The rules the registry binds itself to. They are load-bearing: records cite them by number (see PIR-2026-0045, registered under rule 4 before the registry had a single visitor). Amendments are made by pull request, take effect on merge, and never renumber existing rules - a retired rule keeps its number, like a retired id.
Nothing enters the registry unverified. Every record is checked against primary sources, adversarially - looking for corrections, retractions, and inflated figures, not confirmation. "Unknown" is an honest field value; an invented one is grounds for rejection.
Corrections are published inside the affected record, never slipped. Every published number carries its basis; where sources conflict, the record states the range and names the conflict. Being late is acceptable; being quietly wrong is not.
Ids are opaque permanent names: never deleted, never reused, never renumbered. Chronology lives in the record and the citation, not the id. History does not rewrite: force-pushes are blocked, commits are signed, and releases are archived externally (Zenodo DOI) beyond the registry's own custody.
Anyone connected to an incident - as operator, funder, competitor, insurer, or otherwise - may still submit or register it, but the connection is stated in the record itself, where every future reader sees it. Undisclosed conflicts, once found, are treated as rule-2 corrections and published. This binds the founding editor first: the registry's first record discloses the founder's stake in its subject.
The data is CC BY 4.0, the schema is open and stays open, and anyone - including AI agents - may submit. Registration authority does not open: merge is the act of registration and rests with the editors. Wikipedia intake, CVE authority.
Registry counts are a floor, never a frequency estimate. Absence from the registry is not evidence of safety. No failure rate can be computed from registry data alone, because the exposure base is unknown - and every aggregate the registry publishes says so.
PipeRoll records what happened and what the evidence is. It does not rate vendors, certify systems, or underwrite risk - conclusions belong to the reader, the underwriter, and the court, all of whom need a measurer with nothing to sell them.