NakedSignal OS · Documentation
Back to the consoleDocumentation

PubMedBERT-sentence frozen + linear probe

LIVE

The signed evidence record for pubmedbert_st_probe. Everything below was read out of the passport file; the signature was checked when this page was built, by the same code the Verify button runs.

SIGNATURE VALIDexit 0signature valid, issued by NakedSignal under key ns-passport-2026-07, not expired
SubjectPubMedBERT-sentence frozen + linear probe pubmedbert_st_probe
Configuration109M frozen, mean-pooled 768-d, logistic head; biomedical pretraining PLUS a sentence objective
Code fingerprintb5b34c074f7f
Spec versionMedEval-1 v0.1
Issued2026-08-03T16:03:42Z by NakedSignal
Expires2026-09-20T00:00:00Zthe sealed held-out generation this evidence cycle is anchored to (gen2, set hash ad30d214daa285c5...) is published to expire 2026-09-20; per spec, a passport lapses when its generation retires or its spec version is superseded, whichever comes first
key ns-passport-2026-07 · Ed25519

The check runs against the public key published on the governance page, using your browser's own Ed25519 implementation. The exit code shown is the exit code verify_passport.py returns for the same document.

Measured by NakedSignal

Computed in this repo by the MedEval-1 harness on data the model had never seen. Every number below was copied out of a file the harness wrote — 8 of them, each listed with its SHA-256 at the foot of this panel — and is printed exactly as it was signed, not re-rounded for display.

TaskDomainn testaccuracycalibrationuncertaintysubgroupcorruptionacquisitionlimited datacostspec sensitivityIndex
jobpost_fraudlabour447071.56488195.2825598.60772422.43589793.106603n/a63.4604899.83278n/a75.215637
ledgarlegal1000064.17211627.18755889.826776093.209557n/a88.8446598.687457n/a60.348161
medabstractsmedicine288845.59118210.63107461.43104431.85618799.261585n/a87.955836100n/a55.469813

Cross-site retention

not measured for this subject — it is only defined within a family of tasks that share a corpus and differ in acquisition, and this model was not run on one.

Private held-out track

this subject was not submitted to a sealed generation.

Known limitations

Subgroup metadataabsent on 2 of 3 corpora, so the subgroup score falls back to the worst diagnostic class. That absence is a disclosure, not a pass.
Training set cappedyes on at least one task — see the raw JSON for which
Observed in deploymentnothing — see the third panel

Audit chain

Bundles re-derived48 of 48
Ledger100 entries, head 6b7b371ff650a8ed, chain intact
Re-run it yourselfpython src/heldout/audit.py 1f66c7719ab3943c6fcc
8 source files, with hashes
results/heldout/audit_report.jsondf460b6d91a6512dfa1e7dc650637fce2b4dd3a1ec32e03446bf6e11f9c597d2
results/heldout/cycle.jsone012b8978457b51b5c31d18d14d2cc92f100731897523306acae19934f943502
results/heldout/manifests/gen1.seal.json91a7adfa29870a0719125cdd48f6dcb149f1f6485ac1cfa104c6e00057ad9b81
results/heldout/manifests/gen2.seal.jsonf61470918a09cf39e074ef14fb7ade4ac3a13d36d9385f18cf9b92e4b5329547
results/heldout/manifests/public.seal.json1a4fd930d2e781ac7163483990f15d6694e28e507d1b3ca009ff09395e47497c
results/records/jobpost_fraud__pubmedbert_st_probe.jsonca302e5a92452acd2d930a3ea40a3168321ccb17714a5f47c89098f53de7ff16
results/records/ledgar__pubmedbert_st_probe.json80dc83a7b7f1cbc7c92fd69f99d5b735d830ee71daa6e4db2145e582d199f271
results/records/medabstracts__pubmedbert_st_probe.jsonee02ef05f0983a50903e862202a0c102502f1421626f80597d572f8b4acab14e
Declared by vendor

Five fields a vendor asserts about its own product — intended use, forbidden use, training cutoff, regulatory clearances, and who is personally attesting. NakedSignal never fills these in on a vendor's behalf.

No vendor declaration. This is an open reference baseline implemented by NakedSignal, not a commercial product: there is no vendor to assert an intended use or to sign an attestation, so the declared block is null rather than filled in on the vendor's behalf.

