<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <title>Primmortal Development Log</title>
  <subtitle>Progress notes from the founder of Primmortal, an immutable consortium archive for primary sources.</subtitle>
  <link href="https://primmortal.org/blog/feed.xml" rel="self" type="application/atom+xml" />
  <link href="https://primmortal.org/blog/" rel="alternate" type="text/html" />
  <id>https://primmortal.org/blog/</id>
  <updated>2026-09-29T13:00:00.000Z</updated>
  <author>
    <name>Neff Moore</name>
  </author>
  <icon>https://primmortal.org/favicon-32x32.png</icon>
  <logo>https://primmortal.org/apple-touch-icon.png</logo>
  <entry>
    <title>Hello, I&#39;m Neff</title>
    <link href="https://primmortal.org/blog/hello-im-neff/" rel="alternate" type="text/html" />
    <id>https://primmortal.org/blog/hello-im-neff/</id>
    <published>2026-09-29T13:00:00.000Z</published>
    <updated>2026-09-29T13:00:00.000Z</updated>
    <author>
      <name>Neff Moore</name>
    </author>
    <summary>A quick introduction to the person behind Primmortal, and what&#39;s coming next.</summary>
    <category term="introduction" />
    <content type="html">&lt;p&gt;I&#39;m Neff Moore, a student at LSU and the founder of Primmortal.&lt;/p&gt;
&lt;figure class=&quot;post-figure post-figure--fade&quot;&gt;
  &lt;img src=&quot;https://primmortal.org/blog/images/trust-but-verify.jpg&quot; alt=&quot;The words &#39;Trust, but verify&#39; in 18th-century script on parchment beside a faded portrait of George Washington&quot; width=&quot;1600&quot; height=&quot;900&quot; decoding=&quot;async&quot;&gt;
  &lt;figcaption&gt;Portrait: Gilbert Stuart, 1796 (public domain)&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;I&#39;ve always been fascinated by one process. Data becomes information once someone organizes it and gives it context. Information becomes narrative once someone decides what it means. And narrative is what changes the world, for better or worse. Every step in that chain is a place where the truth can be kept or lost.&lt;/p&gt;
&lt;p&gt;That&#39;s why I care so much about the first link, the original record. If the primary sources behind our stories can be quietly edited, lost, or faked, then everything built on them is only as trustworthy as whoever last touched the file. Truth matters, and it deserves better protection than that.&lt;/p&gt;
&lt;p&gt;Primmortal is my answer: an archive where a scanned document, once added, can&#39;t be silently changed, and where anyone can check that a citation points to exactly what it claims to.&lt;/p&gt;
&lt;p&gt;As George Washington famously said, &amp;quot;Trust, but verify.&amp;quot;&lt;/p&gt;
&lt;p&gt;(He didn&#39;t. It&#39;s an old Russian proverb that Ronald Reagan made famous in the 1980s. But you probably weren&#39;t going to check, and that&#39;s exactly the problem Primmortal exists to solve.)&lt;/p&gt;
&lt;h2&gt;What&#39;s next&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Late October:&lt;/strong&gt; feedback conversations with archivists and librarians.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;This fall:&lt;/strong&gt; a working demo built on real public-domain scans, and a reviewed version 1.0 of the &lt;a href=&quot;https://primmortal.org/docs/primmortal-white-paper-v0.2.pdf&quot;&gt;white paper&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;December and January:&lt;/strong&gt; a formal pilot proposal for founding partners.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I&#39;ll post here as each milestone happens. Thanks for reading.&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>How Primmortal Works: Register, Cite, Verify</title>
    <link href="https://primmortal.org/blog/how-primmortal-works/" rel="alternate" type="text/html" />
    <id>https://primmortal.org/blog/how-primmortal-works/</id>
    <published>2026-09-27T00:50:00.000Z</published>
    <updated>2026-09-27T00:50:00.000Z</updated>
    <author>
      <name>Primmortal</name>
    </author>
    <summary>A plain-language tour of Primmortal&#39;s basic structure, with screenshots from the working prototype: what gets stored, what the ledger records, how citation tokens work, and how anyone can check a file. Plus what students, archivists, academics and journalists can do with it, and what isn&#39;t built yet.</summary>
    <category term="explainers" />
    <category term="prototype" />
    <content type="html">&lt;p&gt;Primmortal is an archive for primary sources: scans of original documents, and born-digital files exactly as they were received. Each item is registered once and never edited. Anyone can check that a file in front of them is the exact file that was registered, and anyone can cite it with a short code that leads back to the record.&lt;/p&gt;
