<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.10) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

<!ENTITY RFC2119 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml">
<!ENTITY RFC8174 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml">
<!ENTITY RFC3339 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.3339.xml">
<!ENTITY RFC6973 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.6973.xml">
<!ENTITY RFC7942 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.7942.xml">
]>


<rfc ipr="trust200902" docName="draft-morrison-compute-location-gate-01" category="info" submissionType="independent">
  <front>
    <title abbrev="Compute-Location Gate">The Compute-Location Gate: Provenance-Class Routing of Identity Inference with Wire-Layer Refusal of Unconsented Provenance Classes</title>

    <author fullname="Blake Morrison">
      <organization>Alter Meridian Pty Ltd (~truealter)</organization>
      <address>
        <email>blake@truealter.com</email>
        <uri>alter:~blake</uri>
      </address>
    </author>

    <date year="2026" month="August" day="24"/>

    
    
    

    <abstract>


<?line 108?>

<t>This memo specifies the compute-location gate: a mechanism by which a
client and an identity-inference server negotiate, at the wire layer
and before any inference is performed, the location at which an
identity inference will compute, as a deterministic function of the
provenance class of the input signal.  Three provenance classes are
distinguished.  Active inference, initiated by the inferred-about
principal, MAY compute server-side and produce a server-held identity
vector.  Passive aggregate observation over a cohort no smaller than a
declared minimum MAY compute server-side but yields only a
population-level observation that is not attributable to an
individual.  Passive individual observation is local-only: it is
computed and retained on the device that observed it and is never
transmitted to a server.  The gate is enforced by consent-class
matching and by a wire-layer refusal returned when a requested
provenance class is not consented; it is not enforced by any
cryptographic proof concerning data that was not used.  The memo is
Informational.  The wire surface composes with the discovery
mechanism of <xref target="MCPDNS"></xref>, the handle namespace of <xref target="IDPRONOUNS"></xref>, and the
organisational policy substrate of <xref target="POLICYPROV"></xref>; no new transport is
introduced.</t>



    </abstract>



  </front>

  <middle>


<?line 131?>

<section anchor="introduction"><name>Introduction</name>

<t>An identity-inference system derives statements about a principal
(traits, competencies, dispositions, belonging measures) from signals
the principal emits.  Such systems face a question that access control
alone does not answer: <em>who may read</em> a derived statement, and
<em>where the derivation itself is permitted to compute</em>.</t>

<t>These are distinct questions.  Access control governs the read path of
a datum that already exists.  The compute-location question governs
whether the datum may be brought into existence on a given machine at
all.  A system that answers only the first question can decline to
serve an inferred trait to an unauthorised reader, but it has, by the
time of that refusal, already computed and persisted the trait on its
server.  The compute-location question, asked earlier, prevents the
server-side derivation from occurring when the signal's provenance
does not warrant it.</t>

<t>This memo specifies a mechanism, the compute-location gate, that
answers the second question at the wire layer.  Before an inference is
performed, the client and the server negotiate the <em>provenance class</em>
of the input signal.  The provenance class deterministically selects
a <em>compute location</em>.  Where the negotiated provenance class is not
covered by the principal's consent, the server returns a wire-layer
refusal, and no inference is performed at any location.</t>

<t>The mechanism rests on a principle the present author has elsewhere
termed identity-as-inference: that a principal's identity is inferred
from manifestation rather than declared, and that every such inference
is admissible only under an explicit gate on the provenance of the
signal from which it is drawn.  The first clause of that principle is:
no inference without a compute-location gate.  This memo is the
wire-layer codification of that clause.</t>

<t>The mechanism is deliberately narrow.  It specifies provenance-class
negotiation, the routing function from provenance class to compute
location, the consent-class match, and the refusal returned on a
consent miss.  It does NOT specify, and explicitly excludes from its
scope (Section 11), any cryptographic proof that a particular data
category was excluded from a derivation.  The gate's enforcement model
is consent-class matching plus wire-layer rejection.  Verification
that the gate held is addressed by build-time pipeline checks
(Section 9) and by post-hoc audit, not by a cryptographic attestation
of absence.</t>

<t>The wire surface composes with four Morrison-family Internet-Drafts:
the discovery surface of <xref target="MCPDNS"></xref>, the handle namespace of
<xref target="IDPRONOUNS"></xref>, the cross-session coordination posture of <xref target="SUBSTRATE"></xref>,
and the organisational policy substrate of <xref target="POLICYPROV"></xref>.  No new
transport, no new handle category, and no new discovery record is
introduced.</t>

</section>
<section anchor="conventions-and-definitions"><name>Conventions and Definitions</name>

<t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
"SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and
"OPTIONAL" in this document are to be interpreted as described in
BCP 14 <xref target="RFC2119"></xref> <xref target="RFC8174"></xref> when, and only when, they appear in all
capitals, as shown here.</t>

<t>The following terms are defined for the purposes of this document.
Terms previously defined by the referenced Morrison-family memos
retain their established meaning and are reproduced here only when
operative for the present specification.</t>

<dl>
  <dt>Identity inference</dt>
  <dd>
    <t>A computation that derives a statement about a principal (a trait
value, a competency estimate, a disposition, a belonging measure,
or a comparable derived attribute) from one or more signals the
principal has emitted.</t>
  </dd>
  <dt>Provenance class</dt>
  <dd>
    <t>A property of an input signal, established before inference, that
records how the signal came to be observed.  Three provenance
classes are defined in Section 3.</t>
  </dd>
  <dt>Compute location</dt>
  <dd>
    <t>The machine class on which an identity inference is permitted to
execute.  Two compute locations are distinguished: server-side, on
infrastructure operated by the inference service; and device-local,
on the device that observed the input signal.</t>
  </dd>
  <dt>Server-held identity vector</dt>
  <dd>
    <t>A persisted, server-side representation of a principal's inferred
identity, readable through the inference service's consented query
surface.  Only inference of the active provenance class (Section 3.1)
may write to the server-held identity vector.</t>
  </dd>
  <dt>Device-local daemon</dt>
  <dd>
    <t>A long-running process executing on a device under the principal's
control, on which device-local inference (Section 3.3) is computed
and where the resulting representation is retained.  The device-local
daemon does not transmit individual-attributable derived statements
to a server.</t>
  </dd>
  <dt>Cohort floor</dt>
  <dd>
    <t>The minimum cohort size, declared by the inference service, below
which a passive aggregate inference (Section 3.2) MUST NOT be
computed.  The cohort floor exists so that a population-level
observation cannot be narrowed to an individual.</t>
  </dd>
  <dt>Consent class</dt>
  <dd>
    <t>A unit of consent granted by a principal, keyed to a provenance
class and a signal stream.  A consent class is the grant against
which a negotiated provenance class is matched (Section 7).</t>
  </dd>
  <dt>Wire-layer refusal</dt>
  <dd>
    <t>A typed response returned by the inference service, before any
inference is performed, when a requested provenance class is not
covered by a consent class.  The refusal terminates the inference
request; no inference is performed at any compute location.</t>
  </dd>
  <dt><spanx style="verb">~handle</spanx></dt>
  <dd>
    <t>A principal identity handle as defined by <xref target="IDPRONOUNS"></xref>.</t>
  </dd>
</dl>

</section>
<section anchor="provenance-classes"><name>Provenance Classes</name>

<t>Every input signal admitted to an identity inference carries exactly
one of three provenance classes.  The provenance class is established
before inference and is immutable for the lifetime of the signal
record.  The provenance class, not the signal's content and not the
trait category of the prospective output, is the value on which the
compute-location gate routes.</t>

<section anchor="active-inference"><name>Active Inference</name>

<t>An input signal is of the active provenance class when the
inferred-about principal initiated the act that produced it.
Challenge-response exchanges, a consented structured assessment, an
explicit attestation the principal authored, and inputs the principal
supplied to a deliberate identity-elaboration flow are all of the
active class.  The defining property is principal initiation: the
principal performed an act whose purpose, as understood by the
principal at the time of the act, was to contribute signal to their
own identity inference.</t>

<t>An inference drawn solely from active-class signal MAY compute
server-side and MAY write to the server-held identity vector
(Section 8.1).</t>

</section>
<section anchor="passive-aggregate-observation"><name>Passive Aggregate Observation</name>

<t>An input signal is of the passive aggregate provenance class when it
was observed without a principal-initiated act, and when the inference
drawn from it is computed over a cohort of principals no smaller than
the cohort floor (Section 5) and yields only a population-level
observation.  A passive aggregate inference produces a statement about
the cohort (a distribution, a rate, a population parameter) and does
not produce a statement attributable to any individual within the
cohort.</t>

<t>An inference of the passive aggregate class MAY compute server-side
(Section 8.2).  Its output is a population-level observation; it MUST
NOT write an individual-attributable statement to the server-held
identity vector.</t>

