Field definitions, proof levels, gap model, and verification rules. This page is technical reference, not the marketing path.
A VPEC describes who ran what, against which declared controls, on which committed artifacts, with what proof level and what gaps. It is meant to leave the originating system and remain useful to another party later.
Content-blindness is the load-bearing property. It is what lets a VPEC travel to an auditor, regulator, reinsurer, or downstream team without turning the credential into a data spill.
When a stronger proof path is available, Poseidon2 commitments are ZK-friendly. When ordinary SHA-256 is the right engineering choice, the credential should still be explicit about the resulting proof level.
The floor is the weakest link. The surface is the distribution. A run can be mostly Mathematical and still have an Attestation floor because one important step was opaque. A good credential carries both instead of hiding the weak segment.
If part of the declared workflow was not instrumented, not reviewable, or not provable end to end, the credential should say so by code, scope, and reason.
A VPEC should not depend on a live SaaS screen to be meaningful. Signature material, timestamps, and public verification records are what let another party review the artifact after it has left the issuing system.
Verification is the reason the format matters. If the artifact cannot be checked later, the spec is only a serialization detail. If it can, the artifact becomes evidence another party can test.