The glossary
The words VeraTrace uses carry precise meanings, and several are close enough to be mistaken for one another. This page gives the authoritative definition, states what separates neighbouring notions, and points at the code that implements them.
These definitions are also published in RDF, identically, for agents and engines: https://veratrace.xyz/ontology
Proof
What VeraTrace means by proving, and the objects that carry that proof.
- ProofAt VeraTrace a proof is not a claim of trustworthiness but a replayable chain: a record, its hash, a signature verifiable against a published key, and the inclusion of that hash in an anchored batch. Every link can be re-checked without asking us. Accurate but unsigned data is not a proof in this vocabulary; it is a statement.
- AttestationEd25519-signed record freezing a dated business fact — a batch genealogy, a HACCP reading, a carbon footprint, a recall. It carries the hash of a canonical payload, the reference of its signer, and its anchoring state. About forty types exist, from `genealogy` to `haccp_ccp`.
- AnchoringPublication of an attestation batch’s Merkle root on a ledger we do not control. That is what makes precedence assertable: without anchoring, a signature only proves that a key holder signed, not that they did so before today. The anchor driver is pluggable — a local driver exists so the stack runs offline, and it anchors nothing in the above sense.
- Merkle rootSingle hash summarising an entire attestation batch. Anchoring that one value is enough to make every attestation in the batch verifiable through a short inclusion path — which is what allows thousands of facts to be anchored for the cost of one.
- PassportPublic, readable view of a batch: its origin, its journey, its certifications and the attached proofs. A passport creates no data — it makes already-signed data consultable. Three variants coexist: the consumer passport reached by QR, the Digital Product Passport in the ESPR sense, and the business-to-business delivery passport.
- Delivery passportSigned document a wholesaler hands to its buyer for one delivery: the batches involved, their origins and certifications, and the cold-chain span. It carries an Ed25519 envelope that makes it assertable without the buyer having to trust the seller.
- Delivery receiptCounterpart to the delivery passport, signed this time by the buyer: what was actually received, in what condition, and any reservations. That counter-signature is what turns a seller’s claim into a bilateral fact.
- Traceability proofCryptographic block attached to a traceability record: hash of the content, Ed25519 signature of the issuer, and where applicable the anchoring reference. It lets the verification be replayed without trusting whoever presents the record.
- has proofAttaches a traceability proof to the entity it seals.
- content hashHash of the signed content, computed over a canonical form of the document. Recomputing it against the presented data is the first of the two checks; if it differs, the data has moved since it was signed.
- signatureEd25519 signature over the hash, base64-encoded.
- public keyPublic key the signature verifies against. Published so that verification does not depend on us.
- signed atTimestamp of the signature, as declared by the issuer. Not to be confused with `vrt:anchoredAt`: only anchoring makes precedence assertable against a third party.
- anchored atTimestamp at which the attestation batch containing this proof was anchored.
- transaction hashIdentifier of the transaction carrying the batch Merkle root, on whichever chain was used.
- block numberNumber of the block containing the anchoring transaction.
- explorer URLAddress of a chain explorer where the anchoring transaction can be inspected by a third party.
Scores
Four measures coexist and do not say the same thing. Conflating them is the most common mistake.
- Trust IndexScore from 0 to 100 qualifying an ACTOR, aggregated from its verifiable proofs: anchored attestations 30 %, certifications 27 %, HACCP audits 18 %, carbon transparency 15 %, B2B endorsements 10 %. Recomputed on demand — freshness is what makes it credible. Tiers: platinum ≥ 85, gold ≥ 70, silver ≥ 50, bronze ≥ 25, otherwise unrated.
- Transparency scoreScore from 0 to 100 measuring what a producer DISCLOSES, not how good they are: profile completeness 20 %, lots signed over twelve months 30 %, valid certifications 30 %, recency of activity 20 %. An impeccable but silent producer scores low — by design, since the measure is about disclosure.
- Proof score (discovery)RANKING score computed from the already-loaded fields of a listing, so a result list can be ordered without one store read per entity. It shares the tier scale of the other scores but not their inputs: for the same listing it may differ from the transparency score. The list badge is therefore labelled « proof », never « transparency ».
- Trust capitalPer-owner aggregate of the signed attestations they have accumulated: a volume, not a grade. Where the Trust Index weights and normalises to a hundred, trust capital counts what has been produced and surfaces it inside its owner’s workspace.
