lines record can be handed over as a file. It does not require a Ledger dashboard account to open, retain or check with a compatible verifier.","oss-ledger.banner.conRead.footer":"Checkable by somebody who is not us","oss-ledger.banner.conRead.secondary.left":"What arrives is ordinary lines of text, one for each thing that happened. The small marks on those lines show if somebody removed or changed a note before you saw it.","oss-ledger.banner.conRead.secondary.right":"You can give the file to somebody acting for you. Once Ledger publishes, they can run a matching check on their copy, without access to the organisation's systems.","oss-ledger.banner.engDurableReplay.body":"A write is useful evidence only when its durability choice is visible, its compact bytes still identify themselves and a stopped run can be walked without performing the work again. Those are three parts of one reading contract.","oss-ledger.banner.engDurableReplay.footer":"The next boundary is the store: the same reading must survive a change of home","oss-ledger.banner.engDurableReplay.secondary.left":"JSONL storage can sync every write or follow a configured batch, size or adaptive strategy. A successful return is not, on its own, proof that the device has the entry.","oss-ledger.banner.engDurableReplay.secondary.right":"The compact form carries a marker, version and checksum. Dry-run replay reads the same entries without calling external tools; exact and debug modes serve different investigation needs.","oss-ledger.banner.engPortableFields.body":"Moving a record from a file to a database must not change what an entry means. The content, chain position and sealed compliance fields travel together, and the destination is checked before the move is called complete.","oss-ledger.banner.engPortableFields.footer":"A portable record keeps one contract from storage through review","oss-ledger.banner.engPortableFields.secondary.left":"The migration follows entry addresses, resumes from a known point and verifies the destination against the source. It changes the home of the record without silently re-encoding its evidence.","oss-ledger.banner.engPortableFields.secondary.right":"Lawful basis, review date and the other compliance fields stay inside the entry seal. A reviewer therefore receives the action and the reason it was permitted as one object after the move.","oss-ledger.banner.bizConsentRecord.body":"Consent is not one current flag. The useful record keeps the request, its purpose and scope, the moment permission was granted and the separate moment it was withdrawn.","oss-ledger.banner.bizConsentRecord.footer":"The next control asks where those recorded details were allowed to be processed","oss-ledger.banner.bizConsentRecord.secondary.left":"A review asks whether permission existed at the time of an action. Keeping the grant and withdrawal as separate sealed entries answers that question without reconstructing an earlier value from a field that now says no.","oss-ledger.banner.bizConsentRecord.secondary.right":"Scope remains attached as well. The record can distinguish permission for one purpose from permission for three, and it leaves any use after withdrawal on a dated line that a reviewer can select.","oss-ledger.visual.onDisk":"ON DISK","oss-ledger.visual.refused":"REFUSED","oss-ledger.visual.stored":"STORED","oss-ledger.visual.readCorrupt":"READ-SIDE CORRUPT LINE","oss-ledger.visual.breakEntry":"BREAK AT ENTRY FOUR","oss-ledger.visual.oneLineDiffers":"ONE LINE DIFFERS","oss-ledger.visual.withdrawn":"WITHDRAWN","oss-ledger.visual.never":"NEVER","oss-ledger.visual.kept":"KEPT","oss-ledger.visual.approval":"APPROVAL / CONSENT","oss-ledger.visual.person":"PERSON ASKED","oss-ledger.visual.condition":"CONDITION","oss-ledger.visual.answer":"ANSWER","oss-ledger.visual.reason":"REASON IF NO","oss-ledger.visual.yes":"YES, 12 JAN","oss-ledger.visual.sameChain":"same chain","oss-ledger.visual.source":"source","oss-ledger.visual.archive":"archive","oss-ledger.visual.entry":"entry","oss-ledger.visual.decision":"decision","oss-ledger.visual.checkable":"CHECKABLE","oss-ledger.visual.breakPrevious":"previous value not produced by this file","oss-ledger.visual.corruptNeighbours":"4,118, neighbours intact","oss-ledger.visual.diffNumber":"and it has a number","oss-ledger.visual.withdrawnOpen":"one use remains open","oss-ledger.visual.partnerNineDays":"partner sharing, nine days","oss-ledger.visual.conditionAttached":"the condition stays attached","oss-ledger.visual.toAnswer":"to the answer","oss-ledger.visual.chainContinuous":"CHAIN CONTINUOUS","oss-ledger.visual.throughMaterial":"through every material","oss-ledger.visual.oneAfternoon":"ONE AFTERNOON, ONE RUN","oss-ledger.visual.lineOrder":"the line stays in order","oss-ledger.visual.status.broken":"BROKEN","oss-ledger.visual.status.checked":"CHECKED","oss-ledger.visual.meta.measured":"MEASURED","oss-ledger.visual.meta.illustrative":"ILLUSTRATIVE","oss-ledger.visual.bookMissing":"ONE PAGE IS MISSING","oss-ledger.visual.bookSeam":"the next seal matches no page left in the book","oss-ledger.visual.correctionVisible":"THE CORRECTION STAYS VISIBLE","oss-ledger.visual.correctionNoErase":"the first entry remains beside it","oss-ledger.visual.walkerOne":"A PERSON TODAY","oss-ledger.visual.walkerTwo":"A PERSON LATER","oss-ledger.visual.permissionAttached":"PERMISSION ATTACHED","oss-ledger.visual.notWrittenAfter":"NONE OF THESE NOTES WAS WRITTEN BY HAND AFTERWARDS","oss-ledger.visual.compact.command":"cargo test compact_encoding_is_30_percent_smaller","oss-ledger.visual.correction.entries":"ENTRY 8,112\u001fENTRY 8,140","oss-ledger.visual.correction.amounts":"5,000 EUR for 500\u001f5,000 EUR for 5,000\u001f5,000 EUR for 5,000","oss-ledger.visual.consent.dates":"12 JAN\u001fJAN\u001fAPR\u001f4 JUN\u001fJUL","oss-ledger.visual.consent.timeline":"1 May / 09:14\u001f18 May / 16:42\u001f27 May / 11:03","oss-ledger.visual.compliance.dates":"3 March / 11:04\u001f3 March\u001f19 March","oss-ledger.section.led-eng-chain.visualTitle":"The break in the chain","oss-ledger.section.led-eng-refused.visualTitle":"The write gate","oss-ledger.section.led-eng-file.visualTitle":"The line formats","oss-ledger.section.led-eng-durability.visualTitle":"Flush choices over one run","oss-ledger.section.led-eng-compact.visualTitle":"The compact record","oss-ledger.section.led-eng-replay.visualTitle":"Replay without action","oss-ledger.section.led-eng-storage.visualTitle":"One check, five stores","oss-ledger.section.led-eng-move.visualTitle":"The migration pass","oss-ledger.section.led-eng-compliance.visualTitle":"Fields inside one seal","oss-ledger.section.led-eng-thread.visualTitle":"A session view","oss-ledger.section.led-eng-agents.visualTitle":"The eight-tool rail","oss-ledger.section.led-eng-surfaces.visualTitle":"One record, three doors","oss-ledger.section.led-biz-account.visualTitle":"Four sources, one account","oss-ledger.section.led-biz-append.visualTitle":"A correction trail","oss-ledger.section.led-biz-findings.visualTitle":"Where verification stops","oss-ledger.section.led-biz-questions.visualTitle":"The entries a review asks for","oss-ledger.section.led-biz-consent.visualTitle":"A dated consent trail","oss-ledger.section.led-biz-locality.visualTitle":"Required and actual","oss-ledger.section.led-biz-oversight.visualTitle":"The named breach","oss-ledger.section.led-biz-retention.visualTitle":"A reason to keep","oss-ledger.section.led-biz-move.visualTitle":"The record changes ground","oss-ledger.section.led-biz-cost.visualTitle":"The self-managed path","oss-ledger.section.led-con-today.visualTitle":"An afternoon in four notes","oss-ledger.section.led-con-sealed.visualTitle":"The stitched chain","oss-ledger.section.led-con-consent.visualTitle":"The dated yes and no","oss-ledger.section.led-con-approval.visualTitle":"A permission with conditions","oss-ledger.section.led-con-replay.visualTitle":"A read-back boundary","oss-ledger.section.led-con-kept.visualTitle":"The keeping line","oss-ledger.visual.writtenAsHappened":"each one was written as it happened","oss-ledger.section.led-eng-chain.chrome":"Two fingerprints, one entry\u001fOne hash catches an edit\u001fthe other catches a gap\u001fThe mechanism\u001fCONTENT HASH\u001eCHAIN HASH\u001eBLAKE3\u001fWhat each hash covers\u001fand what it therefore catches\u001fSEALED\u001fThe seal holds because a nonsense entry never gets into the file in the first place","oss-ledger.section.led-eng-refused.chrome":"Refused before it is stored\u001fAn entry an hour ahead\u001fnever enters the record\u001fWhy it matters\u001fVALIDATED\u001eREFUSED\u001eAT WRITE TIME\u001fWhat the door checks\u001fbefore the line exists\u001fAT THE DOOR\u001fA refusal is part of the evidence, not an exception hidden in an operator log","oss-ledger.section.led-eng-file.chrome":"The record on disk\u001fThe record is a text file\u001fwith one entry per line\u001fWhat somebody else needs\u001fONE LINE EACH\u001ePLAIN TEXT\u001eREADABLE\u001fFormats on disk\u001fthe line tells you how to read it\u001fON DISK\u001fA plain file gives the other side somewhere concrete to start","oss-ledger.section.led-eng-durability.chrome":"The write said it landed\u001fThe disk had not seen it\u001funtil the flush\u001fFour durability choices\u001fEVERY WRITE\u001ePER BATCH\u001eADAPTIVE\u001fWhen the bytes leave\u001fthe setting is visible\u001fDURABILITY\u001fA write is durable when the storage path says why it is durable","oss-ledger.section.led-eng-compact.chrome":"One entry, two ways to read it\u001fRead the entry in place\u001frather than rebuild it\u001fThe compact form\u001fREAD IN PLACE\u001eCOMPACT AND CHECKSUMMED\u001fThe compact record\u001fa marker, version and checksum\u001fFORMAT\u001fSmall bytes still have to tell an auditor what they are","oss-ledger.section.led-eng-replay.chrome":"A stopped run can be read back\u001fStep through last month\u001fwithout repeating any of it\u001fThree ways to walk it\u001fEXACT\u001eDRY RUN\u001eSTEP AND BREAK\u001fReplay modes\u001fsame entries, different reach\u001fREPLAY\u001fA record earns trust when a stopped run can be walked without starting it again","oss-ledger.section.led-eng-storage.chrome":"One interface, many homes\u001fThe same check runs over\u001fwhichever store you chose\u001fThe storage interface\u001fONE CHECK\u001eANY STORE\u001eIN BATCHES\u001fStorage reach\u001fone record, five materials\u001fINTERFACE\u001fA change of storage must not become a change of evidence","oss-ledger.section.led-eng-move.chrome":"The record can move\u001fA file today, a database\u001fin eighteen months from now\u001fA move you can audit\u001fBY ADDRESS\u001eRESUMABLE\u001eVERIFIED AFTER\u001fMigration stages\u001fno silent re-encoding\u001fMIGRATE\u001fPortability is useful only when the seal travels with the bytes","oss-ledger.section.led-eng-compliance.chrome":"Compliance belongs on the entry\u001fLawful basis is a field\u001fnot a spreadsheet column\u001fWhy the field is sealed\u001fON THE ENTRY\u001eSEALED WITH IT\u001eDEFAULTED\u001fFields inside the seal\u001fthe answer travels with the action\u001fFIELDS\u001fOne action and its lawful basis should be one object","oss-ledger.section.led-eng-thread.chrome":"Every session is a thread\u001fA thread is carried\u001finside the seal\u001fDerived, not duplicated\u001fA THREAD\u001eIN THE SEAL\u001eBUILT ON READ\u001fThread fields\u001fthe selection is a view\u001fDERIVED\u001fA useful view should never outrank the record it came from","oss-ledger.section.led-eng-agents.chrome":"The agent-facing