{
  "object": "seal.status",
  "source": {
    "readme": "spec/README.md",
    "changelog": "spec/CHANGELOG.md",
    "repository": "https://github.com/AnyRouteRH/AnyRoute/tree/main/spec"
  },
  "spec": {
    "version": "0.1.0",
    "released": "2026-09-29",
    "unreleased_changes": true,
    "license": "Apache-2.0",
    "license_url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/spec/LICENSE",
    "documents": [
      {
        "number": null,
        "title": "SEAL: the Anyroute privacy protocol",
        "file": "spec/README.md",
        "url": "/spec/"
      },
      {
        "number": "0001",
        "title": "SEAL 0001: Attestation",
        "file": "spec/0001-attestation.md",
        "url": "/spec/0001-attestation/"
      },
      {
        "number": "0002",
        "title": "SEAL 0002: Transport",
        "file": "spec/0002-transport.md",
        "url": "/spec/0002-transport/"
      },
      {
        "number": "0003",
        "title": "SEAL 0003: Anonymous credits",
        "file": "spec/0003-credits.md",
        "url": "/spec/0003-credits/"
      },
      {
        "number": "0004",
        "title": "SEAL 0004: Receipts and verification",
        "file": "spec/0004-receipts.md",
        "url": "/spec/0004-receipts/"
      },
      {
        "number": "0005",
        "title": "SEAL 0005: Measured policy",
        "file": "spec/0005-policy.md",
        "url": "/spec/0005-policy/"
      },
      {
        "number": null,
        "title": "Changelog",
        "file": "spec/CHANGELOG.md",
        "url": "/spec/changelog/"
      }
    ]
  },
  "meaning": [
    "\"Implemented\" means the code and its validation are in this repository. It does not mean it is deployed or switched on: most privacy features are off by default and need configuration. \"Planned\" means specified here and not yet in code."
  ],
  "lanes": [
    {
      "lane": "public",
      "path": "TLS to the router, then to any provider",
      "who_can_run_it": "Any provider",
      "payment": "API key, credits, per-call payment or blind token"
    },
    {
      "lane": "attested",
      "path": "TLS to the router, then to an enclave whose attestation the router verified recently",
      "who_can_run_it": "Attested providers only",
      "payment": "API key, credits, per-call payment or blind token"
    },
    {
      "lane": "unlinkable",
      "path": "Oblivious HTTP through an independent relay to the router's gateway, or Tor to the router's onion service; then to an attested enclave",
      "who_can_run_it": "Attested providers only",
      "payment": "Blind tokens only; an API key or a wallet is refused"
    }
  ],
  "guarantees": [
    {
      "id": "G1",
      "name": "Attested execution",
      "target": "A request is served only by an enclave whose CPU quote and GPU evidence match a publicly logged manifest."
    },
    {
      "id": "G2",
      "name": "Weights identity",
      "target": "The digest of the served weights is measured at boot and named in every receipt."
    },
    {
      "id": "G3",
      "name": "Confidentiality",
      "target": "Plaintext exists only in confidential-VM memory and confidential-GPU memory; requests are encrypted from the client to a key the enclave's evidence binds."
    },
    {
      "id": "G4",
      "name": "Unlinkable payment",
      "target": "The credit issuer cannot link a purchase to a redemption, and a DLEQ proof shows it signed with the published key rather than a per-user one."
    },
    {
      "id": "G5",
      "name": "Network privacy",
      "target": "On the unlinkable lane the client's address is hidden from the router by an Oblivious HTTP relay run by another operator, or by Tor when the request reaches the router's onion service."
    },
    {
      "id": "G6",
      "name": "Verifiable receipt",
      "target": "Each response has a signed receipt with request and response hashes, a hash chain over streamed chunks, the execution profile and the policy hash; receipt roots are anchored on chain."
    },
    {
      "id": "G7",
      "name": "Verifiable policy",
      "target": "What the enclave blocks is defined by a measured policy document whose hash is public; nothing else is filtered and no content is logged."
