# SITEBORNE Public Model Documentation

**One Contract. Any Platform. Verified Outcomes.**

SITEBORNE is the contract and assurance layer for autonomous systems.

**VCM defines what must be true. AVUF determines how to fulfill it. PCC proves what happened.**

## Canonical semantic model

SITEBORNE uses one canonical semantic truth and projects it deterministically into machine surfaces.

### VCM
The VCM Capability Contract is the current/core semantic contract model. It defines acceptable completion independently of provider, transport, or protocol.

### AVUF
AVUF is the governed execution/fabric layer that determines how an eligible contract is fulfilled. The broader fabric is **candidate/evolving** and must not be described as a production-wide routing claim without runtime evidence.

### Assurance
Assurance evaluates the returned state against the contract. Execution success alone does not equal contract satisfaction.

### PCC
PCC is proof/evidence of what happened.

Release 3 candidate work uses a full PCC result envelope with schema `2.0.0`.

PCC is not:
- identity;
- permission;
- payment authority;
- result-access authority;
- settlement authority.

### Result authorization
Result authorization governs whether a caller is allowed to receive a controlled result.

Release 3 candidate semantics include `BUYER_AUTHORIZED` handling for:
- `document_evidence_json.v3`
- `verify_agent_output.v3`

Payment does not prove identity, and execution does not automatically authorize result retrieval.

### Settlement authority
Settlement authority remains separate from execution, proof, and result authorization.

## Technical thin waist

`VCM Capability Contract`
→ `Policy + Authority Decision`
→ `Causal Execution State`
→ `Assurance Decision`
→ `PCC two-proof envelope`
→ `Settlement Authority`

Sensitive-service result handling can require an additional governed result-authorization decision before disclosure.

## Release-state model

SITEBORNE uses these states consistently:

- **DESIGN** — architectural intent, not executable state.
- **CANDIDATE** — implemented release candidate, not the production default.
- **QUALIFIED** — a specific gate has passed with evidence.
- **QUALIFYING** — qualification/convergence work is in progress.
- **PRODUCTION** — activated and observed in the live runtime.
- **DISABLED** — defined but not admitted for production use.
- **NOT RUN** — a required gate is not established by the available evidence.

A candidate is not production simply because source, routing, or generated schemas exist.

## Current live production

Live production remains the v2 generation:
- `verify_agent_output.v2` / standard — `$0.017/request`
- `web_context_verified.v2` / direct — `$0.008/request`

`utility.siteborne.net` and its live OpenAPI/quote are authoritative.

## Release 3 candidate

- Service Contract: `3.0.0`
- PCC schema: `2.0.0`
- Candidate services:
  - `company_evidence_graph.v3`
  - `web_context_verified.v3`
  - `document_evidence_json.v3`
  - `verify_agent_output.v3`

Release 3 is under pre-release qualification and is not the production default.

## Machine surfaces

The four primary contract surfaces are:
- MCP
- A2A / Agent Card
- OpenAPI
- Catalog / Registry

The intent is:

`one canonical semantic truth → deterministic machine projections`

Current live surfaces and Release 3 candidate projections are represented separately.

Release 3 MCP candidate execution wiring is implemented, while projection metadata convergence remains **QUALIFYING**. That is not production activation.

The Release 3 candidate OpenAPI artifact is:
`contracts/releases/3.0.0/openapi/service-contracts.openapi.json`

The public live OpenAPI remains:
`https://utility.siteborne.net/openapi.json`

## Domain topology

- `siteborne.com` — Product / human-facing explanation and conversion.
- `siteborne.net` — Network / contracts, schemas, releases, discovery, public status.
- `utility.siteborne.net` — Runtime / authoritative executable machine state.
- `alerts.siteborne.net` — operational communications namespace only; not a fourth product surface.

## Security reporting

Authorized next-release contact:
`security@alerts.siteborne.net`

RFC 9116 expiry:
`2027-08-31T23:59:59Z`

The build does not claim mailbox deliverability, reply behavior, active monitoring, or live publication without external verification.

## Authority hierarchy

For current executable behavior:
1. live runtime observation;
2. live OpenAPI/current quote for live request semantics/economics;
3. release-qualified repository/candidate artifacts for Release 3 candidate state;
4. website projections;
5. third-party observers as independent evidence only.

See [Developers](developers.md), [Status](status.md), [Pricing](pricing.md), and [Trust](security.md).


## Fresh external propagation snapshot — 2026-09-24 UTC

Current public observation is intentionally kept separate from SITEBORNE authority.

- Fresh runtime readiness reports `status=ready`, `phase=production`, and paid production services active.
- `siteborne.net` still states that paid services are disabled by policy. This is first-party publication drift and should be reconciled; it does not override runtime state.
- Agenstry observes A2A 1.0, 8 declared skills, x402 metadata, machine/search discovery, and 100% 30-day uptime. Its mutable trust/owner fields have varied across current indexed views, so those scores are not canonical SITEBORNE facts.
- MCPMetrics observes 6 MCP tools and 79/79 successful probes over its current 30-day window, with p50 latency around 706 ms.
- Glama independently observes 6 tools and a healthy endpoint, but its longer-window uptime differs materially from MCPMetrics; the two measurements are preserved rather than averaged.
- Small Print tracks two registry versions, 11 semantic changes in one release, and 0 recorded public advisories at this observation.
- PluginBench exposes the official registry identifier `net.siteborne/utility` and direct Streamable HTTP configuration.
- Mcprush currently misinterprets the server as 0 tools / free. Treat this as observer/parser drift, not SITEBORNE runtime truth.
- FastDrop currently records repeated probe failures despite successful observations by other MCP observers. This is a monitoring/probe-compatibility conflict requiring re-check.
- Search indexes still expose some historical SITEBORNE paths/copy, so search identity convergence is incomplete.
- No confirmed public chain transaction, third-party package integration, or organic community adoption signal was established in the searched sources. Absence of evidence is not evidence of nonexistence.

Machine-readable evidence and monitoring configuration:
- `/osint-snapshot.json`
- `/monitoring-manifest.json`

External observers are evidence only. They never become execution, release, pricing, settlement, or semantic authority.


## Governing architecture update

Current **GOVERNING DESIGN** further separates `AuthorityGrant → ExecutionLease + fencing → CommitGrant where required → Assurance → FinalPccDocument → Result Authorization + ResultBinding → Settlement Authority + SettlementGrant`. This design context is not a production-deployment claim; fresh repository/runtime evidence remains required for implementation state.