surface\u001fAn agent appends entries\u001fand checks its own record\u001fEight operations, one rail\u001fEIGHT TOOLS\u001eON STDIN\u001eSELF CHECK\u001fAgent operations\u001feach call has a schema\u001fAGENTS\u001fThe protocol is small enough to inspect one turn at a time","oss-ledger.section.led-eng-surfaces.chrome":"The same record reaches callers\u001fOne record, three ways in\u001fand the same seals on it\u001fThree caller surfaces\u001fLIBRARY\u001eCOMMAND LINE\u001eHTTP\u001fCaller-led entry\u001fsame record, different door\u001fSURFACES\u001fConvenience changes at the edge; the evidence does not","oss-ledger.section.led-biz-account.chrome":"The evidence you hand over\u001fIs a summary you wrote\u001for a record that can answer back\u001fFour accounts, one test\u001fYOUR LOGS\u001eYOUR REPORT\u001eYOUR WORD\u001fWhat was observed\u001fand who had to remember it\u001fOBSERVED\u001fA report about your system is still your account of your system","oss-ledger.section.led-biz-append.chrome":"Corrections stay visible\u001fA correction is a new line\u001fand the first one stays\u001fThe correction trail\u001fAPPEND ONLY\u001eA NEW LINE\u001eDATED\u001fOriginal and correction\u001fboth remain answerable\u001fRECORD\u001fA correction you can see is safer than a clean history nobody can prove","oss-ledger.section.led-biz-findings.chrome":"Verification hands back findings\u001fIt hands back the entries\u001fand how each one failed\u001fA finding has a position\u001fFINDINGS\u001eBY ENTRY\u001eBY LINE\u001fWhat the check returns\u001fpoints at, leaves in question\u001fCHECKED\u001fThe useful answer is where the record stopped agreeing with itself","oss-ledger.section.led-biz-questions.chrome":"Reviews ask for kinds of entry\u001fThe questions a review asks\u001fare already on the record\u001fOne question, one kind\u001fAPPROVALS\u001eINCIDENTS\u001eRIGHTS\u001fWhat each kind keeps\u001fthe question closes on the line\u001fON RECORD\u001fA review should find a named entry, not a team member who remembers","oss-ledger.section.led-biz-consent.chrome":"Consent has a time and scope\u001fA withdrawal has a time\u001fnot a flag set back to no\u001fConsent is a trail\u001fPURPOSE\u001eSCOPE\u001eWITHDRAWN AT\u001fThe use matrix\u001fan empty cell still says something\u001fGDPR\u001fA person should be able to point to the day they said yes and the day they stopped","oss-ledger.section.led-biz-locality.chrome":"Where the data had to stay\u001fAnd where it actually sat\u001fare both recorded\u001fRequired and actual\u001fREQUIRED\u001eACTUAL\u001eATTESTED AT\u001fThe crossed-over card\u001fa location change has a clock\u001fSOVEREIGN\u001fA residency promise is only as good as the place the record says the bytes were","oss-ledger.section.led-biz-oversight.chrome":"A named breach is better than a vague warning\u001fHigh risk and no oversight\u001fcomes back as a finding\u001fThe check names the gap\u001fHIGH RISK\u001eNO OVERSIGHT\u001eNAMED\u001fWhat comes with the failure\u001fone breach, three next steps\u001fAI ACT\u001fOversight is evidence when a person is named before the action runs","oss-ledger.section.led-biz-retention.chrome":"A period is a decision\u001fEvery retention period\u001fcarries a reason and a date\u001fKeep, review, release\u001fA PERIOD\u001eA REASON\u001eA REVIEW DATE\u001fRetention state\u001fthe pin says who reviews it\u001fRETENTION\u001fKeeping less is not forgetting when the reason and review date remain","oss-ledger.section.led-biz-move.chrome":"Storage is a choice, not a destiny\u001fThe storage you choose now\u001fis not the one it ends on\u001fPortable by construction\u001fTHE RECORD OUTLIVES IT\u001eSTILL CHECKABLE\u001fOne record, changing ground\u001fnothing stamped at the joins\u001fPORTABLE\u001fA migration is complete when the other side can check the target without your source","oss-ledger.section.led-biz-cost.chrome":"A licence you can read once it publishes\u001fThe record is a file\u001fon hardware you already run\u001fWhat remains yours\u001fAPACHE 2.0\u001eYOUR MACHINES\u001eYOUR FILE\u001fThe path without a vendor\u001fread it, run it, keep it\u001fPATH\u001fApache 2.0 terms give the record room to remain useful after the procurement meeting ends","oss-ledger.section.led-con-today.chrome":"A small record of an ordinary afternoon\u001fSomething acted for you\u001fand wrote down what it did\u001fWhat you can point to\u001fWRITTEN DOWN\u001eIN ORDER\u001eKEPT\u001fThe plain afternoon\u001ffour notes, no dashboard\u001fPLAIN\u001fNone of these notes was written by hand afterwards","oss-ledger.section.led-con-sealed.chrome":"A mark follows every note\u001fEach note carries a mark\u001ftaken from the one before\u001fWhy the mark matters\u001fSEALED\u001eANYONE CAN CHECK\u001fA page and its answer\u001fthe seam is visible\u001fLOCKED\u001fYou do not need to trust the person who hands you the notebook","oss-ledger.section.led-con-consent.chrome":"Your yes has a date\u001fWhat you agreed to is kept\u001fand the day you stopped\u001fYour yes and no\u001fWHAT YOU AGREED\u001eWHEN\u001eTHE PROOF\u001fThe answer on the form\u001fa date is part of the yes\u001fYOUR YES\u001fA changed answer leaves the earlier answer where you can still see it","oss-ledger.section.led-con-approval.chrome":"Permission has a person attached\u001fWho was asked, and what\u001fthey attached to the yes\u001fA permission slip\u001fWHO WAS ASKED\u001eWHAT THEY SAID\u001eTHE CONDITION\u001fThe answer column\u001fthree permissions, three shapes\u001fPERMISSION\u001fA yes is not a blank cheque when its condition is on the line","oss-ledger.section.led-con-replay.chrome":"Reading is not doing\u001fIt can all be read back\u001fwithout anything happening\u001fA quiet walkthrough\u001fREAD BACK\u001eNOT REDONE\u001eSTEP BY STEP\u001fRead-only replay\u001fthe work stays behind the line\u001fREADING\u001fA record is safer when reading it cannot repeat the action","oss-ledger.section.led-con-kept.chrome":"Kept for a stated reason\u001fKept for a stated time\u001fwith the reason written down\u001fHow long, why, where\u001fHOW LONG\u001eWHY\u001eWHERE\u001fThe keeping line\u001fa reason hangs beside each ribbon\u001fKEPT\u001fLetting go can be a recorded decision too","oss-ledger.side.chain":"EDITS A VALUE\u001fthe content hash stops matching\u001fREMOVES AN ENTRY\u001fthe next entry points at nothing\u001fREORDERS TWO\u001ftime and order no longer agree\u001fAPPENDS AT THE END\u001fthe only legal change","oss-ledger.side.refusal":"THE INPUT\u001fchecked before it is stored\u001fTHE VERDICT\u001frefused or accepted at the door\u001fTHE POSITION\u001fthe line is named on read\u001fTHE FINDING\u001fthe record stays available to check","oss-ledger.side.file":"PLAIN JSON\u001fone readable entry per line\u001fCMP:\u001fa compressed line says what it is\u001fB64:\u001fthe compact marker names its form\u001fCORRUPT LINE\u001fneighbouring entries remain readable","oss-ledger.side.compact":"DLEV\u001fthe compact marker\u001fVERSION\u001folder files stay readable\u001fFLAGS\u001fthe representation is named\u001fBLAKE3\u001fa checksum closes the record","oss-ledger.side.timeline":"THE MOMENT\u001fthe time is written down\u001fTHE DECISION\u001fthe action and answer stay together\u001fTHE REVIEW\u001fa date says when to look again\u001fTHE RESULT\u001fthe order remains checkable","oss-ledger.side.compare":"THE FIRST VALUE\u001fit remains on the record\u001fTHE SECOND VALUE\u001fit is a new, linked answer\u001fTHE DIFFERENCE\u001fit has a field and a position\u001fTHE CHECK\u001fit names what changed","oss-ledger.side.grid":"THE SCOPE\u001feach use has its own place\u001fTHE EMPTY CELL\u001fnever granted is not forgotten\u001fTHE CHANGE\u001fthe time remains visible\u001fTHE QUESTION\u001fthe record already holds an answer","oss-ledger.side.form":"THE REQUEST\u001fwho was asked and when\u001fTHE ANSWER\u001fyes, no, or still open\u001fTHE CONDITION\u001fthe words stay with the answer\u001fTHE REASON\u001fa refusal keeps its reason","oss-ledger.side.stack":"THE SOURCE\u001fthe record starts where it is written\u001fTHE MOVE\u001fthe material can change\u001fTHE SEAL\u001fthe chain stays continuous\u001fTHE TARGET\u001fit is checked before it is used","oss-ledger.banner.led-eng-numbers.chrome":"LEDGER / THE VOCABULARY\u001fNine groups, 23 kinds\u001fOne typed vocabulary\u001fThe vocabulary","oss-ledger.banner.led-eng-durable-replay.chrome":"LEDGER / THE READING CONTRACT\u001fThe write can stop\u001fthe record must still walk\u001fDurability and replay","oss-ledger.banner.led-eng-portable-fields.chrome":"LEDGER / THE MOVE\u001fMove the bytes\u001fkeep the sealed meaning\u001fOne record across stores","oss-ledger.banner.led-eng-close.chrome":"LEDGER / THE CLOSING TEST\u001fA log is something you trust\u001fthis is something you check\u001fTwo copies of one record","oss-ledger.banner.led-biz-handover.chrome":"LEDGER / THE HANDOVER\u001fCan they check it without you\u001fthat is the whole test\u001fWhat the other side can do","oss-ledger.banner.led-biz-consent-record.chrome":"LEDGER / THE CONSENT TRAIL\u001fA yes is one moment\u001fscope and withdrawal are the record\u001fPermission over time","oss-ledger.banner.led-biz-numbers.chrome":"LEDGER / THE SECOND RECORD\u001fA second sealed record\u001fcovers who touched the first\u001fThe record about the record","oss-ledger.banner.led-con-read.chrome":"LEDGER / WHO CAN CHECK\u001fNobody can tidy it up\u001fbefore you are shown it\u001fWhat you ask for, and what arrives","oss-ledger.section.led-eng-chain.body":"Ledger validates an event's content hash before it appends the event. The event can also carry the previous event's chain hash, so a verifier can detect a missing or reordered entry in the copy it checks. Content-hash recomputation on reads is available through the optional VerifiedStore wrapper.","oss-ledger.section.led-eng-chain.secondary":"The content hash covers the event type and sorted metadata. The chain hash binds the event identifier, timestamp, predecessor, session and content hash together, so the two answer different questions about the same entry.\u001fBoth use BLAKE3. Chain verification recomputes predecessor links, while VerifiedStore can additionally recompute the content hash. These checks report a mismatch; they do not stop an authorised storage operator from replacing every copy.","oss-ledger.section.led-eng-refused.body":"Three checks run before Ledger stores anything. A timestamp more than an hour into the future is refused. Metadata beyond 64 KB is refused rather than trimmed to fit. A fingerprint supplied by a caller that does not match a recomputation of the entry it claims to cover is refused. What a record declines to write is part of what the record is worth.","oss-ledger.section.led-eng-refused.secondary":"An hour-ahead clock would put an entry before events that had not happened yet, so Ledger refuses it. The 64 KB ceiling keeps an entry from becoming a pasted response body that nobody meant to store in the record.\u001fLedger recomputes a supplied fingerprint before accepting it, so callers cannot invent their own seal. Fuzzed boundary inputs return named failures for the caller to handle rather than one generic rejection.","oss-ledger.section.led-eng-file.body":"JSONL storage writes one JSON object per line and appends new lines to the file. A text editor can open and count those lines. The same reader can also recognise compressed and compact-binary lines by their prefixes. Checking integrity requires a compatible implementation of Ledger's event and hash rules.","oss-ledger.section.led-eng-file.secondary":"JSON Lines make the stored entries directly inspectable without a proprietary viewer. A compatible verifier still needs to parse the event and apply its hash rules, rather than treating BLAKE3 alone as a file format.