I11 — PUBLIC VERIFIABILITY: "Every sealed document must be publicly verifiable. Forever."

Document Overview

Document IDWINDI-VERIFY-MASTER-SPEC-20260305
Version1.0.0
StatusACTIVE — SEALED
ClassificationINTERNAL / ARCHITECTURAL
AuthorThree Dragons Protocol (Human Dragon + Architect)
Date05 March 2026
Related InvariantI11 — Public Verifiability (IRREMEDIABLE)
Genesis RecordWINDI-VERIFY-GENESIS-20260305

Constitutional Basis

Invariant I11 — Public Verifiability

"Every sealed document must be publicly verifiable. Forever."

Invariant I11 is irremediable. It cannot be revoked, suspended, or modified by any operator, administrator, or system update. Its activation on 05 March 2026 permanently commits the WINDI infrastructure to maintaining public verifiability for all sealed documents.

Infrastructure

Service Port:8114
Public URLwindi-domain.com/verify-public/
Direct Verify URLwindi-domain.com/verify/{hash}
Nginx Path/verify-public/ → proxy_pass :8114
Process Managersystemd
Database SourceForensic Ledger :8101 (SQLite + SHA-256)
API: verifyGET /api/verify/{id}
API: receiptsPOST /api/receipts
Total Receipts39,711+ (05.03.26)

Verification Pipeline

INPUT: QR scan | File upload | Document ID | Direct URL ↓ HASH EXTRACTION: SHA-256 fingerprint from document ↓ LEDGER QUERY: GET /api/verify/{hash} → :8101 ↓ RESULT A: hash found → VERIFIED ✔ RESULT B: hash not found → NOT FOUND ✗ RESULT C: structure only → ANALYSIS ⚠

Verification Modes

Mode 1 — WINDI Verification (Primary)

The authoritative mode. Used for all documents produced and sealed within the WINDI ecosystem.

This mode is the sole basis for legal and institutional claims of document authenticity.

Mode 2 — Generic Analysis (Secondary) — Planned

An analytical mode for documents not produced by WINDI. Provides structural analysis without making authenticity claims.

Mode 3 — Constitutional Scanner — Future

The long-term vision: WINDI Verify as an authenticity antivirus. Any document enters. The system answers one question:

"Does this document have cryptographic proof of existence?"

FREMDE Data Policy

FREMDE (external/foreign) data refers to documents and cryptographic elements not originating from WINDI.

PhasePolicyRationale
NOW (v1.x)Zero FREMDE. WINDI documents only.Authority-building phase. No ambiguity.
MEDIUM (v2.x)FREMDE read, not certified.WINDI still = superior standard.
FUTURE (v3.x)Constitutional scanner. Any document.WINDI = authenticity infrastructure.

Principle: WINDI Verify first builds authority, then expands jurisdiction. FREMDE analysis never dilutes WINDI certification.

Liveness Detection (Planned)

Camera capture for liveness detection is a planned capability for HIGH-tier document signing and DID creation.

Use Cases

Technical Approach

Passive livenessMicro-movement analysis — blink, breath, natural motion
Active livenessUser prompted — turn, blink, smile, finger count
Storage policyNO face image or video stored — constitutional requirement
Ledger recordliveness_confirmed=true + timestamp + event_hash ONLY
GDPR basisExplicit consent required — biometric data category
I9 complianceCamera does not escalate AI autonomy — human confirms presence

Roadmap

v1.0 LIVE Verify Public :8114. QR + Upload + ID. WINDI-only. I11 sealed. Genesis record.
v1.1 NEXT QR in documents → direct verify URL. Verify button in all email correspondence.
v1.2 PLANNED Verify Public UI refinement. Institutional design. Public documentation.
v2.0 MEDIUM FREMDE structural analysis. Hash/QR/signature detection without WINDI claim.
v2.1 MEDIUM Liveness detection for HIGH-tier signing. eIDAS substantial compliance.
v3.0 FUTURE Constitutional scanner. Universal authenticity analysis. WINDI = standard.

Document Sealing Record

Document typeARCHITECTURAL_SPEC
Impact levelCRITICAL
Risk levelR5 — Institutional
Seal requirementMandatory — Three Dragons Protocol
RetentionPermanent — I11 scope
DistributionInternal — WINDI Architecture team
Sealed hash[TO BE FILLED ON SEALING]
Serial[WINDI-2026-XXXX]