&lt;p&gt;This post explains how that works, first in general and then for students, archivists, and the academics and journalists whose work depends on sources others can check. Throughout, we separate what exists today from what is still planned.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;About the screenshots.&lt;/strong&gt; Every screenshot in this post comes from the Primmortal v0 prototype running on a single computer. The documents in them are synthetic samples, generated by software for the demo and stamped &amp;quot;SAMPLE&amp;quot;. Their names, dates and people are fictional. None of them is a real archival item, and the prototype is not a production archive.&lt;/p&gt;
&lt;h2&gt;The short version&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Register.&lt;/strong&gt; A steward (an archive or library that looks after a collection) adds a file and a description of where it came from. The file&#39;s fingerprint is recorded, and the record can never be edited.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cite.&lt;/strong&gt; Each record gets a short citation token, such as &lt;code&gt;PMRT-33E3Z-EJWJ1-9&lt;/code&gt;, that can be printed in a footnote and looked up later.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Verify.&lt;/strong&gt; Anyone holding a copy of the file can check whether it matches the record, byte for byte.&lt;/li&gt;
&lt;/ol&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-home.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-home.png&quot; alt=&quot;The home page of the Primmortal v0 prototype. A gold banner across the top reads &#39;Prototype — not a production archive.&#39; Below it are a purple welcome panel, a green &#39;Ledger integrity verified&#39; badge, and three cards titled Register once, Cite with a token, and Verify independently.&quot; width=&quot;1104&quot; height=&quot;916&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;The prototype&#39;s home page. The banner at the top appears on every page: synthetic sample data, a single local steward, and demo-only sign-in.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;The basic structure&lt;/h2&gt;
&lt;h3&gt;What gets stored&lt;/h3&gt;
&lt;p&gt;When a steward registers a file, Primmortal first computes its &lt;strong&gt;hash&lt;/strong&gt;. A hash is a fingerprint of the exact bytes in a file: a long string of letters and numbers that changes completely if even one pixel changes. The prototype uses SHA-256, a widely used standard.&lt;/p&gt;
&lt;p&gt;The file is then kept in &lt;strong&gt;content-addressed storage&lt;/strong&gt;: it is stored under its own fingerprint, so whoever fetches it by that address can confirm they got exactly the right bytes. The prototype also computes an address in the format used by IPFS, a peer-to-peer storage network, so the files could later be shared that way.&lt;/p&gt;
&lt;p&gt;What gets registered is the original capture itself: the master scan, or the born-digital files as received. We call that registered original a &lt;strong&gt;prime&lt;/strong&gt;. Transcriptions, OCR text and web-sized images are copies of a prime, never primes themselves.&lt;/p&gt;
&lt;h3&gt;What the ledger records&lt;/h3&gt;
&lt;p&gt;The &lt;strong&gt;ledger&lt;/strong&gt; is the list of every registration, in order. Nothing is ever removed from it or rewritten; new entries are only added to the end. Each entry records the file&#39;s fingerprint, its size and type, the description the steward supplied (its provenance), which steward registered it, and when.&lt;/p&gt;
&lt;p&gt;Each entry also contains the fingerprint of the entry before it, which chains them together: change any earlier entry, even by one character, and every link after it breaks. The steward also &lt;strong&gt;signs&lt;/strong&gt; each entry. A digital signature is a seal made with a secret key only the steward holds; anyone can check it with the matching public key, and it fails if anything in the entry changes.&lt;/p&gt;
&lt;p&gt;Records are never edited. If a description turns out to be wrong, the steward adds a new &lt;strong&gt;correction notice&lt;/strong&gt; that points to the old record. The old record stays exactly as it was, visible and checkable.&lt;/p&gt;
&lt;h3&gt;How citation tokens work&lt;/h3&gt;
&lt;p&gt;Every record gets a citation token like &lt;code&gt;PMRT-33E3Z-EJWJ1-9&lt;/code&gt;. It is derived from the ledger entry itself, so it points to exactly one record, and therefore to exactly one file. The last character is a check character: mistype any single character and the prototype notices, instead of sending you to the wrong record. Upper or lower case and hyphens don&#39;t matter.&lt;/p&gt;