Observed in deployment

Production history and drift — how the model has actually behaved since it was deployed, on real traffic.

Not available: this requires continuous monitoring. Production history and drift are observed fields, and nothing is deployed, so there is nothing to observe. The object is present and null on purpose. The shape is the roadmap, not a claim.

Raw JSON — the whole signed document, 19,856 characters
{
 "canonicalisation": {
  "float_rounding": "every float is rounded once at emit to 6 decimal places (Python round(), banker's rounding); integers are left exact",
  "form": "RFC 8785 (JCS)-compatible: UTF-8, object keys sorted by code point, no insignificant whitespace, ECMAScript number formatting",
  "signed_over": "the whole document with the `signature` member removed, canonicalised as above and encoded UTF-8"
 },
 "computed": {
  "audit": {
   "audit_command": "python src/heldout/audit.py 1f66c7719ab3943c6fcc",
   "bundles": 48,
   "ledger_entries": 100,
   "ledger_head": "6b7b371ff650a8edaf477490f2a5f9b043433f3ba9941989ee1962ed8f1b1d88",
   "ledger_intact": true,
   "rederived": 48
  },
  "cross_site": null,
  "evaluations": [
   {
    "code_fingerprint": "b5b34c074f7f",
    "composite": {
     "coverage": 0.75,
     "dimensions_scored": [
      "accuracy",
      "calibration",
      "corruption",
      "cost",
      "limited_data",
      "subgroup",
      "uncertainty"
     ],
     "index": 75.215637
    },
    "device": "mps",
    "dimensions": {
     "accuracy": {
      "accuracy": 0.974944,
      "auc": 0.931117,
      "balanced_accuracy": 0.857824,
      "ci95": [
       0.825441,
       0.884263
      ],
      "n_test": 4470,
      "score": 71.564881
     },
     "acquisition": null,
     "calibration": {
      "accuracy": 0.974944,
      "brier": 0.042337,
      "ece": 0.009435,
      "mean_confidence": 0.982221,
      "overconfidence": 0.007277,
      "score": 95.28255
     },
     "corruption": {
      "basis": "text degradation (vocabulary drift, formatting damage, field-length truncation, register change, OCR noise)",
      "clean_reference_cc": 0.737676,
      "mean_agreement": 0.986222,
      "mean_kappa": 0.860801,
      "mean_retention": 0.931066,
      "n_cases": 1200,
      "per_perturbation": {
       "format_damage": {
        "agreement_by_severity": [
         1,
         0.995,
         0.9675
        ],
        "mean_kappa": 0.874914,
        "mean_retention": 0.939141,
        "retention_by_severity": [
         1,
         1,
         0.8174
        ],
        "scored": true
       },
       "ocr_noise": {
        "agreement_by_severity": [
         0.9908,
         0.9808,
         0.9742
        ],
        "mean_kappa": 0.81491,
        "mean_retention": 0.910899,
        "retention_by_severity": [
         0.9341,
         0.9517,
         0.847
        ],
        "scored": true
       },
       "register_change": {
        "agreement_by_severity": [
         1,
         0.9925,
         0.9858
        ],
        "mean_kappa": 0.929587,
        "mean_retention": 1,
        "retention_by_severity": [
         1,
         1,
         1
        ],
        "scored": true
       },
       "truncation": {
        "agreement_by_severity": [
         0.9825,
         0.9708,
         0.9533
        ],
        "label_survival": {
         "at_severity": [
          3
         ],
         "note": "the transform may remove the evidence the label depends on, not merely obscure it; retention at these severities is not a clean robustness measurement"
        },
        "mean_kappa": 0.684594,
        "mean_retention": 0.80529,
        "retention_by_severity": [
         0.8869,
         0.8222,
         0.7067
        ],
        "scored": true
       },
       "vocabulary_drift": {
        "agreement_by_severity": [
         1,
         1,
         1
        ],
        "mean_kappa": 1,
        "mean_retention": 1,
        "retention_by_severity": [
         1,
         1,
         1
        ],
        "scored": true
       }
      },
      "score": 93.106603,
      "worst_retention": 0.706742
     },
     "cost": {
