{"answered":true,"attestation_plane":"vulcora-attestation/v1","attested":["bradarr/qwen2.5-0.5b-instruct-abliterated","chainik08/qwen2.5-0.5b-instruct-gensyn-swarm-fast_whistling_sparrow","cognitivecomputations/dolphin3.0-llama3.2-1b","conich/qwen2.5-0.5b-instruct-gensyn-swarm-gregarious_galloping_alpaca","dania19862017/qwen2.5-0.5b-instruct-gensyn-swarm-unseen_nocturnal_zebra","dekodez/qwen2.5-1.5b-instruct-abliterated","dphn/dolphin3.0-qwen2.5-0.5b","efficient-large-model/gemma-2-2b-it","elstuhn/qwen2.5-1.5b-instruct-abliterated","failspy/meta-llama-3-8b-instruct-abliterated-v3","geventy/qwen2.5-0.5b-instruct-gensyn-swarm-skittish_durable_okapi","goekdeniz-guelmez/josiefied-qwen2.5-0.5b-instruct-abliterated-v1","goekdeniz-guelmez/josiefied-qwen2.5-1.5b-instruct-abliterated-v1","gorkimark/qwen2.5-0.5b-instruct-gensyn-swarm-fluffy_rapid_wildebeest","haseebasif/qwen2.5-1.5b-abliterated","historya/qwen2.5-0.5b-instruct-gensyn-swarm-territorial_mangy_ox","huggingfacetb/smollm2-1.7b-instruct","huihui-ai/llama-3.2-1b-instruct-abliterated","huihui-ai/meta-llama-3.1-8b-instruct-abliterated","huihui-ai/qwen2.5-0.5b-instruct-abliterated","huihui-ai/qwen2.5-0.5b-instruct-abliterated-v3","huihui-ai/qwen2.5-1.5b-instruct-abliterated","huihui-ai/qwen2.5-14b-instruct-1m-abliterated","huihui-ai/qwen2.5-14b-instruct-abliterated-v2","huihui-ai/qwen2.5-32b-instruct-abliterated","huihui-ai/qwen2.5-3b-instruct-abliterated","huihui-ai/qwen2.5-coder-0.5b-instruct-abliterated","huihui-ai/qwen2.5-coder-1.5b-instruct-abliterated","huihui-ai/qwen2.5-coder-3b-instruct-abliterated","ilyagusev/gemma-2-2b-it-abliterated","ilyagusev/gemma-2-9b-it-abliterated","kalantar/qwen2.5-0.5b-instruct-gensyn-swarm-leaping_thick_hippo","kepom/qwen2.5-coder-1.5b-instruct-abliterated","kikichi/qwen2.5-3b-instruct-uncensored","kingnish/reasoning-0.5b","martin2012/qwen2.5-0.5b-instruct-gensyn-swarm-zealous_winged_locust","masha34/qwen2.5-0.5b-instruct-gensyn-swarm-camouflaged_placid_ferret","masterkristall/qwen2.5-0.5b-instruct-abliterated","meowstronot/qwen2.5-0.5b-instruct-gensyn-swarm-patterned_ferocious_ox","mergekit-community/qwen2.5minus2-0.5b-instruct","merhabawer/qwen2.5-0.5b-instruct-gensyn-swarm-skittish_shiny_gerbil","mkashifali1/qwen2.5-0.5b-instruct-gensyn-swarm-arctic_muscular_heron","mlabonne/chimerallama-3-8b","mlabonne/chimerallama-3-8b-v2","mlabonne/chimerallama-3-8b-v3","mlabonne/daredevil-8b","mlabonne/hermes-3-llama-3.1-8b-lorablated","mlabonne/meta-llama-3.1-8b-instruct-abliterated","mlabonne/numinillama-3.1-8b","mlabonne/orpollama-3-8b","mlabonne/qwen3-1.7b-abliterated","mlabonne/twinllama-3.1-8b","mlabonne/twinllama-3.1-8b-dpo","mlabonne/ultrallama-3.1-8b","motocat/qwen2.5-0.5b-instruct-gensyn-swarm-rabid_vigilant_caterpillar","nousresearch/hermes-3-llama-3.1-8b","ohhmoo/qwen05b-gsm8k-sft-instruct","oliviaxiiiii/qwen2.5-1.5b-sft-mixture-all","open-unlearning/tofu_llama-3.2-1b-instruct_full","ophirparwez/qwen2.5-0.5b-instruct-gensyn-swarm-invisible_mammalian_worm","ops-malware/qwen2.5-1.5b-abliterated","pew404/qwen2.5-3b-instruct-abliterated","phamhai/llama-3.2-1b-instruct-frog","phantomcloak19/gemma2-2b-dpo","phantomcloak19/qwen2.5-3b-dpo","prithivmlmods/bellatrix-tiny-1b-v3","promptrails/piimask-qwen2.5-0.5b","puettmann/llamaestra-3.2-1b-translation","qwen/qwen2-0.5b-instruct","qwen/qwen2.5-0.5b-instruct","qwen/qwen2.5-1.5b-instruct","qwen/qwen2.5-14b-instruct","qwen/qwen2.5-14b-instruct-1m","qwen/qwen2.5-32b-instruct","qwen/qwen2.5-coder-0.5b","qwen/qwen2.5-coder-0.5b-instruct","qwen/qwen2.5-coder-1.5b-instruct","qwen/qwen2.5-coder-3b-instruct","qwen/qwen2.5-math-1.5b","recursivemas/sequential-light-critic-llama3.2-1b","rgerb7363/qwen2.5-0.5b-instruct-gensyn-swarm-plump_scampering_jaguar","sicariussicariistuff/nano_imp_1b_abliterated","skywork/skywork-reward-v2-llama-3.2-1b","stupidity-ai/qwen2.5-0.5b-noised3.0","suchnost/qwen2.5-0.5b-instruct-gensyn-swarm-clawed_ravenous_gibbon","sudhisrk1982/gemma-2-2b-legal","temmy77/qwen2.5-0.5b-instruct-gensyn-swarm-nimble_nasty_falcon","thu-coai/setox-qwen2.5-3b","