Source Registry
Registry version 0.1 — verified 2 August 2026
This registry tracks the sources behind Foundation claims. A working URL is not sufficient: editors must also verify that the source supports the specific statement being made.
Source policy
Section titled “Source policy”ANUKA Foundation documents should prefer sources in this order:
- enacted law, official regulator guidance, or an adopted technical standard;
- official documentation maintained by the protocol or project;
- primary research or an original framework;
- first-party operating documentation;
- high-quality secondary analysis when no primary source is available.
Sources must not be cited merely because they agree with a desired conclusion.
Validation states
Section titled “Validation states”- Normative baseline — suitable as the current Foundation baseline.
- Implementation reference — useful for design or integration, but not a universal standard.
- Conceptual influence — informs ANUKA language or architecture without being adopted wholesale.
- Legal watch — authoritative or official, but implementation requires current qualified legal review.
- Tracking — useful emerging work that is not yet the stable baseline.
Network, organization, and delivery
Section titled “Network, organization, and delivery”The Network State
Section titled “The Network State”- Publisher: The Network State
- URL: thenetworkstate.com
- State: Conceptual influence
- Used for: The idea of a highly aligned online community capable of collective action and the phrase “network state.”
- ANUKA boundary: ANUKA uses Network State as a design horizon and does not claim present sovereignty, diplomatic recognition, citizenship authority, or territorial status.
- Checked: 2 August 2026
Manifesto for Agile Software Development
Section titled “Manifesto for Agile Software Development”- Publisher: Original Agile Manifesto authors
- URL: agilemanifesto.org
- State: Conceptual influence
- Used for: Value-pair structure, collaboration, working outcomes, and response to change.
- License note: The declaration may be copied only in its entirety under the notice on the source site; ANUKA uses an original manifesto rather than reproducing it.
- Checked: 2 August 2026
Principles behind the Agile Manifesto
Section titled “Principles behind the Agile Manifesto”- Publisher: Original Agile Manifesto authors
- URL: agilemanifesto.org/principles
- State: Conceptual influence
- Used for: Continuous delivery, motivated individuals, technical excellence, simplicity, self-organizing teams, and regular adaptation.
- Checked: 2 August 2026
The Scrum Guide
Section titled “The Scrum Guide”- Authors: Ken Schwaber and Jeff Sutherland
- URL: scrumguides.org/download.html
- Current official version shown: November 2020
- State: Conceptual influence
- Used for: Empiricism, transparency, inspection, adaptation, accountabilities, and bounded goals.
- ANUKA boundary: Scrum is not mandatory for resident products.
- Checked: 2 August 2026
Normative language and open standards
Section titled “Normative language and open standards”BCP 14 — RFC 2119 and RFC 8174
Section titled “BCP 14 — RFC 2119 and RFC 8174”- Publisher: IETF / RFC Editor
- URL: rfc-editor.org/info/bcp14
- State: Normative baseline
- Used for: Meanings of uppercase MUST, MUST NOT, SHOULD, SHOULD NOT, MAY, and related requirement words.
- Version note: RFC 8174 clarifies that the special meanings apply only when the terms appear in uppercase.
- Checked: 2 August 2026
The Open Source Definition
Section titled “The Open Source Definition”- Publisher: Open Source Initiative
- URL: opensource.org/osd
- State: Normative baseline
- Used for: Whether software may accurately be described as open source.
- ANUKA rule: Source-available software must not be called open source unless its license satisfies the Open Source Definition.
- Checked: 2 August 2026
OSI Approved Licenses
Section titled “OSI Approved Licenses”- Publisher: Open Source Initiative
- URL: opensource.org/licenses
- State: Normative baseline
- Used for: License selection and validation for open-source software.
- Checked: 2 August 2026
Apache License 2.0
Section titled “Apache License 2.0”- Publisher: Apache Software Foundation
- Canonical URL: apache.org/licenses/LICENSE-2.0
- SPDX identifier:
Apache-2.0 - State: Normative licensing option
- Used for: A permissive software license including an express patent grant and notice obligations.
- ANUKA note: License selection remains repository-specific; this registry does not itself apply the license.
- Checked: 2 August 2026
Creative Commons Attribution 4.0 International
Section titled “Creative Commons Attribution 4.0 International”- Publisher: Creative Commons
- Canonical URL: creativecommons.org/licenses/by/4.0
- Legal code: creativecommons.org/licenses/by/4.0/legalcode.en
- SPDX identifier:
CC-BY-4.0 - State: Normative documentation-license option
- Used for: Sharing and adapting documentation with attribution.
- ANUKA note: Creative Commons licenses are generally intended for content, not software; trademarks, patents, privacy, and publicity rights are not granted by CC BY 4.0.
