Open protocol · independent implementation

Reuse rights
and governance

LARRI is an open protocol with implementation-independent conformance. LARRI Core remains proprietary, while the LARRI Verifier is governed by the exact software license published with its source.

Effective
22 July 2026
Status
Public rights and governance statement
Contact
hello@larriverification.org

Rights at a glance

This policy separates the public protocol from commercial implementations. It also defines how technical decisions are made, how conformance is claimed, and how published rights survive changes in stewardship.

ComponentStatusPublic rights
LARRI protocol specificationsOpen specificationStudy, copy, publish, translate, adapt, and implement under CC BY 4.0, subject to attribution and change identification.
Schemas, registries, examples, and conformance materialsOpen implementation materialsUse, modify, and redistribute under Apache License 2.0 unless the individual file states another license.
LARRI CoreProprietary implementationNo Core source-code or product license is granted by the open protocol. Rights arise only under the applicable commercial agreement.
LARRI VerifierRepository-defined software statusInspection and reuse rights are governed by the exact repository license. It is described as open source only when licensed under an OSI-approved license.
LARRI names and logosProtected marksTruthful reference and compatibility statements are permitted. Use that implies certification, sponsorship, or endorsement requires authorization.

1. Purpose and scope

This policy defines reuse rights for the LARRI protocol materials and the governance rules that protect their open implementation. It also states the proprietary boundary of LARRI Core and the license boundary of the LARRI Verifier.

The policy applies to materials published through larriverification.org or an official repository identified by that website. An individual file may carry a more specific license notice. The individual notice controls for that file when it grants rights consistent with this policy.

No vendor permission, membership, certification purchase, or commercial agreement is required to implement the published LARRI protocol. Commercial agreements may govern use of LARRI Core, hosted services, support, training, or independent assessment services.

The protocol preserves a public integrity boundary while allowing proprietary decision methods to remain private. Protocol conformance does not require disclosure of internal decision mathematics, business rules, model weights, implementation architecture, or confidential operational methods.

2. Defined materials and roles

TermMeaning
Specification MaterialsOfficial normative specifications and informative protocol documentation published as LARRI materials.
Conformance MaterialsSchemas, registries, examples, test vectors, expected outputs, traceability records, and harness materials used to evaluate protocol-visible behavior.
LARRI CoreA proprietary producer-side implementation that may create LARRI receipts or related artifacts. Its commercial and technical rights are separate from rights in the protocol.
LARRI VerifierSoftware that evaluates LARRI artifacts. Its inspection, modification, redistribution, and deployment rights are controlled by the exact license stated in its repository or distribution.
Independent ImplementationSoftware created without a requirement to use LARRI Core or the published LARRI Verifier.
Official PublicationA versioned LARRI specification or contract package identified as official on larriverification.org.
LARRI StewardThe individual or entity identified on the governance page as responsible for publication authority and administration of this policy.
Technical Governance BodyThe committee or other documented body authorized to approve normative changes. During an initial stewardship period, this function may be exercised by the LARRI Steward.
MarksThe LARRI name, logos, certification marks, and other source-identifying names used by the project.

3. Reuse rights by component

3.1 Specification Materials

Except where an official file states otherwise, Specification Materials owned or controlled by the LARRI Steward are licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).

Subject to that license, a person may reproduce, publish, translate, adapt, and use the Specification Materials for commercial or noncommercial purposes. Attribution must identify LARRI and the applicable specification version. Material changes must be identified. Adapted materials must not be represented as official LARRI publications.

The license applies only to rights the licensor has authority to grant. It does not grant rights in third-party material, patents, trademarks, confidential information, or software governed by another license.

3.2 Conformance Materials

Except where an official file states otherwise, Conformance Materials are licensed under the Apache License, Version 2.0. This allows the materials to be embedded in software, test systems, and commercial implementations subject to the license terms.

Generated schemas, registries, vectors, and expected outputs may be copied into independent implementations. Modified conformance materials must be clearly distinguished from the official set. A modified set cannot be used to support an unqualified claim of official LARRI conformance.

