Release 1.0: platform and standard live; no real packet audits yet August 6, 2026
R0 · Catalogue relationships

Who appears at the far end of the app?

The institution providing a service, the store account publishing its app and the supplier building it may be different actors. The first map begins with the relationship verifiable now: the store publisher.

30apps in the registry
24distinct publishers
5publishers with multiple apps
11apps in those groups
Repeated publishers

Visible concentration in the registry

Two or more apps under one publisher may indicate reuse, a product family or merely a shared publishing identity. A common contract, SDK or backend has to be established separately.

R0

Every publisher in the sample

Relationships come from public store metadata and descriptions. They do not by themselves prove the existence or scope of a contract.

What this map does not prove

  • that the store publisher is the actual developer
  • that a current contract exists between the publisher and named institution
  • that two apps share code, an SDK or backend
  • that an observed technical domain is an independent data recipient

What a real dependency record adds

Contract or policy provenance, endpoint observation, SDK documentation, role confirmation, disputes and the date on which each relationship was true.