Chain-of-Custody Rider
The evidentiary-grade attestation regime that binds each Notification to the license under which it was issued. This Rider is Exhibit F to the MSA and is invoked when Notifications are used as evidence, produced under subpoena, or introduced in an administrative or judicial proceeding.
1. Overview
Each Notification generated by the Platform is committed at creation time to an append-only, cryptographically signed record maintained by the Lotus Chain-of-Custody service ("Chain-of-Custody Record" or "Record"). Each Record is bound to (a) the license under which it was issued, (b) the Coverage Area, (c) a monotonic sequence number, and (d) the Notification's categorical payload. Records are hashed and included in a Merkle tree; the root of that tree is anchored to a public witness at least once every twenty-four (24) hours. This yields a tamper-evident trail from creation to production without exposing the Trade-Secret Schedule.
2. Contents of a Chain-of-Custody Record
Each Record contains, at a minimum: (a) a globally unique Record identifier; (b) the deploying Authority's License identifier; (c) the Coverage Area identifier; (d) the Notification's categorical class (as defined in the Capability Statement); (e) the Notification's Universal Coordinated Time timestamp with sub-second precision; (f) a monotonically increasing per-license sequence number; (g) the Merkle path proving inclusion in the daily tree; and (h) the WCE signature over the Record produced by a certificate whose chain terminates at the WCE Root CA. Records do not contain the internal features, model weights, or sensor traces that produced the Notification.
3. Verification
A Record can be independently verified using the WCE Verifier tool, published at /verify/. Verification confirms: (a) the Record is well-formed, (b) the Record is signed by a certificate that chains to the WCE Root CA, (c) the Merkle path is valid, and (d) the daily root is present at the public witness. A Verifier report is admissible under Federal Rule of Evidence 902(13) and (14) and analogous state and international rules for records generated by an electronic process producing an accurate result.
4. Retention
Records are retained for the greater of (a) the retention period configured in the Order Form, (b) seven (7) years, or (c) the period required by applicable law. Records subject to a legal-hold notice are retained until the hold is released.
5. Production under legal process
Where WCE receives valid legal process for a Record or set of Records, WCE will (a) authenticate the process, (b) notify the affected Customer unless prohibited by law, (c) produce the requested Records together with a Verifier report and a custodian declaration, and (d) contest overbroad or non-compliant process. Nothing in this Rider requires WCE to produce any part of the Trade-Secret Schedule. Where a court seeks disclosure of internal mechanisms, WCE will move for a protective order.
6. Custodian testimony
Where required, WCE will make available a records custodian qualified to authenticate Chain-of-Custody Records under applicable evidentiary standards, at Customer's or requesting party's reasonable expense. The custodian shall testify only to the operation of the Chain-of-Custody service and shall not testify to the internal workings of the Platform.
7. Categorical outputs are not identifications
A Chain-of-Custody Record documents that the Platform produced a categorical Notification at a specific time in a specific Coverage Area. A Record does not, in itself, identify any individual as the source of the Notification. Identification, where required, is a separate process undertaken by the deploying Authority and its personnel.
8. Cryptographic parameters
Records are signed using an algorithm suite that is FIPS 140-3 approved at the effective date of this Rider (currently ECDSA over P-384 for signature and SHA-384 for hash). Suite parameters may be updated for cryptographic hygiene; each Record identifies the suite in effect at the time of its creation, and the Verifier is backward-compatible.
9. Public witness
Daily Merkle roots are anchored to the WCE Transparency Log at /verify/log/ and, additionally, to at least one independent public witness selected by WCE for the purpose. The identity of the current independent witness is published in the Transparency Log.
This Rider is Exhibit F to the MSA and applies to every Notification produced by the Platform on and after the Effective Date.