3.3 LARRI Core

LARRI Core is proprietary software. Publication of the protocol does not grant access to its source code or a license to its binaries. It does not grant rights in its decision methods, workflow logic, models, private data structures, deployment systems, or confidential implementation material.

Rights to use LARRI Core arise only under the applicable commercial license, service agreement, or other written authorization. An independent implementation does not need LARRI Core to claim protocol conformance.

A protocol-conforming receipt may bind proprietary inputs or private decision context by cryptographic commitment. The protocol does not require disclosure of the underlying proprietary material.

3.4 LARRI Verifier

The LARRI Verifier is governed by the exact license included in its official repository or distribution. Source publication alone does not establish open-source status. The website and repository must describe the Verifier as open source only when the governing license satisfies the Open Source Definition.

The Open Source Initiative explains that open source requires more than source visibility and includes redistribution and modification rights under the applicable license.

When the Verifier is released under an OSI-approved license, users receive the rights granted by that license. When it is released under a source-review or source-available license, inspection rights and reuse limits are controlled by that license. Rights in the Verifier do not extend to LARRI Core.

Use of the published Verifier is optional. Independent verifiers may claim conformance by satisfying the same public protocol contracts and conformance requirements.

3.5 No implied endorsement or product license

A protocol license does not create a reseller relationship, partnership, agency, certification, or endorsement. A software or service provider may state truthful compatibility. It must identify the tested protocol version and claimed scope.

4. Independent implementation and conformance

LARRI conformance is based on observable protocol behavior. It does not depend on the programming language, software architecture, deployment model, business model, or use of a particular codebase.

LARRI Core, the published LARRI Verifier, and independent implementations are evaluated against the same official specifications and conformance materials for the scope claimed. No implementation receives preferred conformance status because of its relationship to the LARRI Steward.

A public conformance statement must identify the protocol version, verification target, applicable profiles, contracts digest, vector-set digest, and outcome. A claim must not exceed the evidence supporting it.

Basic implementation rights do not depend on purchasing certification. The LARRI Steward or a third party may charge for optional review, hosted testing, training, support, or certification services. Those services do not control the underlying right to implement the protocol.

5. Royalty-free patent commitment

The purpose of this section is to support implementation of the mandatory normative requirements on a royalty-free basis. It applies only to patent rights controlled by a party that has made the commitment described here.

5.1 Essential Claims

An Essential Claim is a patent claim that would necessarily be infringed by every technically compliant implementation of a mandatory normative requirement in an Official Publication, where no technically feasible non-infringing implementation of that requirement exists.

Essential Claims do not include claims directed only to optional product features, proprietary decision methods, user interfaces, analytics, deployment techniques, implementation optimizations, or combinations with technology not required for protocol conformance.

5.2 Steward commitment

For Essential Claims it controls, the LARRI Steward commits to provide a worldwide, perpetual, non-exclusive, royalty-free right to make, use, sell, offer for sale, import, and distribute a conforming implementation of the applicable Official Publication. The commitment continues for the life of the Essential Claim and survives a change in stewardship or commercial strategy.

The commitment may include a defensive-termination condition for a party that initiates patent litigation alleging that implementation of LARRI infringes a patent controlled by that party. Any defensive condition must be stated in the formal patent commitment published with this policy.

5.3 Contributor obligations

A normative contribution may be accepted only after the contributor has disclosed known patent claims that may be essential and has accepted the published contribution and patent terms. The governance record must identify any permitted exclusion before approval of the affected specification.

The LARRI project cannot grant rights in patents controlled by a third party that has not made a commitment. A known unresolved patent risk must be disclosed. The Technical Governance Body may delay publication, redesign the requirement, or publish a clear limitation.

6. LARRI names, logos, and compatibility statements

The LARRI name and associated logos identify the protocol and its governing project. The open licenses for specifications or software do not transfer ownership of the Marks.

