Signed, deterministic, machine-verifiable compliance state per object per jurisdiction - resolved upstream, before any agent asks, and served over MCP and A2A. A buyer's agent consumes the result of the rules, not the rules.
MCP: https://mcp.rco-a2a.ai/mcp - four read tools, no auth, typed errors. A2A: /a2a on this host, the 49 jurisdiction doors and every slot agent.
Rails: rco-a2a-bpc.ai (GSC rail - 1,000 record-holding agents, 1,000 prefab GSC-class) and rco-a2a-cpg.ai (partner rail - 1,000 prefab partner-class; record-holders when an issuer signs). Counts: each rail's index.json, reported separately.
Rule sets: versioned, hashed, signed; served per jurisdiction door at /rule-sets/. The apex rule set is at /rule-sets/apex-2026.08.json.
Records: https://rco-a2a-bpc.ai/records/<record_id>.json; ledger receipts at /ledger/<record_id>.json; every record hash is written to Azure Confidential Ledger.
Specification (MIT protocol layer): schema, tool contract, rule-set schema, issuer-registry schema, signature test vectors - engineering state, no more and no less.