Normative library#
These are the immutable HushSpec v1.0.0 release documents. They define the portable contracts. The adjacent guides explain how to use them; a guide is not an alternate specification.
| Contract | Read it when you need to know |
|---|---|
| Core | Document validity, twelve rules, conditions, decisions, enforcement, and L0-L5 |
| Canonical form | Exactly which bytes determine a policy hash |
| Receipts | The v0.2 decision evidence structure |
| Signing | Ed25519 envelopes, trust, verify-on-load and receipt signing |
| Receipt log | Hash links, rotation and ordering |
| Bundles | DSSE / in-toto policy distribution |
| Grammars | Portable identifiers, patterns and wire strings |
| Security | Threat assumptions and enforcement boundaries |
| Posture | Capabilities, budgets and state transitions |
| Origins | Trusted origin selection and narrowing |
| Detection | Exact heuristic scoring and detector traces |
| Versioning | Compatibility and frozen contracts |
| Errata | Corrections without silent semantic drift |
Every page exposes its pinned source and raw Markdown. The site records the release commit separately from the revision of its explanatory guides. Registries and JSON Schemas supply machine-readable companions; schema validation alone is not evaluator conformance.