Skip to main content
waiOS · Audit

An audit record that verifies offline.

waiOS will keep the receipts and claims an organisation's WAI work produces, with its own records of policy decisions, and export them for audit. Every WAI receipt and claim in an export will verify offline with the open verifiers. waiOS's own records will be new formats, which the standard does not define.

Roadmap Not yet operating. Each open component below is labelled with where it stands on the WAI status page.

The three labels

In the standard
The open component is in the main branch of the WAI open standard. Its link goes to its row on the dated WAI status page, and its notes are that row's.
Building
The open component is in active development, as the WAI status page lists it.
Roadmap
Planned: a WAI roadmap item, or a waiOS service. Every waiOS service is on the roadmap; none is operating yet.

Attested, in WAI, means signed by the party that did the work and measured it: a reader can check the signature, not re-measure the figure. It is not hardware attestation.

01 · The service

What waiOS will keep, and for how long.

  • Retention of receipt chains, stage and session claims and key-release decisions, for the period the organisation sets.
  • Retention of policy-decision records, a waiOS format.
  • Registration of receipts with a transparency service where an organisation requires it, with the inclusion evidence kept verbatim.
  • Audit bundles: the WAI receipts and claims, the key-log revisions that sign them, and the open verifier that checks them.
  • Lawful-basis receipts where processing needs one.
  • A gap in a chain reported as a gap. A missing receipt is never filled in.
02 · Builds on

Open components, each with its WAI label.

  • In the standard

    Typed receipt classes, among them lawful-basis, log-inclusion and delivery-gap, with an independent verifier.

  • In the standard

    A relay cannot splice, replay or hold back a track's receipts unnoticed.

  • In the standard

    Transparency: an external receipt encoding and transparency-service registration, and log-inclusion claims.

    Notes A log-inclusion claim carries the log's evidence verbatim; accepting the claim is not verifying the inclusion.

  • In the standard

    Offline verification of receipts and claims against a key log.

  • In the standard

    One signature rule for every Ed25519 signature WAI defines.

    Notes OER/2 keeps the signature rule its own extension settles. The quantum toolkit's receipts are verified by its own verifier, which does not yet apply this rule.

  • In the standard

    Key-release decision records: every release and every refusal is a signed receipt.

    Notes Records decisions; speaks no licence protocol.

No certification claimed

waiOS will produce evidence; it is not a certification. It holds none today, and this site names a certification only once it is held.

03 · Roadmap

Planned, in the standard and in the service.

  • Roadmap· waiOS

    Retention, audit bundles and transparency registration.

04 · Limits

What this page does not claim.

  • The open verifiers check WAI receipts and claims. Policy-decision records, fleet inventories, aggregated reports and carbon figures will be waiOS formats; no open verifier in the standard checks them.