The full provenance record — the intellectual lineage, the institutional history, and the documentary chain from 1985 to the present — is set out at length in the unabridged edition and in the Conceptual Provenance document. What follows is only what a reader assessing the architecture needs.
The patent position. Priority for the present architecture was established by provisional 62/309,153, filed 16 March 2016, carried forward through an unbroken chain of continuations into application 17/321,700. The foundational patent, US 12,316,610 B1, Privacy Network and Unified Trust Model for Privacy-Preserving Computation and Policy Enforcement, was granted 27 May 2025: nineteen claims, five of them independent, on a hundred and fifty-seven sheets of drawings, with named inventors Richard Arthur Muth and Jonathan Paul Hare. The portfolio now comprises nine filings; six of them, covering 2,071 claims, are publicly reviewable, with three held as trade secrets and made available under conventional mutual non-disclosure terms until Paris Convention deadlines require foreign-filing conversion. The public index is maintained at webshield.io/patents.
The granted specification contains, in the vocabulary of 2016, a great deal of what this document formalizes: Privacy Domains as compliance perimeters, Privacy Pipes between them, Trust Criteria cryptographically bound to resources to form Trust Blocks, inheritance of those criteria by every aggregate and derivative through a Proof of Trust chain, a Unified Trust Model that reconciles nothing and lets incompatible regimes coexist, and — in the passages on syndication — revenue splitting among contributors, founding members receiving ongoing revenue shares in exchange for contributing the resources that establish critical mass, and crypto-derivatives allocated by smart contract. The Exchange Root, the contribution graph and the QPT Derivative are visible there in outline, filed before any of them had a name.
The deployment record. A trust network went into production in Salt Lake City in November 2008. Between 2014 and 2016 a production deployment, funded by two of its participants as a proof of concept, connected Aetna, Experian Health, LexisNexis and the Internal Revenue Service into a single person-centered network. Their participation was public at the time and the deployment is now a decade old, which is why they are named. Its object was a requirement counsel on every side had said could not lawfully be met: the Affordable Care Act obliged insurers to report coverage using the Social Security number as the primary key, which appeared to require exposing identifiers across parties governed by four incompatible regimes at once — HIPAA, Gramm–Leach–Bliley, the Driver's Privacy Protection Act, and section 6103 of the Internal Revenue Code. It was met, with no party revealing anything to any other.
What that deployment was, and was not. It was called the Privacy Network; the quantum vocabulary came later, and so did most of the architecture. Measured against what this document describes it was primitive — the first website measured against the web — and the full quantum-privacy mechanism was not implemented, because a customer-funded proof of concept pays for what the customer needs proved. Two facts about it are worth more than the achievement. It ran entirely dual-use, on infrastructure the participants already operated. And it was built in large part by the participants' own engineers, who were paying to have the method demonstrated and transferred rather than delivered. Containment-first deployment and implementation by many hands are not properties this document reasoned its way to and then justified; they are what the only real deployment actually did, a decade before the claims made about them here.
Why it did not propagate — and what was learned. The industry-wide deployment that was to follow did not follow, for reasons on the public record rather than in the technology: the anchor counterparty spent three and a half consecutive years inside merger proceedings. The regulatory question and the technical question had both been answered; what had not been secured was an institution with attention left to proceed. A single anchor had been persuaded, so propagation was hostage to that anchor's corporate weather. That is the episode from which the cascade independence argued in section 9, and the prediction staked on it in section 23, were learned.