A receipt has a face.
Two marks for the surfaces where Sable has to show something it deliberately does not hold. The sigil is a pure function of a receipt's own hash — nothing is random and nothing is awarded, so the same receipt always draws the same mark and a changed hash draws a different one. The sealed view proves an object exists, has a shape, a size and a moment, while revealing nothing of its contents.
Every mark below is a sha256 digest, drawn.
The phase of the eclipse, how deep the bite cuts, and every tick around the ring come off the bits of the hash. What does not vary is the construction: a solid body on a one-cell dial, in one palette, in one frame — which is what makes a wall of them read as one system rather than as a pile of avatars.
Same hash, same mark. One nibble, and it is a different mark.
The left pair is the same digest rendered twice, from two separate calls. The right is that digest with its final character changed from 7 to f — one nibble, at the far end of the string, nowhere near the bytes the mark reads first. Every part of the figure moves, because the whole digest is folded into the seed. Without that, two receipts sharing a prefix would draw the same face.
From a table row to a poster.
Whole cells, crisp edges, no anti-aliasing to smear. The body is what survives at 24px, where it still reads as a phase of the moon; the ring is what you compare at 96px and up.
Loud beside a heading, quiet beside a line of text.
The same figure at two ink weights — not two figures. A fingerprint that redrew itself to suit its surroundings would not be a fingerprint, so quiet lightens the mark and changes nothing about it.
Paste a hash. It has exactly one mark.
- Hex digits
- 64
- Phase
- 14/16 turn
- Body
- 80 cells
- Ring code
- 36/68 lit
Non-hex characters are ignored, so a receipt id pasted with its prefix still resolves. A sigil is a lossy fingerprint over a finite grid: it makes a change obvious at a glance, it is not a commitment, and it is never a substitute for verifying the signature.
The same object, sealed and open.
One panel, two states. Every register along the foot is identical either way — the size, the fingerprint, the moment it was sealed — because those are the parts that were always true. Only the body changes.
The blocks are a deterministic shape derived from the size and the fingerprint. They are not the bytes, and nothing about them leaks the bytes — the commitment is public from the moment it is made, the text is not.
Open-weight models will clear 90% of frontier benchmark parity before the end of Q3. Committed 2026-09-13. Revealed on schedule.
After the reveal, anyone holding the text and the salt recomputes the commitment themselves. The panel is the same object; it did not become trustworthy by opening.
- A pure function of the hex it is given: no clock, no randomness, no state, so it draws the same on a server and in a browser.
- Two registers. The body is an eclipse — a disc minus an offset disc, the house mark's own construction — and carries the phase. The ring is a code read straight off the hash bits, and carries the detail.
- Derived from the whole input, so a change anywhere redraws the whole figure.
- Not a commitment. The grid is finite, so the mapping is lossy; two different hashes can in principle land on the same figure.
- Not verification. It is a seal you can recognise, not proof you can check — the signature is the proof, and it verifies at /verify.
- Not content. Neither mark ever reads a prompt, a completion, or a file; a sealed panel is drawn from a size and a fingerprint alone.