\u001fA corrupt line is reported by position, so recovery focuses on that entry rather than the whole file. The lines around it stay readable, and counting them is still something a person can do by hand.","oss-ledger.section.led-eng-durability.body":"The gap between a write returning and the operating system putting bytes on a device is where a power failure can lose recent entries. JSONL storage lets you choose a sync strategy: every write, batch or size thresholds, or an adaptive strategy. That is a durability and throughput decision for the deployment, not evidence that a successful write has already reached durable media.","oss-ledger.section.led-eng-durability.secondary":"The top-level JSONL configuration enables sync. JsonlConfig exposes the more specific strategies, per write, per batch, by size threshold or adaptive, when the deployment needs a different trade-off.\u001fKeep the active durability configuration with your operational evidence: a chain check can detect inconsistency in stored events, but it cannot recover an entry that was never durably written.","oss-ledger.section.led-eng-durability.secondary.more":"The committed position stays visible in the record, so an incident review does not have to guess which durability rule was active.","oss-ledger.section.led-eng-compact.body":"Ledger can read an entry where it lies. The reader points into the buffer and takes the fields it needs instead of allocating a copy of every field on the way past, so going through a long file costs what it costs to get the bytes off the device rather than what it costs to turn them into objects. The rebuilding path is still there for callers that want owned values, and both read the same bytes.","oss-ledger.section.led-eng-compact.secondary":"A compact entry begins `DLEV`, carries a two-byte version and a flag, then ends with its own BLAKE3 checksum. Older files remain readable because the representation names itself.\u001fThe compact form must test at least thirty percent smaller than the same text entry. The measuring harness ships with the code, so the claimed saving is reproducible and inspectable.","oss-ledger.section.led-eng-replay.body":"Replay reads entries in order and offers exact, dry-run and debug modes. Dry run mocks external dependencies, so it is the mode to use when you need to inspect a recorded session without calling tools again. Exact and debug modes support validation or controlled investigation.","oss-ledger.section.led-eng-replay.secondary":"A replay can start from a session, a range, a single event or, when enabled, a snapshot. Hooks are registered and cleared deliberately, so nothing stays attached from the previous investigation.\u001fTreat replay as a tool for inspecting or rebuilding recorded state, with the mode chosen explicitly for the risk of the surrounding workflow rather than left at whatever the last session used.","oss-ledger.section.led-eng-replay.secondary.more":"That makes replay a bounded investigation, not a second execution with an unknown result.","oss-ledger.section.led-eng-storage.body":"Ledger separates its API from storage through the LedgerStorage interface. Available implementations include memory, JSONL, binary files, SQLite, PostgreSQL and S3, with feature flags for optional backends. VerifiedStore is an optional wrapper that adds content-hash, chain and timestamp checks around a backend.","oss-ledger.section.led-eng-storage.secondary":"Keeping verification in a wrapper avoids copying the same read-side checks into every backend. The wrapper reports mismatches in the records it reads; it is not a substitute for controlling access to storage or retaining an independent copy.\u001fChoose a backend for its durability, query and operational properties, then verify the stored record in the way your deployment requires. The interface is what keeps that a storage decision rather than an evidence one.","oss-ledger.section.led-eng-storage.secondary.more":"A new backend therefore inherits the proof rule before it earns the right to carry production history.","oss-ledger.section.led-eng-move.body":"Moving a Ledger record is a job rather than a script. Source and target are named by address, entries move in batches with progress reported, a stopped run picks up where it stopped, and the chain is verified in its new home before anything relies on it. Until it verifies there the old home is still the record, because a move that quietly reordered the entries would otherwise look exactly like a success.","oss-ledger.section.led-eng-move.secondary":"Ledger starts with memory or JSONL storage; SQLite, PostgreSQL and S3 are available when their features are enabled. A migration job carries a record by source and target address.\u001fAddresses cover files, databases and object storage. Validate event counts, latest hashes and integrity at the target before relying on it, and keep the old home until that validation has passed.","oss-ledger.section.led-eng-move.secondary.more":"A destination that cannot pass that check has received data, but it has not received a ledger.","oss-ledger.section.led-eng-compliance.body":"Compliance data sits on the Ledger entry itself: the lawful basis, the consent it relied on, the region the data had to stay in, where it was actually processed, and how long it may be kept. Seventeen fields, each with a default, so every entry carries them whether or not somebody filled them in.","oss-ledger.section.led-eng-compliance.secondary":"Keeping compliance in another store creates a second history that can drift. On the entry, the lawful basis, the ground a piece of processing rests on and one of the six the regulation allows, is covered by the same chain as the action.\u001fDefaulted fields turn a missing basis into a named finding, and a pseudonymised entry records that the identifying parts were replaced by a reference. The audit can point to the entry, field and action that need a response.","oss-ledger.section.led-eng-compliance.secondary.more":"The audit can name the missing field at the entry where it matters, alongside the action it justified.","oss-ledger.section.led-eng-thread.body":"Entries carry the identifier of the thread they belong to, inside the seal, and that is the whole of what a Ledger session is. Ask for a session and the answer is built by selecting the entries carrying that identifier, in order, at the moment you ask. The same selection assembles a single run, an afternoon, or a whole month.","oss-ledger.section.led-eng-thread.secondary":"Stored summaries are a second truth and the first thing to go stale. Ledger builds each session view directly from the sealed entries, at the moment the question is asked rather than the moment they were written.\u001fThat is a selection on read, not a row to maintain on write. The reader reconstructs the source instead of trusting another record's freshness, and the same selection assembles a run, an afternoon or a month.","oss-ledger.section.led-eng-thread.secondary.more":"The reader reconstructs the view from the source instead of maintaining a second record whose freshness must be assumed.","oss-ledger.section.led-eng-agents.body":"When the optional MCP server is enabled, Ledger exposes eight stdio tools: append, query, fetch an event or session, list sessions, verify integrity, read metrics and replay a session. Each tool has a JSON Schema for its arguments. Verification reports what the selected checker can establish about the record it read.","oss-ledger.section.led-eng-agents.secondary":"The MCP server wraps a Ledger instance; its storage is selected when that instance is configured. The same tool names can operate over a durable backend when that backend is enabled.\u001fAn operator can use the result to investigate a failing record, rather than treating a verification failure as an unexplained service symptom. The report names what the selected checker was able to establish.","oss-ledger.section.led-eng-agents.secondary.more":"The operator can point at the first failing entry instead of treating a bad result as a service-level mystery. Changing the storage does not change what the agent knows how to check.","oss-ledger.section.led-eng-surfaces.body":"Ledger is a Rust library first, and every failure comes back as a value the caller has to handle. It is also the `ledger` command line tool, which appends, fetches, queries, lists, verifies, counts, reports information and migrates, working on a file named `ledger.jsonl` unless you name another. And it is an HTTP service, with an OpenAPI document and a browsable page for it, so a team that does not write Rust still writes to the same record.","oss-ledger.section.led-eng-surfaces.secondary":"The library seals entries in process before the call returns. No network sits in the way. The command-line tool verifies and counts any copy handed to an operator or auditor. The library also exposes an Ed25519 signing interface for entries that need a signature from your own key.\u001fHTTP gives non-Rust systems append, query, session and metric endpoints under optional TLS. Whatever surface receives an entry, the same checks apply, and Apache 2.0 covers the source once Ledger publishes.","oss-ledger.side.cards":"THE SOURCE\u001fwhat it can tell you\u001fTHE RECORD\u001fthe action and its evidence together\u001fTHE QUESTION\u001fthe detail stays with it\u001fTHE ANSWER\u001fit can be checked later","oss-ledger.detail.lawfulBasis.term":"LAWFUL BASIS","oss-ledger.detail.lawfulBasis.body":"The ground a piece of processing rests on, one of the six the regulation allows.","oss-ledger.detail.pseudonymised.term":"PSEUDONYMISED","oss-ledger.detail.pseudonymised.body":"The identifying parts replaced by a reference, so the record stays usable and the person is not named in it.","oss-ledger.banner.secondaryKicker":"The test","oss-ledger.banner.secondary":"The panel is illustrative. The question is real: can somebody who is not us check what happened?","oss-ledger.banner.sideSub":"the answer stays visible","oss-ledger.banner.tag":"CHECKABLE","oss-ledger.banner.tag.durable":"READABLE AFTER STOP","oss-ledger.banner.tag.portable":"VERIFIED AFTER MOVE","oss-ledger.banner.tag.consent":"TIME AND SCOPE","oss-ledger.banner.led-eng-durable-replay.items":"Flush policy recorded\u001fCompact entry identifies itself\u001fReplay reads without acting\u001fReader stops on one entry","oss-ledger.banner.led-eng-portable-fields.items":"Source store read\u001fEntries moved by address\u001fSealed fields travel intact\u001fDestination verified","oss-ledger.banner.led-biz-consent-record.items":"Permission requested\u001fPurpose and scope attached\u001fGrant time sealed\u001fWithdrawal time sealed","oss-ledger.visual.kind.chain":"CHAIN","oss-ledger.visual.kind.refusal":"REFUSAL","oss-ledger.visual.kind.file":"FILE","oss-ledger.visual.kind.compact":"COMPACT","oss-ledger.visual.kind.timeline":"TIMELINE","oss-ledger.visual.kind.compare":"COMPARE","oss-ledger.visual.kind.grid":"GRID","oss-ledger.visual.kind.cards":"CARDS","oss-ledger.visual.kind.form":"FORM","oss-ledger.visual.kind.stack":"STACK","oss-ledger.section.led-biz-account.body":"A customer says the assistant cancelled something on their behalf and should not have. What you can produce is assembled from an application log that rotated a fortnight ago, a supplier dashboard that reports totals rather than actions, a ticket thread holding the customer's version, and somebody's memory of the release that week.","oss-ledger.section.led-biz-account.secondary":"An application log, supplier dashboard, ticket thread and memory may all be true, yet none is the record. They are a reconstruction controlled by the organisation answering, assembled from sources kept for other purposes.