ukhagani/qwen2.5-0.5b-instruct-gensyn-swarm-yapping_slimy_tarantula","unsloth/gemma-2-2b-it","unsloth/gemma-2-9b-it","unsloth/llama-3-8b-instruct","unsloth/llama-3.1-8b-instruct","unsloth/llama-3.2-1b-instruct","unsloth/meta-llama-3.1-8b","unsloth/meta-llama-3.1-8b-instruct","unsloth/qwen2.5-0.5b","unsloth/qwen2.5-0.5b-instruct","unsloth/qwen2.5-14b-instruct","vagosolutions/sauerkrautlm-gemma-2-2b-it","vikhrmodels/vikhr-llama-3.2-1b-instruct","vikhrmodels/vikhr-qwen-2.5-0.5b-instruct","vikhrmodels/vikhr-qwen-2.5-1.5b-instruct","w34423g2/qwen2.5-0.5b-instruct-gensyn-swarm-colorful_ferocious_bear","xinnn32/qwen2.5-0.5b-instruct-gensyn-swarm-amphibious_savage_mantis","yingfanbot/gsm-cot-llama1b","ymcki/gemma-2-2b-jpn-it-abliterated-17-orpo","ymcki/gemma-2-2b-jpn-it-abliterated-18","ymcki/gemma-2-2b-orpo-jpn-it-abliterated-18","youter3/qwen2.5-0.5b-instruct-gensyn-swarm-stubby_shrewd_rooster"],"coverage":{"complete":true,"falsifier":"LC_ALL=C comm -13 <(curl -s https://api.vulcora.se/api/attestations | jq -r '.attested[]' | LC_ALL=C sort) <(curl -s https://api.vulcora.se/api/model_records | jq -r '.data[] | select(.attributes.protora_assessed) | .id' | LC_ALL=C sort)","falsifier_contradictions":"curl -s https://api.vulcora.se/api/attestations | jq -r '.verdict_mismatch[]'","falsifier_self_contradictions":"curl -s https://api.vulcora.se/api/attestations | jq -r '.tier_conflict[]'","falsifier_served_verdict_is_signed":"for m in $(curl -s https://api.vulcora.se/api/attestations | jq -r '.attested[]'); do curl -s \"https://api.vulcora.se/api/attestations/$m\" | jq -r 'select(.verdict != .dossier.detect.verdict) | .hf_id'; done","models_with_disagreeing_signature":4,"models_with_public_verdict":210,"models_with_self_contradicting_signature":1,"models_with_signed_attestation":110,"note":"`attested` is every model this plane will serve a signed dossier for, computed by the same function the per-model route answers with — so the list and the per-model answers cannot disagree. Every catalog model that publishes a verdict but is NOT in `attested` is a verdict this plane serves no signed evidence for, and that difference splits in two: most of it means we hold nothing, but the ids in `verdict_mismatch` mean we hold signed evidence that disagrees with the verdict we publish — a different fact, and a worse one. Those ids are enumerated here so you need one request rather than one per model. The per-model route names the same reason for each of them (`attestation_verdict_mismatch`), and for anything else answers one of the closed `unattested_reasons` — or, in the single case where a stored dossier of ours fails our own read-time content gate, a 500 carrying the `refusals` code `dossier_not_firewall_clean`. Those three keys are every outcome this plane can produce. Take the difference yourself; that is the check, and it needs no trust in this sentence."},"public_keys":[{"key_id":"12de523fe3a942fa","public_key_b64":"NMjndDyQuaLqm/XIPrCoA46iE5TmmMU0l0DUJQp2GhY="}],"question":"Does Vulcora hold a signed attestation dossier for a given model?","refusals":{"dossier_not_firewall_clean":"A stored record for this model failed our own read-time content gate. That is a bug on our side; we refuse to serve it rather than serve it unchecked. This is NOT a statement that we hold no attestation for the model."},"routes":{"one_model":"GET /api/attestations/{owner}/{name}","the_catalog":"GET /api/model_records","this_index":"GET /api/attestations"},"tier_conflict":["unsloth/gemma-3-1b-it"],"unattested_reasons":{"attestation_subject_mismatch":"Vulcora holds a stored record for this model whose own attested subject names a DIFFERENT model. We refuse to serve it as this model's attestation, and the mismatch is logged for investigation.","attestation_tier_conflict":"Vulcora holds a signed dossier for this model whose OWN TIERS disagree with each other: the model-level read and the coarse pre-read carry different verdicts inside a single signature. There is therefore no such thing as `the` verdict of this dossier, and