&lt;p&gt;In the prototype, a token opens its record at the address &lt;code&gt;/c/&lt;/code&gt; followed by the token. Each record page also shows a suggested citation that includes the token.&lt;/p&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-record.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-record.png&quot; alt=&quot;A record page in the prototype for &#39;Letter reporting the quarantine of the schooner Marigold (synthetic sample).&#39; It shows the citation token PMRT-33E3Z-EJWJ1-9 with green badges reading Signature valid, Stored copy intact and Ledger chain OK; a preview of the sample letter stamped SAMPLE; a Provenance table; and a Suggested citation box.&quot; width=&quot;1104&quot; height=&quot;1088&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;A record page for a synthetic sample letter: the citation token, three integrity checks, the provenance the steward supplied, and a suggested citation. In the demo, the &quot;Verify at&quot; link points to the local test computer. The capture-level wording is a placeholder (see &quot;Scan levels&quot; below).&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-record-identifiers.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-record-identifiers.png&quot; alt=&quot;The &#39;Integrity &amp; identifiers&#39; panel of the same record, listing the file&#39;s SHA-256 fingerprint, its IPFS-style content address, size and file type, ledger position, entry hash marked &#39;recomputed&#39;, the previous entry&#39;s hash, the steward and key, and the digital signature marked &#39;verified against the public steward registry.&#39;&quot; width=&quot;1104&quot; height=&quot;482&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;Further down the same page: the file&#39;s fingerprint (SHA-256), its IPFS-style address, the fingerprints that chain this entry to the one before it, and the steward&#39;s signature, each checked again when the page loads.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h3&gt;How anyone verifies&lt;/h3&gt;
&lt;p&gt;The prototype offers three checks. You can upload a file and ask whether it matches anything registered. You can check a file against a specific citation token. And you can re-run the whole chain: every fingerprint and every signature, from the first entry to the last.&lt;/p&gt;
&lt;p&gt;None of this requires trusting our server. The ledger can be downloaded as a public export and checked offline, on your own computer, by a short verification program. (The prototype&#39;s code is not published yet; the plan is for the verifier to be open source.)&lt;/p&gt;
&lt;h2&gt;Scan levels: how the original was imaged&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Level 1: a basic optical scan.&lt;/strong&gt; An ordinary photograph or flatbed-style scan of the page.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Level 2: multispectral and other non-destructive imaging.&lt;/strong&gt; Captures made under different kinds of light, such as multispectral or hyperspectral imaging, ultraviolet and infrared, or raking light. They can show what the eye misses. The Library of Congress, for example, uses &lt;a href=&quot;https://www.loc.gov/preservation/scientists/projects/hyperspec_imaging.html&quot;&gt;hyperspectral imaging&lt;/a&gt; to study inks and to reveal writing that has faded, been erased, or been covered over. Nothing about the original may be damaged to make the capture.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Level 3: a holographic scan.&lt;/strong&gt; This level is theoretical. It describes a future kind of capture that does not exist today.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Scan levels describe how a physical original was captured. How born-digital files fit into this scale is still being worked out.&lt;/p&gt;
&lt;h2&gt;Citation levels: how a source is cited&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Level 1 citation: the universal citation.&lt;/strong&gt; A citation token that anyone can use to point to a registered record and verify it. This is what the prototype issues today.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Level 2 citation: a registered link.&lt;/strong&gt; The citing work (an article, a paper, a news story) is itself registered in the ledger and linked to the source record it cites, so the connection between the two is on the record. Level 2 citations are planned, not built.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There is no Level 3 citation.&lt;/p&gt;
&lt;h2&gt;For students&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Finding a source.&lt;/strong&gt; Each registered source has a record page with its description, fingerprint and suggested citation. If a book or article gives you a Primmortal token, type it in to go straight to the record.&lt;/p&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-token-resolved.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-token-resolved.png&quot; alt=&quot;The prototype&#39;s record page for &#39;Field notebook page, Hollin Moor botanical survey (synthetic sample),&#39; showing citation token PMRT-EWMH6-RC5N1-Y, integrity badges, the top of a handwritten sample notebook page, and the first rows of its provenance.&quot; width=&quot;1104&quot; height=&quot;557&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;Looking up a token. Typing the address with the token in lower case and without hyphens (/c/pmrtewmh6rc5n1y) opens the same record as PMRT-EWMH6-RC5N1-Y, the token&#39;s standard form.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;strong&gt;Checking a copy you found online.