</section>
<section anchor="passive-individual-observation"><name>Passive Individual Observation</name>

<t>An input signal is of the passive individual provenance class when it
was observed without a principal-initiated act and the inference drawn
from it would yield a statement attributable to a single principal.</t>

<t>An inference of the passive individual class is local-only.  It MUST
be computed on the device-local daemon (Section 4) running on the
device that observed the input signal, and the resulting derived
statement MUST be retained on that device.  An individual-attributable
statement of the passive individual provenance class MUST NOT be
transmitted to a server, and MUST NOT, by any derivation path, reach
the server-held identity vector.</t>

<t>The passive individual class is the governing constraint of this
memo.  The other two classes describe what server-side inference MAY
do; this class describes what server-side inference MUST NOT do.  A
system that routes passive individual observation to server-side
compute has not implemented the compute-location gate, irrespective of
any access control it applies to the resulting datum afterward.</t>

</section>
</section>
<section anchor="the-device-local-daemon"><name>The Device-Local Daemon</name>

<t>Inference of the passive individual provenance class is computed on a
device-local daemon.  The device-local daemon is a process under the
principal's control, executing on the device that observed the input
signal.</t>

<t>The device-local daemon:</t>

<t><list style="numbers" type="1">
  <t>Receives passive individual signal observed on its host device.</t>
  <t>Computes the identity inference locally.  No input signal of the
passive individual class, and no statement derived from it, leaves
the device for the purpose of the inference.</t>
  <t>Retains the derived statement in device-local storage under the
principal's control.</t>
  <t>Exposes the derived statement to the principal, and only to the
principal, through a device-local interface.  The principal MAY,
by a subsequent active-class act, elect to contribute a derived
statement to a server-held inference; such an act re-enters the
pipeline as active-class signal (Section 3.1) and is gated afresh.</t>
</list></t>

<t>The device-local daemon MUST NOT expose an interface by which a
server, or any party other than the principal operating the device,
can read an individual-attributable statement of the passive
individual class.  The transition of a passive-individual-derived
statement to server-side visibility occurs only through a fresh
active-class act by the principal, never through a daemon-exposed
read surface.</t>

<t>The device-local daemon participates in the substrate-observation
posture of <xref target="SUBSTRATE"></xref> for the purpose of cross-session coordination
of the principal's surfaces; that participation is orthogonal to the
present memo and introduces no path by which passive individual
derived statements reach a server.</t>

</section>
<section anchor="the-cohort-floor"><name>The Cohort Floor</name>

<t>A passive aggregate inference (Section 3.2) MUST NOT be computed
unless the cohort over which it is computed is no smaller than the
cohort floor.  The cohort floor is a positive integer declared by the
inference service and exposed at the negotiation surface (Section 6)
so that a client can determine, before requesting an inference,
whether a passive aggregate request is admissible.</t>

<t>The cohort floor exists to ensure that a passive aggregate inference
yields a population-level observation and not an individual-attributable
one.  An inference computed over a cohort smaller than the floor risks
re-identification: with a sufficiently small cohort, a population
parameter is a near-individual statement.  The floor is the structural
boundary between the passive aggregate class, which MAY compute
server-side, and the passive individual class, which MUST NOT.</t>

<t>The cohort floor is a parameter of this mechanism, not a fixed
constant of this memo.  An inference service SHALL declare its cohort
floor and SHALL NOT compute a passive aggregate inference over a
cohort below it.  A service whose declared cohort floor is so low that
a population parameter computed at that size is individually
identifying has not satisfied the intent of this section; the floor is
a number, but a number chosen so that the resulting observation is
genuinely population-level.  The reference deployment described in
Section 12 declares a cohort floor of 1000.</t>

<t>The cohort floor governs the <em>aggregate</em> boundary only.  It is not a
privacy budget, it is not a noise-calibration parameter, and it does
not compose additively across queries.  The relationship of the
cohort floor to the statistical-disclosure-control literature is
discussed in Section 10.</t>

</section>
<section anchor="wire-layer-negotiation"><name>Wire-Layer Negotiation</name>

<t>Before an identity inference is performed, the client and the
inference service negotiate the provenance class of the input signal
and, by the routing function of Section 8, the compute location.  The
negotiation is a request-response exchange carried over the client's
existing transport to the inference service; this memo introduces no
new transport.  Where the inference service is reached as a Model
Context Protocol <xref target="MCP"></xref> surface, the negotiation is a tool invocation
and its response; where it is reached over another transport, the
negotiation is the corresponding request-response pair.</t>

<section anchor="the-inference-request"><name>The Inference Request</name>

<t>A client requesting an identity inference SHALL include, in the
request, an inference-negotiation object carrying at minimum the
following fields.</t>

<dl>
  <dt><spanx style="verb">provenance_class</spanx> (enum, REQUIRED)</dt>
  <dd>
    <t>One of <spanx style="verb">active</spanx>, <spanx style="verb">passive-aggregate</spanx>, <spanx style="verb">passive-individual</spanx>.  The
provenance class the client asserts for the input signal of the
prospective inference.</t>
  </dd>
  <dt><spanx style="verb">signal_stream</spanx> (string, REQUIRED)</dt>
  <dd>
    <t>A stable identifier for the stream from which the input signal is
drawn.  Consent classes (Section 7.2) are keyed to the pair
(<spanx style="verb">provenance_class</spanx>, <spanx style="verb">signal_stream</spanx>); the stream identifier is the
second key.</t>
  </dd>
  <dt><spanx style="verb">requested_output</spanx> (string, REQUIRED)</dt>
  <dd>
    <t>An identifier for the category of derived statement the inference
is to produce.  The requested output does not select the compute
location (the provenance class does), but it is carried so that
the consent match (Section 7) and the audit record (Section 9) can
record what was requested.</t>
  </dd>
  <dt><spanx style="verb">cohort_size</spanx> (integer, OPTIONAL)</dt>
  <dd>
    <t>Present only when <spanx style="verb">provenance_class</spanx> is <spanx style="verb">passive-aggregate</spanx>.  The
size of the cohort over which the aggregate inference is to be
computed.  The service SHALL reject the request if <spanx style="verb">cohort_size</spanx> is
below the declared cohort floor (Section 5).</t>
  </dd>
  <dt><spanx style="verb">principal</spanx> (string, OPTIONAL)</dt>
  <dd>
    <t>The <spanx style="verb">~handle</spanx> of the inferred-about principal, present when the
inference is attributable to a named principal.  Absent for a
passive aggregate inference, which is by construction not
attributable to an individual.</t>
  </dd>
</dl>

</section>
<section anchor="the-negotiation-response"><name>The Negotiation Response</name>

<t>The inference service SHALL respond to an inference-negotiation
request with one of three typed responses.</t>

<dl>
  <dt><spanx style="verb">accepted</spanx></dt>
  <dd>
    <t>The asserted provenance class is consented (Section 7), the routing
function (Section 8) has selected a compute location, and the
inference will proceed at that location.  The response carries the
selected <spanx style="verb">compute_location</spanx> (<spanx style="verb">server-side</spanx> or <spanx style="verb">device-local</spanx>), so
that the client and any audit observer record where the inference
computed.</t>
  </dd>
  <dt><spanx style="verb">refused</spanx></dt>
  <dd>
    <t>The asserted provenance class is not covered by a consent class.
No inference is performed at any compute location.  The structure
of the refusal is specified in Section 7.3.</t>
  </dd>
  <dt><spanx style="verb">redirected</spanx></dt>
  <dd>
    <t>The asserted provenance class is consented, but the routing
function has selected a compute location other than the one the
client is positioned to satisfy.  The most common case is a client
requesting a server-side inference on signal the service classifies
as <spanx style="verb">passive-individual</spanx>: the service does not perform the inference
server-side, and the response directs the client to perform the
inference on the device-local daemon (Section 4).  A <spanx style="verb">redirected</spanx>
A <spanx style="verb">redirected</spanx> response is not a refusal; the inference is admissible.
It is not a server-side acceptance either.</t>
  </dd>
</dl>

<t>The negotiation response, in every case, is returned <em>before</em> any
inference is performed.  An inference service MUST NOT compute an
identity inference and then decide, from the result, whether to
return it; the compute-location gate is evaluated on the negotiation
object alone, ahead of the inference.</t>

</section>
</section>
<section anchor="consent-class-matching"><name>Consent-Class Matching</name>

<t>The compute-location gate is enforced by consent-class matching.  The
asserted provenance class of an inference request is matched against
the consent classes the principal has granted; an inference proceeds
only when a matching consent class is found.</t>

<section anchor="provenance-class-is-distinct-from-trait-category"><name>Provenance Class Is Distinct from Trait Category</name>