\u001fOlder cases are weakest, cost days to assemble, and arrive after sources have rotated away. Across the table that is an account rather than evidence, because nobody on the other side can check it against a copy of their own.","oss-ledger.section.led-biz-append.body":"Ledger provides append operations for event streams. An application can model a correction as a later event with a parent link to the event it corrects, keeping both in the retained record. An integrity check can then expose broken links in the copy being checked.","oss-ledger.section.led-biz-append.secondary":"A hash chain makes a retained record testable for gaps and reordered entries. It does not make storage indelible or prevent an authorised operator from replacing every copy, which is a different problem with a different answer.\u001fFor a correction trail you can rely on, define the correction event, retain independent copies and check them against the chain rule. The three together are what makes a later comparison mean anything at all.","oss-ledger.section.led-biz-findings.body":"Ledger's standard integrity report identifies broken predecessor links, timestamps out of order and missing parent references. The optional VerifiedStore wrapper can also recompute content hashes. These are findings about the copy and verifier you chose, not proof that no one ever replaced every available copy.","oss-ledger.section.led-biz-findings.secondary":"A broken predecessor link identifies the event after a gap or reordered sequence. A content-hash mismatch, when that check is enabled, identifies the event whose stored contents no longer match its hash.\u001fThose are different causes with different remedies, and reading them as one alarm throws the distinction away. Keep the verification report with the copy and configuration it checked, so a later reader knows what was tested.","oss-ledger.section.led-biz-questions.body":"Approvals requested, granted and denied. Consent. Data subject requests. Impact assessments. Erasure requests with their deadline. AI incidents. Bills of materials and attestations. Each is its own kind of entry with its own shape, recorded when it happened, so the question a reviewer asks is a selection rather than a project.","oss-ledger.section.led-biz-questions.secondary":"The value is in the shape, not the storage. An approval keeps who was asked, its deadline, its condition and its refusal reason, so the question survives the answer rather than collapsing into a yes or a no.\u001fAn erasure request keeps its legal deadline, while an artefact keeps type, location and fingerprint. A review can select its working set without rebuilding the evidence first, because the entry already carries the fields being asked about.","oss-ledger.section.led-biz-consent.body":"Ledger records consent with the purpose it was given for, the scope in detail, a version number, the evidence behind it, the moment it was granted and the moment it was withdrawn. A withdrawal is therefore an event with a time on it, rather than a field that used to say yes and now says no with nothing to show it ever changed.","oss-ledger.section.led-biz-consent.secondary":"A regulator asks whether consent existed then, not only whether it exists now. A flag hides the work that happened between a withdrawal and the next system catching up with it, because a flag has no memory of the gap.\u001fA recorded moment turns that window into a selection you can settle. Detailed scope also exposes consent for three purposes when only two were granted, which a single box cannot show whichever way it is set.","oss-ledger.section.led-biz-locality.body":"Each Ledger entry records the region the data was required to remain in, the location it was actually processed in, the moment that was attested, whether a cross-border transfer was approved, and which adequacy decision was relied on if one was. Two separate facts recorded separately, which is the only arrangement in which the gap between them can show.","oss-ledger.section.led-biz-locality.secondary":"A policy saying data stays in the European Union is only an intention. Required region and actual location become a control when both sit on the same entry and are compared as each entry is written, rather than at the next audit.\u001fThat catches a nineteen-minute overnight failover that no policy names. Its attestation and approval stay beside the mismatch, so a reviewer sees the breach as it happened rather than inferring it later.","oss-ledger.section.led-biz-locality.secondary.more":"The entry keeps the attestation and approval beside that mismatch, so a reviewer sees the breach as it happened rather than inferring it later.","oss-ledger.section.led-biz-oversight.body":"An automated decision recorded at high risk with nobody recorded as overseeing it does not pass quietly. It comes back as a named failure against Article 14 of the EU AI Act, with three remediation steps attached to the failure itself. Two warnings sit beside it: AI processing carrying no lawful basis, and no bill of materials above the confidential classification.","oss-ledger.section.led-biz-oversight.secondary":"A score must be interpreted before anybody can act, which is where findings disappear. A named breach carries its violated obligation and the remediation steps that answer it, so nothing has to be translated first.\u001fThe board receives work with an owner and a date, not a number to argue down. That is why a named failure is more useful than a pass: the work stays visible until the review is complete.","oss-ledger.section.led-biz-oversight.secondary.more":"The failure comes with its remediation steps, so the board receives a named obligation, an owner and a date rather than a score.","oss-ledger.section.led-biz-retention.body":"Retention in Ledger is not a number in a policy. It is a duration carried with the data, the rationale for that duration, and the date the decision is next reviewed. A validator warns when a review date has passed and when a period looks excessive for the category of data it covers.","oss-ledger.section.led-biz-retention.secondary":"Most organisations can show a retention schedule, not the reasoning or last review behind one line. Carried with the data, both become a lookup rather than a request to whoever owns the policy document.\u001fPolicies convert to delete, archive or keep-forever decisions with counts. Expiry arrives as a decision someone signs, not a job that may or may not have run, and an overdue review date is named rather than left to notice.","oss-ledger.section.led-biz-move.body":"A record outlives the contract that paid for it. Whoever answers for this in five years will not be you, will not have your suppliers, and will not be running the store you chose this week. What makes an entry written this year still worth something then is that it can be checked then, by somebody who takes none of it on your word.","oss-ledger.section.led-biz-move.secondary":"The useful contract claim is narrow: this year's entries need no re-explaining to the next owner. Each carries its basis and seal into its new home, so the file arrives already saying what it is rather than needing a covering note.\u001fThe store, supplier and people can change without changing the check. In year five, a review still asks for the same file and the same seals, and gets the same answer from them whoever is operating the storage by then.","oss-ledger.section.led-biz-move.secondary.more":"A completed move changes the home of the record, not the way its entries are checked.","oss-ledger.section.led-biz-cost.body":"Ledger is a Rust library that can run on infrastructure you manage, publishing under Apache 2.0 terms. In embedded use, appending is an in-process library call, so Ledger does not require a hosted service in the critical path. Your deployment still determines storage, backup, access and retention.","oss-ledger.section.led-biz-cost.secondary":"Procurement should ask who controls the record, the storage and the verifier. With Ledger, teams can retain the record and operate the chosen backend themselves, so none of those three answers has to be a supplier name.\u001fStart with memory or JSONL for development, then choose SQLite, PostgreSQL or S3 when the deployment needs their trade-offs. Once Ledger publishes, the source, its licence and the backend configuration remain reviewable.","oss-ledger.section.led-biz-cost.secondary.more":"That is why the evidence path does not acquire a new dependency simply because the record grows.","oss-ledger.section.led-con-today.body":"An application that uses Ledger can add an event when it sends a message, moves an appointment or reads a file. The event can say what happened, when and whether a person was asked first. Events are appended in order to the storage the application chose.","oss-ledger.section.led-con-today.secondary":"You may never need to read those events. They matter when something unexpected happened and you need to know what was recorded, in what order and with whose permission.\u001fA note made at the time can answer that better than a later memory. Whether it remains available depends on the application's storage and retention choices, which are set by whoever runs it rather than by the note itself.","oss-ledger.section.led-con-sealed.body":"Each event can carry the hash of the event before it, joining the notes into a chain rather than merely stacking them. A compatible verifier can check the chain in a copy of the record. That can reveal a missing or reordered note in that copy; it does not stop somebody with storage access from replacing every copy.","oss-ledger.section.led-con-sealed.secondary":"Once Ledger publishes, you can run a matching verifier on a copy. It reports the event where a predecessor link no longer fits, rather than only saying that something is wrong.\u001fKeeping an earlier independent copy gives the check something meaningful to compare a later one with. Without a second copy the chain can still be tested, but only against the same set of notes.","oss-ledger.section.led-con-consent.body":"If you agreed to something, the note says what you agreed to, when you agreed, what you were shown at the time, and which parts you agreed to rather than treating it as one blanket yes. If you later changed your mind, that gets a moment of its own in the record instead of quietly replacing the agreement.","oss-ledger.section.led-con-consent.secondary":"Most systems turn your agreement into one box, then empty it when you withdraw. That loses both the fact that you agreed and the day you stopped, which are the two things a later question is usually about.