Skip to content
ECZ-IDAPI

evidence

LedgerCore

Tamper-evident receipts of what happened, kept for the retention period your tier includes.

LedgerCore keeps the decisive lifecycle evidence for the identities your organisation holds — issuance, activation, material bindings, authority changes, suspension and revocation — as receipts that can be shown to have not been altered since they were written. Eligible evidence is anchored to a permissioned, append-only ledger, and each tier states the enhanced receipts it includes each month and the retention period it carries. An anchor shows that an entry has not changed. It does not make the statement inside it true.

Most organisations can show what is true about a machine identity today. Far fewer can show what was true on the day something went wrong, and fewer still can show that the record has not been tidied since. That evidence usually sits in logs the operator controls, on a retention policy set for storage cost rather than for scrutiny, and it is the operator's own account of the operator's own conduct. LedgerCore keeps the identity-level events outside that, for the retention period your tier includes, in a form a reader can check has not been edited. It is not a certification, an approval or a trust claim, and it does not make what was recorded true — it establishes only that the entry is the one that was made at the time.

What this means for API

An API outlives its base URLs, and the arguments it causes are almost always about dates: when a version was deprecated, when a breaking change went out, when ownership moved to another team, when callers were told. Gateway logs answer traffic questions, not identity questions, and they are rotated on a policy written for volume rather than for scrutiny. LedgerCore keeps the lifecycle events of the API's identity for a retention period you have chosen deliberately, and each receipt can be shown to be the one written at the time.

What you already have

  • 2 enhanced LedgerCore anchors, granted once rather than monthly

The ladder

The price is set, but online purchase is not open yet. There is no checkout route for it today. Agreed directly rather than bought online, so the scope and the price are settled with you.

How LedgerCore works
  1. 1.Essential canonical evidence is already kept for every identity your organisation holds, free ones included, and it stays permanent and free at every tier. LedgerCore is what sits above that baseline, and a one-time allowance of enhanced anchors comes before any subscription — the figure is shown beside the tiers.
  2. 2.Decisive lifecycle events are written as receipts when they happen: issuance, activation, material bindings, authority changes, suspension and revocation. Nothing is filed after the fact, and nothing is reconstructed later from memory.
  3. 3.Eligible receipts are anchored to a permissioned, append-only ledger. The anchor is what lets someone reading the entry later see that it has not been altered since it was written.
  4. 4.Receipts are retained for the period your tier carries, and the enhanced receipts included each month are a real ceiling rather than a soft guideline. No tier offers unlimited variable-cost activity, which is how the service cannot run up an unbounded bill on your behalf.
  5. 5.The subscription is held by your organisation, not by one Passport, and it covers the identities the organisation holds whichever family they come from. It needs a signed-in account and a Parent organisation that is at least DECLARED, which the free Passport already gives you.
Limits and conditions
  • One paid tier at a time within a billing scope. Tiers replace one another rather than stacking.
  • An upgrade replaces the lower tier rather than adding to it: the higher tier's allowances become the ones that apply.
  • No tier offers unlimited variable-cost activity. Every plan states the volume it includes.
  • Usage is cost-governed: the included volumes are real ceilings, not a soft guideline, so the service cannot run up an unbounded bill on your behalf.
  • No VAT charged. EcoCitizenz Ltd is not VAT-registered, so no VAT is added and no VAT invoice is issued.
How LedgerCore differs from the other ECZ-ID products
PulseGuard
PulseGuard evaluates the state of something as it stands now, and tells you when that state changes. LedgerCore keeps what already happened, so it can still be read once the state has moved on. One answers what is true at the moment; the other answers what took place, and when.
The free Resolver record
A Resolver record publishes what is currently declared and what evidence exists, with the time it was read. It is a current state rather than a history: it shows where the record stands, not the sequence of events that produced it, and it is not proof. LedgerCore keeps that sequence.
Graph Intelligence
The graph is about relationships — which organisation, which Passport, which binding, and how they connect. LedgerCore is about events: the things that happened to those identities, in order, with a receipt for each. A link in the graph is not an event, and an event is not an endorsement of either end of a link.
EvidenceCore
EvidenceCore is about what sits behind a claim on a record: what supports it, where it came from, when it was checked and who may see it. LedgerCore is about the fact that something occurred and has not been altered since. One explains a claim; the other dates an event.
After you buy, and how to change or cancel

