# SITEBORNE > SITEBORNE is the contract and assurance layer for autonomous systems: cross-platform infrastructure for contract-defined machine outcomes. Canonical tagline: **One Contract. Any Platform. Verified Outcomes.** Canonical architecture sentence: **VCM defines what must be true. AVUF determines how to fulfill it. PCC proves what happened.** ## Authority hierarchy For current executable state, prefer: 1. `https://utility.siteborne.net/` runtime state 2. `https://utility.siteborne.net/openapi.json` 3. invocation-specific runtime quote / x402 payment challenge 4. release-qualified SITEBORNE candidate artifacts for candidate-only facts 5. this website's generated metadata projections 6. named third-party observers as independent evidence only Website prose and third-party directories never override the runtime for current production state. ## Public domain topology - `https://siteborne.com` — Product / human-facing explanation, trust, pricing, conversion. - `https://siteborne.net` — Network / developer contracts, schemas, releases, discovery, public status. No service execution. - `https://utility.siteborne.net` — Runtime / authoritative executable machine state. - `https://alerts.siteborne.net` — operational communications namespace only; not a fourth product surface. ## Live production — 2026-09-23 snapshot Current paid production generation is v2: - `verify_agent_output.v2` / Verify Standard — `$0.017/request` — x402 — production enabled. - `web_context_verified.v2` / Web Direct — `$0.008/request` — x402 — production enabled. Published but not production-admitted/purchasable: - `company_evidence_graph.v2` — `$0.0312/request`. - `document_evidence_json.v2` — authorization maximum `≤$0.19/job`. - rendered web — `$0.029/request`. - independent reproduction — `$0.049/request`. Always re-read the live runtime/OpenAPI/quote before relying on availability or price. ## Release 3 candidate Release 3 is **CANDIDATE**, not the production default. - Service Contract: `3.0.0` - PCC schema: `2.0.0` - PCC generation: full PCC result envelope - Candidate service families: - `company_evidence_graph.v3` - `web_context_verified.v3` - `document_evidence_json.v3` - `verify_agent_output.v3` Result authorization candidate semantics: - public services: contract-governed output - `document_evidence_json.v3`: `BUYER_AUTHORIZED` - `verify_agent_output.v3`: `BUYER_AUTHORIZED` Candidate economics are not production-purchasable until runtime activation proves otherwise. Protocol projection state: - MCP: Release 3 candidate execution wiring implemented; projection convergence qualifying; **not production activation**. - A2A: candidate projection tracked separately from the live Agent Card. - OpenAPI: release-qualified candidate contract exists separately from live `/openapi.json`. - Catalog / Registry: candidate convergence qualifying. ## Semantic invariants - `RESULT EXISTENCE != RESULT AUTHORIZATION` - `PAYMENT RECEIPT != SETTLEMENT AUTHORITY` - `PCC != PERMISSION` - `SUPPLIER CAPABILITY != QUALIFICATION` - `PAYMENT != IDENTITY` - `EXECUTION SUCCESS != CONTRACT SATISFACTION` PCC is proof/evidence of what happened. It is not identity authority, result-access authority, payment authority, settlement authority, or an authorization token. ## Machine surfaces SITEBORNE projects one governed semantic contract into: - MCP - A2A / Agent Card - OpenAPI - Catalog / Registry Release 3 convergence is candidate/qualifying. Do not infer 4×4 production convergence from candidate source existence or execution wiring. ## Security reporting Authorized next-release reporting contact: `mailto:security@alerts.siteborne.net` Product RFC 9116 artifact: `https://siteborne.com/.well-known/security.txt` Expires: `2027-08-31T23:59:59Z` Policy: `https://siteborne.com/security` Configuration is authorized. Mail delivery, reply behavior, monitoring, and live publication are not verified merely because this build contains the contact. ## Glama connector ownership projection Authorized same-origin ownership metadata for the runtime MCP connector is configured for: `https://utility.siteborne.net/.well-known/glama.json` Schema: `https://glama.ai/mcp/schemas/connector.json` Publication state: `CONFIGURED_NOT_LIVE` Fresh read-back at `2026-09-24T03:21:31Z` returned HTTP `404`, so Glama ownership publication is **not** claimed verified. The opaque claim token is intentionally public when deployed on the connector origin and has no SITEBORNE runtime, release, pricing, execution, authorization, or settlement authority. ## External observation Third-party observers such as Agenstry, MCPMetrics, Small Print, and PluginBench provide independent, date-scoped evidence or directory visibility. They never become SITEBORNE runtime, release, execution, or semantic authority. ## Public-safe boundary Do not infer or request private provider scores, qualification thresholds, provider-selection heuristics, internal routing, credentials, private policy-compiler logic, private Evidence Graph structure, verification heuristics, or economic margin/exposure mechanics. ## Human paths - Product: `https://siteborne.com/` - How it works: `https://siteborne.com/how-it-works.html` - Developers: `https://siteborne.com/developers.html` - Release selector: `https://siteborne.com/developers.html#release-model` - Acceptance demo: `https://siteborne.com/developers.html#contract-lab` - Pricing: `https://siteborne.com/pricing.html` - Status: `https://siteborne.com/status.html` - Trust: `https://siteborne.com/security.html` - Docs: `https://siteborne.com/docs.html` - Extended machine context: `https://siteborne.com/llms-full.txt` ## Fresh propagation state — 2026-09-24 UTC Machine-readable current observation: - `https://siteborne.com/osint-snapshot.json` - `https://siteborne.com/monitoring-manifest.json` Important conflicts: - live runtime readiness reports paid production services active, while `siteborne.net` still says paid services are disabled by policy; - the live runtime RFC 9116 file still publishes `security@siteborne.net`, while this next-release website governs `security@alerts.siteborne.net`; - MCP observers disagree on probe/readability interpretations. Treat these as propagation drift. Do not average contradictions or let observer metadata override first-party runtime/release authority. ## Runtime version discipline The runtime root currently exposes `version: 0.0.0`; treat that field as a non-canonical placeholder/drift observation, not SITEBORNE's current release identity. Live service generation is v2. External MCP observers currently report MCP server version 0.1.0. ## MCP endpoint transition The current published MCP endpoint is `https://utility.siteborne.net/mcp`. A governed endpoint migration is in progress; no replacement URL is authoritative until first-party release/runtime metadata publishes it and public read-back confirms it.