Entities
The objects the platform models: the batch, the listing, the parcel, the market.
- BatchThe pivot unit of traceability: a quantity of product from one production run, carrying an origin, dates, a current holder and possibly a parent batch. Attestations, passports and scans attach to the batch — not to the generic product.
- Register listingFactual page describing a food-chain business, built exclusively from public sources (SIRENE, BAN, RNE, BODACC, OpenStreetMap, eAmbrosia) and stating those sources. A listing exists without the company’s agreement; it becomes claimed when its legal representative asserts it, which alone unlocks owner-supplied content.
- Land parcelCultivated parcel described by its WGS84 geometry, area, commune and declared crop, tied to the French Registre Parcellaire Graphique. Basis for deforestation checks and per-campaign crop rotations.
- National wholesale marketFrench wholesale market holding the « marché d’intérêt national » status — nineteen exist. Each carries its operator, its product categories and its partnership tier, and acts as the entry point to the directory of wholesalers operating there.
- Trade workspacePer-trade rendering of the application — baker, winemaker, wholesaler, canteen, territory… Twenty trade workspaces exist, each with its own vocabulary, screens and pricing. A workspace is not a permission role: it is the vantage point from which the same traceability data is presented.
- ScanConsultation of a passport from the field — QR, social link, search or direct access. Recorded without identifying the person: segment, source, device, country. Feeds usage measurement and recall alerting, never individual profiling.
- Product recallWithdrawal or recall published by an authority or an operator, matched against our batches at four decreasing levels of certainty: exact GTIN, exact batch number, product and supplier, product alone. The level reached is exposed — a product-name-only match does not carry the weight of a GTIN match.
Identifiers
Keys from public registers or GS1 standards, and what each one designates exactly.
- SIRETFourteen-digit SIRET number identifying a French establishment. It is the universal join key across our public sources; the Data Food Consortium ontology has no equivalent term.
- legal formLegal form of the company, in the INSEE nomenclature.
- certified byBody that issued the certification. The Data Food Consortium ontology describes the certification but not its issuer.
- valid untilExpiry date of the certification.
- SIRENNine-digit SIREN number identifying a French company — the first nine digits of each of its SIRET numbers. It designates the legal entity where SIRET designates the establishment.
- GTINGS1 identifier of a trade item, the one the barcode carries. It designates a product TYPE, never an instance nor a batch — two pallets of the same yoghurt share a GTIN and nothing else.
- GLNGS1 identifier of a location or party. Provided at the producer’s initiative, it lets a partner recognise them inside an EDI message without going through their legal name.
- SSCCGS1 identifier of a logistic unit — pallet, case, roll cage. Unlike a GTIN it designates a unique instance, which makes it the natural key for shipment tracking.
- NAF/APE codePrincipal-activity code assigned by INSEE. It states what the company declared doing at registration, not what it does today: which is why our classifiers cross NAF with the trade name rather than trusting it alone.
- INSEE commune codeFive-character INSEE code of the commune. Preferred over the postcode for any territorial reasoning: one postcode can span several communes and one commune can hold several postcodes.
- health markEuropean health identification mark carried by an establishment approved for products of animal origin under regulation EC 853/2004. It attests to a current approval, not to a quality level.
- official facetTrue when the referenced concept comes from the official Data Food Consortium taxonomy, false when it is a provisional identifier we minted for want of an upstream concept. Exposing this boolean is what stops a consumer from mistaking our stopgap for a shared reference.
Stances
Product decisions no reading of the site would reveal, and which explain certain absences.
- Showcase, not marketplaceVeraTrace exposes neither prices nor a cart on its public discovery surfaces, and intermediates no transaction. This is not a missing feature but a stance: the showcase is a showcase of proof, and putting a price on it would turn proof-based ranking into disguised commercial ranking.
- Declared dataData asserted by an actor about themselves or their products. Publishable as-is because it commits its author, but never presented as verified: telling it apart from observed data is what stops the platform from laundering a claim by republishing it.
- Derived dataData the platform infers from real exchanges — for instance a point of sale inferred from a delivery passport followed by a receipt. Publishing an inference exposes two parties who did not consent jointly, which is why it stays subject to double consent.
- Double consentRule that a commercial relationship between two actors is publishable only if BOTH consent. The sender’s consent alone is not enough: making « X supplies Y » public reveals as much about Y as about X, and Y signed nothing.