&lt;/strong&gt; Found a scan on a website and want to know whether it is the registered original or something changed along the way? Upload it on the Verify page. If it matches, you&#39;ll see the record it belongs to. If you have a token from a citation, you can check the file against that token specifically.&lt;/p&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-verify-match.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-verify-match.png&quot; alt=&quot;The prototype&#39;s Verify page showing a green result box headed MATCH. It says the uploaded file sample-01-harbourmaster-letter.png matches a registered primary source, and lists the record title, citation token PMRT-33E3Z-EJWJ1-9, ledger entry, SHA-256, IPFS-style address and size.&quot; width=&quot;1104&quot; height=&quot;669&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;MATCH: the registered sample file, uploaded to the Verify page, is identical to the file on record. The uploaded copy is fingerprinted, not stored.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-verify-no-match.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-verify-no-match.png&quot; alt=&quot;The prototype&#39;s Verify page showing a red result box headed NO MATCH. It says the file altered-copy-of-sample-01-NOT-REGISTERED.png does not match any registered primary source, and that even a one-byte change produces a different hash. It lists the file&#39;s own fingerprint and size.&quot; width=&quot;1104&quot; height=&quot;568&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;NO MATCH: a copy of the same sample letter with a single pixel changed. To the eye it looks the same; its fingerprint is completely different.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;A NO MATCH doesn&#39;t necessarily mean anyone was dishonest: re-saving, cropping or compressing an image changes its bytes too. It does mean the file is not the registered original, so it&#39;s worth finding the one that is.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Citing it.&lt;/strong&gt; Copy the suggested citation from the record page, or add the token to your own citation style. Readers can then follow it back to exactly the file you used.&lt;/p&gt;
&lt;p&gt;One caution: a MATCH tells you the file is the one that was registered, not that the document is true or its description correct. Those remain questions for you and your sources.&lt;/p&gt;
&lt;h2&gt;For archivists and stewards&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Registering a capture.&lt;/strong&gt; Registration is for stewards only. In the prototype, a steward signs in with a demo password and fills in a form.&lt;/p&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-register.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-register.png&quot; alt=&quot;The prototype&#39;s Register form, marked &#39;Steward only.&#39; A note says registration is permanent and can never be edited or deleted. A dashed box labelled &#39;Steward authentication (DEMO ONLY)&#39; holds a token field. Below are Object fields (file, capture method, capture level, sample checkbox) and Provenance fields (title, creator or origin, date of original, holding institution).&quot; width=&quot;1104&quot; height=&quot;787&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;The steward&#39;s Register form (top part). Sign-in here is a shared demo password, not real authentication. The capture-level menu still uses placeholder labels written before the scan levels were settled; they will be updated.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;strong&gt;Provenance fields.&lt;/strong&gt; The form asks for a title, the creator or origin, the date of the original (free text, so &amp;quot;c. 1887&amp;quot; is fine), the holding institution, the capture method, the scan level, rights, a source link, and &lt;strong&gt;uncertainty notes&lt;/strong&gt;: what is doubtful about the date, the attribution, or the completeness of the item. Primmortal records these as the steward&#39;s statements. It does not judge them.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Registered once, never edited.&lt;/strong&gt; There is no way to edit or delete a record, whether through the website, the programming interface or the command line. If you register the same file twice, nothing new is written and you get the existing record back.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Corrections are new records.&lt;/strong&gt; To fix a description, the steward submits a correction notice that names the old record and gives a reason. The new entry gets its own token. The original record stays exactly as registered, with a notice pointing to the correction, and its suggested citation switches to the corrected description.&lt;/p&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-correction.