    },
    {
      "id": "G8",
      "name": "No key partitioning",
      "target": "Every key or configuration a client encrypts to or verifies against is in a witnessed transparency log, and clients refuse keys that are not."
    }
  ],
  "parties": [
    {
      "symbol": "U",
      "party": "User or agent, with the client SDK",
      "learns": "Everything about its own requests",
      "does_not_learn": ""
    },
    {
      "symbol": "R",
      "party": "Oblivious HTTP relay (another operator); on the Tor path, the volunteer relays of U's Tor circuit instead",
      "learns": "U's address (on the Tor path only the entry relay, which does not learn the destination), ciphertext sizes and timing",
      "does_not_learn": "Content, destination host or model, payer"
    },
    {
      "symbol": "G",
      "party": "Anyroute gateway and router",
      "learns": "That a valid credit was presented, cost, destination host, ciphertext",
      "does_not_learn": "U's address (behind R), U's identity, plaintext (on the E2EE path)"
    },
    {
      "symbol": "M",
      "party": "Credit issuer (mint)",
      "learns": "That someone bought N credits on some rail",
      "does_not_learn": "Which requests those credits paid for"
    },
    {
      "symbol": "H",
      "party": "Host operator running the sidecar",
      "learns": "That its enclave served ciphertext, token counts",
      "does_not_learn": "Plaintext, U's address, payer"
    },
    {
      "symbol": "E",
      "party": "The enclave (confidential VM and GPU)",
      "learns": "Plaintext, in memory only",
      "does_not_learn": "U's address, payer identity, purchase"
    },
    {
      "symbol": "L, C",
      "party": "Transparency log and chain",
      "learns": "Public measurements, keys, receipt roots",
      "does_not_learn": "Anything about users"
    }
  ],
  "honest_limits": [
    "Trust rests on Intel, AMD and NVIDIA silicon, reproducible builds and witnessed logs. It is not a cryptographic proof of inference.",
    "GPU attestation on shipping Hopper and Blackwell parts proves a genuine confidential-computing GPU is reachable. It does not bind that GPU to the confidential VM (no TDISP yet). Physical memory-interposer attacks on DDR5 are out of scope.",
    "AMD SEV-SNP hosts cannot carry confidential-GPU claims yet: SNP has no runtime measurement register to bind GPU evidence into.",
    "Unlinkability holds against Anyroute, against hosts and against any single relay. It does not hold against a relay colluding with the gateway, or against a global network observer correlating timing.",
    "On the Tor path of unlinkable, Tor takes the place of the independent relay. Anyroute runs the onion service and never learns the client's address, because a Tor onion service is never given it. Ordinary chat exposes plaintext to Anyroute’s router; the distinct encrypted-chat adapter forwards encrypted content to the gateway enclave. Anyroute sees clear routing metadata and request size and timing directly, with no relay in between. An observer who watches both the client's entry into Tor and the router's side can match them by timing, and requests sent on one Tor circuit can be linked to each other.",
    "Deterministic (batch-invariant) serving and confidential-computing mode both cost throughput.",
    "Credits are non-transferable prepaid inference, not money and not an investment.",
    "A minimal, measured block list runs inside the enclave and its hash is public. Nothing else is filtered.",
    "Stylometric identification from prompt content is out of scope: the protocol hides the channel, not what you write."