\u001fHere both moments remain, so a particular day in April has an answer. Anything that continued after you said no has a date beside it, and the parts you agreed to are listed apart from the parts you did not.","oss-ledger.section.led-con-approval.body":"Where a step needed a person to allow it, the note records who was asked, by when, and what they said. A yes carries whatever condition came with it. A no carries the reason the person gave, in their own words, which is the half that usually never reaches a record at all and the half you would want most if the answer had gone against you.","oss-ledger.section.led-con-approval.secondary":"Conditions usually disappear: one purpose, until Friday, or nothing leaves the building. A week later, the record only says approved. The detail matters, and nobody should have to reconstruct the conversation.\u001fKeeping the condition beside the request makes the difference between allowed and done visible. The request, answer and condition remain together when someone reviews the action.","oss-ledger.section.led-con-approval.secondary.more":"The request, the answer and the condition therefore remain together when the action is reviewed later.","oss-ledger.section.led-con-replay.body":"The recorded events can be read in order to inspect what happened. In dry-run mode, Ledger mocks external dependencies, so checking a session does not call the original tools again. Exact and debug modes are separate choices for workflows that need restoration, validation or guided investigation.","oss-ledger.section.led-con-replay.secondary":"Someone looking into a complaint can read the stored events in order and stop at the event that matters. They still need the relevant retained record and the right replay mode for the workflow.\u001fTwo people inspecting the same verified copy have the same record to discuss, rather than relying only on memory. That does not settle who was right, but it stops the argument being about what happened.","oss-ledger.section.led-con-replay.secondary.more":"Stopping at one note changes nothing in the notes before it or after it.","oss-ledger.section.led-con-kept.body":"Each note carries how long it may be kept, why it is kept that long in ordinary words, and the date somebody is due to look at that decision again. So the answer to how long do you keep this is written on the thing itself, in the words whoever set it used, rather than living in a policy document somewhere else.","oss-ledger.section.led-con-kept.secondary":"Each note separately records where information should stay and where it was actually handled. Most days those match and there is nothing to say. When they do not, the two sit side by side to be compared.\u001fAn overnight nineteen-minute failover appears as a difference, not an invisible gap. The record also names an overdue review or a period that no longer fits the information it covers, so the finding reaches a person.","oss-ledger.visual.file.lines":"{\"kind\":\"tool_call\",\"line\":4180}\u001f{\"kind\":\"tool_result\",\"line\":4181}\u001fCMP:{zstd bytes…}\u001fB64:DLEV 02 01 …\u001fCORRUPT LINE 4,118","oss-ledger.visual.book.pages":"page cut out\u001fa note from the afternoon\u001ffirst mark\u001fmark from page","oss-ledger.visual.chain.slips":"14:02 tool call\u001fown 9c41 2fd8\u001f14:02 tool result\u001fhead 9c41 2fd8\u001fgap left open\u001fapproval request removed\u001f14:05 approval granted\u001fhead 7be0 41ca","oss-ledger.visual.chain.recomputed":"recomputed a35d 90e7","oss-ledger.visual.refusal.attempts":"tomorrow's clock\u001f96 KB pasted whole\u001fsupplied fingerprint 4d19 8ab2\u001fordinary entry accepted","oss-ledger.visual.findings.report":"214,880 checked\u001f2 findings\u001fbreak at 91,204\u001fmissing predecessor\u001faltered entry 118,540\u001fcontent hash failed\u001fworking record\u001fstill legible","oss-ledger.visual.findings.verdict":"FINDINGS BY ENTRY AND LINE","oss-ledger.visual.findings.detail":"the working stays with the report","oss-ledger.visual.oversight.report":"Article 14\u001fno named overseer\u001fremediation one\u001fname an owner\u001fremediation two\u001fset a due date\u001fremediation three\u001frecord the review","oss-ledger.visual.oversight.verdict":"A NAMED BREACH","oss-ledger.visual.oversight.detail":"comes back with the work to close it","oss-ledger.visual.compact.reads":"READ IN PLACE\u001fone byte run, checked where it sits\u001fREBUILT OBJECT\u001fthe same entry, lifted into fields\u001fkind\u001etime\u001ethread\u001econtent\u001eprevious\u001eseal\u001f30 PERCENT FLOOR","oss-ledger.visual.correction.labels":"original invoice\u001fcorrection, dated and linked\u001fAN EDITED SCREEN\u001fthe first value is gone","oss-ledger.visual.walk.notes":"asked\u001fcalendar read\u001fpermission\u001fmessage sent\u001freceipt\u001freply\u001fcheck\u001fclose\u001fkept","oss-ledger.visual.walk.boundary":"no message is sent\u001fno appointment moves\u001fnothing is charged","oss-ledger.visual.compare.labels":"RECORDED\u001fSECOND SHEET\u001fentry id\u001eprevious hash\u001elawful basis\u001ereview date\u001fsealed\u001fdifferent\u001fcopied later","oss-ledger.visual.form.answers":"this one message only\u001fnot granted","oss-ledger.visual.afternoon.notes":"You asked it to move a dentist appointment.\u001fIt read your calendar to find a free slot.\u001fIt asked a person before sending a message.\u001fIt sent the message, with the words that went out.","oss-ledger.visual.flush.batch":"batch full\u001f4 MB\u001fwriter idle","oss-ledger.visual.store.heads":"WRITE\u001fCHECK","oss-ledger.visual.store.names":"JSONL\u001fSQLITE\u001fPOSTGRES\u001fS3\u001fMEMORY","oss-ledger.visual.move.stages":"READ\u001fCOPY\u001fVERIFY\u001fCUTOVER","oss-ledger.visual.question.objects":"REQUEST\u001f14 days\u001fsealed entry","oss-ledger.visual.locality.same":"same place","oss-ledger.visual.periods":"24 months\u001f7 years\u001f10 years","oss-ledger.visual.portable.ends":"supplier\u001fcontract\u001fteam","oss-ledger.visual.supplier.lines":"YOUR MACHINES\u001fYOUR BACKUPS\u001fYOUR FILE","oss-ledger.visual.vocabulary":"ToolCall\u001fApproval\u001fArtefact\u001fSession\u001fReplay\u001fRight\u001fIncident\u001fAttestation\u001fCustom","oss-ledger.visual.secondRecord":"AUTHENTICATION\u001fAUTHORISATION\u001fREAD\u001fCHANGE\u001fEVENT\u001fCHECK\u001fRETAIN\u001fSEAL","oss-ledger.visual.ask.dates":"01 JAN to 30 JUN","oss-ledger.visual.account.sources":"LOG\u001fretained for thirty days\u001fDASHBOARD\u001fone supplier total\u001fTICKETS\u001fthree partial accounts\u001fRECORD\u001fone sealed history","oss-ledger.visual.account.conclusion":"every word of this is our account of our own system","oss-ledger.visual.thread.view":"THE INTERLEAVED RECORD\u001fSESSION A17\u001fA17\u001fOTHER SESSION\u001fONE THREAD, BUILT ON READ\u001ffive selected entries remain part of the same sealed run","oss-ledger.visual.agent.exchange":"01 / append entry\u001fsealed\u001f02 / fetch session\u001ffive entries\u001f03 / read measurements\u001favailable\u001f04 / verify integrity\u001fbreak at entry four","oss-ledger.visual.agent.verdict":"THE PROTOCOL STAYS UP","oss-ledger.visual.agent.detail":"the finding names where the record stopped agreeing","oss-ledger.section.led-eng-thread.side":"THE THREAD ID\u001fsealed into each entry\u001fTHE VIEW\u001fselected when somebody asks\u001fTHE ORDER\u001fthe written order is retained\u001fTHE CHECK\u001fthe same chain is verified","oss-ledger.section.led-eng-agents.side":"WRITE\u001fappend one sealed entry\u001fREAD\u001fquery, fetch and list sessions\u001fCHECK\u001fverify and read measurements\u001fREPLAY\u001fwalk a recorded session","oss-ledger.section.led-biz-findings.side":"THE BREAK\u001fpoints at entry 91,204\u001fTHE ALTERATION\u001fpoints at entry 118,540\u001fTHE WORKING\u001fstays legible beneath failure\u001fTHE HANDOVER\u001fhas a line and an entry","oss-ledger.section.led-biz-oversight.side":"THE BREACH\u001fArticle 14, high risk\u001fTHE GAP\u001fno named overseer\u001fTHE REMEDY\u001fthree steps, owner and date\u001fTHE WARNINGS\u001flawful basis and materials","oss-ledger.section.led-con-today.side":"THE FIRST NOTE\u001fsomething was requested\u001fTHE NEXT NOTE\u001fthe calendar was read\u001fTHE PERSON\u001fpermission was asked\u001fTHE MESSAGE\u001fthe words that went out","oss-ledger.section.led-con-sealed.side":"WHAT JOINS THEM\u001feach note takes a mark from the one before\u001fWHAT A CUT DOES\u001fthe next mark no longer fits\u001fWHO CAN CHECK\u001fanyone with a copy\u001fWHAT THEY LEARN\u001fwhere the trouble starts","oss-ledger.section.led-eng-chain.instrument":"Edits a value\u001cown mark stops matching\u001cnext entry fails too\u001dRemoves an entry\u001cremaining entries still match\u001cnext entry points at nothing\u001dReorders two\u001cboth own marks still match\u001ctime and order change both links\u001dAppends at the end\u001cmatches\u001cthe only legal change","oss-ledger.section.led-eng-refused.instrument":"A time an hour ahead\u001cfuture bound\u001crefused\u001dMetadata over 64 KB\u001cserialised ceiling\u001crefused, never trimmed\u001dA supplied fingerprint\u001crecomputed and compared\u001crefused on mismatch\u001dA bad line on read\u001cparsed in place\u001creported by line number","oss-ledger.section.led-eng-file.instrument":"none\u001cPlain object\u001cone JSON object per line\u001dCMP:\u001cCompressed\u001csame entry, Zstandard compressed\u001dB64:\u001cCompact binary\u001cbase64 beside the plain lines","oss-ledger.section.led-eng-durability.instrument":"01\u001cEvery write\u001con device before acknowledgement\u001d02\u001cPer batch\u001cyou set the recent-entry bound\u001d03\u001cPer size\u001cflush after accumulated bytes\u001d04\u001cAdaptive\u001cdecides each time and records why","oss-ledger.section.led-eng-compact.instrument":"In place\u001cpoints into the buffer\u001cnothing copied out\u001dRebuilt\u001clifts every field\u001cone allocation per field\u001dEither way\u001cthe same bytes underneath\u001cno second encoding\u001dAs text\u001cone JSON object per line\u001cthe portable form\u001dCompact\u001cmarker, version, flags, checksum\u001c30 per cent smaller under test","oss-ledger.section.led-eng-replay.instrument":"01\u001cExact\u001crestores outputs and checks them\u001d02\u001cDry run\u001cstands in for outside calls\u001d03\u001cDebug\u001ccontinue, skip or abort\u001d04\u001cStart from\u001cthread, range, entry or snapshot","oss-ledger.section.led-eng-storage.instrument":"Writing\u001cappend one entry or a batch\u001dReading\u001ctime range, identifier, query, count, latest mark\u001dMaintenance\u001cverify, compact, back up, restore, migrate","oss-ledger.section.led-eng-move.instrument":"01\u001cValidate only\u001cfind what the target refuses\u001cno writes\u001d02\u001cDry run\u001ccounts and a plan\u001cno writes\u001d03\u001cIn batches\u001cprogress and resume point\u001cresumable\u001d04\u001cVerified after\u001ccheck the chain at home\u001cblocking","oss-ledger.section.led-eng-compliance.instrument":"Lawful basis\u001cwhich ground processing rested on\u001cGDPR, one of six\u001dData locality\u001crequired region and actual location\u001ctransfer rules\u001dHuman oversight\u001cperson, mode and moment\u001cEU AI Act, Article 14\u001dRetention\u001cperiod, reason and review date\u001cstorage limitation","oss-ledger.section.led-eng-thread.instrument":"01\u001cIdentifier\u001csealed into every entry\u001d02\u001cSelection\u001cgathered in order on read\u001d03\u001cNever stale\u001cno summary can disagree\u001d04\u001cAny grouping\u001cone run, afternoon or month","oss-ledger.section.led-eng-agents.instrument":"01\u001cWrite\u001cappend one typed entry\u001d02\u001cRead\u001cquery, fetch and list sessions\u001d03\u001cCheck\u001cverify and read measurements\u001d04\u001cReconstruct\u001creplay in the requested mode","oss-ledger.section.led-eng-surfaces.instrument":"Your service\u001cRust library\u001cappend in