CanopyProof OSEnvironmental accountability infrastructure

Evidence Collection Network

Offline-first field reporting for restoration, water, biodiversity, soil, and climate observations.

Mobile evidence is captured locally, hashed before upload, synchronized idempotently, and routed through community verification before it can support a public proof record.

Create offline evidence draftInspect evidence schemaEvidence Layer

Evidence Workbench

Field capturetree planting / biodiversity / water project / soil regeneration
Sync disciplinemedia hash / encrypted object / malware scan / idempotency key
Community verificationsupport / challenge / needs review / audit event

AHIN event contract

ASSERT - REASON - DELEGATE - FULFILL - CHALLENGE

Report classes

6

planting, restoration, biodiversity, water, soil, climate

Required signals

8

photo, GPS, timestamp, device, EXIF, sync, scan, community

Offline mode

idempotent

sync by evidence ID and media hash

Final authority

human

AI never finalizes evidence

ok

Field capture

Capture photos, GPS, timestamp, device fingerprint, EXIF metadata, and local notes while offline.

  • tree planting
  • biodiversity
  • water project
  • soil regeneration
review

Sync discipline

Uploads are content-addressed, scan-gated, and replay-safe; conflicts become review tasks instead of overwrites.

  • media hash
  • encrypted object
  • malware scan
  • idempotency key
watch

Community verification

Community observations can support proof, but they remain bounded until accredited review completes.

  • support
  • challenge
  • needs review
  • audit event

Workflow Control

Evidence to public record, without collapsing review.

CanopyProof actions use Dropin identity, agents, trust, governance, memory, and AHIN events. AI can observe and recommend, but accredited human review remains final authority for proof records.

  1. 1

    Draft

    Evidence envelope is created before network availability.

    Contributor device

    offline

  2. 2

    Hash

    Media and GPS commitments are calculated before upload.

    Evidence Agent

    local

  3. 3

    Sync

    Batch sync is replay-safe and conflict-aware.

    Dropin Memory

    idempotent

  4. 4

    Attest

    Community support or challenge is appended without final authority.

    Community

    non-final

  5. 5

    Queue

    Validation, AI, TerraProof, and review work items preserve dependency order.

    Verification Layer

    backpressure aware

  6. 6

    Review

    Accepted status requires accredited human review.

    Verifier

    human gated

Evidence Schema

The mobile report envelope is typed, hashable, and reviewable.

id

Stable evidence identifier used for offline sync and audit lineage.

Verification

Generated once, replay-safe, and tied to the append-only audit event.

location

Latitude, longitude, accuracy, and privacy mode for environmental context.

Verification

Compared against GPS hash, EXIF coordinates, and TerraProof geospatial expectations.

timestamp

Observed time for photos, field reports, sensor readings, or community attestations.

Verification

Checked against device time, EXIF time, sync time, and satellite acquisition windows.

contributor

Dropin identity subject for human, organization, agent, or device.

Verification

Settlement-grade evidence requires authenticated identity and reputation context.

media_hash

Content-addressed photo, video, document, or sensor artifact.

Verification

Duplicate detection, object storage integrity, and proof-root construction.

gps_hash

Privacy-preserving commitment to raw device location signals.

Verification

GPS spoofing detection without exposing unnecessary personal data publicly.

verification_status

Current state from submitted through challenged, accepted, revoked, or superseded.

Verification

State transitions require policy checks and audit entries.

confidence_score

Bounded confidence estimate from deterministic and AI-assisted checks.

Verification

Advisory only; cannot replace human review.

reviewers

Accredited humans and organizations responsible for final review.

Verification

RBAC, accreditation, conflict disclosure, and governance approval checks.

audit_history

Append-only mutation trail for evidence, review, certificate, and challenge actions.

Verification

Hash-chained audit events with request IDs and policy decisions.

offline_sync_id

Replay-safe identifier for evidence captured without network access.

Verification

Synced through idempotent batches; conflicting ID reuse is challenged rather than overwritten.

device_fingerprint_hash

Privacy-preserving commitment to the collection device or field terminal.

Verification

Used for duplicate, compromised-device, and GPS-spoofing review without exposing raw device identifiers.

exif_hash

Commitment to raw EXIF metadata extracted from field photos or media.

Verification

Compared with timestamp, location, and satellite windows during human review.

community_attestations

Local support, challenge, or needs-review context from accountable community actors.

Verification

Can challenge evidence and inform reviewers, but cannot finalize proof.

media_objects

Confirmed object-storage media bound to upload intent, content hash, encryption mode, and malware scan state.

Verification

Pending, quarantined, or duplicate media objects remain non-final until accredited review resolves them.

consent_receipts

Privacy-preserving receipts for field evidence collection, geolocation, media upload, and research-sharing consent.

Verification

Active consent is required before device-bound EXIF/GPS metadata can enter proof lineage.

device_attestations

Hash-bound device integrity statements for secure enclave, WebAuthn, platform key, field kit, or sensor gateway capture.

Verification

Risk flags and low reputation force metadata extraction into human review.

media_metadata_extractions

EXIF/GPS extraction records bound to clean media objects, active consent receipts, and active device attestations.

Verification

Metadata hashes, GPS accuracy, privacy mode, and clock skew are evaluated before use in proof records.

review_tasks

Human moderation queue for quarantined media, duplicate media, pending scans, and metadata extraction risks.

Verification

Open, assigned, resolved, and escalated tasks keep non-final evidence blocked until accountable review.

retention_policy_decisions

Append-only consent-retention, revocation, minimization, tombstone, and legal-hold decisions.

Verification

Retention automation records decisions without silently deleting or mutating evidence lineage.

verification_work_items

Backpressure-aware work queue for validation, advisory AI, TerraProof, human review, and proof issuance.

Verification

Dependencies are explicit, AI remains advisory, and proof issuance requires human review before public records.

Production Boundary

CanopyProof records are environmental accountability records. They are not certified carbon credits, financial assets, carbon-tax offsets, guaranteed yield instruments, or automatic CANOPY distribution claims. Public admin routes must remain blocked and every mutation must be audit logged.