# Glossary AOC - Aggregation-Only Contract. Ingestion stores raw facts without derived verdicts. CAS - Content-addressed storage. Artifacts are addressed by digest. Decision Capsule - Signed bundle of inputs, outputs, and evidence for a decision. DPoP - Proof of possession for sender-constrained tokens. DSSE - Dead Simple Signing Envelope. Binds payload and type. OpTok - Short-lived operational token issued by Authority. PoE - Proof of Entitlement used by Signer to enforce licensing. Reachability - Evidence of whether vulnerable code is reachable from entrypoints. Rekor - Transparency log for signed artifacts. SBOM - Software Bill of Materials. VEX - Vulnerability Exploitability eXchange. Unknowns - Explicit records for missing or ambiguous evidence.