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-correction.png&quot; alt=&quot;A record page labelled correction-notice for &#39;Public notice inviting tenders for gas lamps, Borough of Wendlesham (synthetic sample),&#39; token PMRT-4V3KC-3HZ3W-X. A purple notice says it corrects PMRT-T2GTD-3YW44-7 because the year was misread during cataloguing. The Date of original row reads &#39;June 1857 (fictional; corrected from 1854).&#39;&quot; width=&quot;1104&quot; height=&quot;648&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;A demonstration correction notice. It fixes a misread year on a synthetic sample notice, gives its reason, and links to the record it corrects.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-corrected-original.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-corrected-original.png&quot; alt=&quot;The original record for the same sample notice, token PMRT-T2GTD-3YW44-7, with a yellow banner saying it has been corrected by a later entry, PMRT-4V3KC-3HZ3W-X, and that the original registration is preserved unchanged.&quot; width=&quot;1104&quot; height=&quot;428&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;The original record is still there, unchanged, with a banner pointing to the correction.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;strong&gt;Public export.&lt;/strong&gt; The Ledger page lists every entry, newest first, with a badge that re-checks the entire chain, and links to download the full ledger and the stewards&#39; public keys. It also shows the ledger&#39;s latest fingerprint, its &amp;quot;head&amp;quot;. Publishing that value elsewhere lets anyone detect a later rewrite.&lt;/p&gt;
&lt;figure class=&quot;post-figure post-figure--wide&quot;&gt;
  &lt;a href=&quot;https://primmortal.org/blog/images/how-it-works-ledger.png&quot;&gt;&lt;img src=&quot;https://primmortal.org/blog/images/how-it-works-ledger.png&quot; alt=&quot;The prototype&#39;s Ledger page, with buttons to download the public export and steward public keys, a green &#39;Ledger integrity verified&#39; badge (5 entries, hash chain intact, 5 signatures valid), and a table of five entries numbered 4 to 0, each with a thumbnail, a title marked SAMPLE, a type (register or correction), a citation token, shortened fingerprints and a timestamp. The ledger head fingerprint is shown at the bottom.&quot; width=&quot;1104&quot; height=&quot;1063&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;&gt;&lt;/a&gt;
  &lt;figcaption&gt;The demo ledger: four synthetic sample registrations and one correction, with the integrity badge and the head fingerprint. Times are shown in UTC.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;For academics and journalists: Level 2 citations&lt;/h2&gt;
&lt;p&gt;Scholars and reporters make claims that others need to check. Level 2 citations are designed for that work.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What a Level 2 citation adds (planned).&lt;/strong&gt; With a Level 2 citation, your article, paper or story would itself be registered in the ledger and linked to the source records it cites. The connection would be part of the record, not only in your footnotes: readers could see that this exact version of your work cited that exact source. The prototype does not do this yet; it links records to each other only through correction notices.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scan levels matter to evidence.&lt;/strong&gt; A Level 2 multispectral capture can preserve features that a basic Level 1 scan misses, such as faded or erased writing. The scan level tells a reader what kind of capture they are looking at. In the prototype, though, scan levels are simply declared by the steward, not proven.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How an editor or reader can check a token independently.&lt;/strong&gt; Level 1 tokens work in the prototype today, and checking one doesn&#39;t have to go through Primmortal&#39;s website. An editor with the file and the token can download the public export, obtain the steward keys and a recent head fingerprint through a separate channel, and run the verifier on their own machine:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;python -m primmortal verify-ledger --bundle primmortal-ledger-export.json &#92;
    --keys stewards.json --expect-head &amp;lt;published head&amp;gt;
python -m primmortal verify-file scan.png --bundle primmortal-ledger-export.json &#92;
    --keys stewards.json --token PMRT-33E3Z-EJWJ1-9
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The first command re-checks every entry and signature. The second checks the file against the token, and refuses to give a verdict if the ledger itself fails the check. The verifier needs only Python and one widely used cryptography library.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Before you publish, look for corrections.&lt;/strong&gt; A record&#39;s page shows whether a later correction notice exists. Because nothing is overwritten, you can cite the original and note the correction.&lt;/p&gt;