<t>A consent class is keyed to a provenance class and a signal stream,
not to the category of the derived output.  A principal who has
consented to active-class inference of a disposition has not thereby
consented to passive-individual-class inference of the same
disposition.  Consent granted for one provenance class does not
generalise to another.  This is the defining property of provenance-
class consent: the <em>how it was observed</em> is consented separately from
the <em>what is derived</em>.</t>

<t>It follows that an inference service MUST carry the provenance class
on every signal record and on every derived statement throughout its
internal architecture, so that the consent match can be evaluated and
so that the audit record (Section 9) can record the provenance class
that was matched.  A derived statement that has lost its provenance
class is not consent-checkable and MUST NOT be served.</t>

</section>
<section anchor="the-consent-class"><name>The Consent Class</name>

<t>A consent class is a grant, authored by the principal, carrying at
minimum:</t>

<t><list style="symbols">
  <t>The <spanx style="verb">provenance_class</spanx> the grant covers.</t>
  <t>The <spanx style="verb">signal_stream</spanx> the grant covers.</t>
  <t>The set of <spanx style="verb">requested_output</spanx> categories the grant admits, or an
explicit marker that the grant admits all output categories for the
covered (provenance class, signal stream) pair.</t>
  <t>A revocation marker; consent classes are revocable, and a revoked
consent class MUST NOT satisfy a subsequent match.</t>
</list></t>

<t>A consent class for the <spanx style="verb">passive-individual</spanx> provenance class
authorises device-local inference (Section 4) only.  No consent class,
of any provenance class, authorises the transmission of an
individual-attributable passive-individual derived statement to a
server; that transmission is precluded by Section 3.3 and is not a
grantable scope.</t>

<t>Consent for inference from a third-party signal stream is a separate
consent class from any authorisation the principal may have granted
the third-party platform itself.  A principal's authorisation of a
platform's data-access grant is not a consent class for ALTER-side or
any inference-service-side inference from that platform's stream; the
inference service SHALL require a distinct, separately revocable
consent class, keyed to the (<spanx style="verb">provenance_class</spanx>, <spanx style="verb">signal_stream</spanx>)
pair, before inferring from a third-party stream.</t>

</section>
<section anchor="the-wire-layer-refusal"><name>The Wire-Layer Refusal</name>

<t>When the asserted provenance class of an inference request is not
covered by a consent class, the inference service SHALL return a
<spanx style="verb">refused</spanx> negotiation response.  The refusal carries at minimum:</t>

<dl>
  <dt><spanx style="verb">reason</spanx> (enum, REQUIRED)</dt>
  <dd>
    <t>One of <spanx style="verb">no-consent-class</spanx> (no consent class covers the asserted
provenance class and signal stream), <spanx style="verb">consent-revoked</spanx> (a consent
class existed but has been revoked), <spanx style="verb">cohort-floor</spanx> (a
<spanx style="verb">passive-aggregate</spanx> request carried a <spanx style="verb">cohort_size</spanx> below the
declared floor), or <spanx style="verb">provenance-not-routable</spanx> (the asserted
provenance class is not one the service admits for the requested
output).</t>
  </dd>
  <dt><spanx style="verb">provenance_class</spanx> (enum, REQUIRED)</dt>
  <dd>
    <t>The provenance class that was asserted and refused, echoed so that
the client and audit observer record what was requested.</t>
  </dd>
  <dt><spanx style="verb">explanation</spanx> (string, REQUIRED)</dt>
  <dd>
    <t>A human-readable explanation, sufficient for the client's reasoning
surface to present to the principal without a further round-trip.</t>
  </dd>
</dl>

<t>A <spanx style="verb">refused</spanx> response is terminal for the inference request.  The
inference service MUST NOT, having returned a refusal, perform the
refused inference at any compute location, and MUST NOT perform a
substitute inference of a different provenance class without a fresh
negotiation.  The refusal is a wire-layer event: it is observable to
the client, it is recorded in the audit log (Section 9), and it
occurs before any inference computation.</t>

<t>The refusal model of this memo is consent-class matching plus
wire-layer rejection.  It is not, and does not rely on, any
cryptographic attestation that a refused signal was absent from a
computation.  The refusal asserts that the inference was not
performed; it does not produce a proof, verifiable without access to
the underlying data, that a particular data category did not
contribute to some other computation.  The boundary between the
mechanism this memo specifies and the cryptographic-attestation
question it does not address is stated in Section 11.</t>

</section>
</section>
<section anchor="routing-and-compute-location-selection"><name>Routing and Compute-Location Selection</name>

<t>The routing function maps a consented provenance class to a compute
location.  The function is total over the three provenance classes
and is deterministic: the same provenance class always selects the
same compute location.</t>

<section anchor="active-class-to-server-side"><name>Active Class to Server-Side</name>

<t>A consented inference of the <spanx style="verb">active</spanx> provenance class is routed to
server-side compute.  Its output MAY be written to the server-held
identity vector and MAY be served, subject to the inference service's
ordinary read-path consent, through the service's consented query
surface.  The principal initiated the act that produced the signal;
server-side derivation and persistence is the routing outcome.</t>

</section>
<section anchor="passive-aggregate-class-to-server-side-population-level-output"><name>Passive Aggregate Class to Server-Side, Population-Level Output</name>

<t>A consented inference of the <spanx style="verb">passive-aggregate</spanx> provenance class,
whose <spanx style="verb">cohort_size</spanx> is no smaller than the declared cohort floor, is
routed to server-side compute.  Its output is a population-level
observation.  The output MUST NOT be written to the server-held
identity vector as an individual-attributable statement; the
server-held identity vector is, by Section 3, the destination of
active-class inference alone.  A passive aggregate output is a
statement about the cohort, retained as such.</t>

</section>
<section anchor="passive-individual-class-to-device-local"><name>Passive Individual Class to Device-Local</name>

<t>A consented inference of the <spanx style="verb">passive-individual</spanx> provenance class is
routed to device-local compute on the device-local daemon (Section 4).
The inference service does not perform the inference.  Where a client
requests a server-side inference on signal the service classifies as
<spanx style="verb">passive-individual</spanx>, the service returns a <spanx style="verb">redirected</spanx> negotiation
response (Section 6) directing the client to the device-local daemon.</t>

<t>The routing function has no branch by which a <spanx style="verb">passive-individual</spanx>
inference computes server-side.  A server-side compute location is not
a selectable outcome for the <spanx style="verb">passive-individual</spanx> provenance class
under any consent configuration.  This is the structural property
that distinguishes the compute-location gate from an access-control
mechanism: access control could, in principle, be configured to admit
a reader of a server-side passive-individual trait; the routing
function of this section has no such configuration, because the trait
is never computed server-side to be read.</t>

</section>
</section>
<section anchor="audit-and-build-time-verification"><name>Audit and Build-Time Verification</name>

<t>The compute-location gate is verifiable in two complementary ways: by
a per-event audit record written at negotiation time, and by a
build-time check on the inference pipeline's data-flow.</t>

<section anchor="per-event-audit-record"><name>Per-Event Audit Record</name>

<t>Every negotiation, whether it resolves to <spanx style="verb">accepted</spanx>, <spanx style="verb">refused</spanx>, or
<spanx style="verb">redirected</spanx>, SHALL produce an append-only audit record carrying at
minimum: the asserted <spanx style="verb">provenance_class</spanx>; the <spanx style="verb">signal_stream</spanx>; the
<spanx style="verb">requested_output</spanx>; the negotiation outcome; the selected
<spanx style="verb">compute_location</spanx> where the outcome was <spanx style="verb">accepted</spanx>; the <spanx style="verb">reason</spanx>
where the outcome was <spanx style="verb">refused</spanx>; an <xref target="RFC3339"></xref> timestamp; and the
attribution of the requesting party.  The audit record is written to
an append-only log; admitted records are not retractable or amendable.
Where the inference service is operated as, or alongside, an
organisational identity substrate, the audit record SHOULD be emitted
to that substrate's audit-signal ingestion surface as specified by
<xref target="POLICYPROV"></xref>.</t>

<t>The audit record makes the gate's operation observable after the
fact: an auditor can determine, for any inference the service
performed, what provenance class was asserted, what compute location
was selected, and which consent class was matched.</t>

</section>
<section anchor="build-time-data-flow-verification"><name>Build-Time Data-Flow Verification</name>

<t>In addition to the per-event audit record, an inference service
SHOULD verify, at the time its inference pipeline is built, that the
pipeline contains no data-flow path by which a signal of the
<spanx style="verb">passive-individual</spanx> provenance class reaches the server-held
identity vector.</t>

<t>The verification treats the inference pipeline as a directed graph
whose nodes are pipeline stages and whose edges are data-flow
dependencies between stages.  The verification is the property: for
every signal node of the <spanx style="verb">passive-individual</spanx> provenance class, and
for every node representing a write to the server-held identity
vector, there exists no directed path from the former to the latter.
A pipeline that fails this property has a route by which a
device-local-only inference could reach the server, and the build
SHOULD fail.</t>