  ],
  "status": [
    {
      "part": "Attested sidecar: opt-in SHA-256 bindings v2 adds source archive hash, engine image and model ID while preserving v1 verification; weights hashed at boot against an allow-list; Intel TDX quote whose report data binds the TLS, receipt and HPKE keys and the image, compose and model digests; quote-pinned TLS certificate",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "sidecar/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/sidecar"
        }
      ]
    },
    {
      "part": "Host install package: one-command installer (engine detection, seal.yaml schema and validator), Compose file, Helm chart, Terraform modules (GCP TDX, Azure SEV-SNP public lane only, Phala deployment skeleton), seal CLI (init, add-node, verify, status)",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        }
      ],
      "status": "Implemented; the hosted installer address is planned",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "deploy/seal/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/deploy/seal"
        },
        {
          "text": "scripts/seal-cli.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/scripts/seal-cli.ts"
        }
      ]
    },
    {
      "part": "Router verifies provider evidence: fresh nonce-bound quotes, pluggable quote verifiers, NVIDIA remote attestation for GPU evidence a provider reports, quote-pinned TLS, attestation history",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "src/services/attestor.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/services/attestor.ts"
        },
        {
          "text": "src/providers/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/providers"
        }
      ]
    },
    {
      "part": "Client-side checks of a sidecar's evidence and receipts (quote signature through a caller-supplied verifier)",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        },
        {
          "number": "0004",
          "url": "/spec/0004-receipts/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "packages/client",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client"
        },
        {
          "text": "packages/client-py",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client-py"
        }
      ]
    },
    {
      "part": "Measurement bundles published to a public Sigstore Rekor log; router verifies inclusion",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "scripts/publish-measurement.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/scripts/publish-measurement.ts"
        },
        {
          "text": "src/services/measurements.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/services/measurements.ts"
        }
      ]
    },
    {
      "part": "On-chain measurement registry (image, compose and model digests, log entry, quote-proof hash)",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "contracts/src/MeasurementRegistry.sol",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/contracts/src/MeasurementRegistry.sol"
        }
      ]
    },
    {
      "part": "GPU evidence bound into the sidecar's own quote; policy-hash and exec-profile-hash boot events; RTMR3 replay by clients",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        }
      ],
      "status": "Planned",
      "state": "planned",
      "off_by_default": false,
      "where": []
    },
    {
      "part": "In-toto manifests, policy registry contract, threshold KMS with on-chain governance",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        }
      ],
      "status": "Planned",
      "state": "planned",
      "off_by_default": false,
      "where": []
    },
    {
      "part": "Anyroute-run transparency log (tlog-tiles) with witnesses, or with public-log anchoring of checkpoints in Sigstore Rekor; client split-view checks",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        },
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented, off by default; logs receipt keys, Oblivious HTTP key configurations, blind-token issuer keys, measurement bundles and sidecar key bindings and signed host admission policies (manifests and e-cash keysets are planned). Rekor anchoring is the alternative to witnesses: it detects a split view after the fact and does not prevent one",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "src/tlog/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/tlog"
        },
        {
          "text": "src/tlog/rekor.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/tlog/rekor.ts"
        },
        {
          "text": "packages/client/src/tlog.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client/src/tlog.ts"
        },
        {
          "text": "scripts/tlog-witness.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/scripts/tlog-witness.ts"
        }
      ]
    },
    {
      "part": "Signed host admission policy with host_policy key-log entries; automatic admission and probation against quote-bound pins and screened operator/payout addresses",
      "spec": [
        {
          "number": "0001",
          "url": "/spec/0001-attestation/"
        }
      ],
      "status": "Implemented, off by default (NETWORK_POLICY_ENABLED, NETWORK_HOSTS_ENABLED); switched on at anyroute.tech for the approved Intel TDX Qwen2.5 0.5B build",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "src/network/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/network"
        },
        {
