The sixteen questions a careful skeptic asks first — answered short, limits included. Longer answers live in About Earned Trust and the protocol.
No. No organization examines a work and awards the mark. The author chooses to work under the Earned Trust protocol, the protocol keeps the record as the work happens and assigns the AIast disclosure from that record, and the author approves it and answers for it. What the reader gets instead of a certificate is something checkable: the disclosure, the record, and fingerprints that can be verified.
It is a compact disclosure, short for AI-assisted, naming which AI services were used and the role each performed: i ideation, d drafting, c critique, v verification, s source retrieval.
AIast3 denotes that three different AI services were involved in the writer’s workflow. What it does not indicate: that more is better, or fewer is purer. It is simply the number of services used.
Optional and self-applied: Lost Innovator — the author is publishing without the credentials their field usually treats as a license to author. It is a description, not a qualification, and it claims nothing about the worth of the work.
Identity. A matching SHA-256 or MD5 proves the file in your hands is byte-for-byte the file that was published — not altered, not swapped. Fingerprints exist to document work done with AI accurately; they are not a judgment of the work’s validity or quality.
Yes — and the standard assigns no cost to declining. No one acquires any right of access, audit, or compulsion under this standard, and a refusal implies nothing about the work. Retention is a commitment; production is a choice. The author keeps the working record (five years is the floor) and stays able to produce it; whether to open it for any particular person is the author’s decision. Four honest answers to a good-faith request are recommended practice, not a requirement: the scoped evidence, a redacted version, a reasoned refusal, or an honest “unavailable.” Unproduced claims stand unsubstantiated, not false — the reader weighs that.
This is the rule of v1.14 (the author’s production ruling of 2026-09-06; its deposit is pending). Under v1.13, the version whose deposit is current, conformance asked for a response of one of those four kinds; v1.14 makes the response recommended rather than required. The site follows v1.14.
In layers. The record card — sessions, dates, services, and roles — is public and rides inside the work’s link or QR. The seal manifest, listing the retained files and their fingerprints, is public. The working files themselves are sealed in an encrypted archive: anyone may download it and verify its fingerprint, but its contents open only when the author produces files in response to a petition.
The mark carries no authority by itself, so a dishonest mark gains nothing. It is a statement that records exist; a false statement fails the moment a reader asks to check. The records, not the mark, are what carry weight.
No. The protocol works by copy-and-paste into any AI, free tiers included, and the record can be kept by hand with plain templates. Code-capable AIs automate the folder and the sealing, and a free AI at a computer loses nothing — the computer runs the tools. The Field Notes describe what each setup can do.
Yes. The standard is CC BY 4.0 and the tools are AGPL-3.0 — no permission or fee. Nobody institutional has yet, and this site will say so until it changes (see adoption status). If you’re considering it, write: William@earnedtrust.org.
Yes, both — anyone can write any mark on any work, and anyone can mint any record link, because there is no central authority to stop them. That is by design, and it is why the mark carries no authority by itself (question 8). What a forger cannot counterfeit is the anchor chain behind an honest record: a deposit carrying a third-party DOI timestamp, a published seal manifest, and a retained record whose fingerprints match it. The QR is the doorbell, not the evidence — a swapped code produces a card that diverges from the deposited record, and anyone who follows the DOI can see it. A link with no deposit behind it is a claim and nothing more; the protocol says so in as many words.
That is what the legacy baseline is for — and it cuts both ways. Existing work is fingerprinted at intake, so the record proves, and openly displays, exactly when the receipts began; everything before that date rests on the author’s disclosure, and the mark’s duty covers the whole work, including any AI use before the record. An honest author discloses it and the record says so. A dishonest one has converted a vague, deniable omission into a dated, fingerprinted false declaration inside a record they sealed themselves. And trust earned scales with what the receipts cover: a thin record over a finished manuscript is visibly thin to anyone who reads the card.
Check the fingerprint. The kit page publishes the SHA-256 of the current kit zip; the Reader can verify your download against it in your browser. The protocol instructs any AI working under it to do the same before running kit scripts — a file’s name never authorizes its execution. The standard itself is deposited on Zenodo under a DOI, third-party timestamped and unalterable, so the genuine text survives and stays checkable even if this website someday doesn’t.
No. A downloaded zip is a frozen snapshot — the kit never phones home, holds no account, and sends nothing, by design. Current versions are always listed at version.json, and what changed in each release is at What’s new. An AI working under the protocol checks the version once per session if it can reach the web and mentions a newer release in one sentence. And because the kit cannot reach you, we recommend — never require — leaving an email address for update notices: if a serious fix ships, it is the only way we can tell you.
Yes. Updates are recommended, never required: a record made honestly under an older kit or protocol revision is a conforming record. The Working setup row pins which Field Kit and protocol version the record was made under — that is a fact about the record, like its dates, not a defect. The alternative would be an expiring credential, which is the very thing this standard exists to escape.
No — portable is not private. The record card travels inside the link itself, and anyone who holds the link or scans the QR can read it; links also land in browser histories, chat threads, and server logs wherever they go. That is why a record card carries only dates, services, and one-line synopses — never transcripts, personal data, passphrases, or unpublished material. Compression is not encryption, and the link is not an authenticated record: treat everything encoded in it as potentially public.