<t>This build-time verification is a check on the pipeline's structure,
performed before the pipeline runs; it is independent of, and
complementary to, the per-event audit record, which observes the
pipeline's behaviour after each negotiation.  The combination of a
structural check at build time and a behavioural record at run time
is the verification model of the compute-location gate.  Neither
component is a cryptographic proof, and the verification model does
not depend on one; the boundary is stated in Section 11.</t>

</section>
</section>
<section anchor="relation-to-prior-art"><name>Relation to Prior Art</name>

<t>The compute-location gate is structurally distinct from the prior-art
families with which it is most likely to be confused.</t>

<t>Differential privacy <xref target="DWORK"></xref> and the broader statistical-disclosure-
control literature address the population-versus-individual boundary
at the algorithmic layer: a query mechanism adds calibrated noise so
that the presence or absence of any single record is statistically
masked, and a privacy budget composes the guarantee across queries.
The compute-location gate addresses a different boundary at a
different layer.  The cohort floor of Section 5 is not a privacy
budget: it does not compose additively across queries, and it
calibrates no noise.  It is a categorical admissibility threshold:
below the floor, the passive aggregate class is simply not the
applicable provenance class, and the inference is not computed
server-side at all.  Differential privacy makes a server-side
individual-sensitive computation safe to release; the compute-location
gate routes the individual-attributable computation off the server
entirely.  The two are composable: a passive aggregate inference
admitted by the cohort floor MAY additionally apply differential
privacy to its population-level output.  They are not substitutes.</t>

<t>Decentralised personal-data architectures (Solid <xref target="SOLID"></xref> and
comparable personal-data-store designs) move the <em>storage</em> of personal
data to a principal-controlled pod and govern the <em>read path</em> through
access control.  The compute-location gate governs the <em>compute path</em>:
it determines where a derivation is permitted to run, not merely where
its result is stored or who may read it.  A personal-data store can
hold a passive-individual trait that was nonetheless computed
server-side and copied to the pod; the compute-location gate precludes
the server-side computation in the first place.  The two are
complementary (a device-local daemon (Section 4) may use a
personal-data store as its retention surface), but the gate's
contribution is the routing of computation, which a storage-layer
architecture does not address.</t>

<t>Consent-management and access-control frameworks generally govern
which parties may read which data.  The compute-location gate's
consent classes (Section 7) govern, in addition, the provenance class
under which an inference may be <em>brought into existence</em>.  A consent
framework that admits a reader of a derived trait has not, by that
admission, said anything about whether the trait may be derived
server-side from passively observed individual signal; that is the
question the provenance-class consent of this memo answers.</t>

<t>The contribution of this memo is the wire-layer composition of the
compute-path question with provenance-class consent: a negotiation,
ahead of inference, that routes computation by provenance class and
refuses at the wire layer when the provenance class is not consented.</t>

</section>
<section anchor="scope-boundary-what-this-memo-does-not-specify"><name>Scope Boundary: What This Memo Does Not Specify</name>

<t>This memo specifies the compute-location gate: provenance-class
negotiation, the routing function, consent-class matching, and the
wire-layer refusal.  It deliberately does not specify several adjacent
mechanisms, and an implementer SHOULD NOT read the gate as providing
them.</t>

<t>This memo does not specify a cryptographic proof, attestation, or
guarantee that any specified data category, provenance class, or
derivation pathway was excluded from a particular computation.  The
gate's enforcement model is consent-class matching plus wire-layer
rejection (Section 7) and its verification model is per-event audit
plus build-time data-flow checking (Section 9).  A refusal under this
memo asserts that an inference was not performed; it does not produce,
and does not rely on, any object that proves (verifiably without
access to the underlying data) that a data category did not
contribute to some output.  Such a proof is a different mechanism,
addressed by separate work, and is outside the scope of this
specification.  An implementer requiring a cryptographic
exclusion guarantee MUST NOT infer one from the audit record or the
build-time check described here; neither is such a proof, and the
compute-location gate does not become one by composition.</t>

<t>This memo does not specify the internal inference algorithms, the
trait taxonomy, the identity-vector representation, or the
device-local daemon's storage format.  These are implementation
matters of an inference service; the memo specifies only the wire
surface at which compute location is negotiated.</t>

<t>This memo does not specify a discovery mechanism, a transport, or a
handle namespace.  It composes with <xref target="MCPDNS"></xref>, the principal's existing
transport, and <xref target="IDPRONOUNS"></xref> respectively.</t>

</section>
<section anchor="implementation-status"><name>Implementation Status</name>

<t>A reference implementation of the compute-location gate is operated by
the present author against a production identity-inference service
reachable at the <spanx style="verb">~truealter.com</spanx> substrate.  The reference deployment
classifies input signals into the three provenance classes of
Section 3, performs the negotiation of Section 6 ahead of inference,
routes by the function of Section 8, returns the wire-layer refusal of
Section 7.3 on a consent miss, declares a cohort floor of 1000 for
passive aggregate inference, and runs the build-time data-flow
verification of Section 9.2 as a gate on its inference-pipeline build.
The device-local daemon of Section 4 is the reference deployment's
local-execution surface for passive individual inference.</t>

<t>In the spirit of <xref target="RFC7942"></xref>, the present author notes that this section
documents implementation experience and is expected to be removed
before the document advances beyond the Independent Stream.  No claim
of interoperability is made; the reference deployment is a single
service operated by the specification's author.</t>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>

<t>This memo requests no IANA action.</t>

<t>The negotiation field names and the negotiation-response type names
used in Sections 6 and 7 are illustrative of the reference deployment
described in Section 12.  Conforming inference services MAY name the
corresponding fields and response types by any convention consistent
with their transport's addressing primitive; the central
contribution of this memo is the three-provenance-class routing
function and the wire-layer refusal, not the field names.  No new DNS
record types, transport identifiers, port numbers, URI schemes, or
media types are introduced.</t>

</section>
<section anchor="security-considerations"><name>Security Considerations</name>

<t>The compute-location gate concentrates an admissibility decision
(where an identity inference may compute) at a wire-layer negotiation
performed ahead of inference.  The following considerations arise.</t>

<section anchor="provenance-class-misassertion"><name>Provenance-Class Misassertion</name>

<t>A client may assert a provenance class that does not correspond to how
the input signal was actually observed; for example, asserting the
<spanx style="verb">active</spanx> class for a signal that was passively observed, so as to
route an individual-attributable inference to server-side compute.
The asserted provenance class is a claim, and the inference service
MUST NOT treat it as self-certifying.  The service SHALL establish the
provenance class from substrate it observes (the act that produced
the signal, the stream the signal arrived on, the presence or absence
of a principal-initiated trigger) and SHALL refuse a request whose
asserted provenance class is inconsistent with the observed substrate.
A provenance class established from observed substrate, rather than
accepted from a client assertion, is the integrity foundation of the
gate.</t>

</section>
<section anchor="cohort-floor-evasion"><name>Cohort-Floor Evasion</name>

<t>An attacker may attempt to extract an individual-attributable
statement through repeated passive aggregate queries whose cohorts
overlap such that the difference between two near-identical cohorts
isolates an individual.  The cohort floor of Section 5 bounds the size
of any single cohort but does not, alone, bound a differencing attack
across cohorts.  An inference service SHOULD additionally constrain
the <em>composition</em> of passive aggregate queries, for example by
refusing aggregate queries whose cohorts differ by fewer than the
cohort floor, and SHOULD record passive aggregate cohort definitions
in the audit log (Section 9) so that a differencing pattern is
detectable post-hoc.</t>

</section>
<section anchor="redirect-suppression"><name>Redirect Suppression</name>

<t>A <spanx style="verb">redirected</spanx> negotiation response (Section 6) directs a client to
perform a passive-individual inference on the device-local daemon
rather than server-side.  An attacker positioned between the client
and the inference service might suppress or rewrite the <spanx style="verb">redirected</spanx>
response so that the client believes a server-side inference is
unavailable and abandons the inference, or believes a server-side
inference occurred when it did not.  Negotiation responses SHOULD be
carried over a channel authenticated by the cryptographic identity
envelope of <xref target="MCPDNS"></xref>, so that a consuming client can verify the
response bears the inference service's declared signing key, and a
suppressed or rewritten response is detectable.</t>

</section>
<section anchor="device-local-daemon-compromise"><name>Device-Local Daemon Compromise</name>

<t>The device-local daemon (Section 4) holds passive-individual derived
statements that, by Section 3.3, never reach a server.  Compromise of
the device-local daemon exposes those statements.  The gate does not
make the device-local daemon's storage secure (that is the device's
responsibility), but it does ensure that the blast radius of a
device-local compromise is confined to a single device's
passive-individual derivations and does not extend to a server-held
aggregate of many principals' passive-individual traits, because no
such server-held aggregate exists.  The compute-location gate's
routing is itself a blast-radius mitigation.</t>

