Fuzzy, because memory is
You can't demand a verbatim 128-bit blob from a person, so the marker is a memorable passphrase and the match is fuzzy. That forces the bar high: only a near-exact recall, by someone who had access, after you showed it, is a memory crossing. Everything else is a control against reading a recall that isn't there.
Held-out arm
Passphrases shown to no one. If one is recited near-exact, it reached them another way — INVALID.
Fidelity gate
Only a near-exact recall (≥ 0.9) counts. A partial is FUZZY — reconstruction or coincidence, gated.
Access gate
The reciter must have had access. Near-exact by someone who never saw it came another way — gated.
Corroboration ≠ proof
Strength = how many independent people carried it. Never proof it was memorised vs written down.
The control arm, live
This is the harness's own logic — recitation.py + score.py — running in your browser: the same Jaccard fidelity, the same held-out arm, the same fidelity and access gates. Fresh passphrases each round; flip the failure modes and watch a recall gate out. Nothing leaves this page.
the registry & the recitations
the panel · run & score
What a certified recall does — and does not — mean
What it does mean
A passphrase only you showed, recited near-exactly by someone who had access, after you showed it, with a held-out arm proving the harness isn't fabricating.
It crossed via a person's memory — carried out with no digital trail.
What it does not mean
It does not prove it was truly memorised (vs written down or photographed), name anyone's intent, or prove theft.
A corroborated lead — and a negative means little.
Sound — and the limits it names out loud
Sound
python selftest.pyproves — no network — that a near-exact recall with access is certified and corroborated; a held-out passphrase recited spikes FPR and the run is refused; a partial recitation is FUZZY-gated; a no-access near-exact is gated; a pre-show recitation isn't certified; a run with no arm is refused; an unrelated phrase falls below the floor.- The fidelity gate is the honest move: it refuses to read reconstructive memory as a crossing.
- The self-test above is that exact logic — client-side.
Limits (and it says so)
- Memorised vs copied is unprovable — a recall is a human-carried crossing, not proof of mechanism.
- Entropy is bounded by memorability — use a large wordlist; a memorable phrase carries less than a hex canary.
- One membrane only. See the map for the others.
- A lead, not an accusation. It names no one's intent.
canary.py (memorable passphrases) · recitation.py (fuzzy Jaccard match) · score.py (held-out + fidelity gate + access gate + corroboration) · harness.py · selftest.py (no network). Closure-Loop layered: Detection → Anchoring → Comparison → Witness → Lineage.