      "basis": "measured wall-clock inference over the evaluated cases on mps; score = 2*ref/(ref+measured), capped at 100",
      "cases": 29598,
      "cases_per_second": 49.833,
      "caveat": "hardware-dependent. This number must never be quoted without the device it was measured on.",
      "device": "mps",
      "latency_reference_seconds": 0.02,
      "parameters": 109482240,
      "parameters_millions": 109.5,
      "score": 99.83278,
      "scored": true,
      "seconds_per_case": 0.020067,
      "seconds_total": 593.9397
     },
     "limited_data": {
      "full_reference_cc": 0.715649,
      "mean_retention": 0.634605,
      "per_budget": {
       "n100": {
        "chance_corrected": 0.520585,
        "n_labels": 200,
        "retention": 0.72743
       },
       "n20": {
        "chance_corrected": 0.443887,
        "n_labels": 40,
        "retention": 0.620259
       },
       "n5": {
        "chance_corrected": 0.397991,
        "n_labels": 10,
        "retention": 0.556126
       }
      },
      "score": 63.46048
     },
     "spec_sensitivity": null,
     "subgroup": {
      "attributes": {
       "country": {
        "gap": 0.380971,
        "per_group": {
         "AU": 0.85544,
         "CA": 0.612179,
         "GB": 0.912422,
         "IN": 0.993151,
         "US": 0.860056,
         "unknown": 0.69375
        },
        "worst": 0.612179
       },
       "required_education": {
        "gap": 0.194361,
        "per_group": {
         "Bachelor's Degree": 0.805639,
         "Certification": 0.987805,
         "High School or equivalent": 0.855506,
         "Master's Degree": 0.928571,
         "Professional": 1,
         "Some College Coursework Completed": 1,
         "Unspecified": 0.893808,
         "not specified": 0.848831
        },
        "worst": 0.805639
       }
      },
      "basis": "worst demographic subgroup (real metadata)",
      "has_real_metadata": true,
      "score": 22.435897,
      "worst_class_recall": 0.728111
     },
     "uncertainty": {
      "full_accuracy": 0.974944,
      "risk_coverage_auc": 0.993039,
      "score": 98.607724,
      "selective_acc_at_50": 0.993736,
      "selective_acc_at_80": 0.99189
     }
    },
    "domain": "labour",
    "kind": "text",
    "limitations": {
     "has_real_subgroup_metadata": true,
     "n_train_available": 10728,
     "notes": null,
     "subgroup_basis": "worst demographic subgroup (real metadata)",
     "train_capped": false
    },
    "modality": "Recruitment text",
    "n_classes": 2,
    "n_test": 4470,
    "runtime_s": 874.6,
    "seed": 20260727,
    "spec_version": "MedEval-1 v0.1",
    "split_origin": "no official split published; 60/15/25 train/val/test minted at the standard seed (20260727), stratified on the 4.8% positive class",
    "task": "jobpost_fraud",
    "task_name": "Fraudulent job posting detection",
    "timestamp": "2026-08-01T23:28:41+00:00"
   },
   {
    "code_fingerprint": "b5b34c074f7f",
    "composite": {
     "coverage": 0.75,
     "dimensions_scored": [
      "accuracy",
      "calibration",
      "corruption",
      "cost",
      "limited_data",
      "subgroup",
      "uncertainty"
     ],
     "index": 60.348161
    },
    "device": "mps",
    "dimensions": {
     "accuracy": {
      "accuracy": 0.741,
      "auc": 0.973659,
      "balanced_accuracy": 0.645304,
      "ci95": [
       0.633676,
       0.659625
      ],
      "n_test": 10000,
      "score": 64.172116
     },
     "acquisition": null,
     "calibration": {
      "accuracy": 0.741,
      "brier": 0.406546,
      "ece": 0.145625,
      "mean_confidence": 0.886528,
      "overconfidence": 0.145528,
      "score": 27.187558
     },
     "corruption": {
      "basis": "text degradation (vocabulary drift, formatting damage, field-length truncation, register change, OCR noise)",
      "clean_reference_cc": 0.619152,
      "mean_agreement": 0.879333,
      "mean_kappa": 0.877036,
      "mean_retention": 0.932096,
      "n_cases": 1200,
      "per_perturbation": {
       "format_damage": {
        "agreement_by_severity": [
         1,
         1,
         0.6117
        ],
        "mean_kappa": 0.868372,
