Verifiable-evidence infrastructure

Infrastructure for the morning after.

Trust cannot be engineered away, regardless of promises made during each hype cycle: greengage is the calm to reach for, making trust accountable on rails you already have.

The morning after

A decade chasing trustlessness comes with a long hangover.

The industry has sunk an enormous amount of money and talent into the promise of trustlessness: if everything moves onto a shared ledger and is tokenized, counterparties no longer need to trust each other, or any middleman.

As this is revealed to be an over-promise, we are left with a long hangover. Consortium chains are siloed closed-loops. Bridges, the connective tissue between the new tokens, drained for billions, again and again. Ad-hoc clearing houses are required for "the digital dollar". A landscape that's ever more over-tokenized, full of incompatible stacks that can't talk to each other, while underneath it all, system architects grapple with the quiet realization that the trust never actually left the room, and true value still transacts on traditional rails.

The premise

You can't remove trust from anything real, but you can make it accountable.

Full trustlessness only exists for "native assets" (in reality just tokens) native to a blockchain itself. The moment something real enters - a dollar of USDC, a wire of fiat, a megawatt of power, a cargo of ore - you're trusting an issuer, a custodian, a sensor, or an oracle again. "Trust me" isn't a flaw in one system; for everything that matters, it's the ground floor, and this is never going to change.

Instead of struggling to replace "trust me" we can instead turn the screws as tight as possible on "trust, but verify."

Everything greengage does serves this goal: gather evidence around each and every claim, and commit to that evidence strongly enough that so that anyone can prove what was agreed, what happened, and who's responsible.

The simplification and it's implications

Bilateral commitment format favoring detection over prevention.

Once trust is decomposed to irreducible and composable elements, the cost of machinery built to globally prevent misbehavior is revealed to be significantly overpriced. Global consensus networks are a slow, hard-to-integrate way to guarantee only the on-chain shadow of a real-world outcome. Greengage simplifies: identified parties sign directly (no network to join); misbehavior is made provable and attributable rather than globally blocked; heavy cryptography costs are spent only where it pays, for instance when value crosses from one rail to another.

While this takes some capabilities off the table, this is a strong part of the case. True simplicity is not just what you don't need - it is what you can't have. And blockchains are just one of many technologies to reach for when eventual finality is required.

What we lose (but can borrow back as needed)

  • A single global source of truth
  • Automatic prevention of misbehavior
  • Base-layer fair exchange of signatures
  • The promise of native-asset trustlessness
  • Global network effects

What we gain (and is missing from almost all platforms)

  • Bilateral truth, with an escalation ladder climbed only as far as needed
  • Attributable evidence, which is what deters among accountable parties
  • Atomic hop to other platforms, spent precisely where value crosses rails
  • Base layer operation: we sign directly over real evidence for real assets
  • Massively lower adoption barrier, working on existing rails
What greengage provides

The agreement layer.

Two or more identified parties agree on a statement and independently sign it, producing a small artifact that travels with whatever it describes. The infrastructure world has mature formats for one party attesting to something: a certificate, a build attestation, a platform's word. What it lacks is a small, portable standard for two parties agreeing, and for that agreement evolving over time without either side rewriting it. That gap is what greengage fills.

Self-contained

Verifiable offline by anyone, with no network or permission required.

Non-repudiable

Neither side can later disown what they signed.

Chained

Agreements link by cryptographic hash into one verifiable thread of history.

Domain-agnostic

The content is opaque to the protocol. The same atom carries a payment, a custody handoff, a meter reading, or a build.

Rides existing rails

It layers onto the systems already in place rather than replacing them.

Open by design

An open specification with conformance vectors: a standard to build to, not a box to route through.

How the evidence accumulates

The accountability of a public ledger, without the ledger.

Blockchains fuse distinct problems into one expensive answer. greengage pulls them apart: agreement (what did two parties commit to?) is settled by a signature, offline, with no network; consistency over time (is a party telling everyone the same story, and not rewriting its past?) is settled by a witnessed commit log, with no consensus. You climb this ladder only as far as the trust gap requires, and cost rises with each rung.

