visibility.cloud

What ships today.

Everyone in this market has built a network that is authoritative because you joined it. This platform makes a record that is verifiable whether or not you joined anything — and it carries, in the record itself, an attested answer to who observed the event, including when the observer was an agent. That sentence is also a description of this page’s method: we publish both lists, dated, so the reader does not have to trust us either.

This page exists so the landing page can be read as a description rather than as marketing. It is dated, and it is the ledger the rest of the site is checked against.

Ledger date: 6 August 2026. Live today, checkable by curl: POST epcis.dev/translate, /validate and /hash, and — with a capture key — POST api.epcis.dev/capture and GET api.epcis.dev/events. 1031/1031 spine tests pass against GS1's normative artifacts. No conformance attestation has ever been issued, and none is claimed; no customer, adoption or reference claim appears anywhere on this site. Everything this platform does beyond that list is in the right-hand column below, named.

Live and verified

  • POST epcis.dev/translate — EPCIS 1.1 / 1.2 / 2.0 XML → 2.0 JSON-LD, with a per-job fidelity report. Live; curl it
  • POST epcis.dev/validate — verdict against the sha256-pinned official GS1 EPCIS 2.0.1 schema, per-path errors. Live; curl it
  • POST epcis.dev/hash — the CBV 2.0 §8.9 event hash, GS1 Digital Link normalized, gated on OpenEPCIS reference vectors. Live; curl it
  • 1031/1031 spine tests pass; GS1's normative artifacts vendored and pinned by sha256 digest, re-checked in CI
  • EPCIS 2.0 capture and query interfaces, against the pinned official OpenAPI — hosted at api.epcis.dev since 2026-08-05, capture key required
  • Validation against the official GS1 EPCIS 2.0 JSON schema, on every capture
  • RFC 7807 errors carrying the standard's exception types
  • Gateway stamping, with caller-supplied values stripped
  • Append-only storage law, minimally scoped reads
  • An MCP door for agents, at api.epcis.dev/mcp
  • npm: npx epcis.dev and npx visibility.cloud — both published at 0.1.0, 2026-07-31

Not built yet

  • Issued capture keys — the hosted door answers a key today; issuing one to you waits on a verified sending address and a named human sender
  • The Iceberg write path (Pipelines → R2 Data Catalog) — the hosted spine writes the same rows, on the same daily partitions, straight to R2 today; the Pipelines stream that would carry them is refused by the account quota (code 1017, 20 of 20 streams used), so the cutover is a backfill behind a limit increase
  • The public repository and its clone URL — the engine is MIT-licensed and published on npm; opening the repository itself is a decision we have not taken
  • The seat-ready send path behind the waitlist promise — the list stores your row today; the mail that tells you a seat is ready waits on the same verified address and named sender
  • Traces, custody evidence packets, the exception desk — product surfaces over the tested spine reads
  • SharingGrants, seats, and the deputization ceremony
  • Identity resolution and attestation
  • Published prices — they post here as numbers when set

How to read the two columns.

The left column is behavior you can exercise now — the three doors answer over HTTPS at epcis.dev, the hosted spine answers a capture key at api.epcis.dev — plus code verified against GS1's normative artifacts, vendored and pinned by digest and re-verified in continuous integration. The repository is not open, which is itself a line in the right column, so what you can check today without us is the doors, the pins, the MIT-licensed npm package, and this page.

The right column is not built. Each line names the thing and the specific reason it is not built, and it moves to the left column the day it answers over HTTPS. Nothing is on this page as a promise about when. A claim anywhere on visibility.cloud that a right-column line already works is a defect, and it should be reported the way a defect is reported.

What this page is for.

Every claim on this site is either behavior in the left column or a limit stated inside the sentence that makes the claim. This page is the two lists in one place, dated, so a reader checking one sentence does not have to read a hundred. It is the whole of what we publish about what is and is not built.

Numbers on this site.

The rule is stronger than “no numbers”: no first-party market figure exists anywhere on this site — no adoption count, no customer count, and no performance percentage of this platform’s own, because there are no customers to count and a count you cannot check is not a fact. Every performance figure that does appear is a named third party’s, dated and linked where it is used — McDonald’s China and Cainiao’s receiving-efficiency figure as China Daily reported it, Golden State Foods’ encode rate as GS1 US published it, Chipotle’s rollout scale as RFID Journal reported it — and each stays its owner’s, never inherited as ours. The first-party numbers that remain are all checkable in kind: version numbers, standard section numbers, dates, example identifiers in figures labeled illustrative, the spine’s own test count (verified against the suite, dated), the interview instrument’s own question and ending counts (asserted by the build’s exhaustive-walk gate on every build, never remembered), and the $0-per-event capture price, which is stated as intent, not terms, until its ledger entry closes.

The standard.

visibility.cloud conforms to EPCIS 2.0 and CBV 2.0 and claims nothing above them. GS1 is the standards body; GS1 has not reviewed, certified or endorsed this platform. Sunrise 2027 is the industry's milestone and is named as the industry's.

← The landing page