</section>
<section anchor="audit-log-integrity"><name>Audit-Log Integrity</name>

<t>The per-event audit record (Section 9.1) is the after-the-fact
evidence that the gate operated.  An attacker able to amend or delete
audit records could conceal a server-side passive-individual
inference.  The audit log MUST be append-only; admitted records MUST
NOT be retractable or amendable by the inference service operator.
Where the audit record is emitted to an organisational identity
substrate per <xref target="POLICYPROV"></xref>, the append-only property of that
substrate's ingestion surface carries the integrity requirement.</t>

</section>
</section>
<section anchor="privacy-considerations"><name>Privacy Considerations</name>

<t>The compute-location gate is, in its substance, a privacy mechanism;
its routing function is a privacy decision.  The considerations of
<xref target="RFC6973"></xref> apply, and three are operative here.</t>

<section anchor="provenance-class-as-a-consent-boundary"><name>Provenance Class as a Consent Boundary</name>

<t>The gate's central privacy property is that consent is keyed to
provenance class, not to trait category (Section 7.1).  A principal
controls not merely <em>what</em> is inferred about them but <em>from what
manner of observation</em>.  A principal may consent to active-class
inference of a disposition while withholding consent for
passive-individual inference of the same disposition; the gate honours
that distinction at the wire layer.  An inference service that
collapses the distinction, treating consent for a trait category as
consent for all provenance classes of that category, has not
implemented the privacy property this memo specifies.</t>

</section>
<section anchor="local-only-retention-of-passive-individual-inference"><name>Local-Only Retention of Passive Individual Inference</name>

<t>The passive individual provenance class is routed to device-local
compute and device-local retention (Sections 3.3, 4, 8.3).  The
privacy consequence is that the inference service holds no
server-side, individual-attributable representation derived from
passively observed individual signal.  A principal's passive
individual derivations are, by construction, not present in the
inference service's data holdings, not subject to the service's
breach exposure, and not reachable by a server-side query however
authorised.  The principal's later election to contribute such a
derivation to a server-held inference is an active-class act
(Section 4) and is independently consented.</t>

</section>
<section anchor="third-party-stream-inference"><name>Third-Party Stream Inference</name>

<t>A principal's authorisation of a third-party platform's data-access
grant is not consent for an inference service to infer identity
statements from that platform's stream (Section 7.2).  Inference from
a third-party stream requires a consent class distinct from, and
separately revocable from, the platform authorisation.  This
separation matters because a principal's mental model of a platform
authorisation is "this platform may use my data on this platform",
not "any inference service may derive identity traits from my
behaviour on this platform".  The gate's consent classes make the
second a separate, explicit, revocable grant.  Inference from a
third-party stream conducted without such a separate consent class is
a privacy violation that the gate is specifically structured to
prevent.</t>

</section>
<section anchor="regulatory-context"><name>Regulatory Context</name>

<t>The compute-location gate's routing of passive individual inference
off the server is consistent with data-minimisation expectations under
data-protection regimes generally, and with <xref target="GDPR"></xref> in particular: a
derivation that is never computed server-side produces no server-side
personal datum to minimise, retain, or erase.  Implementers operating
in jurisdictions that categorically prohibit certain inferences in
certain contexts (for instance the prohibition under <xref target="EUAIACT"></xref> of
emotion inference in workplace and education settings) should note
that the compute-location gate is a routing-and-consent mechanism and
does not itself satisfy a categorical prohibition: a categorical
prohibition bites regardless of provenance class or compute location,
and an inference service subject to one MUST refuse the prohibited
inference outright rather than route it.  The gate composes with a
categorical refusal; it does not replace one.</t>

</section>
</section>
<section anchor="relation-to-companion-memos"><name>Relation to Companion Memos</name>

<t>This memo composes with four Morrison-family Internet-Drafts.</t>

<t><xref target="MCPDNS"></xref> supplies the DNS-based discovery surface by which a client
locates an inference service, and the cryptographic identity envelope
specified in <xref target="MCPDNS"></xref> Section 7.  This memo introduces no new DNS records
or labels.</t>

<t><xref target="IDPRONOUNS"></xref> supplies the <spanx style="verb">~handle</spanx> namespace by which principals and
substrates are named.  This memo introduces no new handle category.</t>

<t><xref target="SUBSTRATE"></xref> supplies the substrate-observation posture under which the
device-local daemon (Section 4) coordinates with the principal's other
sessions; that coordination introduces no path by which
passive-individual derived statements reach a server.</t>

<t><xref target="POLICYPROV"></xref> supplies the organisational identity substrate to whose
audit-signal ingestion surface the per-event audit record (Section 9.1)
SHOULD be emitted.  An inference service operated alongside an
organisational identity substrate inherits that substrate's append-only
audit posture for the compute-location gate's audit trail.</t>

<t>The compute-location gate is the wire-layer codification of the first
clause of the identity-as-inference principle: no inference without a
compute-location gate.  The companion memos codify adjacent clauses
and surfaces of the same principle; this memo is the clause concerning
where inference is permitted to compute.</t>

</section>
<section anchor="document-history"><name>Document History</name>

<t>draft-morrison-compute-location-gate-00 (May 2026):</t>

<t><list style="symbols">
  <t>Initial submission.</t>
  <t>Defines the three provenance classes (active, passive aggregate,
passive individual) and the immutability of a signal's provenance
class.</t>
  <t>Specifies the device-local daemon as the compute location for
passive individual inference.</t>
  <t>Specifies the cohort floor for passive aggregate inference.</t>
  <t>Specifies the wire-layer negotiation (inference request, negotiation
response) performed ahead of inference.</t>
  <t>Specifies consent-class matching, the distinctness of provenance
class from trait category, and the wire-layer refusal.</t>
  <t>Specifies the routing function from provenance class to compute
location.</t>
  <t>Specifies the per-event audit record and the build-time data-flow
verification.</t>
  <t>States the scope boundary excluding cryptographic exclusion
guarantees from the specification.</t>
</list></t>

</section>


  </middle>

  <back>


<references title='References' anchor="sec-combined-references">

    <references title='Normative References' anchor="sec-normative-references">

&RFC2119;
&RFC8174;
<reference anchor="MCPDNS" target="https://datatracker.ietf.org/doc/draft-morrison-mcp-dns-discovery/">
  <front>
    <title>Discovery of Model Context Protocol Servers via DNS TXT Records</title>
    <author fullname="Blake Morrison">
      <organization>Alter Meridian Pty Ltd</organization>
    </author>
    <date year="2026"/>
  </front>
</reference>
<reference anchor="IDPRONOUNS" target="https://datatracker.ietf.org/doc/draft-morrison-identity-pronouns/">
  <front>
    <title>Identity Pronouns: A Reference-Axis Extension to ~handle Identity Systems</title>
    <author fullname="Blake Morrison">
      <organization>Alter Meridian Pty Ltd</organization>
    </author>
    <date year="2026"/>
  </front>
</reference>
<reference anchor="SUBSTRATE" target="https://datatracker.ietf.org/doc/draft-morrison-substrate-observation/">
  <front>
    <title>Substrate-Observation as an Alternative to Envelope Coordination for Concurrent Sessions</title>
    <author fullname="Blake Morrison">
      <organization>Alter Meridian Pty Ltd</organization>
    </author>
    <date year="2026"/>
  </front>
</reference>
<reference anchor="POLICYPROV" target="https://datatracker.ietf.org/doc/draft-morrison-org-alter-policy-provision/">
  <front>
    <title>Policy Provision and Governance Inheritance from an Organisational Identity Substrate</title>
    <author fullname="Blake Morrison">
      <organization>Alter Meridian Pty Ltd</organization>
    </author>
    <date year="2026"/>
  </front>
</reference>
<reference anchor="MCP" target="https://modelcontextprotocol.io">
  <front>
    <title>Model Context Protocol Specification</title>
    <author >
      <organization>Agentic AI Foundation</organization>
    </author>
    <date year="2026"/>
  </front>
</reference>


