Inclusion against the checkpoint
“The bundle's range proof and per-record inclusion proofs, verified against the bundle's checkpoint.” It reads inconclusive “when the checkpoint carries no independently verifiable signed statement.”
Action State Countersign
Verification has always been free and open: anyone can recompute a record (a capsule) offline against public keys at verify.agentactioncapsule.org, no Action State required. Countersign is the operated layer we add on top: it recomputes a fixed set of structural checks over an evidence bundle with every payload withheld, then signs the bundle digest with which checks ran and their results. Exactly what it checks, and what it never checks, is in its practice statement. Countersign becomes a paid service once the first acceptors are on record.
Verification never depends on Countersign. Verification runs the same way whether or not Countersign exists.
Free · open
Every record is sealed with a digest and a signature, then checkpointed to a public witness. Recomputing that digest, checking the signature, and confirming the checkpoint includes the record are all things anyone can do offline, with the open verifier, no account and no request to us. That confirms the record hasn't been altered since it was sealed and that it's part of a committed checkpoint.
If Action State Group disappeared tomorrow, this half keeps working. Nothing about free verification requires us to still be here.
Operated
Action State CountersignFree verification tells you a record wasn't altered after it was sealed. Countersign adds a second signature. In the words of the Countersign practice statement, version 1, a countersignature is “a signature by a party other than the producer over a bundle digest, accompanied by a statement of which claims that party recomputed and with what result.” The instance accepts “an Evidence Bundle with every payload withheld (digests only), recomputes a fixed set of structural checks over it,” and signs the bundle digest with the statement of which checks ran and their results. Version 1 runs five checks:
“The bundle's range proof and per-record inclusion proofs, verified against the bundle's checkpoint.” It reads inconclusive “when the checkpoint carries no independently verifiable signed statement.”
“No profile's own checks are loaded on this instance in version 1,” so it reads not checked whenever the bundle's records declare a kind, and not present when none does.
“The bundle carries one checkpoint, not a history.”
“The bundle declares no window to bound against.”
“Records carry no per-record signer key.”
Each check returns exactly one of five results (established, failed, not present, not checked, inconclusive), and they are “never combined into a score, a grade, or a single pass/fail.”
“Never checked, on any countersignature from this instance: capture coverage (whether everything that happened was recorded) and outcome correctness (whether a judged outcome was right).”
A countersignature over a bundle the operator itself produced “should be read as not independent”; our own sample countersignatures are of that kind. Who may register, key custody, rotation, incidents and wind-down are all in the practice statement.
Side by side
FREE · ANYONE
Recompute the digest and check the signature offline against public keys. Confirms the record wasn't altered since sealing and is included in a committed checkpoint. No account, no request to us, and it keeps working even if we don't.
OPERATED · ACTION STATE
Recomputes a fixed set of structural checks over a digests-only evidence bundle (range membership, profile conformance, chain consistency, cadence, key hygiene) and signs the bundle digest with which checks ran and their results. Never checked: capture coverage and outcome correctness.
Operated at countersign.actionstate.ai
Get in touch
Countersign is available to teams who want an independent party to check their records. Talk to us to see whether it fits your setup.