we refuse to pick one — a tie-break we invented would be exactly the unbacked word this plane exists to prevent, wearing a valid signature. Read this as: the read did not settle on this model. It is NOT a clean bill of health and NOT an accusation. The conflict is logged; the model is served again once a re-read produces one verdict.","attestation_verdict_mismatch":"Vulcora holds a signed dossier for this model whose SIGNED verdict is not the verdict this site publishes for it. We refuse to serve the two together, because doing so would put a valid Ed25519 signature next to a label it never covered — and our own verify recipe would then print that label as though the signature vouched for it. Read this as: we hold signed evidence here, and it disagrees with our published verdict. It is NOT a clean bill of health, and NOT a claim that we hold nothing. The discrepancy is logged; the model is served again once a re-read reconciles the two.","attestation_verdict_unsigned":"Vulcora holds a signed dossier for this model that carries no verdict inside its signed bytes. Any verdict we printed beside it would be unsigned — a word with a valid signature next to it and no signature over it — so we serve none. This is NOT a statement that we hold nothing, and NOT a verdict of any kind.","no_signed_dossier":"Vulcora publishes a verdict for this model but holds NO signed attestation dossier behind it — that verdict came from an imported projection or a ratings source, not from a completed, signed scan. Treat it as unbacked; this endpoint is how you check.","not_assessed":"Vulcora holds a catalog record for this model but no concluded Protora read, so there is no attestation to serve.","unknown_model":"Vulcora holds no record of this model. Nothing has been read and no attestation exists. This is our answer, not a missing route.","verdict_under_review":"A Protora read concluded on this model and its verdict is withheld pending human review. We serve no evidence for a withheld verdict. This response discloses that a verdict exists and is held — never what it says."},"verdict_mismatch":["carsenk/llama3.2_1b_2025_uncensored_v2","google/gemma-2-2b-it","google/gemma-2-2b-jpn-it","mlabonne/neuralllama-3-8b-instruct-abliterated"],"verify":{"alg":"ed25519","canon":"json.dumps(obj, sort_keys=True, separators=(',',':'), ensure_ascii=True).encode() over the dossier MINUS the signature (and countersignatures) keys","key_id_field":"public_key_id","key_provenance":{"how_to_anchor_the_key":"pin it out of band and re-check later: record the key_id and key bytes now, obtain them from a second channel, and re-run the verify against your pinned copy rather than the served one. A key that changes under a stable key_id — or a dossier that starts verifying under a different key_id — is the signal.","independent_anchor":"NONE PUBLISHED YET. This key is not currently mirrored in any channel independent of this API, so the trust anchor is circular and the check above is integrity-only. We would rather state that than let `verified` do work it has not earned. Until an independent mirror exists, treat a passing check as `unanchored`.","key_id_derivation":"key_id = the first 16 lowercase-hex characters of sha256(the raw 32-byte public key). Recompute it yourself from public_key_b64; do not trust our label.","what_it_does_not_prove":"that the key is Vulcora's. The keys are served by the same host that serves the dossier, so this check alone cannot rule out a fully compromised host serving a self-consistent forgery.","what_the_check_proves":"that this dossier is byte-for-byte the one signed by the holder of the named key, and that its verdict has not been altered in transit or at rest."},"note":"recompute canon(dossier - signature), base64-decode `signature`, Ed25519-verify against the public_key whose key_id matches `public_key_id`","public_key_ids":["12de523fe3a942fa"],"recipes":{"no_dependencies":["#!