    </references>

    <references title='Informative References' anchor="sec-informative-references">

&RFC3339;
&RFC6973;
&RFC7942;
<reference anchor="GDPR" >
  <front>
    <title>Regulation (EU) 2016/679 (General Data Protection Regulation)</title>
    <author >
      <organization>European Parliament and Council</organization>
    </author>
    <date year="2016"/>
  </front>
</reference>
<reference anchor="EUAIACT" >
  <front>
    <title>Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act)</title>
    <author >
      <organization>European Parliament and Council</organization>
    </author>
    <date year="2024"/>
  </front>
</reference>
<reference anchor="DWORK" target="https://www.iacr.org/archive/tcc2006/38760266/38760266.pdf">
  <front>
    <title>Calibrating Noise to Sensitivity in Private Data Analysis</title>
    <author fullname="Cynthia Dwork">
      <organization></organization>
    </author>
    <author fullname="Frank McSherry">
      <organization></organization>
    </author>
    <author fullname="Kobbi Nissim">
      <organization></organization>
    </author>
    <author fullname="Adam Smith">
      <organization></organization>
    </author>
    <date year="2006"/>
  </front>
</reference>
<reference anchor="SOLID" target="https://dig.csail.mit.edu/2016/solid/">
  <front>
    <title>Solid: A Platform for Decentralized Social Applications Based on Linked Data</title>
    <author fullname="Andrei Sambra">
      <organization></organization>
    </author>
    <author fullname="Essam Mansour">
      <organization></organization>
    </author>
    <author fullname="Sandro Hawke">
      <organization></organization>
    </author>
    <author fullname="Maged Zereba">
      <organization></organization>
    </author>
    <author fullname="Sarven Capadisli">
      <organization></organization>
    </author>
    <author fullname="Abdurrahman Ghanem">
      <organization></organization>
    </author>
    <author fullname="Ashraf Aboulnaga">
      <organization></organization>
    </author>
    <author fullname="Tim Berners-Lee">
      <organization></organization>
    </author>
    <date year="2016"/>
  </front>
</reference>


    </references>

</references>


<?line 968?>

<section numbered="false" anchor="acknowledgements"><name>Acknowledgements</name>

<t>This memo grew out of internal architectural work on the question of
how an identity-inference system should decide not merely who may read
a derived trait, but where the derivation is permitted to compute.
The realisation that the compute-location question is prior to the
access-control question: an access-control refusal arrives after
the server has already computed and persisted the datum it declines to
serve.  That observation is the central insight behind this specification.</t>

</section>

    <section anchor="contributors" numbered="false" toc="include" removeInRFC="false">
        <name>Contributors</name>
    <contact fullname="Christopher Whiteside">
      <organization></organization>
      <address>
        <email>cwhiteside.engineering@gmail.com</email>
      </address>
    </contact>
    </section>

