# Verification receipts — public derivations

These are **curated public derivations** of the internal
verification record — condensed, with connective prose written for
public reading; repository, branch and checkout names, hosts and
internal record identifiers neutralised. The guarantee is separate
and exact: **every verdict, gate, number and hash copied from the
internal record is unchanged.** Four receipts.

## Receipt A — Part II consolidation (2026-08-26)

The four experiment reports were re-verified against sealed artefacts
before this paper was drafted.

**Gates, with results:**

- **Regeneration:** all four score files (E1, E2, E3-assembled, E5)
  regenerate **byte-identically** from the archived raw trajectories
  under the frozen scorers. Scorer identity is blob-pinned: the E3
  scorer is byte-identical to its freeze blob `c7855be8…` and the E5
  scorer to blob `f40c5340…`; scoring registries `m1-registry-1`
  (E1/E2) and `m1-registry-e5-1` (E5) as declared.
- **Recount:** every ruled headline in all four reports recomputed
  exactly from per-run rows.
- **Archive integrity:** the evidence archive's `SHA256SUMS` verified
  — all six run tarballs OK.
- **Copies are copies:** every main-tree mirror of a branch-owned
  report or score file is blob-identical to its source branch.
- **Not re-verifiable from the consolidation machine:** container
  image and wheel digests (pinned values, relied on as documented,
  not re-hashed — the images live on the execution estate); the
  proxy-reported cost figure is the proxy's number, not recomputed.

**Deviation register (complete — the six sentences in the internal
reports' prose whose printed numbers the artefacts do not reproduce;
none changes a ruled claim's direction, magnitude or standing; all
six are corrected in the paper):**

1. E3 "unclassifiable 0" → artefact: 639/140/416/555 per cell —
   1,750 of 64,137 declared claims (2.7%) outside the two scored
   predicate families. The adjacent "all claims sourced" is exact.
2. E3 "coverage 1.0 on own accepted events" → artefact: pooled
   2,382/2,414 = **0.987**; 32 of 59 graded minds at 1.0; minimum
   0.9333.
3. E3 "claims-per-call mean ~9.6" → artefact: 9.06 pooled (9.10
   mind-mean); 59 empty calls of 7,077; ceiling 12 — the
   abstention/ceiling reading is unaffected.
4. E5 "559 consults across the set" → admitted banks: 750 consult
   rows = 705 model-labelled + 45 scripted deliveries (no model
   call); the exact-model-set property holds at every denominator
   (705/705 the accepted model, unique request ids); 559 reproduces
   from no bank.
5. E5 ungated perseveration band "884–993" → the refusal-count band
   is 885–993; 884 is the attributed minimum (the trusting arm's
   838–963 is the refusal band, exact). One endpoint, mixed basis.
6. E5 authentic-consult nuance (omission, not error): of 266
   authentic quiet-arm consults, 262 were clean declines and 4
   malformed replies — all 266 delivered zero claims, which is what
   the no-exposure ruling rests on.

## Receipt B — Part I artefact recount (2026-08-26)

An artefact-plane review, performed independently of the drafting
session, recomputed every quantitative and seed-level claim from the
sealed arms and grids (manifest, Part I section) — not from the
draft.

- **Chain of custody:** the three degradation-grid hashes match the
  values pinned in the registered design records before analysis
  (`937b3520…`, `73c67f58…`) and the estate-side final in the §4.4
  independent-verification receipt (`30bdf8d5…`); the three §4.1 arm
  hashes are banked in the manifest.
- **Recount:** 0 mismatches in all 220 grid rows recounted from raw
  verdict rows; 33 + 55 + 55 + 110 = 253 runs. §4.1's pooled
  35/28/44 → 75/28/4 on 107 verdicts/arm exact, current head
  verdict-row-identical to the treated arm at every seed. §4.2's 55
  rows recount; p=0 is per-seed identical to the untreated arm;
  unexplained exactly 28 at every level. §4.3's set-identity claim
  verifies exactly: the one seed that improves under full removal is
  the one seed with residual false attribution, the same seed §4.1's
  repair could not touch (false 4 → 0; jointly 40 + 4 = 44). §4.4's
  5 × 2 table exact in every cell; Δcorrect −5, −4, −4, −4, 0 and
  Δfalse +4, +15, +30, +49, +60 exact; 0 false attributions in all
  510 blinded-arm verdicts; the eyewitness rung fired in **0 of all
  253 runs, anchors included**. The behavioural-invariants gate
  passed in all 220 grid rows.

## Receipt C — related-work query provenance (2026-08-26)

The search appendix's Group 2 query list (28 strings) was restored in
full from the sweep agent's own record after an external reviewer
noted an earlier condensed listing. The receipt establishes that the
restored strings were **preserved in the contemporaneous agent
record**, not reconstructed after the discrepancy was noticed:

- All 28 strings occur verbatim on a single line of the drafting
  session's append-only record, timestamped
  `2026-08-26T03:58:28.017Z` — hours before the review that flagged
  the condensed listing existed. Line SHA-256:
  `1c580bfa84e920774382edfc62f7b9cf7dd4427bc2d038be019e4ba63ba538c7`
  (22,512 bytes).
- The mechanical occurrence check (exact string match, no
  interpretation) returned **28/28**, and was independently re-run
  the same day by a separate session with no part in the sweep or
  the restoration, read-only, with the same result.
- Location details of the internal record are withheld under the
  disclosure posture; the check is available to a verifier with
  access on request.

This receipt completes the appendix's accounting distinction:
*verbatim query strings preserved in the contemporaneous agent
record* (85, enumerated) versus *total search executions* (not
claimed — adjudication follow-ups were not contemporaneously
enumerated).

## Receipt D — §4.5 witnessed-strike collection (2026-09-01)

The §4.5 collection postdates the Receipt A/B consolidation and is
verified on its own chain, derived from the internal collection
report; the four file identities below were re-verified against the
private archive's stored bytes at derivation time (full values in
the manifest).

- **Collection integrity:** 88/88 cells, exit 0, zero error rows,
  zero refusals; the results file (`895d4b03…`) byte-identical in
  five independently held locations.
- **Instrument identity:** tree aggregate `02445d7c…` equals the
  value frozen with the preregistration; driver `85dcbdd9…`; the
  preservation archive's unchanged scorer/instrument aggregate
  confirms the collection modified no instrument file.
- **Anchor receipts, re-executed live:** both untreated anchor cells
  reproduce the frozen pre-collection gate verdict arrays — sighted
  `168e5323…` byte-exact, blind matching the recorded prefix
  `a1ee2230…` — checkable against the gate-receipts file
  (`cd994994…`).
- **Causal boundary:** all four preregistered gates pass in all 44
  twins, zero VOIDs; the entire saboteur decision stream is identical
  in every twin (strikes = 44 and marked faces = 107 in every cell).
- **Scoring, by the rule frozen before collection:** the primary
  recomputes from the results file under the committed scorer
  (`e8a3feca…`): per-seed vector +2, +1, +1, +1, +1, +2, +3, +2, 0,
  +3, 0 → mean +1.455, 9 of 11 seeds positive. Secondaries recount
  from the same file: +16 correctly named attributions at each marks
  level with the identical per-seed vector; zero false names in all
  32 fired verdicts; historical false attribution 65 → 55 at zero
  legibility; 8 of 176 treated strikes had no eligible witness,
  recorded and never retried.