        "mean_retention": 0.92206,
        "retention_by_severity": [
         1,
         1,
         0.7662
        ],
        "scored": true
       },
       "ocr_noise": {
        "agreement_by_severity": [
         1,
         0.8575,
         0.7442
        ],
        "mean_kappa": 0.864599,
        "mean_retention": 0.922336,
        "retention_by_severity": [
         1,
         0.939,
         0.828
        ],
        "scored": true
       },
       "register_change": {
        "agreement_by_severity": [
         1,
         0.94,
         0.9017
        ],
        "mean_kappa": 0.946117,
        "mean_retention": 0.996079,
        "retention_by_severity": [
         1,
         0.9973,
         0.9909
        ],
        "scored": true
       },
       "truncation": {
        "agreement_by_severity": [
         0.8417,
         0.7083,
         0.585
        ],
        "label_survival": {
         "at_severity": [
          3
         ],
         "note": "the transform may remove the evidence the label depends on, not merely obscure it; retention at these severities is not a clean robustness measurement"
        },
        "mean_kappa": 0.706095,
        "mean_retention": 0.820002,
        "retention_by_severity": [
         0.9386,
         0.8266,
         0.6947
        ],
        "scored": true
       },
       "vocabulary_drift": {
        "agreement_by_severity": [
         1,
         1,
         1
        ],
        "mean_kappa": 1,
        "mean_retention": 1,
        "retention_by_severity": [
         1,
         1,
         1
        ],
        "scored": true
       }
      },
      "score": 93.209557,
      "worst_retention": 0.69473
     },
     "cost": {
      "basis": "measured wall-clock inference over the evaluated cases on mps; score = 2*ref/(ref+measured), capped at 100",
      "cases": 32800,
      "cases_per_second": 48.704,
      "caveat": "hardware-dependent. This number must never be quoted without the device it was measured on.",
      "device": "mps",
      "latency_reference_seconds": 0.02,
      "parameters": 109482240,
      "parameters_millions": 109.5,
      "score": 98.687457,
      "scored": true,
      "seconds_per_case": 0.020532,
      "seconds_total": 673.4502
     },
     "limited_data": {
      "full_reference_cc": 0.641721,
      "mean_retention": 0.888446,
      "per_budget": {
       "n100": {
        "chance_corrected": 0.648839,
        "n_labels": 7680,
        "retention": 1
       },
       "n20": {
        "chance_corrected": 0.586942,
        "n_labels": 1960,
        "retention": 0.914637
       },
       "n5": {
        "chance_corrected": 0.481742,
        "n_labels": 500,
        "retention": 0.750703
       }
      },
      "score": 88.84465
     },
     "spec_sensitivity": null,
     "subgroup": {
      "attributes": {},
      "basis": "worst diagnostic class (no demographic metadata in source)",
      "has_real_metadata": false,
      "score": 0,
      "worst_class_recall": 0
     },
     "uncertainty": {
      "full_accuracy": 0.741,
      "risk_coverage_auc": 0.899285,
      "score": 89.826776,
      "selective_acc_at_50": 0.9282,
      "selective_acc_at_80": 0.833375
     }
    },
    "domain": "legal",
    "kind": "text",
    "limitations": {
     "has_real_subgroup_metadata": false,
     "n_train_available": 60000,
     "notes": null,
     "subgroup_basis": "worst diagnostic class (no demographic metadata in source)",
     "train_capped": true
    },
    "modality": "Legal text",
    "n_classes": 100,
    "n_test": 10000,
    "runtime_s": 1523.2,
    "seed": 20260727,
    "spec_version": "MedEval-1 v0.1",
    "split_origin": "official LexGLUE published split (train/validation/test released files, test scored whole); train capped to 12,000 by a stratified subsample at seed 20260727",
    "task": "ledgar",
    "task_name": "Contract provision type (100-class)",
    "timestamp": "2026-08-02T00:06:36+00:00"
   },
   {
    "code_fingerprint": "b5b34c074f7f",
    "composite": {
     "coverage": 0.75,
     "dimensions_scored": [
      "accuracy",
      "calibration",
      "corruption",
      "cost",
      "limited_data",