  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA819WXPcSJLme/yKMPWDRBmSpaO2qou0NRuWpK6mja4VWVM7
WyZrgZlIJlpIIAdAispe2/7t62eEB46kamwe5qG7KBIIxOHh4f755x6LxcL1
ZV8VZ/7B9abwL5rtbt8Xi9fNMu/Lpva/5D387X3bfCnqvF4WixdV3nX+Q7Pv
y/rWN2t/uSpqaOLgL+t10RbwjL8r+43/rWyhnfxQtP5Dsd53eYVP/1ovm7qD
N4qVadVTq0X3wOU3N23xBXoz2ZMHbtUs63wLXVq1+bpfbJu2LbumXizl8Uoe
X9zC44snTx38s7ht2sOZL+t147r9zbbsOnji+rAr8JerYlfUOAZX7toz37f7
rn/25MlPT545l+/7TdOeOe8X8D/v1/uq4s//XOWfC/9GPk9/bNrbvC7/QZ8/
8xdVDyN/U7Tlqsxr/x4m6HW/8o/+CR8ocvzjCb1VbPOyOvM32N6/hL+dwnjo
z/u2PPP0q7N/0jPOwQT2bXmz76d79mIDXeqb3QY+/9um7IuuXBX2U8s7/e1p
Ud+WdQF9rG//5Rb/St91ddNuYRhfCmz/w19ePHv69Cf58c9Pf/wef3zz4v3L
t1dn1K4K0MuyW8KKtgdc6DfNqqhAnmClv/a41H2zbCp/VbTwROe/lLmHBvz1
/74G8Vg27QoWHxuLU37vhH/blHMX8/a26M/8pu933dl3363yPu/bfPkZpros
+vUptPQdyNZ3A7HaLneLVd0tVjq076i5Fe2KZ0+e/QD/vHz5/sO7t+9+HU5H
2Bgw+LrZ1x30ELcCb5LFxdey86++9kWN0uj7xv9zk9erqog76urQ9cX2v+XE
lNLHxU4GNzExV7/+fHX94eL6VTovV/ubDj4B2/PdTQfiwNs77zx0jXpak+zh
jLyqvxRVs0O9BBJS1vzoumlRsJb7FmayB5Gi/fzfcpq6MNYmjnViqt6/e335
4t9Bjv4tnav3TVUuSYK+lCQmICH+F5RE1puXNWzzsqef122zxTl8R4Pq6FOg
dKM0aV/+O04U/HpBam6xoyGjXPGQJ2YLlE86TXPKZlcsy3XJJ8LUqOGrMJpb
nKClv7j0fwFJXtHTk4PZ4meW/JWdfOS0bIYddHjSpBr0+fPnqkF/+OnH5/Lj
jz99/wx//AU0SDqgD8XtvmJpf/Tq1xNo9+kP3/3w40/+0S9FXbSwrC9hYmmk
xZIei2+czI701b6FzYQrlrdVCasNuwcF6gUMe1lWyTie4kS/+vXi8uLF9X19
e/b9d09/+PNPHk57NApeNne1/2vebhsQQzjnP+yrovPw+EXb43KUKJUwiVVV
3pK98GjuDxfL/r9mNM++h3++/O3dh39Nx/Iir8ob2BPY7bcN9Ba1zhWqZFg8
3DQlNN+WsG8LnvEL2FKHrpxUNgv5b3IaH+p+g2fdXdN+PvLcX9q8/uzfLK9g
P7eHIw/+a3NzU/q3aMNsjzx2scq3/moLhlgyD09+mBTsu7u70zJftrQ783a5
Acn9rl8u8YXvnv/5xx9ArOMPp7vVGtU76KyXA9UOe3eFx9x7EBDcA6SrXxZL
WBsQ2vIfIA1XDa3zxW5Xyc7s/M85yglIyOuy/gw/4VR/6wxf1Ku2KP1VvoWF
PPLcq66DKXmT112zb488dwUy1DYgv3efiyOPvclvoaP/Bw7zm2NfvcrB3qn9
i3yXgw1RlccGcrOCEy3fbEGkfwFToDi6vt0GFCi80+zhN7fHunBdbv3PcGCA
2bV4XRTjXT6htcvb02WH9iBI0Gmx2n9HCqjD5f3OucVi4XM6TJa9c9cbMGS2
xbbxHetb2Ow9+BJDk9zf0kdzeHa5wRNq628OHozR5cbnblmVuoFh/MG8KINT
0ZHl6Guw5vsSWsp83tN37sDR8BU6Gg7fvilA5gpoBDevvgw93BUtSmSxyuit
0CtoRfpQO/2sefOurCodSkZWil8VcE5tSxgBHhtr0DbUEBi90LDbRa9mSb4S
/x6ahCZ8V96CBjn1/nrTFoUfPgxTl7eFW2HT9e2+7DbFCh4GPYgWUehVBj+W
NAsrnENuHv7WFqtFDiLRQy9KUIK7vMr8m4t/1wHIJC7Q+Kephu+v9vDxXP+y
KapVmH33BQ6XpoUOvIe+YQ/y29u2wHX0xp7xaI9AE8sGtmrvaxCEbV5V8Lse
1hnWdlXA4KBvHidtu9/OdgmcGn8ooQt4XFQHeHXX7OSwWVQFGIPJd6H5Hpe2
bkBwenaK8puKlDiuZr0CJb7a03zrCOIvk6agFZSIaoHfBbcQ23XSxRVNVVv0
OThLpKZwwlfFlxJmjvrALcHfSpZg7BP0tnWwReoO9hA2gp2S0dL6F7Qh8NkC
7YUlr6W4xwsSBwdGBChjOJxIsmFCSNoXJO3QI3aroWf7Fnt2twFVk8O//2Nf
gOewGsuiTFbwwc95pPRL2wvYPW7ZHnZ9c9vmO9geKCkgyPDiElQJ9ggtOx79
Xc4N7DsSVhwZqQOYwUu1hBqVetmv3b5d50tWEg2KPWEGNK/qarmoJ+DLv7PH
+ZF3r3hKqOC6HbaDT0RHDJ7CCcPt2KTWMFuXPtjl9GK0vj+eo/jWxZ2nlduh
PMMwSji+aKOsTln7bcsVfN+5P6G9Qn8io9FdTKsu8uNAYsCSgKF2YBIXaK7A
ZsfNCksWtqt7BB8u+y6jmQFFA78u4F8wKzBPJR2XGei4qkHX/RYmOoepLLoT
Nv9ZvXQO5yi0CY4/tAizf7UHNced6TxNf+5JVMJmypdL8KY8QQxN5XL4DKxI
U8geq7u7oj3zj+82jd/mB5C0fPWYNCKObBVHRvPv4DmYAdktZEXRVuu7olqL
So57Qzbb41M8UQqwxEBjeFaEyz50syNtaDvpb8kd4jMHO+R3OYhSs3Y5yiho
Gx5ZhX87+ALcbpqM66kjKsyGNOpgBP2GNFkhreG4b0BVtc3+dgPSUUPfqVFa
ajxQ/G2JZ/42x60L4+hhHlH4L1QQuEM0maLosPl12XZxoH4JqhMVJzbRN44U
Bx2Noug9CQqrOr+v2VAiexsHWrQZaVN4YpOjxNA3XF9uCz6QoAeiP7IwN4m+
g8XpcFS0jeRjvHouUWKzc4inJRpzBZrn2J9dCzoRpR57YtW+EQ6S4maJvj2K
N2k0/D4L9sPOnJguyOVdDnZTjYM9nTZHjM2RzdsmGU2L04WhzxYgZau4KCOT
AybhZzU4EnvDDewNY99ww6k1Q798PNTXj92c8TA2HVKzBCQOtFxRwQHewUZ4
rKetDvgxtPJb2J2hG6txs3w6ONLJ0dwIyuVhp6dJZgfGZ1KXHFguChzMAujZ
afvM0+Y4hK6yQjBWI6i7vuOdJt2oCulU0dEk015AwfdF1RWkhRxOThFtm0Xe
RQ19JlsyGVY0Bruw6RzJJ1jo5bpAZYcyAcfIRm0dtXT0/IFGC0JEO1S94XsO
msxXBESjuUIqYF+v0IqqQZmgZwS7je2sWoYWlkXsTBYG3jBswPJRvmrzu1pk
hFUKdAmO5rDt45yV3ZlLlgEPYT6QJjcItaq7q+R9bOyRZbMKaEv4Gn98tIbY
0QJ87wIPYRh9DVu4uYMPXPZm38ZRiz2kgkrqhRS+BCKCFU7zMRLieL44HZEq
AmNueTK3gu0wNrBQ5py84nH5uMOkiN6+u5aeH7gFXccKD51ltV/BQ9Q7UqFL
hDUfXQl68/TpSUZCP2V0qWzmLWxssIZbsr1CZIPsL/nCSlBAo1KNrfkwmJoE
lhCchaI4MQk4p7tq36X25t+5u9Dkv0H7utaOOtirQcsuBAo4OOZdxzrjZl9W
qwUdP7tyV9CpttwUy8+dC5Pw04mauWDq9ItNs4SdvCpBsaCSJ+s3nR6w+XUX
oqIElxSlWGTtiJm5bvZtQDgX63xbVgcCnmCR+8VLRCZhZyTGaGjpW0xRl5qi
JGdt03WLjqFq6I6Bs3GwYMJRywEy/5g5lcI/aMHC4rwlE9YFEzZTo1b6qpIT
FDH+LQ61pXjMyO79EwKseIATZINvvizW5IfCv3nOPxcgjRjL8Q/e/Hp1/SDj
/+LewJ8/vPpfv15+ePUSf77668Xr1+EHfsLBP979+lr+jj/FN1+8e/Pm1duX
/DLutcGvwKV8wFbng3fvry/fvb14/QDRux4V1qpZ7hkfbMk5vMETFZYbDgwy
d1AZdUvwH/GAqN3PL977p9/73yX09fH3j/Qzxr7wZzRKeOpIcfM/YaVAQHc7
sHbws3D+wgbdlT1Y4wQbdBtERfEkEvlcN1XV3OE+w5OpY3MXJxQ3ccMW527f
stiSFjADOXXX9BKaVGWz76Ab+q4c0K0GmlYjSUf13Tn2Z/HZsvW4jW4qghvQ
pajV5cROtYWgBCvqfhy0AxXWcqwmdFhO4M4i7zDgyxGw4hAmZJ1snHl1kfLo
Sox9JP8oZ3vUef8lr/aIy0R36YCDKbeMEFm/Cf85cpwyh2iyvJ+3hB6oN6OQ
QiHOFfpC8OwWrT1xtOgI9KZrZHOwUwPDfj84h2jQO4St256ipGQ0RtMuSxZC
kCyD+pB96mWDdh5EyhjHsK23Kt0KSEwATfC+gZqC2IAoqB5+Dj1/MbAXoed0
gItPI8hWHaAzPwGdDTw8+HDxtVju2Y64Cydy+EZnXD7Bvs4sPJR5isvAB9oc
dB/43KQ2SQgHQFhADMtlcU6SzHAN2TMVLfoRFGdkcTt3NQGPeYbHeFHVW8oS
QAv3Du2IYBQNbEy1K31oNSP/jWGsDTmZ08OKhndBDgpFDeSUggl+h7s0viR+
RM5A4sg+ehTX/inyEtDJvWvLnuQpmvWT44fZeWkmF4wT0C81zQputkW7r0mf
wEfJb2chIPZITZYKrQCbvwPXAmWVvfwsCptdSTNCM4TnJ56sGvZmoREUgIhF
wIrsK+rAYHngJUX5xGqy33JehhYBEYX3DKq4SIDIETCCQ7JAIO40Qk3XVUOi
RLtMYFIBVLvyHyD7AUSdk3OGhe7gA7IpwWIcoraT0/XsxOspDU3QnPPMBQ8/
