diff --git a/ESTATE.md b/ESTATE.md
index cf9fb49..3aa6fe4 100644
--- a/ESTATE.md
+++ b/ESTATE.md
@@ -9,7 +9,7 @@ machinery hub and the only repo that changes freely.
State snapshot (2026-07-22): log **13 leaves**, root `3488a2d0…`, key
fingerprint `874c8a00…`, paper **v0.9 camera-ready (23 pp)**, five
-attested components, one campaign open (SLH-DSA — **zero
+attested components, one campaign open (SLH-DSA — **eleven
certificates**), pacta suite 144 green.
```mermaid
@@ -28,7 +28,7 @@ flowchart LR
r["risc0-ed25519-verified
16 certs · leaf 10"]
b["betrusted-ed25519-verified
16 certs · leaf 11"]
p["pasta-pallas-verified
field layer only · NOT attested"]
- f["fips205-slhdsa-verified
campaign in progress · 0 certs · NOT attested"]
+ f["fips205-slhdsa-verified
11 certs proven · reviewer attest-with-conditions · NOT in the log"]
c["ltl-accumulator-verified
61 certs · entry-13 subject · frozen 172a1d0"]
end
subgraph M["MACHINERY — pacta + operator-held"]
@@ -122,7 +122,7 @@ deployed verifier; see the corpus KNOWN-GAPS ledger).
| `fips205-source` | upstream | verbatim snapshot of `integritychain/fips205` (pure-Rust FIPS 205 / SLH-DSA); upstream pin `30bac08`, snapshot head `5dca0db` — single deviation: upstream CI workflows stripped, documented in-commit | pinned; moves only for transparent, individually-justified Aeneas-compat patches (nothing proposed upstream) |
| `dalek-` / `anza-` / `risc0-` / `betrusted-ed25519-verified` | subject | Rust source + Lean proofs; 16 certs each; attested (leaves 8–11, generations at 0–7) | frozen at attested commits; branch moves only for docs |
| `pasta-pallas-verified` | subject | field layer proven; curve layer pending; **not attested** | changes freely |
-| `fips205-slhdsa-verified` | subject | SLH-DSA (FIPS 205) verify-path campaign, parameter set SLH-DSA-SHA2-128s; **campaign in progress — zero certificates, `check.sh` non-green by design**; not attested | changes freely — campaign |
+| `fips205-slhdsa-verified` | subject | SLH-DSA (FIPS 205) verify-path campaign, parameter set SLH-DSA-SHA2-128s; **11 certificates proven, `check.sh` green with an 18-attack self-test, outside-reviewer attest-with-conditions**; not appended to the log | changes freely — campaign |
| `ltl-accumulator-verified` | subject | 61-cert corpus about the log's accumulator model; **entry-13 subject**, frozen `172a1d0` | frozen; doc-only commits allowed |
| `proof-aware-crypto-tooling-agent` (this repo) | machinery | provider service, consumer library, warden (+ local read-only cockpit), dogfood signer, paper, course, tests | **changes freely — the hub** |
| `lean-transparency-log` | published | the public mirror: leaves, heads, receipts, fail-closed `verify.py` + selftest | **generated by publish** — canonical files here, templates in pacta, CI-pinned |
@@ -149,7 +149,7 @@ deployed verifier; see the corpus KNOWN-GAPS ledger).
| provider write side (check / append / publish / sign) | **on demand** | operator machine | runs only during an append ceremony, minutes at a time; the signing key is offline otherwise |
| warden (the financial agent) | **not running** | nowhere | implemented prototype: a wallet directory plus CLI/MCP/cockpit processes that exist only while explicitly started; no deployed instance, no funds watched |
| custody cockpit | **on demand** | operator machine, localhost | `pacta wallet cockpit`, stops with Ctrl-C; read-only |
-| SLH-DSA campaign (`fips205-source` + `fips205-slhdsa-verified`) | **no process** | — | static repos, **zero certificates yet**; extraction/proof sessions are episodic operator-machine runs under lean-guard |
+| SLH-DSA campaign (`fips205-source` + `fips205-slhdsa-verified`) | **no process** | — | static repos, **11 certificates**; extraction/proof sessions are episodic operator-machine runs under lean-guard |
| everything else (repos, paper, book, mirror, SD) | **no process** | — | static files; consumers and reviewers are external and episodic |
The human-facing interactive rendering of this whole map, runtime