      "subgroup",
      "uncertainty"
     ],
     "index": 55.469813
    },
    "device": "mps",
    "dimensions": {
     "accuracy": {
      "accuracy": 0.569945,
      "auc": 0.863758,
      "balanced_accuracy": 0.564729,
      "ci95": [
       0.545886,
       0.585342
      ],
      "n_test": 2888,
      "score": 45.591182
     },
     "acquisition": null,
     "calibration": {
      "accuracy": 0.569945,
      "brier": 0.581687,
      "ece": 0.178738,
      "mean_confidence": 0.745223,
      "overconfidence": 0.175279,
      "score": 10.631074
     },
     "corruption": {
      "basis": "text degradation (vocabulary drift, formatting damage, field-length truncation, register change, OCR noise)",
      "clean_reference_cc": 0.462177,
      "mean_agreement": 0.926944,
      "mean_kappa": 0.905375,
      "mean_retention": 0.992616,
      "n_cases": 1200,
      "per_perturbation": {
       "format_damage": {
        "agreement_by_severity": [
         1,
         0.9575,
         0.8108
        ],
        "mean_kappa": 0.900271,
        "mean_retention": 1,
        "retention_by_severity": [
         1,
         1,
         1
        ],
        "scored": true
       },
       "ocr_noise": {
        "agreement_by_severity": [
         0.9592,
         0.9,
         0.845
        ],
        "mean_kappa": 0.872252,
        "mean_retention": 0.999646,
        "retention_by_severity": [
         0.9989,
         1,
         1
        ],
        "scored": true
       },
       "register_change": {
        "agreement_by_severity": [
         1,
         0.9517,
         0.9275
        ],
        "mean_kappa": 0.94789,
        "mean_retention": 1,
        "retention_by_severity": [
         1,
         1,
         1
        ],
        "scored": true
       },
       "truncation": {
        "agreement_by_severity": [
         0.9108,
         0.8725,
         0.8017
        ],
        "label_survival": {
         "at_severity": [
          3
         ],
         "note": "the transform may remove the evidence the label depends on, not merely obscure it; retention at these severities is not a clean robustness measurement"
        },
        "mean_kappa": 0.82049,
        "mean_retention": 0.964385,
        "retention_by_severity": [
         0.9746,
         0.9822,
         0.9363
        ],
        "scored": true
       },
       "vocabulary_drift": {
        "agreement_by_severity": [
         0.9975,
         0.9975,
         0.9725
        ],
        "mean_kappa": 0.985972,
        "mean_retention": 0.999048,
        "retention_by_severity": [
         0.9986,
         0.9986,
         1
        ],
        "scored": true
       }
      },
      "score": 99.261585,
      "worst_retention": 0.93632
     },
     "cost": {
      "basis": "measured wall-clock inference over the evaluated cases on mps; score = 2*ref/(ref+measured), capped at 100",
      "cases": 28652,
      "cases_per_second": 54.692,
      "caveat": "hardware-dependent. This number must never be quoted without the device it was measured on.",
      "device": "mps",
      "latency_reference_seconds": 0.02,
      "parameters": 109482240,
      "parameters_millions": 109.5,
      "score": 100,
      "scored": true,
      "seconds_per_case": 0.018284,
      "seconds_total": 523.8762
     },
     "limited_data": {
      "full_reference_cc": 0.455912,
      "mean_retention": 0.879558,
      "per_budget": {
       "n100": {
        "chance_corrected": 0.489779,
        "n_labels": 500,
        "retention": 1
       },
       "n20": {
        "chance_corrected": 0.400508,
        "n_labels": 100,
        "retention": 0.878476
       },
       "n5": {
        "chance_corrected": 0.346584,
        "n_labels": 25,
        "retention": 0.760199
       }
      },
      "score": 87.955836
     },
     "spec_sensitivity": null,
     "subgroup": {
      "attributes": {},
      "basis": "worst diagnostic class (no demographic metadata in source)",
      "has_real_metadata": false,
      "score": 31.856187,
      "worst_class_recall": 0.454849
     },
     "uncertainty": {
      "full_accuracy": 0.569945,
      "risk_coverage_auc": 0.691448,