/bin/sh","# Re-verify a Vulcora attestation. Needs only curl, python3 (stdlib) and openssl.","# Nothing here trusts Vulcora: the response body is the only thing fetched, and","# every byte of the check runs on your machine.","#   sh verify.sh Qwen/Qwen2.5-0.5B","#","# The signature covers the verdicts INSIDE dossier.detect / dossier.coarse. It does NOT","# cover the top-level `verdict`, which is the label this site publishes. This script","# prints both and never conflates them. Exit codes are kept distinct for the same reason:","#   0      signature verified, and the published label is one the signature covers","#   3      signature verified, but the published label is NOT among the signed verdicts,","#          and/or the signed bytes carry more than one verdict. The signature is fine;","#          the pairing is what is wrong. Read the report under the openssl line.","#   other  the signature check itself failed, or the answer was unbacked.","set -e","D=$(mktemp -d)","curl -sS \"https://api.vulcora.se/api/attestations/$1\" -o \"$D/a.json\"","python3 - \"$D\" <<'PY'","import base64, json, sys","w = sys.argv[1]","b = json.load(open(w + '/a.json'))","if not b.get('attested'):","    sys.exit('UNBACKED (%s): %s' % (b.get('reason'), b.get('statement')))","d = b['dossier']","signed = {k: v for k, v in d.items() if k not in ('signature', 'countersignatures')}","msg = json.dumps(signed, sort_keys=True, separators=(',', ':'), ensure_ascii=True)","open(w + '/msg.bin', 'wb').write(msg.encode())","open(w + '/sig.bin', 'wb').write(base64.b64decode(d['signature']))","k = next(k for k in b['public_keys'] if k['key_id'] == d['public_key_id'])","raw = base64.b64decode(k['public_key_b64'])","der = bytes.fromhex('302a300506032b6570032100') + raw","open(w + '/key.pem', 'w').write('-----BEGIN PUBLIC KEY-----\\n'","    + base64.b64encode(der).decode() + '\\n-----END PUBLIC KEY-----\\n')","print('subject:', d.get('subject'), '| key:', k['key_id'])","# The verdict the signature COVERS is inside d. b['verdict'] is the label this site","# publishes and sits OUTSIDE the signed bytes. Both are reported; neither is merged","# into the other, and where they diverge that is said rather than resolved.","t = [(n, d[n]['verdict']) for n in ('detect', 'coarse')","     if isinstance(d.get(n), dict) and d[n].get('verdict')]","inside = sorted(set(v for _, v in t))","pub = b.get('verdict')","r = ['  signed %-6s verdict : %s   [covered by the signature]' % nv for nv in t]","r.append('  published label       : %s   [NOT covered by the signature]' % pub)","if not t:","    r.append('  this dossier carries no per-tier verdict, so there is nothing to compare.')","if len(inside) > 1:","    r.append('CONFLICT: the signed bytes carry MORE THAN ONE verdict (%s). The signature'","             ' covers that disagreement itself. We do not pick a winner for you.'","             % ', '.join(inside))","if inside and pub and pub not in inside:","    r.append('DIVERGENCE: the published label %r is NOT among the signed verdict(s) (%s).'","             ' The signature above is genuine and says nothing whatever about that label.'","             % (pub, ', '.join(inside)))","open(w + '/verdicts.txt', 'w').write('\\n'.join(r) + '\\n')","if len(inside) > 1 or (inside and pub and pub not in inside):","    open(w + '/divergence', 'w').write('')","PY","openssl pkeyutl -verify -pubin -inkey \"$D/key.pem\" -rawin -in \"$D/msg.bin\" \\","  -sigfile \"$D/sig.bin\"","# Only NOW, with the signature confirmed, is it honest to report what it covers.","echo '--- what that signature covers, and what it does not ---'","cat \"$D/verdicts.txt\"","if [ -f \"$D/divergence\" ]; then exit 3; fi"],"python_pynacl":["#   pip install pynacl && python verify.py Qwen/Qwen2.5-0.5B","# Same check, same honesty: the signature covers dossier.detect / dossier.coarse, NOT","# the top-level `verdict`. Exits 3 when the published label is not one the signature","# covers (or the signed tiers disagree) — the signature itself having passed.","import base64, json, sys, urllib.request","from nacl.signing import VerifyKey","","url = 'https://api.vulcora.se/api/attestations/' + sys.argv[1]","body = json.load(urllib.request.urlopen(url))","if not body.get('attested'):","    sys.exit('UNBACKED (%s): %s' % (body['reason'], body['statement']))","d = body['dossier']","signed = {k: v for k, v in d.items() if k not in ('signature', 'countersignatures')}","msg = json.dumps(signed, sort_keys=True, separators=(',', ':'),","                 ensure_ascii=True).encode()","key = next(k for k in body['public_keys'] if k['key_id'] == d['public_key_id'])","VerifyKey(base64.b64decode(key['public_key_b64'])).verify(","    msg, base64.b64decode(d['signature']))","# The signature is good. Say precisely what it vouched for, and what it did not.","t = [(n, d[n]['verdict']) for n in ('detect', 'coarse')","     if isinstance(d.get(n), dict) and d[n].get('verdict')]","inside = sorted(set(v for _, v in t))","pub = body.get('verdict')","print('SIGNATURE OK', d.get('subject'), '(key %s)' % key['key_id'])","for n, v in t:","    print('  signed %-6s verdict : %s   [covered by the signature]' % (n, v))","print('  published label       : %s   [NOT covered by the signature]' % pub)","if len(inside) > 1:","    print('CONFLICT: the signed bytes carry MORE THAN ONE verdict (%s). The signature'","          ' covers that disagreement itself. We do not pick a winner for you.'","          % ', '.join(inside))","if inside and pub and pub not in inside:","    print('DIVERGENCE: the published label %r is NOT among the signed verdict(s) (%s).'","          ' The signature above is genuine and says nothing whatever about that label.'","          % (pub, ', '.join(inside)))","sys.exit(3 if len(inside) > 1 or (inside and pub and pub not in inside) else 0)"]},"signature_field":"signature","steps":["take d = body.dossier","find the entry in body.public_keys whose key_id equals d.public_key_id","base64-decode that public_key_b64 (32 bytes) and d.signature (64 bytes)","recompute the canonical bytes over d MINUS the `signature` and `countersignatures` keys","Ed25519-verify the decoded signature over those bytes against the decoded key","read the verdict from INSIDE d — `d.detect.verdict`, and `d.coarse.verdict` where the read emitted one. The top-level `verdict` is the label this site publishes and the signature does NOT cover it; compare the two rather than assuming they agree","or skip all six: `jq -r '.verify.recipes.no_dependencies[]' > verify.sh` and run it"],"verdict_scope":{"derived":{"rule":"the top-level `verdict` is the MODEL-level word: `dossier.coarse.verdict` when the dossier carries the union block, else the flagship leg's word with `verdict_scope: \"class\"` and the covered class in `verdict_covers`. It is read in the same function that renders this body, so it cannot drift from the signed bytes by construction rather than by discipline. `verdict_source` names the exact field it came from, per response.","verdict":"dossier.coarse.verdict, falling back to dossier.detect.verdict"},"not_signed":["verdict","verdict_scope","verdict_covers","threat_classes"],"note":"the top-level `verdict` is a COPY of a signed field, not itself inside the signed bytes, so a passing Ed25519 check does not by itself vouch for the copy. Check it in one comparison against the field `verdict_source` names, and read the verdict straight out of the dossier if you would rather trust nothing above the signature at all. The recipes below print both words and never conflate them.","scope_is_load_bearing":"when `verdict_scope` is `class`, the word covers ONE tampering class and rules out no other. Rendering such a `clean` as a clearance of the model is an overclaim — it is the defect we corrected in the dossier's own prose, and we will not re-commit it in the envelope. Check `verdict_scope` before quoting `verdict`.","signed":["dossier.detect.verdict","dossier.coarse.verdict"],"the_two_blocks":{"dossier.coarse":"the MODEL-LEVEL verdict: the union over every detection class we run. Not a coarser or cheaper `detect` — a BROADER one. It can carry a catch from a class the flagship leg does not cover at all. Absent on dossiers issued before 2026-07-27.","dossier.detect":"the FLAGSHIP LEG, and it is CLASS-SCOPED — always. Every dossier we issue stamps `kind: \"abliteration\"` on it. Its verdict answers \"did the abliteration read fire?