- Checked: 2 August 2026
Identity, credentials, and attestations
Section titled “Identity, credentials, and attestations”W3C Verifiable Credentials Data Model v2.0
Section titled “W3C Verifiable Credentials Data Model v2.0”- Publisher: World Wide Web Consortium
- URL: w3.org/TR/vc-data-model-2.0
- Status: W3C Recommendation, 15 May 2025
- State: Normative baseline
- Used for: Issuer–holder–verifier roles, credential data model, privacy and security considerations, credential status, and machine-verifiable presentations.
- Important limitation: Cryptographic verifiability does not by itself prove the truth of a claim or the trustworthiness of its issuer.
- Checked: 2 August 2026
W3C Verifiable Credentials Data Model v2.1
Section titled “W3C Verifiable Credentials Data Model v2.1”- Publisher: World Wide Web Consortium
- URL: w3.org/TR/vc-data-model/all
- Status observed: Working Draft, 11 May 2026
- State: Tracking
- Used for: Monitoring changes beyond the v2.0 Recommendation.
- ANUKA baseline: v2.0 remains the implementation baseline until a later Recommendation is deliberately adopted.
- Checked: 2 August 2026
W3C Verifiable Credentials JSON Schema
Section titled “W3C Verifiable Credentials JSON Schema”- Publisher: World Wide Web Consortium
- URL: w3.org/TR/vc-json-schema
- State: Implementation reference
- Used for: Expressing credential-schema validation and semantic interoperability.
- Checked: 2 August 2026
W3C Decentralized Identifiers v1.0
Section titled “W3C Decentralized Identifiers v1.0”- Publisher: World Wide Web Consortium
- URL: w3.org/TR/did-core
- Status: W3C Recommendation, 19 July 2022
- State: Normative baseline candidate
- Used for: Portable identifier syntax, DID documents, verification methods, and service endpoints.
- Important limitation: A DID method must be evaluated independently for security, privacy, governance, persistence, cost, and operational maturity.
- Checked: 2 August 2026
W3C Decentralized Identifiers v1.1
Section titled “W3C Decentralized Identifiers v1.1”- Publisher: World Wide Web Consortium
- URL: w3.org/TR/did-core/all
- Status observed: Candidate Recommendation Snapshot, 5 March 2026
- State: Tracking
- ANUKA baseline: DID Core v1.0 until a newer Recommendation is deliberately adopted.
- Checked: 2 August 2026
Ethereum Attestation Service — Attestations
Section titled “Ethereum Attestation Service — Attestations”- Publisher: Ethereum Attestation Service
- URL: docs.attest.org/core concepts/attestations
- State: Implementation reference
- Used for: Signed structured claims, attesters, recipients, schemas, revocation, expiration, references, and onchain/offchain records.
- Important limitation: EAS documentation states that credibility depends on the entity making the attestation.
- Checked: 2 August 2026
Ethereum Attestation Service — Schemas
Section titled “Ethereum Attestation Service — Schemas”- Publisher: Ethereum Attestation Service
- URL: docs.attest.org/core concepts/schemas
- State: Implementation reference
- Used for: Modular, reusable, version-aware structures for attestations.
- Design note: EAS recommends concise, descriptive, non-redundant, extensible schemas and community coordination before creating duplicates.
- Checked: 2 August 2026
Ethereum Attestation Service — FAQ
Section titled “Ethereum Attestation Service — FAQ”- Publisher: Ethereum Attestation Service
- URL: docs.attest.org/quick start/faqs
- State: Implementation reference
- Used for: Confirmation that EAS describes itself as open-source, permissionless, tokenless, and capable of onchain and offchain attestations.
- Checked: 2 August 2026
Ethereum Attestation Service — GraphQL API
Section titled “Ethereum Attestation Service — GraphQL API”- Publisher: Ethereum Attestation Service
- URL: docs.attest.org/developer-tools/api
- State: Implementation reference
- Used for: Querying public attestation and schema data across supported networks.
- Operational note: Public endpoints, chain support, availability, indexing behavior, and rate limits must be rechecked before production integration.
- Checked: 2 August 2026
AI, safety, privacy, and quality
Section titled “AI, safety, privacy, and quality”NIST Artificial Intelligence Risk Management Framework 1.0
Section titled “NIST Artificial Intelligence Risk Management Framework 1.0”- Publisher: U.S. National Institute of Standards and Technology
- URL: nist.gov/itl/ai-risk-management-framework
- Publication: NIST AI 100-1, 26 January 2023
- State: Normative risk-management baseline
- Used for: Trustworthy and responsible AI characteristics and the Govern, Map, Measure, Manage lifecycle.