process\u001dAn operator\u001cledger tool\u001cquery, verify and migrate\u001dAnother language\u001cHTTP surface\u001cbatch, sessions, metrics, OpenAPI\u001dAn agent\u001cMCP server\u001ceight operations over stdio","oss-ledger.section.led-biz-account.instrument":"01\u001cApplication log\u001crotated after a fortnight\u001d02\u001cSupplier dashboard\u001ccounts, but no instruction\u001d03\u001cTicket thread\u001cthe customer's account and your reply\u001d04\u001cSomebody's memory\u001cconfident, least admissible","oss-ledger.section.led-biz-append.instrument":"What is the figure now\u001cCorrect\u001cCorrect\u001dWas it ever wrong\u001cNothing says so\u001cthe first entry remains\u001dWhen was it put right\u001cUnknown\u001cthe correction has its own time\u001dWho put it right\u001cWhoever had access\u001cwhatever the integration recorded","oss-ledger.section.led-biz-findings.instrument":"Broken link\u001cnext entry and its line\u001cwhat was between them\u001dAltered entry\u001cthe entry and changed field\u001ceverything downstream\u001dClean pass\u001centry count and last mark\u001cnothing left in question","oss-ledger.section.led-biz-questions.instrument":"Approval\u001cwho, by when, conditions, refusal\u001cwho allowed this\u001dConsent\u001cpurpose, scope, version, evidence\u001cwere we allowed to\u001dIncident\u001cthe event time itself\u001cwhen did you know\u001dErasure request\u001csubject, scope and deadline\u001cwhen must it be done","oss-ledger.section.led-biz-consent.instrument":"Purpose\u001cthe words shown, not a policy link\u001dScope\u001ceach use on its own line\u001dVersion\u001cchanged wording becomes another record\u001dEvidence\u001ca reference to what was relied on\u001dGranted, withdrawn\u001ctwo separate moments","oss-ledger.section.led-biz-locality.instrument":"Region the data must stay in\u001cwhere it was actually processed\u001dAttestation at the time\u001cwhen that location was established\u001dApproval before crossing\u001cwhether anyone approved it, and who\u001dAdequacy decision\u001cwhich decision was relied on","oss-ledger.section.led-biz-oversight.instrument":"01\u001cThe failure\u001chigh risk, no oversight recorded\u001d02\u001cWhat comes with it\u001cthree owned remediation steps\u001d03\u001cFirst warning\u001cno lawful basis on the entry\u001d04\u001cSecond warning\u001cno materials above confidential","oss-ledger.section.led-biz-retention.instrument":"Duration\u001chow long, carried with the data\u001ccarried\u001dRationale\u001cwhy that long\u001ccarried\u001dReview date\u001cwhen somebody looks again\u001cwarn after it passes\u001dAgainst category\u001cten years where it is not called for\u001cexcessive","oss-ledger.section.led-biz-move.instrument":"Year one\u001cfile on one machine\u001cnothing else required\u001dYear two\u001csame entries in a database\u001cnot the supplier contract\u001dYear three\u001csame entries and seals\u001cnot the original team\u001dYear five\u001cchecked from the first entry\u001cnot database support","oss-ledger.section.led-biz-cost.instrument":"Licence\u001cApache 2.0 terms; read, run, modify, keep\u001dWhere it runs\u001cyour machines; append is a call\u001dStorage\u001cmemory, file or single-file database\u001dBackup\u001cwhatever backs up that machine","oss-ledger.section.led-con-today.instrument":"What was done\u001csent, opened, moved or cancelled\u001dWhen\u001cthe time it happened\u001dWho said yes\u001cwho was asked and what they answered\u001dWhere it sits\u001cafter the note before it","oss-ledger.section.led-con-sealed.instrument":"01\u001cHand it on\u001cnothing has to come from us\u001d02\u001cHave the marks checked\u001cthe checker publishes with the repository\u001d03\u001cGet a note named\u001clearn where trouble starts\u001d04\u001cKeep what you were sent\u001ccompare older and newer copies","oss-ledger.section.led-con-consent.instrument":"01\u001cWhat it was for\u001cthe words you were shown\u001d02\u001cWhich parts\u001ceach thing separately\u001d03\u001cWhat you saw\u001ckept rather than described\u001d04\u001cThe two dates\u001cthe day you agreed and stopped","oss-ledger.section.led-con-approval.instrument":"Send one message\u001cyes\u001cthe condition in the person's words\u001dMove an appointment\u001cstill open\u001cthe request and its deadline\u001dShare with a broker\u001cno\u001cthe person's reason, not a code","oss-ledger.section.led-con-replay.instrument":"Nothing happens again\u001cno message resent, nothing moved\u001dIn the order it happened\u001cnot the order somebody remembers\u001dThe same for everyone\u001ctwo readers see the same notes","oss-ledger.section.led-con-kept.instrument":"How long do you keep this\u001ca period on the note itself\u001dWhy that long\u001cthe reason in ordinary words\u001dWho looks at it again\u001ca date and an overdue warning\u001dWhere was it handled\u001crequired place and actual place","oss-ledger.shell.close.headlineAccent":"you can actually prove","oss-ledger.shell.close.panel.title":"What the record is made of","oss-ledger.shell.close.panel.tag":"LEDGER","oss-ledger.shell.close.panel.row0.label":"What an entry carries","oss-ledger.shell.close.panel.row0.value":"Seventeen compliance fields, each with a default","oss-ledger.shell.close.panel.row1.label":"Two hashes","oss-ledger.shell.close.panel.row1.value":"Content hash catches an edit, chain hash catches a gap","oss-ledger.shell.close.panel.row2.label":"Where it can live","oss-ledger.shell.close.panel.row2.value":"Memory, JSONL, binary, SQLite, PostgreSQL or S3","oss-ledger.shell.close.panel.row3.label":"Licence","oss-ledger.shell.close.panel.row3.value":"Apache 2.0","oss-ledger.shell.close.panel.foot":"Verification reports what the selected checker can establish about the copy it read.","oss-ledger-audit-ready.34ed12b349":"23 typed event variants, 9 categories","oss-ledger-audit-ready.b150234609":"The answer is a sealed event, not a reconstruction after the fact.","oss-ledger-audit-ready.73b38f432a":"Recorded as:","oss-ledger-audit-ready.8632e0b3b5":"When the auditor asks","oss-ledger-audit-ready.be44ab615c":"Answer already on record","oss-ledger-audit-ready.df91ee379c":"compliance desk, ledger","oss-ledger-audit-ready.053d5569c9":"ToolCall, ToolResult","oss-ledger-audit-ready.b1d7c34806":"Each tool the AI called, and the result it got back, is a recorded event in sequence. The full sequence reads back in order, so the activity is never a black box.","oss-ledger-audit-ready.efdcb1e31f":"Tool event","oss-ledger-audit-ready.491a006f0f":"What did the AI actually do, step by step?","oss-ledger-audit-ready.5b1130ac34":"SbomGenerated, AttestationCompleted","oss-ledger-audit-ready.1a54b66fe8":"A software bill of materials and its attestation are recorded as events, so you can show what went into a release without trawling build logs after the fact.","oss-ledger-audit-ready.3c6fe75357":"Security attestation event","oss-ledger-audit-ready.253e507263":"Can you prove what was in the software you shipped?","oss-ledger-audit-ready.6d19cc875d":"Requested, granted, denied","oss-ledger-audit-ready.2047dea6fd":"Every approval is recorded as requested, granted or denied. You can show not only who said yes, but every time someone said no, all in the order it happened.","oss-ledger-audit-ready.0c5759cf75":"Approval gate event","oss-ledger-audit-ready.85f505601c":"Who approved this action, and was anything ever refused?","oss-ledger-audit-ready.1a7627d54c":"AiIncidentDetected","oss-ledger-audit-ready.5acf8fe77f":"An AI incident is written down as a distinct event the moment it is detected, with its place in the timeline fixed. You can show exactly when it was noticed and what followed it.","oss-ledger-audit-ready.e7f5edaa64":"EU AI Act incident event","oss-ledger-audit-ready.1da0952f6d":"When the AI went wrong, when did you know and what did you do?","oss-ledger-audit-ready.b90b1e0e30":"Consent, DPIA, erasure, subject rights","oss-ledger-audit-ready.d68eb14fce":"Consent, data-protection assessments, erasure requests and subject-rights actions are each recorded as their own typed event when they happen. The proof is in the record, not in someone’s memory.","oss-ledger-audit-ready.95459d0acf":"GDPR data-rights event","oss-ledger-audit-ready.210469be8c":"Did you have consent to use this person’s data?","oss-ledger-backends.packageName":"ledger","oss-ledger-backends.89c8a2851d":"Memory","oss-ledger-backends.6bbaaf853c":"Tests, ephemeral runs","oss-ledger-backends.64350afcc7":"EventStore","oss-ledger-backends.6be6b824dd":"Zero dependencies. The fastest path, used in the benchmark snapshot.","oss-ledger-backends.db35ca65d0":"JSONL","oss-ledger-backends.4a172e5677":"Portability, grep","oss-ledger-backends.a0408425f1":"One JSON line per event. Human readable, trivially portable, append only on disk.","oss-ledger-backends.9f09ccbd1c":"SQLite","oss-ledger-backends.9f714e5484":"Embedded, single file","oss-ledger-backends.7e0cbf75d8":"A single queryable file. Embedded with no server to run.","oss-ledger-backends.c590abf597":"Postgres","oss-ledger-backends.9e54b163e7":"Production, multi writer","oss-ledger-backends.09f264d383":"Indexed queries and concurrent writers for production scale.","oss-ledger-backends.d178391464":"Archival, WORM","oss-ledger-backends.46c76e0f12":"Object storage for long term retention behind a lifecycle policy.","oss-ledger-backends.1b290eb385":"Cargo.toml","oss-ledger-backends.a719c9274a":"5 backends, one shape","oss-ledger-backends.8348f56979":"feature = &quot;","oss-ledger-backends.eddef408c2":"# enable a storage backend by feature flag","oss-ledger-backends.66fc2bf069":"Same BLAKE3 chain","oss-ledger-backends.33aeb01da4":"Same event schema","oss-ledger-backends.bd340aa2c0":"Migration is a copy, not a re-encode","oss-ledger-backends.3879c43493":"One log shape and one hash chain across all five backends.","oss-ledger-bindings.f24d8d9e66":"OSS, Ledger","oss-ledger-bindings.df166ff9e3":"The same event format flows through every shape. No external service required.","oss-ledger-bindings.cf806846ee":"EventCategory::","oss-ledger-bindings.acb93d355a":"Compliance by event category","oss-ledger-bindings.6fd867ddde":"BLAKE3 + Ed25519","oss-ledger-bindings.cd0a445053":"Dweve Ledger","oss-ledger-bindings.c403dd91f4":"4 deploy shapes","oss-ledger-bindings.e83df2624e":"one event format","oss-ledger-bindings.5f40c5efb4":"how ledger plugs in","oss-ledger-bindings.40730fd594":"Operator surface","oss-ledger-bindings.a010de5c61":"Fabric","oss-ledger-bindings.85592d5c8c":"Knowledge governance","oss-ledger-bindings.4a86080d67":"Spindle","oss-ledger-bindings.3231d6db74":"Multi agent traces","oss-ledger-bindings.485a04fef4":"Nexus","oss-ledger-bindings.521d518019":"Code agent receipts","oss-ledger-bindings.af0854de67":"Aura","oss-ledger-bindings.db5fa64367":"Session and replay lifecycle events reconstruct what happened, in order.","oss-ledger-bindings.bc0792d8dc":"System","oss-ledger-bindings.ab8ac8b17b":"SBOM and attestation events back tamper evident operational reporting.","oss-ledger-bindings.f25ce1b8a3":"Security","oss-ledger-bindings.0e78d4cd04":"AI incident events provide structured inputs for EU AI Act reporting.","oss-ledger-bindings.dedad727ac":"AiAct","oss-ledger-bindings.fb8965fbc1":"Consent, subject rights, DPIA, and erasure events give a queryable access record.","oss-ledger-bindings.7f3feb49a1":"A standalone binary that many services append to over the wire.","oss-ledger-bindings.329cb8b6ba":"Service","oss-ledger-bindings.be7172ec1e":"A companion process beside your app. The most common