A CalConnect standard
Evidence, not faith.
Signatif is an open framework for sealing, delegating, and verifying artifacts in regulated industries. It replaces binary trust with graduated, reproducible evidence — computed the same way by every conforming verifier.
- Organization
- CalConnect
- Verification
- Offline capable
- Algorithms
- Post-quantum agile
- Attestation
- Multi-dimensional
- registry
- Nº 1042
- chain
- root-a → nmi → lab
- scope
- metrology · class M
- dimensions
- authority · person · time
- transparency
- log #1041 · included
- freshness
- within window
Illustrative artifact — verifiable offline, years after issuance.
The name is the architecture
Signatif is a backronym: each letter names a property the standard makes normative.
Sealed
Co-signatures over a canonical payload, one per trust dimension.
Interoperable
One pipeline and report format; scheme rules enter through registries.
Graduated
Coverage report, classification label, acceptance decision.
Non-repudiable
Threshold quorum, ceremony records, transparency logs.
Anchored
Every path ends at a declared trust anchor — fully offline.
Trust
Establishment, assessment, and withdrawal of confidence.
Infrastructure
Shared anchors, logs, and registries beneath any application.
Framework
Requirements that conforming implementations and profiles share.
One pipeline, three decisions
The standard separates what is verified, how it is graded, and whether it is good enough — so schemes and verifiers can differ without forking the machinery.
- 1
Seal and delegate
Authorities sign artifacts; authorization scope narrows monotonically at every delegation link.
- 2
Verify
Hard checks short-circuit to rejected; soft checks accumulate into an objective coverage report.
- 3
Classify
The scheme’s published policy maps the report to a label — a pure, deterministic function.
- 4
Accept
The verifier’s own risk policy turns the label into a decision for its context.
The verifier, live
Toggle the checks. The coverage report is objective, the label is the scheme’s policy, and the decision is the verifier’s.
Hard checks — failure rejects
Soft checks — coverage accumulates
Verifier acceptance policy
Coverage report
- signature_valid
- ✓true
- scope_narrowing
- ✓monotonic
- revocation_status
- ✓clear
- transparency
- ✓included
- time_anchor
- ✓fresh
- independent_roots
- ✓2
- multi_log_quorum
- ✓met
Full dimensional coverage, transparency and multi-root inclusion.
acceptance policy: standard
Built for artifacts that must not lie
Where a certificate carries legal, economic, or safety consequences, "the key was valid" is not enough.
Legal metrology
Calibration and type-approval certificates, verifiable decades after issuance.
Pharmaceuticals
Batch release with manufacturer, operator, conditions, and time each attested.
Food safety
Inspection and provenance records across supply chains and jurisdictions.
Defense procurement
Component provenance with revocation that propagates when trust is withdrawn.
Why not the incumbents
PKI, blockchain, transparency logs, credentials — where each stops
Four regulated scenarios — batch release, offline inspection, cross-border acceptance, withdrawn authorization — and the design boundary each existing solution hits. The comparison is the standard’s own, and it cuts both ways.
Read the comparison