A person may use the word LARRI truthfully to identify the protocol, cite an Official Publication, describe compatibility, report test results, or compare implementations. Such use must not imply sponsorship, certification, or endorsement that has not been granted.

A modified specification must identify its changes and use a title that distinguishes it from an Official Publication. An incompatible fork must not be presented as the official LARRI protocol.

A statement such as “LARRI conforming” must identify the tested scope or provide a link to a conformance report. A product may not use a certification logo unless it has satisfied the rules for that logo.

7. Governance principles and authority

LARRI governance exists to preserve technical coherence and implementation independence. It also protects transparent evolution of the protocol.

  • Public reasoning places normative proposals and decisions in a public workspace, except for temporarily confidential security matters.
  • Version stability makes an Official Publication immutable after release, with every semantic change receiving a new version identifier.
  • Single-source registries define every normative identifier in one authoritative registry and never reassign it to different semantics.
  • Independent conformance applies public tests and claim rules equally to affiliated and independent implementations.
  • Open implementation rights prevent governance from revoking rights already granted under an applicable public license.
  • Commercial separation prevents funding or product ownership from creating an undisclosed right to change protocol semantics.

7.1 Publication authority

The website must identify the current LARRI Steward and the members of any Technical Governance Body. It must disclose their roles and current organizational affiliations.

During an initial stewardship period, the LARRI Steward may exercise final publication authority. Decisions must still follow the public process in this policy. The formation of a committee does not alter rights already granted under published licenses.

7.2 Decision records

Each normative decision must have a public record containing the proposal, technical rationale, compatibility impact, security review, privacy review, decision outcome, and responsible approver. A dissent or unresolved concern should be recorded where material.

8. Public change process

  1. Open an issue that describes the problem and affected protocol surface.
  2. Publish exact proposed text or machine-readable changes.
  3. Identify interoperability, security, privacy, and migration effects.
  4. Provide or update conformance vectors and expected outcomes.
  5. Allow a public review period appropriate to the impact of the change.
  6. Resolve substantive objections or record why they were not accepted.
  7. Obtain approval from the authorized governance body.
  8. Publish an immutable version with its contracts digest and decision record.

Editorial corrections may use an expedited process when they do not alter accepted bytes, trust semantics, verification behavior, refusal precedence, or conformance claims. A behavior-changing change requires a version update and matching conformance materials.

An emergency security change may use an accelerated process when delay creates a material risk. The project must publish a post-decision record when responsible disclosure permits.

9. Registries and conformance materials

Authoritative registries govern protocol identifiers, schema identifiers, cryptographic suites, profiles, extensions, verification targets, refusal codes, and status values.

A registry entry must identify its status and governing specification. An identifier is never reassigned to different semantics. Deprecated entries remain documented so that historical artifacts can be interpreted safely.

Every normative requirement must map to a machine-checkable assertion, a conformance vector, or a clearly identified operational gate. Publication gates must detect duplicate requirement identifiers and unresolved registry references.

Conformance materials must be available without vendor permission. A participant may run the materials locally or incorporate them into an independent test harness under the applicable license.

10. Security reporting and suspension

Security concerns may be reported privately to hello@larriverification.org. A report should avoid real personal data, private keys, and confidential production artifacts unless a secure exchange has been arranged.

The project may temporarily withhold exploit details while a vulnerability is assessed and remediated. A coordinated disclosure record should be published when doing so no longer creates an unreasonable risk.

A conformance claim may be suspended when a defect permits unsafe acceptance, trust substitution, signature bypass, inconsistent normalized results, or unsafe artifact processing. Suspension is a protective action and must identify the affected scope.

A security fix that changes protocol behavior must follow the versioning and publication rules in this policy.

11. Contributions and intellectual-property provenance

Every contribution must be made under published contribution terms. The contributor must represent that it has authority to submit the material and grant the required rights.

The project may use a Developer Certificate of Origin, a contributor license agreement, or another public mechanism that preserves an auditable chain of rights. The selected mechanism must include patent disclosure or commitment terms for normative contributions.