production shape.","oss-ledger-bindings.2b068e1f87":"Sidecar","oss-ledger-bindings.92c3c25110":"A stable C interface for binding from other languages.","oss-ledger-bindings.9652018eda":"C ABI","oss-ledger-bindings.83f84ae370":"Link the Rust crate directly. The ledger lives in your process.","oss-ledger-bindings.761445591d":"Embedded crate","oss-ledger-business-glyph.a92831c31f":"Built in the Netherlands","oss-ledger-business-glyph.c82d1b09cf":"EU","oss-ledger-business-glyph.b7a3f27883":"Risk removed","oss-ledger-business-glyph.66af0b068c":"One event chain","oss-ledger-business-glyph.c36647c508":"Scattered logs","oss-ledger-business-glyph.98b58388d1":"Typed · signed · replayable","oss-ledger-business-glyph.4eb5e81b2c":"Append-only operations history","oss-ledger-business-glyph.cba0624eb5":"Operations record","oss-ledger-business-glyph.83ecf97355":"Sealed off","oss-ledger-business-glyph.f6fff7f33d":"EU cloud","oss-ledger-business-glyph.7c5277c9c8":"Your building","oss-ledger-business-glyph.472d213e85":"Replay restores the sequence","oss-ledger-business-glyph.1607989434":"Incomplete incident timeline","oss-ledger-business-glyph.a37212ac8b":"Hash check exposes the edit","oss-ledger-business-glyph.f6501ca9a2":"Quiet edit before an audit","oss-ledger-business-glyph.5bed69fae6":"Actor and scope stay attached","oss-ledger-business-glyph.200a9fd9ea":"Missing approval context","oss-ledger-business-glyph.1c6cfed547":"Replay from any point","oss-ledger-business-glyph.fc3253c5ae":"Rebuild by hand","oss-ledger-business-glyph.1ef1565eea":"Recovery","oss-ledger-business-glyph.0628c0d544":"Hashes expose change","oss-ledger-business-glyph.942c054a20":"Edits disappear","oss-ledger-business-glyph.e5b4d87593":"Integrity","oss-ledger-business-glyph.6eef664840":"Typed end to end","oss-ledger-business-glyph.7950c7c08f":"Different in every service","oss-ledger-business-glyph.ad1aeaa4e4":"Event shape","oss-ledger-close-to-home.fc8a2d0eb3":"No separate account, no distant dashboard, no missing chapter. The record stays honest and\n          it stays close to home.","oss-ledger-close-to-home.cf5144f1db":"It is sealed, so nothing inside can be quietly changed.","oss-ledger-close-to-home.40488914b2":"The honest notebook can stay inside your own walls.","oss-ledger-close-to-home.729bebe99f":"A small house holding the honest record safely inside.","oss-ledger-close-to-home.9a2dee166c":"Close to home, complete, and yours to read","oss-ledger-close-to-home.db624b9521":"Where the notebook lives","oss-ledger-close-to-home.011961e91f":"The record and its plain format belong to you. You, or anyone you trust, can read it back at any time, in order, from the start.","oss-ledger-close-to-home.eca049f837":"It is yours to read","oss-ledger-close-to-home.dd95458d30":"The history stays beside the system that creates it. Your team does not need a second account or a separate service to read what happened.","oss-ledger-close-to-home.e25d4d7294":"It needs no extra account","oss-ledger-close-to-home.e07362020f":"It can sit on a computer in your own building, so the record stays close to home and never has to travel to a stranger’s machine far away.","oss-ledger-close-to-home.a2f2fa3997":"It lives where you put it","oss-ledger-consumer-glyph.6a79333175":"and the next line, when it happens","oss-ledger-consumer-glyph.2b90a6be18":"Nothing changed behind your back","oss-ledger-consumer-glyph.b7b925c5fc":"An honest notebook","oss-ledger-consumer-glyph.15d881f52c":"Ask what happened, anytime","oss-ledger-consumer-glyph.4cf42642c4":"It lives in your own home","oss-ledger-consumer-glyph.83cc751228":"The same story, everywhere","oss-ledger-consumer-glyph.70da03c94a":"It checked before doing more","oss-ledger-consumer-glyph.50b6aed873":"It wrote a note and saved it","oss-ledger-consumer-glyph.09fca7fb9f":"It looked something up for you","oss-ledger-everyday-map.cbf86628a0":"Something happens","oss-ledger-everyday-map.1d80d53ca8":"When the AI does anything, one new line gets written down, just like a note in a journal.","oss-ledger-everyday-map.71db7fd7fc":"It gets locked","oss-ledger-everyday-map.b15668f8a3":"That line is sealed to the line before it, so no one can quietly change it later.","oss-ledger-everyday-map.76a1856380":"It stays the same","oss-ledger-everyday-map.1bee11d1a8":"Read it back on any computer and you get the very same story, in the very same order.","oss-ledger-everyday-map.5107894be3":"You can ask","oss-ledger-everyday-map.4ffc43688f":"Wonder later what happened, or when? You can read it back from any moment you like.","oss-ledger-everyday-map.d558833fa7":"The record stays with the AI that writes it","oss-ledger-everyday-map.bf83d57df1":"Your team can read the same story at any moment","oss-ledger-everyday-map.d0e5b1280f":"You never have to understand the machinery","oss-ledger-everyday-map.b15f53b20f":"What it quietly does for you","oss-ledger-everyday-map.13ba641d24":"Four everyday moments, start to finish","oss-ledger-everyday-worry.cb4c593f2d":"You do not have to do anything to make this work. It quietly keeps the honest record so the\n          answer to every one of these worries is already written down for you.","oss-ledger-everyday-worry.7d137ed21a":"With this honest record","oss-ledger-everyday-worry.5bf700f8c7":"Without an honest record","oss-ledger-everyday-worry.89e122ee0f":"Pick a worry, see the difference in plain words","oss-ledger-everyday-worry.3d54eab529":"The quiet worries, answered","oss-ledger-everyday-worry.f18f0c8fb1":"This can live on a computer in your own building, so the record stays close to home where you can point at it.","oss-ledger-everyday-worry.2e004de2cb":"Many tools keep your record on a computer you never see, owned by someone else.","oss-ledger-everyday-worry.cf5d283245":"What if it all sits on a stranger’s machine far away?","oss-ledger-everyday-worry.0618964791":"It gives the very same story, in the very same order, on every computer. Like a good recipe, it comes out the same each time.","oss-ledger-everyday-worry.5686f80357":"Some systems give a slightly different story depending on where you look, which is hard to trust.","oss-ledger-everyday-worry.93ad19b93c":"What if it says something different on another computer?","oss-ledger-everyday-worry.ef7548b5ec":"You can read it back from any moment, like rewinding a home video to the exact part you want to see.","oss-ledger-everyday-worry.cc242b2dcf":"Without a record, you are left trying to remember, or asking someone who may not recall either.","oss-ledger-everyday-worry.e413e7200e":"What if I forget what happened last week?","oss-ledger-everyday-worry.045d88ef2b":"Each line is sealed to the one before it. If anyone alters it, the seal stops matching and the change shows itself at once.","oss-ledger-everyday-worry.5c59e9dcc4":"Ordinary notes can be quietly edited, and you would never know a word had moved.","oss-ledger-everyday-worry.9b15b0a065":"What if someone changes the record behind my back?","oss-ledger-hero-glyph.7bbf63ad5c":"ledger append -e session_started -d aura","oss-ledger-hero-glyph.5430305d4e":"ledger append -e tool_call -d '{\"name\":\"fs.read\"}'","oss-ledger-hero-glyph.ab7bc7775d":"14:02:07.118 UTC","oss-ledger-hero-glyph.7637c1a7dc":"14:02:07.214 UTC","oss-ledger-hero-glyph.7d71a97166":"14:02:07.219 UTC","oss-ledger-hero-glyph.4ee0452f66":"14:02:08.602 UTC","oss-ledger-hero-glyph.17c422bb5d":"14:02:09.331 UTC","oss-ledger-hero-glyph.db35ca65d0":"JSONL","oss-ledger-hero-glyph.fe7dc42426":"Ledger [v0.1.0]","oss-ledger-hero-glyph.66c95e7fc7":"Sealed","oss-ledger-hero-glyph.a00e210af3":"Immutable event ledger","oss-ledger-hero-glyph.6fd867ddde":"BLAKE3 + Ed25519","oss-ledger-hero-glyph.662c151b2e":"Event appended:","oss-ledger-hero-glyph.9159a97ef2":"Total events: 5","oss-ledger-hero-glyph.9ce3bd4224":"OK","oss-ledger-hero-glyph.a0007be570":"Integrity check passed","oss-ledger-hero-glyph.bfecdd4880":"Events checked: 5","oss-ledger-hero-glyph.52780ad569":"ledger info","oss-ledger-hero-glyph.d541a61ec0":"BLAKE3 chain","oss-ledger-hero-glyph.0ff4db97af":"23 event types, 9 categories","oss-ledger-hero-glyph.e9045ea057":"9 stores","oss-ledger-log-forensics.43ec3da5fd":"Logs are not evidence. A hash chain is evidence.","oss-ledger-log-forensics.03be9c2cf5":"Change any byte and the next hash no longer matches. The break names the entry.","oss-ledger-log-forensics.9b37561069":"append only, BLAKE3 linked","oss-ledger-log-forensics.cf2a2e1441":"plain text, anyone can edit","oss-ledger-log-forensics.615991c3f7":"logs vs ledger","oss-ledger-log-forensics.80e0164cc2":"tamper detected","oss-ledger-log-forensics.c713a36a81":"A log of events cannot recompute the state they produced.","oss-ledger-log-forensics.b90a38ae7f":"No replay","oss-ledger-log-forensics.8ffc2c21a5":"Multi process clocks drift. The true sequence is forensic work.","oss-ledger-log-forensics.4d4b0f1f77":"No order","oss-ledger-log-forensics.4d3a26f3e1":"Rotate, truncate, edit. The file cannot prove its own history.","oss-ledger-log-forensics.6525d4e56d":"No integrity","oss-ledger-log-forensics.e3d0bfbab1":"Free text, grep only. Two teams write the same event two ways.","oss-ledger-log-forensics.80cdce0d5b":"No schema","oss-ledger-log-forensics.db68747d5b":"14:22:09 INFO  payment released","oss-ledger-log-forensics.21b10b30e3":"... 2 lines truncated by rotation ...","oss-ledger-log-forensics.08bbb161dc":"14:22:06 INFO  amount 9.99 (was 4210.00)","oss-ledger-log-forensics.80bb4200c8":"14:22:06 INFO  approval granted by ops","oss-ledger-log-forensics.484496cfbf":"14:22:04 INFO  balance check ok","oss-ledger-log-forensics.8dcc98ba56":"14:22:01 INFO  approval requested for vendor-281","oss-ledger-ownership-brief.f3c6cf1ef0":"Typed · signed · replayable","oss-ledger-ownership-brief.c3264894d7":"One event shape from the first append to the last replay.","oss-ledger-ownership-brief.3915907107":"CHAIN VERIFIED","oss-ledger-ownership-brief.18e531c922":"Keep the same record shape in memory, SQLite, Postgres, S3, or your own backend.","oss-ledger-ownership-brief.d82c49bd23":"Choose where the history lives","oss-ledger-ownership-brief.8e388ae4ea":"Replay any window of events to reconstruct state instead of reverse-engineering a mutable snapshot.","oss-ledger-ownership-brief.6bac4fc4e0":"Rebuild state from the record","oss-ledger-ownership-brief.f42d547146":"Filter by actor, event type, time, or correlation ID without reducing the history to plain text.","oss-ledger-ownership-brief.fb3d5bc14d":"Query the moment that matters","oss-ledger-ownership-brief.5073158ed0":"Every entry extends the BLAKE3 chain, so deletion, reordering, or mutation breaks verification.","oss-ledger-ownership-brief.db2f918870":"Every entry proves its place","oss-ledger-ownership-brief.78764dc740":"New events are added at the end. Earlier history remains intact and readable.","oss-ledger-ownership-brief.12d7454903":"Append without rewriting history","oss-ledger-pipeline.6fd867ddde":"BLAKE3 + Ed25519","oss-ledger-pipeline.db7e8c6c1a":"Tamper evident on hash. Replayable end to end.","oss-ledger-pipeline.6113f978ac":"append to replay","oss-ledger-pipeline.02a92a8e34":"5 stages, one path","oss-ledger-pipeline.6ea74774d1":"event pipeline","oss-ledger-pipeline.711f869569":"Replay is a linear walk in event order. No solver, no external dependency. The same window gives the same state every time.","oss-ledger-pipeline.6e21acc714":"Walk events up to a timestamp, rebuild state.","oss-ledger-pipeline.c0f85d6679":"Replay","oss-ledger-pipeline.3f85e51b16":"Memory, JSONL, SQLite, Postgres, or S3. The