draft-dogru-cedulon-00

Internet-Draft seed. Category: informational. Author: Emek Can Dogru. Full text lives in the repository at spec/draft-dogru-cedulon-00.md.

Cedulon is an audit layer above payment rails. It is not a rail, not a custodian, and not an arbitral award.

Sections

  1. Introduction — rails move value; the audit layer is missing.
  2. Terminology — RFC 2119; Trade Manifest, PDP, Spend Receipt, Anchor, Dispute Evidence Bundle.
  3. Architecture — PDP before the rail; Receipt Issuer after; optional SCITT.
  4. Trade Manifest — signed offer before payment; price, acceptance hash, expiry.
  5. Spend Receipt — signed record after a gated payment; no-manifest is explicit.
  6. COSE Profile — deterministic CBOR; COSE_Sign1 with alg EdDSA; claim labels 100–110.
  7. Reconciliation and Epoch Checkpoints — completeness: extract versus receipts; checkpoint chain; equivocation.
  8. Lifecycle — Manifest → Policy → Payment → Receipt → Dispute Evidence Bundle.
  9. Policy Semantics — limit, velocity, scope; fail-closed default deny.
  10. SCITT Anchoring — optional registration; this draft does not operate a service.
  11. Privacy Considerations — public encodings omit or hash identifiers and amounts.
  12. Security Considerations — T1–T11, including rail-bypass completeness (T10) and checkpoint suppression (T11).
  13. IANA Considerations — placeholder; no actions in -00.
  14. Informative Notes — x402, AP2, draft-sharif-attp, draft-bates-atp as neighbors.

Neighbor drafts: Sharif ATTP is identity and score. Bates ATP is causal lineage. Neither defines rail-extract completeness.