          "text": "deploy/network/approved/tdx-qwen2.5-0.5b/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/deploy/network/approved/tdx-qwen2.5-0.5b"
        }
      ]
    },
    {
      "part": "Inner E2EE anyroute-hpke/v1 (single-shot request, framed streaming response)",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented, off by default",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "sidecar/src/hpke.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/sidecar/src/hpke.ts"
        },
        {
          "text": "packages/client/src/hpke.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client/src/hpke.ts"
        }
      ]
    },
    {
      "part": "Encrypted chat adapter through the Phala attested gateway; client-encrypted content reaches the gateway enclave, with routing metadata visible to the router; distinct from sidecar HPKE",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented, off by default (E2EE_PASSTHROUGH_ENABLED); switched on at anyroute.tech",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "src/e2ee/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/e2ee"
        },
        {
          "text": "packages/client/src/e2ee.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client/src/e2ee.ts"
        }
      ]
    },
    {
      "part": "Sidecar anyroute-hpke/v1 ciphertext carried through ordinary router chat routes (ordinary chat still exposes text to the router)",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Planned",
      "state": "planned",
      "off_by_default": false,
      "where": []
    },
    {
      "part": "Chunked inner E2EE for streamed requests; fixed-size padding and send tick",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Planned",
      "state": "planned",
      "off_by_default": false,
      "where": []
    },
    {
      "part": "Oblivious HTTP gateway (RFC 9458, 9292); per-epoch keys; key history as a signed hash chain; relay list with operator independence",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented, off by default; non-streaming only",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "src/ohttp/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/ohttp"
        }
      ]
    },
    {
      "part": "Independent Oblivious HTTP relay",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "relay/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/relay"
        }
      ]
    },
    {
      "part": "Chunked Oblivious HTTP for streaming responses",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented, off by default",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "src/ohttp/chunked.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/ohttp/chunked.ts"
        },
        {
          "text": "relay/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/relay"
        },
        {
          "text": "packages/client/src/ohttp.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client/src/ohttp.ts"
        }
      ]
    },
    {
      "part": "Tor onion service in front of the router",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "deploy/onion/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/deploy/onion"
        }
      ]
    },
    {
      "part": "Lane unlinkable over the onion service: Tor instead of an independent relay, blind tokens only, onion requests recognised only by the proxy's secret",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented, off by default",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "src/onion/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/onion"
        },
        {
          "text": "src/ohttp/lane.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/ohttp/lane.ts"
        }
      ]
    },
    {
      "part": "Lanes public, attested, unlinkable in the router: per request, per key and per saved route; no fallback off an attested lane (no_attested_endpoint); lane-aware selection weight",
      "spec": [
        {
          "number": "0002",
          "url": "/spec/0002-transport/"
        }
      ],
      "status": "Implemented; unlinkable needs blind tokens and Oblivious HTTP or the onion path switched on",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "src/router/disclosure.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/router/disclosure.ts"
        },
        {
          "text": "src/router/select.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/router/select.ts"
        },
        {
          "text": "src/ohttp/lane.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/ohttp/lane.ts"
        }
      ]
    },
    {
      "part": "Blind RSA tokens (Privacy Pass type 0x0002), per-epoch issuer keys, on-chain key commitments",
      "spec": [
        {
          "number": "0003",
          "url": "/spec/0003-credits/"
        }
      ],
      "status": "Implemented, off by default",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "src/blind/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/blind"
        },
        {
          "text": "contracts/src/BlindIssuer.sol",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/contracts/src/BlindIssuer.sol"
        }
      ]
    },
    {
      "part": "Blinded e-cash credits (BDHKE, DLEQ, P2PK, swap and change); issuer in an enclave; sealed nullifier store",
      "spec": [
        {
          "number": "0003",
          "url": "/spec/0003-credits/"
        }
      ],
      "status": "Planned",
      "state": "planned",
      "off_by_default": false,