&lt;h2&gt;What the demo does not do yet&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Scan levels are placeholders, and they are self-declared.&lt;/strong&gt; The demo&#39;s capture-level labels were written before the scan levels above were settled and will be updated. Whatever level a steward picks, the prototype does not check it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No real multispectral captures, and no holographic ones.&lt;/strong&gt; The demo holds only four synthetic, single-image sample &amp;quot;scans&amp;quot;. Level 2 multispectral captures are not demonstrated, and Level 3 holographic scanning is theoretical.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No Level 2 citations.&lt;/strong&gt; Registering a citing work and linking it to its sources is planned, not built.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;One steward on one computer.&lt;/strong&gt; Whoever controls that machine and its key could rebuild the whole ledger from scratch. That would be detectable only by someone who kept an earlier head fingerprint or export.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Demo-only sign-in.&lt;/strong&gt; Registration uses one shared password, with no user accounts or roles. The prototype is not safe to put on the open internet as it stands.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A local ledger file, not a shared, permissioned blockchain, and no replication.&lt;/strong&gt; Files and ledger sit on one disk. No other institution holds a copy or co-signs entries.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Local clock only.&lt;/strong&gt; Registration times come from the computer&#39;s own clock, with no independent timestamping.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The code isn&#39;t public yet.&lt;/strong&gt; The prototype, including its verifier, has not been published.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sample data only.&lt;/strong&gt; No real archival items are registered.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The token format may change.&lt;/strong&gt; The white paper draft shows a different token format from the prototype&#39;s, and 50-bit tokens are fine for a demo but too short at global scale.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Not hosted publicly.&lt;/strong&gt; The prototype runs only on a local machine for now.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Where this could go next&lt;/h2&gt;
&lt;p&gt;These are directions from our roadmap and white paper draft, not promises or dates.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;A consortium of stewards.&lt;/strong&gt; The vision is governance by institutions such as university libraries and newspapers. No institution has signed on yet; conversations with archivists are planned for late October.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A shared ledger&lt;/strong&gt; run by several institutions, with Hyperledger Fabric as the current candidate (the white paper also suggests weighing a simpler append-only log).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Replicated storage.&lt;/strong&gt; Keep every file with several stewards in more than one region, via IPFS/Filecoin or institutional replicas, with regular health checks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Evidence behind scan levels.&lt;/strong&gt; Capture equipment could sign each scan at the moment it is made, in the style of &lt;a href=&quot;https://c2pa.org/&quot;&gt;C2PA Content Credentials&lt;/a&gt;, so a declared level has proof behind it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Real steward sign-in and roles.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Linked derivatives and Level 2 citations.&lt;/strong&gt; OCR text and transcriptions linked to the prime they came from without replacing it, and citing works linked to their sources.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Longer, versioned citation tokens&lt;/strong&gt; that still fit in a footnote.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A published head fingerprint, trusted timestamps, and a verifier that runs in your browser.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A hosted demo on real public-domain scans&lt;/strong&gt;, such as historic newspaper pages from the Library of Congress&#39;s &lt;a href=&quot;https://www.loc.gov/collections/chronicling-america/about-this-collection/&quot;&gt;Chronicling America&lt;/a&gt;. We are working toward putting it online, at an address such as demo.primmortal.org, ahead of a pilot proposal planned for December or January. The timing could change.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The white paper draft, &lt;a href=&quot;https://primmortal.org/docs/primmortal-white-paper-v0.2.1.pdf&quot;&gt;v0.2.1 (PDF)&lt;/a&gt;, goes into more of the design, including the scan and citation levels described in this post. The earlier &lt;a href=&quot;https://primmortal.org/docs/primmortal-white-paper-v0.2.pdf&quot;&gt;v0.2&lt;/a&gt; is archived. We&#39;ll post here as each piece lands.&lt;/p&gt;
</content>
  </entry>
</feed>