1 · Commit

Both parties sign one statement. Neither can later deny it.

2 · Chain

It hash-links to prior commitments. Its place in history is fixed: no reordering, no splicing.

3 · Receipt

The counterparty signs for delivery. "I never received it" stops being available.

4 · Chain-head

The publisher signs one root over its whole set of facts. Anyone can check a fact is included; withholding becomes visible.

5 · Commit log

Independent witnesses vouch the history is singular and append-only. It can't tell a counterparty one story and a regulator another, or delete a past commitment. Equivocation is provable by anyone, with no central authority.

6 · Atomic hop (next)

At the one instant value crosses between rails, the exchange is all-or-nothing.

greengage runs between the checkpoints of the systems you already trust (a new block, a BFT finalization, a settlement cutoff), and anchors to that finality only when a deployment needs it. The data stays with the parties and their witnesses; ordering and finality are borrowed from a checkpoint at the cadence required. Where you place a commitment is what determines the finality it inherits. Rungs 1–5 are built and adversarially reviewed; rung 6 is next.

The company it keeps

One missing layer, beside systems that already earned their keep.

greengage doesn't ask you to replace anything. The other layers of the problem were solved years ago, in production, by systems courts and auditors already accept. We supply the one layer they all assume and none of them standardize.

Consistency · transparency logs

Certificate Transparency has run append-only logs at internet scale for over a decade, and its descendants (Sigstore, Sigsum) are growing an ecosystem of independent witnesses. greengage's commit log speaks the same RFC 6962 machinery, so those witnesses can vouch for our history too.

Control · registries and vaults

eVault and registry systems have carried court-accepted, transfer-exactly-once electronic records for twenty years. The vault keeps control; greengage makes the record inside it independently verifiable.

Settlement · the rails you have

Value keeps moving on the rails that already move it: bank rails, card rails, stablecoins where they fit. greengage binds evidence to the movement by hash and never touches the money.

And agreement — the record of what two parties actually committed to, evolving without either side rewriting it — is the layer greengage supplies. Blockchains fit in this picture too: as one kind of checkpoint to anchor to, when open membership or cross-domain finality is genuinely needed.

Where it applies

One primitive, many mornings after.

An index, a clearing record, a custody chain, and a build attestation are, underneath, the same object.

Supply-chain provenance

Minerals, rare earths, pharma, food: each handoff a signed commitment, with tamper-resistant sensors co-signing the physical reading.

Power markets

Micro-monitoring, settlement, and verifiable indices for power derivatives across grids and jurisdictions that will never share one ledger.

Software & deployment provenance

Proof that code was produced by exactly who it claims. Deployments ship complete with their chain of evidence.

Clearing & settlement

Across tokenized products and between incompatible stacks: the neutral evidence layer for a world that over-tokenized.

Regulatory & identity

Reusable KYC/AML, travel-rule, credentials, and reporting an auditor can verify offline.

Cross-border payments

Compliance attestations travelling with the money, every step independently verifiable.

The calm under the hood

Rigor as a repeatable process.

Every protocol element justifies its existence: each specification ends with a removal table for every field, detailing the concrete attack that becomes possible if you delete it. A field that can't name an attack is deleted.

Each rule ships with an executable test vector, including negative vectors that each name the attack they encode, generated by an independent oracle rather than by our own code.

The team attacks its own work, blind, before anything ships. Each milestone ends with an adversarial review by fresh reviewers who see only the artifacts and tries to break them with forged bytes. This has caught and forced fixes for real flaws, including a denial-of-service path, each demonstrated with a concrete exploit and re-verified after the fix.

Where we are

The detect-mode ladder is built. Settlement is next.

We're early and precise about it: the detect-mode ladder (commitments, the chain, receipts, chain-heads, and the witnessed commit log) is built, conformance-tested, and adversarially reviewed. The atomic settlement hop and the running end-to-end demonstration are ahead of us.

Commitment layer: spec, verifier, chainComplete
Receipts, chain-head, and the witnessed commit logComplete
Atomic cross-rail settlementNext
Transaction lifecycle + signed-HTTP bindingPlanned
First end-to-end vertical demonstrationPlanned