Developers
Debate ledger

Verifiable Debate Ledger

Every decision is recorded. including the ones where Heron did nothing.

Why a refusal must be recorded

On the Safe path a refusal is nothing happening. Without a written record the chain cannot distinguish "considered and declined" from "the keeper is down", and that indistinguishability is precisely what this product claims to have removed. So on that path the ledger entry is load-bearing, not supplementary.

On the vault path a refusal is cap = 0. on-chain state, self-evidencing. The vault writes the whole decision, not only the negative half: admitting one market while declining two others is three facts, and all three land in storage.

Content addressing, and its limits

A record is content-addressed: the plan_hash proves these bytes hash to X.

⛔ It does not prove the log is complete. Two failure modes survive it:

Omissionnever publish record N, no auditor can prove an absence
Equivocationserve two auditors different chains, each internally consistent

Heron operates the mirror, so publishing it fixes neither. Only independent witness cosigning converts that evidence into control, and a witness that Heron recruits, funds and instructs answers "did somebody other than Heron press the button" and nothing else.

This is published rather than implied away. See Architecture for what is and is not attested on this deployment.

Replay

See Verify for replaying a decision without asking Heron for anything.