- Current-status note: NIST states that AI RMF 1.0 is being revised; ANUKA must track the revision before ratifying implementation requirements.
- Checked: 2 August 2026
NIST Generative AI Profile
Section titled “NIST Generative AI Profile”- Publisher: U.S. National Institute of Standards and Technology
- URL: nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
- Publication: NIST AI 600-1, 26 July 2024; page updated 8 April 2026
- State: Normative risk-management reference
- Used for: Generative-AI-specific risks and actions aligned to AI RMF 1.0.
- Checked: 2 August 2026
NIST Privacy Framework
Section titled “NIST Privacy Framework”- Publisher: U.S. National Institute of Standards and Technology
- URL: nist.gov/privacy-framework
- State: Normative privacy-risk reference
- Used for: Privacy risk management across products, organizations, and data lifecycles.
- Version note: The hub contains v1.0 resources and ongoing v1.1 work; the exact implementation baseline must be recorded in each architecture decision.
- Checked: 2 August 2026
FTC Policy Statement Regarding Advertising Substantiation
Section titled “FTC Policy Statement Regarding Advertising Substantiation”- Publisher: U.S. Federal Trade Commission
- URL: ftc.gov advertising substantiation policy
- State: Legal watch
- Used for: The principle that objective advertising claims require a reasonable basis before dissemination.
- ANUKA implication: “Verified,” “quality,” “growth,” and performance claims must state what was verified and possess appropriate prior support.
- Checked: 2 August 2026
Work, compensation, and legal boundaries
Section titled “Work, compensation, and legal boundaries”IRS — Independent contractor or employee
Section titled “IRS — Independent contractor or employee”- Publisher: U.S. Internal Revenue Service
- URL: irs.gov independent contractor or employee
- State: Legal watch
- Used for: Federal tax classification factors: behavioral control, financial control, and type of relationship.
- Important limitation: No product label or single factor determines classification; the whole relationship must be evaluated.
- Checked: 2 August 2026
IRS Topic 762
Section titled “IRS Topic 762”- Publisher: U.S. Internal Revenue Service
- URL: irs.gov/taxtopics/tc762
- Page update observed: 5 September 2025
- State: Legal watch
- Used for: Concise current explanation of employee and independent-contractor analysis for federal employment tax.
- Checked: 2 August 2026
IRS Publication 15-A (2026)
Section titled “IRS Publication 15-A (2026)”- Publisher: U.S. Internal Revenue Service
- URL: irs.gov/publications/p15a
- State: Legal watch
- Used for: Current federal employer guidance and detailed worker-classification examples.
- Checked: 2 August 2026
SEC — CorpFin Crypto Assets
Section titled “SEC — CorpFin Crypto Assets”- Publisher: U.S. Securities and Exchange Commission, Division of Corporation Finance
- URL: sec.gov CorpFin Crypto Assets
- Page update observed: 28 January 2026
- State: Legal watch
- Used for: Index of current SEC staff statements and no-action materials concerning crypto assets.
- Important limitation: Staff statements may be nonbinding, fact-specific, superseded, or incomplete. They are not a substitute for securities counsel.
- Checked: 2 August 2026
SEC Statement on Tokenized Securities
Section titled “SEC Statement on Tokenized Securities”- Publisher: SEC Divisions of Corporation Finance, Investment Management, and Trading and Markets
- URL: sec.gov statement on tokenized securities
- Date: 28 January 2026
- State: Legal watch
- Used for: The point that tokenizing a financial instrument does not remove its underlying legal character as a security.
- Checked: 2 August 2026
Review procedure
Section titled “Review procedure”For every document release:
- open every cited URL;
- confirm publisher and document status;
- confirm that the exact claim is supported;
- record the verification date;
- prefer a stable canonical URL;
- identify working drafts and nonbinding guidance explicitly;
- flag legal claims for qualified review;
- update or supersede sources that materially change.
Automated link checking should supplement, not replace, this review.
Known follow-up research
Section titled “Known follow-up research”The following topics require dedicated source packs before implementation:
- U.S. state-by-state worker, marketplace, privacy, and money-transmission requirements;
- sanctions, identity verification, tax reporting, and cross-border payments;
- securities analysis for equity, revenue share, tokenized rights, and feature funding;
- certification-mark and trademark governance;
- accessibility standards and testing policy;
- cybersecurity baseline and software supply-chain requirements;
- dispute resolution, arbitration, and platform liability;
- investor data-room and broker-dealer boundaries;
- identity recovery, guardianship, and key rotation.
Registry maintenance
- Last manual validation: 2 August 2026
- Next scheduled review: Before Foundation v0.9 ratification or within 90 days, whichever comes first
- Maintainer status: Founding draft