      "where": []
    },
    {
      "part": "Receipts v1: Ed25519 over canonical JSON, from the router and from the sidecar",
      "spec": [
        {
          "number": "0004",
          "url": "/spec/0004-receipts/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "src/receipts/",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/receipts"
        },
        {
          "text": "sidecar/src/receipts.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/sidecar/src/receipts.ts"
        }
      ]
    },
    {
      "part": "Hourly Merkle roots of router receipts, with a proof endpoint; the root is posted on chain only where a chain is configured (off chain otherwise, and proofs say so)",
      "spec": [
        {
          "number": "0004",
          "url": "/spec/0004-receipts/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "src/services/anchor.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/services/anchor.ts"
        },
        {
          "text": "contracts/src/ReceiptAnchor.sol",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/contracts/src/ReceiptAnchor.sol"
        }
      ]
    },
    {
      "part": "Per-host anchoring of enclave receipts: leaves from each attested sidecar's feed, kept only if signed by the receipt key its verified quote binds, rooted per host and interval, posted with anchorAttested where a chain is configured (off chain otherwise, and proofs say so), with a proof endpoint and a client check",
      "spec": [
        {
          "number": "0004",
          "url": "/spec/0004-receipts/"
        }
      ],
      "status": "Implemented, off by default",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "src/services/host-anchor.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/services/host-anchor.ts"
        },
        {
          "text": "src/api/host-anchor.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/api/host-anchor.ts"
        },
        {
          "text": "contracts/src/ReceiptAnchor.sol",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/contracts/src/ReceiptAnchor.sol"
        },
        {
          "text": "packages/client/src/host-anchor.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client/src/host-anchor.ts"
        }
      ]
    },
    {
      "part": "Router receipts v2: COSE_Sign1 (EdDSA), chunk hash chain over router streams, bucketed token counts; checks in the SDK, the web verifier and a CLI",
      "spec": [
        {
          "number": "0004",
          "url": "/spec/0004-receipts/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "src/receipts/v2.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/receipts/v2.ts"
        },
        {
          "text": "packages/client/src/receipts-v2.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client/src/receipts-v2.ts"
        },
        {
          "text": "packages/client/bin/verify-receipt.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/packages/client/bin/verify-receipt.ts"
        }
      ]
    },
    {
      "part": "Node receipts v2: signed in the enclave (ES256K), execution profile, epoch nullifier",
      "spec": [
        {
          "number": "0004",
          "url": "/spec/0004-receipts/"
        }
      ],
      "status": "Planned",
      "state": "planned",
      "off_by_default": false,
      "where": []
    },
    {
      "part": "In-enclave classifier: pinned weights, policy hash bound in the quote, one-bit receipt field, signed refusal",
      "spec": [
        {
          "number": "0005",
          "url": "/spec/0005-policy/"
        }
      ],
      "status": "Implemented, off by default",
      "state": "implemented",
      "off_by_default": true,
      "where": [
        {
          "text": "sidecar/src/classifier.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/sidecar/src/classifier.ts"
        }
      ]
    },
    {
      "part": "Privacy-safe stats: no per-request logs in the sidecar; hourly counters (requests, refusals by reason, latency and token buckets) released with snapped Laplace noise from a CSPRNG, epsilon 1 per family per hour by default, daily budget ledger; the router publishes attested and unlinkable traffic the same way and keeps it out of raw public metrics",
      "spec": [
        {
          "number": "0005",
          "url": "/spec/0005-policy/"
        }
      ],
      "status": "Implemented",
      "state": "implemented",
      "off_by_default": false,
      "where": [
        {
          "text": "sidecar/src/dpstats.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/sidecar/src/dpstats.ts"
        },
        {
          "text": "src/services/private-stats.ts",
          "url": "https://github.com/AnyRouteRH/AnyRoute/blob/main/src/services/private-stats.ts"
        }
      ]
    },
    {
      "part": "Blocks counted by policy category; privacy parameters bound in the attestation",
      "spec": [
        {
          "number": "0005",
          "url": "/spec/0005-policy/"
        }
      ],
      "status": "Planned",
      "state": "planned",
      "off_by_default": false,
      "where": []
    },
    {
      "part": "Measured policy.json in a boot event; token-streamed output checks; dispute re-run in a second enclave",
      "spec": [
        {
          "number": "0005",
          "url": "/spec/0005-policy/"
        }
      ],
      "status": "Planned",
      "state": "planned",
      "off_by_default": false,
      "where": []
    }
  ],
  "live": "/api/v1/status"
}
