Documentation · Core concepts
Three entities and one protected relationship
Endpoints own protected meaning, Stations carry opaque data, and a Network supplies an interoperability context without becoming a trust root.
Endpoint
A user-controlled origin or destination of protected communication. Each independently key-holding device or isolated runtime is a separate Endpoint with independent keys and sessions. An Endpoint alone controls its plaintext, protected state, peer acceptance, local approval, effects, and authenticated confirmations.
Station
An independently operated intermediary with only the transport authority granted by the pinned Protocol Line. Endpoints treat it as untrusted. A Station has no user or device roster and cannot decide identity, trust, freshness, confirmation, or finality.
Network
A federation interoperability context whose participants recognize communication under one pinned Protocol Line. It is neither a trust root nor an Endpoint authority.
Endpoint A ── protected exchange ──▶
Network { untrusted Stations } ──▶ Endpoint BGroup is an object
A Group is a protected, versioned collaboration object whose members are Endpoints. It does not introduce a fourth domain entity, and neither Station state nor product permissions can authorize Group state.
Keep the claims separate
Protocol definition, source-integrity verification, publication, implementation, interoperability, audit, deployment, support, and operation advance independently. A complete definition does not imply any of the downstream claims.