<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.mih-scitt-checkpointed-local-log" target="https://datatracker.ietf.org/doc/html/draft-mih-scitt-checkpointed-local-log-01">
   <front>
      <title>The Checkpointed Local Log (CLL)</title>
      <author initials="S." surname="Mih" fullname="Steven Mih">
         <organization>Action State Group</organization>
      </author>
      <date month="September" day="26" year="2026" />
      <abstract>
	 <t>   Many systems emit individually signed records — receipts,
   attestations, statements — and store them locally.  Each record
   verifies on its own, but the collection proves nothing: records can
   be deleted, reordered, or created after the fact without detection.
   This document specifies the Checkpointed Local Log (CLL): a producer-
   operated append-only log, built on the Merkle Mountain Range
   structure whose COSE proof formats are specified in
   [I-D.bryce-cose-receipts-mmr-profile], together with a small signed
   checkpoint that commits to the log&#x27;s entire history.  Records of any
   format are appended as they are produced; checkpoints are emitted on
   a declared cadence and may be registered with one or more independent
   Transparency Services or witnesses using existing SCITT registration.
   A CLL upgrades a set of point receipts into a stream with provable
   order, contemporaneity, and completeness — while defining precisely,
   and narrowly, what such a log does and does not establish.  This
   document defines the log discipline and the checkpoint structure; it
   defines no new proof formats, no transparency service behavior, and
   no payload semantics.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-mih-scitt-checkpointed-local-log-01" />
   
</reference>