log shape and the chain are identical across all five.","oss-ledger-pipeline.31f29a30eb":"Written to one of five backends.","oss-ledger-pipeline.e481064dfd":"Persist","oss-ledger-pipeline.c339a57505":"Segments are anchored with Ed25519. A verifier checks the signature offline, with no call back to any service.","oss-ledger-pipeline.432d348da6":"Trust anchors seal a segment with Ed25519.","oss-ledger-pipeline.8b3d8d665a":"Sign","oss-ledger-pipeline.e5ac66d489":"The chain hash folds the previous hash into the current content. Change any byte and every later link stops matching.","oss-ledger-pipeline.f9600e9bd9":"BLAKE3 links this entry to the previous.","oss-ledger-pipeline.873507a022":"Hash","oss-ledger-pipeline.d254b7425a":"Every entry is one of 23 typed variants. No free text. Adding a variant is a release, not a quiet refactor.","oss-ledger-pipeline.26b2afdc44":"A typed event is added to the tail.","oss-ledger-pipeline.6b3a602280":"Append","oss-ledger-plain-book.c9dacbd092":"It is a diary that nobody can secretly rewrite.","oss-ledger-plain-book.1923cc2929":"Picture a diary where you only ever add a new line at the bottom. You can never go back and erase yesterday. This is exactly that, for a computer that helps with AI. Every time something happens, it writes one more line, and the old lines stay just as they were.","oss-ledger-plain-book.cd79ac57bc":"Nothing gets erased behind your back.","oss-ledger-plain-book.b81932dca1":"Each line locks the one before it, like a wax seal.","oss-ledger-plain-book.99fae8c65f":"Imagine each page of the diary is sealed to the page before it. If anyone tried to tear one out or change a word, the seal would no longer match, and everyone would see it straight away. That is how this keeps the record honest, without anyone having to stand guard.","oss-ledger-plain-book.3193ddadd0":"If someone tampers with it, it shows.","oss-ledger-plain-book.801aedcc4c":"It gives the same answer on every computer.","oss-ledger-plain-book.5acc881d49":"You know how a good recipe makes the same cake in your kitchen and your neighbour’s? This is the part that makes the answers come out the same on every machine. Read the diary back tomorrow, or on a different computer, and you get the very same story, in the very same order.","oss-ledger-plain-book.bf93cd3f4b":"The story never changes between machines.","oss-ledger-plain-book.d17168d36c":"You can always ask what happened, and when.","oss-ledger-plain-book.ede75c07d6":"If you ever wonder who did what, or when something was decided, you can read the diary back from any moment. It is like rewinding a home video to the exact part you want to see, instead of trying to remember.","oss-ledger-plain-book.ce9feb8883":"Curious later? The answer is written down.","oss-ledger-plain-book.52aa14ead1":"It stays beside the system that keeps the notes.","oss-ledger-plain-book.19cb00c3c7":"The notebook can live on the same computers as the AI it remembers. Your team reads it directly, without opening another account or trusting a separate dashboard somewhere else.","oss-ledger-plain-book.7421ee8c3f":"One notebook, kept with the system it remembers.","oss-ledger-plain-book.e977e4fdd1":"The honest notebook","oss-ledger-plain-book.6a35770988":"A plain-words tour, no computer talk","oss-ledger-plain-book.fb06270f7c":"Page","oss-ledger-plain-book.f2c5088b38":"You do not have to understand any of the machinery. It quietly keeps an honest record so the\n          people who look after your AI tools can always tell you what happened.","oss-ledger-replay-console.f24d8d9e66":"OSS, Ledger","oss-ledger-replay-console.807b93f95b":"Figures are an in-memory benchmark snapshot, not a published SLA. Run the harness yourself.","oss-ledger-replay-console.ad5ccf66c3":"Snapshot, in memory","oss-ledger-replay-console.03128bed90":"Verification","oss-ledger-replay-console.41f6aa33e7":"Replay walks the event window in order, links each entry to the previous BLAKE3 hash, and\n            rebuilds state. The same window produces the same result on every machine.","oss-ledger-replay-console.3e6df79cba":"ledger replay","oss-ledger-replay-console.85ce3761d2":"chain verified","oss-ledger-replay-console.eaf0538a1c":"query_by_size, 100,000 events","oss-ledger-replay-console.0f63132c39":"72 ms","oss-ledger-replay-console.85ee51f8c6":"Range query","oss-ledger-replay-console.5d6dc18c16":"replay_session, 1,000 events","oss-ledger-replay-console.52f4b27512":"1.3 ms","oss-ledger-replay-console.3c07893ab3":"Replay walk","oss-ledger-replay-console.1d06f137af":"integrity_verification, 100 events","oss-ledger-replay-console.db23c994b2":"139 us","oss-ledger-replay-console.d0295f339d":"Chain verify","oss-ledger-replay-console.02239a6833":"calculate_chain_hash, per link","oss-ledger-replay-console.14bb1dc703":"0.20 us","oss-ledger-replay-console.a3cee123ce":"Chain hash","oss-ledger-replay-console.515aff92ad":"ledger_append_event, in memory","oss-ledger-replay-console.606497be6f":"2.4 us","oss-ledger-replay-console.a313bc7f88":"Single append","oss-ledger-replay-console.ed10b116a5":"state rebuilt, deterministic","oss-ledger-replay-console.c0f85d6679":"Replay","oss-ledger-replay-console.784ed488c9":"segment 042 accepted","oss-ledger-replay-console.ed36a1a142":"Ed25519 anchor","oss-ledger-replay-console.9c50e3ed76":"42 / 42 links verified","oss-ledger-replay-console.d541a61ec0":"BLAKE3 chain","oss-ledger-replay-console.5e01cb01c2":"ed25519 anchor, segment sealed","oss-ledger-replay-console.9f899741a3":"approver M.Bos, segment 042","oss-ledger-replay-console.9051b9ddae":"ok, 12 ms","oss-ledger-replay-console.ff488da058":"stripe.balance_check, scope read","oss-ledger-replay-console.79019ee149":"gate finance.threshold, amount 4,210.00 EUR","oss-ledger-taxonomy.667cabb48e":"Typed, versioned","oss-ledger-taxonomy.d3b93c0536":"Every variant has a typed schema. New events ship in a release, not a quiet edit.","oss-ledger-taxonomy.cf806846ee":"EventCategory::","oss-ledger-taxonomy.cb954838cb":"EventType, EventCategory","oss-ledger-taxonomy.081ae3fdc4":"Custom","oss-ledger-taxonomy.d12cfa9efc":"A typed escape hatch for domain events you define.","oss-ledger-taxonomy.4cf3240208":"AttestationCompleted","oss-ledger-taxonomy.dd3ae8b6c1":"SbomGenerated","oss-ledger-taxonomy.831cbf3ad4":"Security and attestation. SBOMs and attestations.","oss-ledger-taxonomy.f25ce1b8a3":"Security","oss-ledger-taxonomy.1a7627d54c":"AiIncidentDetected","oss-ledger-taxonomy.4898138bd8":"EU AI Act compliance. Incident detection events.","oss-ledger-taxonomy.dedad727ac":"AiAct","oss-ledger-taxonomy.b3a3748c43":"RightToErasureRequested","oss-ledger-taxonomy.dfe7fcbcba":"DpiaCompleted","oss-ledger-taxonomy.4fab14db5b":"DataSubjectRightExercised","oss-ledger-taxonomy.ab86bc6e9e":"ConsentRecorded","oss-ledger-taxonomy.e873136b8f":"GDPR compliance. Consent, subject rights, DPIA, erasure.","oss-ledger-taxonomy.da0a4b95e8":"ReplayFailed","oss-ledger-taxonomy.578b5b54e2":"ReplayCompleted","oss-ledger-taxonomy.c15d1fc45b":"ReplayStarted","oss-ledger-taxonomy.7d7ef123d3":"CheckpointCreated","oss-ledger-taxonomy.ea08ca0966":"SessionCompleted","oss-ledger-taxonomy.e6de229ac6":"SessionStarted","oss-ledger-taxonomy.b44962147c":"Session and replay lifecycle, plus checkpoints.","oss-ledger-taxonomy.bc0792d8dc":"System","oss-ledger-taxonomy.e4123c1102":"ArtifactReferenced","oss-ledger-taxonomy.d3e615076c":"ArtifactProduced","oss-ledger-taxonomy.0339479823":"Artifacts. What was produced and what was referenced.","oss-ledger-taxonomy.aa778b50a1":"Artifact","oss-ledger-taxonomy.eef1cb6ecc":"ApprovalDenied","oss-ledger-taxonomy.72386de3a3":"ApprovalGranted","oss-ledger-taxonomy.407736eae4":"ApprovalRequested","oss-ledger-taxonomy.0a13893f48":"Approval workflow. The request, the grant, the denial.","oss-ledger-taxonomy.8cc047ac17":"Approval","oss-ledger-taxonomy.2c9d7bf9d6":"PatchApplied","oss-ledger-taxonomy.9784d53322":"PatchCreated","oss-ledger-taxonomy.b97693dd7f":"Code operations. Patches created and patches applied.","oss-ledger-taxonomy.adac69379a":"Code","oss-ledger-taxonomy.c7ace4e00a":"ToolResult","oss-ledger-taxonomy.09d312bd1c":"ToolCall","oss-ledger-taxonomy.63d05f2173":"Tool interaction. The call envelope and the structured result.","oss-ledger-taxonomy.9a830c714b":"Tool","oss-ledger-value-ledger.422a684fc9":"Rebuild any state from events","oss-ledger-value-ledger.ed504b066a":"One ordered record from routine operation to incident review.","oss-ledger-value-ledger.a6c1933f89":"What it de-risks","oss-ledger-value-ledger.aba3dee917":"What it saves","oss-ledger-value-ledger.f2329e5337":"The two columns a procurement review cares about","oss-ledger-value-ledger.676ffa603b":"What it saves, what it de-risks","oss-ledger-value-ledger.80c52fbc33":"Built in the EU with no external service it relies on, it can run entirely on infrastructure you control.","oss-ledger-value-ledger.adf04b0d0c":"It can stay inside Europe","oss-ledger-value-ledger.9587ada4e7":"When a regulator or auditor asks what happened, the history can be read back in order from any point in time.","oss-ledger-value-ledger.317506fe62":"A straight answer when asked","oss-ledger-value-ledger.58044f2110":"Every entry is sealed to the one before it, so a tampered record shows itself instead of slipping past a review.","oss-ledger-value-ledger.0525fd8143":"A record that cannot be quietly edited","oss-ledger-value-ledger.9c33c89b50":"The same record shape works across all five storage choices, so moving between them is a copy, not a costly rebuild.","oss-ledger-value-ledger.9d184603c0":"One record, five places to keep it","oss-ledger-value-ledger.429e71cc9f":"Actors, approvals, artifacts, and outcomes stay in one typed timeline instead of being reconciled across services.","oss-ledger-value-ledger.3e34958589":"No manual log reconciliation","oss-ledger-value-ledger.0f65dc90fe":"Query one ordered event history instead of searching unrelated application logs during an incident or review.","oss-ledger-value-ledger.59fe8c6d79":"Less investigation time","oss-ledger-where-it-runs.4dc7c63d8f":"Same record, no re-platforming","oss-ledger-where-it-runs.afbf4223e1":"Pick one, or move between them with no rebuild","oss-ledger-where-it-runs.d2e1c215eb":"Where it is allowed to run","oss-ledger-where-it-runs.dcd08a03cd":"It runs completely cut off from the internet, with no outside connection it depends on. This suits the most sensitive work, where nothing is allowed in or out.","oss-ledger-where-it-runs.721605b85c":"Good for the most sensitive records, with no outside connection at all.","oss-ledger-where-it-runs.cd36883cc4":"Fully sealed off","oss-ledger-where-it-runs.6655cf0531":"It runs in a cloud region pinned to a European country. You get the convenience of a cloud while the record stays under European rules and inside European borders.","oss-ledger-where-it-runs.ed957bbbd7":"Good for teams that want a cloud, kept on European soil.","oss-ledger-where-it-runs.c8c94df45a":"A cloud inside Europe","oss-ledger-where-it-runs.8752e82d26":"It runs on the computers your own IT team manages, inside your walls. The record stays where you can point at it, and nothing needs to leave the building for it to work.","oss-ledger-where-it-runs.b5b4e0e7b8":"Good for teams that want the record to never leave the premises.","oss-ledger-where-it-runs.37635ed161":"In your own building","page-breadcrumb.c766e66518":"Breadcrumb","page-toc.7e439c353e":"On this page","section_st_a1_display-split.7c9a7c0610":"Detail","section_st_f1_cta-dark.90e40d5043":"Get started","toc-rail.f5cbdf6bfb":"Contents"}
