contestable public-evidence protocol
Research / Prototype
Claims examined as evidence records, not instant verdicts.
DOVADA is a protocol and reference-node implementation for examining one atomic public claim at a time with public evidence. A record keeps the strongest supporting and contradicting evidence, the context, the data gaps and any challenge visible. It never collapses into a single score, never infers hidden intent, and no central authority decides truth for every node. Today the repository holds an accepted specification, an inert application foundation, executable v0.2 domain contracts and an offline AI boundary. Nothing collects, assesses or publishes yet.
I write the specification and the domain contracts, the federated operating model, the legal and publication gates, the AI boundary and the visual language, and I keep the reference foundation synthetic until each gate is actually met.
Project images



What we are building
Atomic claim records
A broad statement is reduced to one precise claim before sources, excerpts, dates, provenance and limitations are attached. Intent and motive are explicit claim types; nothing infers them from timing, similarity or shared infrastructure.
Evidence in both directions
The record shows the strongest accepted supporting and contradicting evidence, context flags, data gaps and what would change the assessment. A low-confidence or disputed assessment must say what would change it; a high-confidence one must name its key evidence.
Challenge and correction
Assessments stay contestable through review, challenge, correction, withdrawal and version history. A signature proves who issued a record and that it was not altered, never that the claim is true, fair or complete.
Bounded pattern analysis
A later Radar direction may examine documented public patterns, but a cluster must carry an alternative explanation, and no contract exposes a person score, ideology or truthfulness property. Radar stays disabled today.
How it works
Steward, not operator
The project maintains the protocol, the schemas, the reference code and the conformance suites. It runs no node. Any real node would independently own its sources, providers, policies, reviewers, keys, infrastructure and publications, and no steward key, licence or conformance result can switch a node on.
Synthetic first, fail closed
Every connector and model provider is disabled by policy, and even a positive capability check returns NO_RUNTIME_CAPABILITY. The only model adapter is an in-memory deterministic fake with no network access, and the frozen offline evaluation covers prompt injection, privacy leakage, citation mismatch and false certainty on synthetic data. LangChain and LangGraph were measured and not adopted yet.
Gates that say what they prove
Eight checks run before a change lands: task cards, the immutable baseline, generated contracts and prompts, strict types, the offline evaluation, browser tests with axe, a secret scan and a CycloneDX SBOM. Today that is 38 of 38 spec and 328 of 328 unit tests, and each gate states that it proves the local foundation only.