\", never \"is this model clean?\".","they may differ, legitimately":"a flagship `clean` under a model-level `caught` is the multi-class case working: the abliteration read found nothing and a different class fired. The fired classes are named in `threat_classes` inside the same signed block. We serve that as `caught`. Treating leg-vs-model divergence as a contradiction would suppress a real catch, and for one model on 2026-07-31 it did — this plane refused to publish anything about a model it holds a signed catch for. Corrected."},"what_is_NOT_refused":"the flagship leg differing from the model-level word. That is the multi-class case working, not a contradiction, and refusing it suppresses a real catch. We got this wrong on 2026-07-31 and this field said so in the opposite direction for several hours; the correction is in the history of this endpoint's own repository.","what_is_actually_refused":"a dossier is refused on verdict grounds ONLY when it contradicts its own signed evidence — when the model-level word is not what the derivation law computes from that same evidence (`attestation_tier_conflict`), when the published site label is not the signed model word (`attestation_verdict_mismatch`), or when no verdict is inside the signed bytes at all (`attestation_verdict_unsigned`). The law: a CATCH is a join — any evidence of a catch anywhere escalates, so a catch can never be lost. A CLEARANCE is a meet — `clean` requires the union AND the flagship leg to have both cleared, so a `clean` union over an abstained leg is refused as a clearance the evidence does not license. Both refused sets are enumerated in the index (`tier_conflict`, `verdict_mismatch`), countable in one request."}},"withheld":{"also_published":"the seal is on the METHOD, not on measurement as such — and where publishing a measurement is what makes a claim checkable, we publish it in full. The replay protocol at github.com/Vulcora/proofora (`proof-carrying-edit/exhibits/model-c/`) deliberately discloses the entire weight-space measurement behind that exhibit's published result: which public model pair, which tensors, the exact quantity to compute, runnable code, the numbers we got, and the tolerance that counts as a reproduction. That is ordinary linear algebra over public weights, and it is disclosed precisely so a third party can re-run it without us and without our software. What stays sealed there is what stays sealed here — the shipped reads from our own gate, which that document marks as sealed and asks nobody to trust.","if_that_is_not_enough":"the proofs the dossier cites are public and independently checkable at the commit it names, and they state their own honest ceiling rather than a universal claim.","in_the_dossier":"the signed verdict and its coarse threat classes, the read's own coverage stamp, every abstain the read owned, and the scope + public commit of the machine-checked proofs that bound what the method claims.","not_in_the_dossier":["how the read is computed: the detector's construction, and the reference material a read is scored against","the per-layer and per-tensor measurements this read took — a dossier carries a verdict and the scope it holds over, not the read's internals","the referent of an internal handle: `detect.witness` is an internal reference, not a public artifact"],"posture":"private methods, public evidence","why":"the method is the product; the evidence is the claim. Publishing how the read is computed would hand an adversary the map to evade it, and would not make a verdict one bit more checkable than the signed dossier already makes it. Publishing a MEASUREMENT does the opposite — it is the thing that lets a stranger reach our conclusion without us. So the line is method-private, evidence-public, and we name which side of it an artifact falls on rather than implying that everything is sealed."}}