ledgerkeep

Ledgerkeep: what has run, and what has not

This document separates what is verified from what is not, by evidence class, so diligence finds nothing that was not disclosed. Milestone 1 is a callable, tested, self-contained service. It is not a deployment, and it has no users.

What has run, and is tested

What has NOT run

Honest scope of the safety layer

The content-safety screen and the read-only-SQL screen in agent_core are deny-list text screens, not parsers. They are defence in depth and are the last line, not the only one. The real boundary for any generated query is a read-only credential with a server-side cost cap. This is documented as such and not claimed to be a formal guarantee.