Evidence and proofs
What REX saw, hashed so it cannot be edited after the fact.
Evidence is what the verifier actually fetched, stored as a hash of the bytes plus a redacted preview — never the third-party payload in full.
{
"source_url": "https://api.exampledata.io/invoices/8812",
"content_hash": "b1946ac92492d2347c6235b4d2611184",
"size": 2418,
"redacted_preview": "{\"invoice\":\"8812\",\"total\":\"84.00\",\"generated_at\":\"…\"}",
"attestation_ref": "rialo:host-evaluated:1786…",
"expires_at": "2026-09-14T12:00:00.000Z"
}The hash outlives the body
content_hash is a digest of the bytes the check fetched. redacted_preview is
a trimmed, redacted extract kept for a human reading an escalation.
They have different lifetimes on purpose. expires_at retires the preview,
while the hash stays. Months later you cannot re-read what a supplier's API
returned, but you can still prove that the bytes someone shows you now are or
are not the bytes the check saw — and that is the claim a dispute actually turns
on.
Raw third-party payloads are never stored in full. A payments system that retains every response it ever fetched is a data-retention problem wearing a verification system's clothes.
Evidence belongs to a check, not to a warrant
The chain is warrant → check → evidence. A check carries attempt, so a retry
is a new check with its own evidence rather than an overwrite of the last one.
That matters when something is flaky. A source that failed at 14:02 and passed at 14:05 leaves both records, and the escalation shows the sequence rather than only whichever answer happened to arrive last.
What a check records
| Field | Meaning |
|---|---|
result | pass, partial, fail, or error |
score | 0–10000 basis points, the share of clauses that passed |
attempt | Which try this was |
started_at / finished_at | Wall-clock bounds of the evaluation |
error is distinct from fail and the difference is not cosmetic. fail means
the deliverable was checked and did not meet the clauses. error means the
check could not be completed — the source was unreachable, the response was
unparseable. Paying or refusing on error would be deciding on evidence that
does not exist, which is why those reason codes are the usual candidates for a
policy's alwaysEscalate list.
Attestations
attestation_ref records where the evaluation ran. Today it reads:
rialo:host-evaluated:<epoch>:<len>:<digest>host-evaluated is literal and it is not a placeholder for something stronger.
It means the clause evaluation happened on the host rather than inside an
attested enclave. When evaluation moves into the enclave the prefix changes to
say so, and until it does the string will not claim otherwise.
Read that as: the record proves what was evaluated and when, and it does not yet prove where. Both matter, and only one is currently true.
Amounts, wherever they appear
Amounts on evidence, checks and every other surface are integer strings of the
asset's smallest unit, validated against ^[0-9]+$.
"8400000" 8.40 USDC
8400000 rejected — a JSON number
"8.40" rejected — not the smallest unit