Aggregation-Only Contract (AOC) Invariants

Scope. The Aggregation-Only Contract is the rule that Stella Ops ingestion and verification services aggregate, validate, and verify evidence without ever making severity or policy decisions. This page is the authoritative checklist of the invariants every AOC-bound component must uphold, plus the Attestor-specific verification contract. It is written for implementers of ingestion/verification surfaces and for auditors verifying that those guarantees hold.

Audience & related reading. Start from the security index. The raw-ingestion guard (aoc:verify) lives on Concelier/Excititor; the verification report contract lives in the Attestor module dossier (../modules/attestor/architecture.md).

Last updated: 2026-05-30 (reconciled against src/Attestor).

Core invariants (all components)

Attestor-specific invariants

Guardrails for implementers

Pending / not-yet-implemented (forward-looking — verify before relying on these)

Audit checklist