The governance record must preserve authorship history and material license notices. Third-party content must be identified before incorporation. A contribution with uncertain ownership may be rejected or quarantined until its status is resolved.

12. Funding transparency and conflicts of interest

As of July 22, 2026, LARRI protocol governance, larriverification.org, LARRI Core and LARRI Verifier receive no material external funding. Accordingly, no governance or intellectual-property rights have been granted in connection with external financial support. Any future material funding and any associated governance or intellectual-property rights will be disclosed on the official LARRI protocol website.

Investment, sponsorship, purchasing activity, or service revenue does not grant an undisclosed right to alter conformance rules or restrict independent implementations.

A decision-maker must disclose a material employment, investment, patent, customer, or competitive interest related to a proposal. A person with a direct conflict may provide technical information and may be required to recuse from the final decision.

13. Appeals and interpretation disputes

A participant may request reconsideration of a governance decision by identifying a procedural defect, unresolved technical contradiction, security issue, or material new evidence. The request and resolution are public unless confidentiality is required for security or law.

Commercial disputes between implementers do not determine protocol semantics. Interpretation is based on the Official Publications, authoritative registries, machine-readable contracts, and conformance evidence.

The Technical Governance Body may publish a non-binding interpretation note when clarification is needed without changing normative behavior. A clarification that changes observable behavior requires a new version.

14. Continuity and succession

Public licenses, published patent commitments, and existing implementation rights survive a change in ownership, sponsorship, investment, or governance personnel according to their terms.

If the LARRI Steward can no longer maintain the protocol, stewardship may transfer to a neutral successor. The transfer should preserve the public archive, version history, registries, conformance materials, security records, and existing rights.

The website should maintain exportable copies of official publications and governance records so that the protocol does not depend on a single hosted platform.

15. Enforcement, warranties, and policy updates

15.1 Compliance with licenses and marks

Reuse is governed by the applicable license. A person who uses the Marks or makes a conformance claim must follow this policy and any published mark rules. The LARRI Steward may request correction of a misleading claim before pursuing other remedies.

15.2 No warranty

Except where applicable law requires otherwise, materials are provided without warranties. A protocol specification does not guarantee that an implementation is secure, fit for a particular purpose, legally sufficient, or compliant with a regulated use case.

15.3 Policy updates

This policy may be updated through the public governance process. An update does not revoke rights already granted under an applicable public license or patent commitment. A material change must identify its effective date and provide a public decision record.

16. Contact

Questions concerning reuse rights, licensing, governance, conformance claims, security reports, or contribution terms may be sent to hello@larriverification.org.

Appendix A. Permitted public statements

The following examples illustrate appropriate public descriptions. They do not replace the governing licenses or conformance requirements.

Use caseExample statement
Open protocol“This product implements LARRI Protocol 0.1.0.”
Scoped conformance“This verifier passed the published LARRI 0.1.0 conformance suite for the receipt target under the identified contracts digest.”
Independent implementation“This implementation was independently engineered and does not require LARRI Core.”
Proprietary Core“LARRI Core is proprietary software that produces LARRI-compatible artifacts under its commercial license.”
Verifier status“The LARRI Verifier source is available under the license stated in its repository.”
Modified materials“Based on LARRI materials licensed under CC BY 4.0. Changes are identified. This is not an official LARRI publication.”

Appendix B. Publication checklist

  • Every official file carries an unambiguous license notice.
  • The website distinguishes open source from source-available software.
  • The LARRI Core proprietary notice appears beside public protocol rights.
  • The Verifier repository contains the exact governing license.
  • The current Steward and decision authority are publicly identified.
  • Normative proposals and decisions have public records.
  • Patent disclosures and contributor commitments are recorded before approval.
  • Official publications are immutable and content-addressed.
  • Registries do not reuse identifiers for different semantics.
  • Conformance materials are publicly downloadable without permission.
  • Mark usage and compatibility statements identify the tested scope.
  • Security and governance inquiries sent to hello@larriverification.org are monitored.

LARRI Verification