Governance

SignedReceipt is maintained by an independent GitHub organisation. No single vendor controls the specification.

Structure

The signedreceipt GitHub organisation holds all specification repositories. Initial maintainers are two engineers acting in personal capacity plus one external auditor from a GRC platform. Maintainer status is merit-based, not vendor-based.

Licences

ArtefactLicenceWhy
SpecificationCC-BY-4.0Attribution required; no sharealike friction for adopters.
JSON SchemasCC0Maximum reuse without attribution overhead.
Reference implementationsApache-2.0Patent grant; permissive.
Badge markCC-BY-NDPrevents modification that dilutes the conformance signal.

Contribution process

  1. Open a GitHub issue to discuss the change before writing a PR.
  2. Fork the repository, write the change, add conformance fixtures where applicable.
  3. Open a pull request; two maintainer approvals required for normative changes.
  4. Breaking format changes require a version bump to v2.

IETF Internet-Draft

Submitted as draft-cloakapi-signedreceipt-00 to SECDISPATCH. Mirrored at signedreceipt/draft-ietf.