Eviulon Public-Source Lifecycle and Attestation
Release: 2.0.0-rc.19-WIP
Lifecycle schema: evulgare.eviulon-source-lifecycle.v1
Lifecycle version: 1.0.0
Latest capture: EVIULON-RC6-WEB-REVIEW-20260806T013000Z
Latest capture time: 2026-08-06T01:30:00Z
Current aggregate state: CURRENT
Source-record SHA-256: 8a6d722957751d97a7ff2b13d3136b26b27bdcfd297dd1aac2aecff5449aad00
Difference-report SHA-256: 42be55c98565be78dfd7db96405746e4de2202e9a259c28e6c1bbd8d1cdc3641
Lifecycle-proof SHA-256: cb3835497a86b56312589566c8f881a7ffa81d7242bfed6d15234506294bd3a7
Purpose
This subsystem preserves a bounded, deterministic record of four public pages controlled by Eviulon. It records what those pages published at a declared capture, identifies material and metadata differences, and qualifies dependent Evulgare claims without making live partner-site access part of Flask startup, request handling, or rendering.
It is not independent third-party verification. Reciprocal first-party publication supports the parties’ public descriptions; it does not by itself authenticate private contract terms, contract value, external sovereign recognition, deployment, readiness, classified capability, or performance.
Exact canonical allowlist
| Record ID | Canonical URL | Published status | Responsible authority | Review date | Current state | Fingerprint |
|---|---|---|---|---|---|---|
EVI-DEF-001 |
https://eviulon.com/state/defense/ | Current | National Defense and Continuity Directorate | 2026-08-05 |
CURRENT | dd3a13979e3b3f6956cf596c59342c1f608b75050aa0f2f63bb61cb515571108 |
EVI-SYS-EVULGARE-001 |
https://eviulon.com/state/defense/evulgare/ | Official national defense and assurance system | National Defense and Continuity Directorate | 2026-08-05 |
CURRENT | 065c34f530f091eec77bced5f5496228fb124389fc3df9fddc2172d4c739ca25 |
EVI-CI-001 |
https://eviulon.com/state/defense/doctrine/ | Current | National Defense and Continuity Directorate | 2026-08-05 |
CURRENT | 5174d56827d33248a33194ec297723180bbec67a2ab1734a4121f45a54684761 |
EVI-COUNTRY-001 |
https://eviulon.com/state/ | Current | Eviulon State Registry | 2026-08-05 |
CURRENT | b60076c9c86a1ffc5ad6ab5966a0e7091534c1b0ef0f70ffb236e682a2b3a017 |
The operator workflow accepts no arbitrary URL. HTTPS host, path, port, query, fragment, credentials, redirects, content type, response size, timeout, request count, and inter-request delay are bounded before content can be captured.
Lifecycle states
- CURRENT: The latest bounded fingerprint matches the prior accepted fingerprint and the page was retrieved successfully.
- CHANGED: A bounded material field or statement fingerprint changed and affected claims require review.
- UNAVAILABLE: The latest bounded retrieval failed or returned a non-success status; prior history remains visible and no retraction is inferred.
- SUPERSEDED: The source explicitly indicates that another record replaced it; affected claims are suspended pending review.
- CONTRADICTED: The current source explicitly conflicts with a previously supported claim.
- NOT_CHECKED: No lawful bounded retrieval was performed for the current capture.
UNAVAILABLE is an availability condition, not a retraction. The previous accepted statement remains visible with an availability qualification. SUPERSEDED and CONTRADICTED require explicit operator review and never delete earlier evidence.
Material fingerprint boundary
The bounded SHA-256 fingerprint includes only:
record_id
canonical_url
page_title
published_record_status
responsible_authority
review_date
matched_material_statements
matched_boundary_statements
Navigation, styling, unrelated body text, analytics, scripts, and footers do not silently change a material source claim. Raw HTML is never retained in the repository snapshot.