      "score": 61.431044,
      "selective_acc_at_50": 0.694598,
      "selective_acc_at_80": 0.612121
     }
    },
    "domain": "medicine",
    "kind": "text",
    "limitations": {
     "has_real_subgroup_metadata": false,
     "n_train_available": 10164,
     "notes": null,
     "subgroup_basis": "worst diagnostic class (no demographic metadata in source)",
     "train_capped": false
    },
    "modality": "Clinical text",
    "n_classes": 5,
    "n_test": 2888,
    "runtime_s": 709.7,
    "seed": 20260727,
    "spec_version": "MedEval-1 v0.1",
    "split_origin": "official test split; validation carved from train (seed 20260727)",
    "task": "medabstracts",
    "task_name": "Medical abstracts (5-class condition)",
    "timestamp": "2026-08-01T23:02:15+00:00"
   }
  ],
  "heldout": null,
  "sources": [
   {
    "path": "results/heldout/audit_report.json",
    "sha256": "df460b6d91a6512dfa1e7dc650637fce2b4dd3a1ec32e03446bf6e11f9c597d2"
   },
   {
    "path": "results/heldout/cycle.json",
    "sha256": "e012b8978457b51b5c31d18d14d2cc92f100731897523306acae19934f943502"
   },
   {
    "path": "results/heldout/manifests/gen1.seal.json",
    "sha256": "91a7adfa29870a0719125cdd48f6dcb149f1f6485ac1cfa104c6e00057ad9b81"
   },
   {
    "path": "results/heldout/manifests/gen2.seal.json",
    "sha256": "f61470918a09cf39e074ef14fb7ade4ac3a13d36d9385f18cf9b92e4b5329547"
   },
   {
    "path": "results/heldout/manifests/public.seal.json",
    "sha256": "1a4fd930d2e781ac7163483990f15d6694e28e507d1b3ca009ff09395e47497c"
   },
   {
    "path": "results/records/jobpost_fraud__pubmedbert_st_probe.json",
    "sha256": "ca302e5a92452acd2d930a3ea40a3168321ccb17714a5f47c89098f53de7ff16"
   },
   {
    "path": "results/records/ledgar__pubmedbert_st_probe.json",
    "sha256": "80dc83a7b7f1cbc7c92fd69f99d5b735d830ee71daa6e4db2145e582d199f271"
   },
   {
    "path": "results/records/medabstracts__pubmedbert_st_probe.json",
    "sha256": "ee02ef05f0983a50903e862202a0c102502f1421626f80597d572f8b4acab14e"
   }
  ]
 },
 "declared": null,
 "declared_note": "No vendor declaration. This is an open reference baseline implemented by NakedSignal, not a commercial product: there is no vendor to assert an intended use or to sign an attestation, so the declared block is null rather than filled in on the vendor's behalf.",
 "expiry_basis": "the sealed held-out generation this evidence cycle is anchored to (gen2, set hash ad30d214daa285c5...) is published to expire 2026-09-20; per spec, a passport lapses when its generation retires or its spec version is superseded, whichever comes first",
 "expiry_utc": "2026-09-20T00:00:00Z",
 "issued_utc": "2026-08-03T16:03:42Z",
 "issuer": {
  "algo": "Ed25519",
  "key_id": "ns-passport-2026-07",
  "name": "NakedSignal",
  "public_key_b64": "0PBCC6mjzcppR5QdPcK7vP/AamB6MP8l1T4ypMYbsMw="
 },
 "observed": null,
 "observed_note": "Not available: this requires continuous monitoring. Production history and drift are observed fields, and nothing is deployed, so there is nothing to observe. The object is present and null on purpose. The shape is the roadmap, not a claim.",
 "passport_version": "0.1",
 "signature": "UUJXvJBni/1uV84Hk4BtkPEmEyimDTKtBtVfa5alPitv2j7QKI6Nm4J1eK0KbQ/pC4XIZ4UaSrf9lrJeiiQfAg==",
 "spec_version": "MedEval-1 v0.1",
 "subject": {
  "behaviour_version": "1.0.0",
  "code_fingerprint": "b5b34c074f7f",
  "code_fingerprints": [
   "b5b34c074f7f"
  ],
  "family": "foundation",
  "model_id": "pubmedbert_st_probe",
  "model_name": "PubMedBERT-sentence frozen + linear probe",
  "params": "109M frozen, mean-pooled 768-d, logistic head; biomedical pretraining PLUS a sentence objective"
 }
}

Canonicalisation: RFC 8785 (JCS)-compatible: UTF-8, object keys sorted by code point, no insignificant whitespace, ECMAScript number formatting. every float is rounded once at emit to 6 decimal places (Python round(), banker's rounding); integers are left exact. Signed over the whole document with the `signature` member removed, canonicalised as above and encoded UTF-8. The public key for ns-passport-2026-07 is 0PBCC6mjzcppR5QdPcK7vP/AamB6MP8l1T4ypMYbsMw= — see Governance.