What happens after purchase

  • The entitlement is held by your organisation and is commercial only. Your ECZ-ID does not change, no Passport is re-issued, and identity truth is untouched.
  • Enhanced receipts are recorded against the identities your organisation holds, up to the volume your tier includes each month, and retained for the period it carries.
  • Your Parent organisation tier does not move. Buying evidence never makes an organisation VERIFIED or ASSURED, and it never changes the assurance of any child Passport — each child carries its own.
  • The free baseline does not go away. Essential canonical evidence stays permanent and free at every tier, alongside whatever you have bought.
  • Nothing here is a certification, an approval or a trust claim. A receipt shows an entry has not been altered since it was written; it does not vouch for the statement inside it.

Upgrading

LedgerCore is a tier, not a pack. Moving up replaces the tier you hold rather than adding to it, so you are not carrying both: the monthly enhanced-receipt volume and the retention period become those of the new tier. Your identities, their ECZ-IDs, your Parent organisation tier and your children's assurance are unaffected by the move. TrustOps owns the purchase and states the terms.

Downgrading

A lower tier replaces the higher one the same way, because only one paid tier is held at a time within a billing scope. What changes is the included monthly volume and the retention period your tier carries. What does not change is any ECZ-ID, the Parent organisation tier, any child Passport's assurance, identity truth, or the essential canonical evidence that is permanent and free at every tier. What a change means for receipts already retained belongs to the terms, and TrustOps states those.

Cancelling

Ending the subscription ends the entitlement, not the history. Past records stay truthful: they are not rewritten or withdrawn, and essential canonical evidence remains permanent and free at every tier. Nothing is revoked, detached or destroyed by stopping, because a subscription is never an identity. TrustOps is where the purchase lives, and where the terms — including anything about retention once a subscription ends — are stated.
LedgerCore — frequently asked questions
Does a receipt prove that what it says is true?
No. An anchor shows that an entry has not been altered since it was written. It says nothing about whether the statement inside it was correct. It is not a certification, an approval or a trust claim, and a reader should still check the live record rather than rely on the receipt alone.
What happens to our history if the subscription lapses?
It stays truthful. Past records are not rewritten or withdrawn, and essential canonical evidence is permanent and free at every tier. What ends is the entitlement to record enhanced receipts at that tier. The terms are stated in TrustOps, not here.
Can we hold more than one LedgerCore tier at once?
No. LedgerCore is a tier family: one paid tier at a time within a billing scope, and an upgrade replaces the lower tier rather than adding to it. Capacity packs stack and add up; tiers do not.
Does buying it change our organisation's tier or our Passports' assurance?
No. A DECLARED Parent organisation can buy it and stays DECLARED. Buying evidence never produces a VERIFIED or ASSURED organisation, and verifying an organisation would never verify its children in any case. Each child Passport carries its own assurance.
What happens when we reach the monthly volume?
You cannot add further enhanced receipts at that tier until the meter turns over or you move up. Nothing is revoked, detached or destroyed: running out of an allowance never touches an identity. The included volumes are real ceilings rather than a soft guideline, which is what stops the service running up an unbounded bill on your behalf.
Does it consume our Active Entity Capacity?
No. Active Entity Capacity counts actively managed entities and is pooled across your organisation; LedgerCore is metered in enhanced receipts on its own allowance. IoT device instances are separate again — they draw on IoT Device Fleet Capacity and never consume Active Entity Capacity.
Where do we buy it, and where are the terms?
TrustOps owns every purchase, the current tiers and the terms. This page describes what LedgerCore does and what it never does; what it costs, what each tier includes and whether it can be bought online are read from the commercial registry and shown beside this section.