Difference result
Previous capture: EVIULON-RC5-PUBLIC-CAPTURE-20260806
Current capture: EVIULON-RC6-WEB-REVIEW-20260806T013000Z
Material changes: 0
Metadata changes: 0
| Record | Lifecycle state | Material differences | Metadata differences |
|---|---|---|---|
EVI-DEF-001 |
CURRENT | 0 | 0 |
EVI-SYS-EVULGARE-001 |
CURRENT | 0 | 0 |
EVI-CI-001 |
CURRENT | 0 | 0 |
EVI-COUNTRY-001 |
CURRENT | 0 | 0 |
Claim-state propagation
| Claim ID | Current state | Source records | Qualification |
|---|---|---|---|
SRC-CLAIM-01 |
RECIPROCALLY_CONFIRMED_BY_EVIULON_FIRST_PARTY_RECORD | EVI-DEF-001, EVI-SYS-EVULGARE-001 | This is reciprocal first-party publication by Evulgare and Eviulon, not independent third-party verification. |
SRC-CLAIM-02 |
EVULGARE_COMPANY_ANNOUNCEMENT | Evulgare announcement / no Eviulon dependency | The reviewed Eviulon records do not publish contract value, procurement terms, award instrument, or private contractual text. |
SRC-CLAIM-03 |
SUPPORTED_BY_BOTH_PARTIES_PUBLIC_DESCRIPTIONS | EVI-DEF-001, EVI-SYS-EVULGARE-001, EVI-CI-001 | The support concerns public doctrine and architecture, not classified capability, readiness, or operational performance. |
SRC-CLAIM-04 |
NOT_ESTABLISHED_BY_THESE_FIRST_PARTY_PUBLIC_RECORDS | Evulgare announcement / no Eviulon dependency | No reviewed first-party page independently establishes these matters. |
The engine never converts reciprocal first-party statements into independent reporting. A passing source capture also does not establish legal recognition, classified performance, readiness, deployment, or private contract terms.
Append-oriented history
| Capture | Retrieved | Method | Snapshot SHA-256 |
|---|---|---|---|
EVIULON-RC4-MIGRATED-20260805 |
2026-08-05T00:00:00Z |
MIGRATED_FROM_RC4_REPOSITORY_RECORD | a045ba280e61f202189c1f9c9d8c923566b5c8f64cc4e6716370dd6c552c76f0 |
EVIULON-RC5-PUBLIC-CAPTURE-20260806 |
2026-08-06T00:07:31Z |
OPERATOR_ASSISTED_ALLOWLISTED_PUBLIC_REVIEW | d8c7db3ea99d03a950281c7243cddafb9db7fe76e3fb58eb4af5b148dae205d1 |
EVIULON-RC6-WEB-REVIEW-20260806T013000Z |
2026-08-06T01:30:00Z |
READ_ONLY_PUBLIC_WEB_REVIEW | 7f1bab4939ec2b2c30b85c6b40043a4b7d159e8b50b5290942af64dafd3fb91f |
Snapshot manifest SHA-256: f5b1b5eaeec8d95e61acfa62915bec491f1c797aaebdf9b509d02d8d9e57daa6
Registry SHA-256: 81a6533de40bca06bd84956699acede9798fd88ef6e2ced96ee48e48d9ffecd7
Runtime, security, and privacy boundary
- The Flask application reads repository-controlled snapshots only.
- No public page or API request contacts Eviulon or any other external host.
- Refresh is operator-initiated, sequential, rate-limited, non-recursive, content-type constrained, and response-size bounded.
- Redirects outside the exact allowlist are rejected.
- Raw HTML, credentials, topology, locations, targeting logic, weapon configurations, and exploitable controls are not retained.
- Public visitor inputs are not persisted.
- No lifecycle state creates force authorization, operational control, or certification.
Operator procedure
Dry run on an authorized networked operator host:
PY=/home/CPANEL_USER/virtualenv/evulgare.com/3.13/bin/python
"$PY" scripts/refresh_eviulon_sources.py
After reviewing the bounded output, append a new capture and regenerate evidence:
"$PY" scripts/refresh_eviulon_sources.py --write
"$PY" scripts/check_eviulon_sources.py
"$PY" scripts/validate_uai_memory.py
Evidence artifacts
app/content/eviulon_sources/registry.json
app/content/eviulon_sources/snapshot-manifest.json
app/content/eviulon_sources/snapshots/
docs/EVIULON_PUBLIC_SOURCE_RECORD.json
docs/EVIULON_PUBLIC_SOURCE_RECORD.md
docs/EVIULON_SOURCE_DIFFERENCE_REPORT.json
docs/EVIULON_SOURCE_HISTORY.json
docs/EVIULON_SOURCE_CAPTURE_MANIFEST.json
docs/EVIULON_SOURCE_LIFECYCLE_PROOF_REPORT.json
Deterministic verification
The packaged proof executes 19 named checks and reports PASS. It covers exact allowlisting, fingerprint stability, append-only history, all six lifecycle states, claim propagation, temporary-unavailability handling, no request-time network dependency, no raw HTML persistence, and the synthetic public-safety boundary.
That proof establishes repository behavior for the exercised inputs. It does not replace a fresh operator capture or independent authentication of external claims.