9lDwE981wSwdILS4twywusxrst4KMfEFCK3NlNEksE0dteS+RrxhrTLub9HD
F3DSG3QbTA7FVsc6js8w1Y+gM4p8S0DM0n5PXBn+BEwWCEDXm2m8xzsmexn+
Fmb0xxMY0W8jnJaG1R92hNDAqQQ9iJ7FsUXVeAbrvsmIxhD5nXXjcXGDI5+n
8yDLrV4Powkw7C7tGh1A9J3z+534oY6HmfkkPJdPchrq0RnUilipZJUFm8aa
1GSMjtljzr0i+9WqbnKzA/w+eUwtQS7R2Sy+gnasDo6OeVSX0wGaOfgFcfx4
eLvh4a1xgXK7Fd2gNlNVrouIy+lp7viQn/kau0QJMEa8BEGY5I+OUbvgKMoH
oDG0z+gkANMKJivTLUDmVFS12MYkEkB+N8wFLMSfNDoV+H8Mg9tFKLv7DiAF
+lwax7LiESJe0o6iGWKbIvj3YoNxp/q2WIQdBo4xyNMtYui5OTCD/YDWP7pl
ilq7AL8Y7zI9lwRfUpSHRtqlj7huj/Ft1UwR6oj4U1HBCFtBPUFvk/ED3Vd8
R2bK7kzaDnKUsgmJW244Q0TR4Uik/sVsy5qm7m4DboW6F+Sf0Pnb9U2jusi8
Lt69FVJoJCPggZAVISQGS5SNhrJ16POMt9ypSIhuDYKs4EipEAliAIMGL4CE
NGqChm4Yx8S/fau9EgGHP4OxwyKs0cGLcFIabtoxeR4fsdOiDc4KzlYwMSPS
FqZ5ESWcZleMlnqgfXmyBEiyds4gDAsdDE13w6Cs64fnepiU/8EoTBKGHR/y
5oinA/WYqSFbdMKrs914RM4aC5J4a604cfHrCIKBl4PsWbbqwRJzqO1MIDt+
YhQSPtjwLy4BO8COuzAUy9kl5nWdCWJb8Xp2QgBhJ2qWULHRXFpzieKxaIw5
NMZYohNbKTUv41jHYu/GZroR9Ms4D39Q0s0M/heJesBbBxrBqZDfNftKJPL4
AkOv69vK6OF7ltSMJRzikQbA4C6txk1htpn1HBOfJ26i70+8uj38uPsmR9NC
z+qjiAvh4rDJWL8pBowEQk/wG7gfZ0XGNPMH1tW6BzOUBu66PpgJicCG9jAs
S87tcuPudymv71kmMtgpSIuThAc7Gjs6rLJziHLJudlwgAYhB0E+FO4DiYV5
s6dJlBXY327VnDPwpiE2fq07+p5O1gq/f+Fs0JfNpqmBJbyWJlEoqmQ2wrMo
t7uKllAkaCaYWbZoBKmdt3a4HGl8n+gqZKd0qkCM3FG0O1+Drr3LWwaAcTLF
139Ncv+SfX13+Q07bMpitpsqdxNbasIP183GylRAhQAfuEFkksGDBHO4H/dx
AfeZ+fiZc09PMXGhILhyYrSiP0PbHDr3YHeFfercs1PNuBEfa+yd0FdJF71t
UtUsdqL3s/sk4Ptx0ysgIao181WRwwiwFTMtA/w5UtiiAfcch4/6p4v8Dgt0
IKCYTBzYlm1+a4Ae6vl4saDt70/9q68MfE+3LcJqYICAxvOfkrazAKTlQ/AI
hFvwsuvEwoe9jyAhO8kYakGHF08ca5eSlUYh9oEVHAgx2ETS6wHPTufznOPD
Ypy3xQI3d9uFkWjELO8mLeMEvVNH85aP1zXs6M28IEdtVdCMs7Uh02L5marl
ESwHRYLByIMqVox8px6SRAYwuBG+mzmktBBD55tMmlSTuKFwy5rRcVQadJUf
X5j2xydoqmA9JhrclBVuPKKeBFKOSg1Nohsu/ogLkTHrz4obTfKC53blaPCK
0c6vCUd6oUXUC6UQYKYySdx07HBq/84HIF2ABeJelD525+Jkhw4JTArW8qa5
baKv5zTyQ9wAdot7tftBAxEnK4jTWGG5MVLKpoKFSvkAEsD0LwSYuuOuxyzK
GdHhfV3hAWI8EfKjLKUinFLlyJEy7gM7UlOYqZj9lFTAkcdbeH0A6LoR9qcs
AhQd9cENASKEpMMgfzhxEZcVwhHTyBjLi2iiAHgc5jMRpsB3mwKP5SWfkFdE
jKcwYiTG1RhkiwyG2ZVy4m8ed48CuDWvQBC+Uws4IHzTHvJwHaX3bdl9xvCo
5LhpFPOMuQN4HKwxVwX+hhQrbEMaTF1VF1xVXv+6yNuFNRBU0JWro6JCu13g
KdgYN5ST1CLpsL8rBA6Y8UkzEdsZqCS6F/MWgzQgO2VqdVmaw+A0NG0YdrRC
fl1+he1Flnke7XIvdnmyQCrwzAWQjUH2En/Z8Zex94EuEHzv43EOXnLdohQh
QaiQ2JjyVQbDwnYcDha2VEWBVuQGTmIRhjgpqCSGbJg3pvNbHcQhX1OOlNry
SOvo1mUwPvvCTFXH+/rcCGeJbL56v71Rgqf+yy9xFHUIzKTGfEp1d7dFvQd1
UB1Guy3GANQTL3ZVcxDb0XAkAnPpmc5cF3cW9xWG8fTJkydTMmQ5u4/Dsj32
Qdij/638fjTsv+RLpBKtbguErOPf4P/LDk5mzeayiyMgbR+xIiEDIUGJNDIi
XHQ8Uhi1LGIghGem25Q7tbaTUSjogiAxky4pUbhqUOkt1MkCuwKNIdSDMPX4
wJ5YUSbi/vQJnW4mZf5t1PPOGYbpXJR9nmo6ca6krNNvSVhBMlIWqCVDzh28
EDCvhF8bwz40o5a+x2pEjpQxXC9RGVHZcVQPO0enC5mWgaIvCzER+u8jX9Ha
Iy6h+Cdc2PF0lWKKMFMo59R2N8o2RVrYRz2Us9FpTePtG/S66y/KqmDR7EJA
8FzC1Czb+lXWYbVY25HV1Y+nlCe/5fZWHOMeTPEuLwUMRCGPnvsHfhBNKpGg
gZUwlj1WxmA2IvcwE1PVyWtZYlosbEebG2QS0hqTNsz7EPPGBiI1ak1WAQYN
o5T+jaT0k38ESgwOGyWVnbgz/45Dd5/YUv+U+U/qDgQdY38ZtfMnEVA/QR01
Owr2bQurpeb1tDtuw2vWY/7ED/6Nw9DQfwS769t0BBe+Yz9IjQ9Ycf0cv2gZ
v6NOlOjJKwM4CaoXhuTxIxrDeMKG4DnbBCXmRT4aTzVMWdr3k3PbIdPVUn1W
Ic7DB3DkIS79NwbC5wZfTw3bhi8noIBBaLoku1PCAUGRa1hccPhA4OjEfY8q
C5oIONqjSfWIL5+E7Ap0D0RVydHrvLQnNGGkB1hyQDDCiNyqbEvLggWbPbC8
GGlEQD2MAmeUz6G/oZ0BkykuReaV+oiz+V48ssDX8xObCLo/sUfCbiA7Rs6D
sXdEg5iwuXgNpqgkqaHHhGIxVcS3gN2bjI0kms02hhKmrDQTvGJdIZ6skTM7
M9iTwEJIwK2JwHMWSI0hRj3gYYzDEEgGXpkoBFibN9QEyjTm6h6xWNUEh4Yl
HZB8ARwdEzjGYa2USyOK3VgQoNpZ97MlNmd3y6ER2pzQ3Krb2RdKmBIps4V0
NqLNO1j8TzLnrD9n2CkxNm/2SkLydz6aHDHIdkK2NG9kPKFHtkfMBbTrRnm9
hB4bsz01VyJNRykiqtvkW5/kU3/T90DePhl/6xOiZZ8swvMJRtQ1pCHERk/y
ng+iEwQ1bqMOGFkndm+Rhl1j+uU3zTTbwLMsICdQ8x+i9cj2VlYFksDWsrGZ
TYTujOR1JKbvj6fPuf8rMH6Xf1hYWA/PCMk9gjGEL1GceYVlUXDkQh7mY5K9
tYMmuSKWD41uiebWsS6QdyNJiuybmVARgjjCmDDKkUZJCTC427tJe+UseSOc
Z7JQI1GZBAGCePPUJ6YOnqGxrWTnfFv8kzzsZFmHv4jfD26cCMv5wBAfAE6J
W5imtJPCIVEpSlxc8T2t7alfJXOVk7Nw8TJhfzId7zHjZI+Jdje9FeYwjAAy
Bnxisq6ALAKljNGqkFkXvXbi9LF8No77BebG+XzAjwhoyN/KTZDaqm4xuimn
F4Rgg1j0RGDnT2o3Sqm3N5IOpF783KfncthDPpEYFfP7WvnwOkUGb1SOpZIz
rYGl5m0agcC9L5zR87RZUfqdi4ZRHpOeRszQNUISQp4YUA79ZedfaoYyrd81
Ee5eiMVKrtSwvUnC6jxdNSPIQkz0IZNPzWE2a5mIE2YAk7RhFlw8WPGjNoaR
8CKSXImAT6EEFjeHtJGJGMtEg6SgwBBypl3jlSihF00i1LyTdjaZPLdc8kiq
84gfrLmIpcYIh9Q44j+F9EHHbcowWHs+3hAW6C1b5XFqinQF4ki98tJI7h7f
SdkJmX3MWL/sJZ+nE6x7VjOQzzuJu4A8arIoC4Ac/hzalD9NOUAUbGrIHaGU
LSwOVnkq44PVoTDLJYEFU88EAwQ3hVEdmENlHz/mpuivJ8cTikPI7iX5nBpA
TknqcC53NAZL5J4qW7GgxEEyfy3nBEchWS/BCFZho+06uR1zFsQskDononoG
p3CCU5w5t2A/YuxT4dvMJScrCywqeXQAAMw91xUEAU94zbL/tcKOENaR4dxJ
ZJaSbITAus3bz2zf9KPHmWnK3rBpVXxuQxN/NKYeJ/rpRPCkBaxtWyiwJd8+
HylpTijDx2D5MlF4+IvPFC1PlyesrNhdaSyepOp0vKiKG0yZTWMhDXUTunsT
S74/UVj6bZN+M6P0UwyLjybLtN9ruFoqkPKB5+Yi4ePuTzMhNDYvsdrkC8QP
LiQ1GATb5MiEQjUErpNscAAeM5NNSgZOZ5wMSS/uN2W7WjAJIBEH3lKqNt1g
ZbhC4SFMyhS5GlOPNvmXQg8I0rn2ezutLcaFRNJT72E3aBzn2Okr8FdMnV4I
DYo3RLAkx2J08fr61Qc2LZvWJSWlFqLVhya9mHEYNI8f5bk5n4Hj1fv+jz2m
LOeh6Elmj5+wadI5zVIM75vAO4c7NkvSC6nYxtTacspM0Kfjor7O/aYc5f+U
ZTeoLTFYhWwGktcpI7M4j+7vpKU/yGtRZz6CzmfkgOYdOfDzqHLdLBLLFh6u
B4pANHkyHVOgMu69VI1miCZw46IOPyElWn4XEpq40syKvF48M28wIiwvcBsI
iy0IFsMG4MUJfC8sgEKX+QB1C4AbwskKuVGjJ3TQGDFbwAou0PlG4fzEmOmx
oct2E2c7ch34WFLlHWtYeTmmTr45CnA9hdoGYyRIKRf1IrnJfLHcNGMI12Az
M7jMFDaLB3BeKyA0jfJv9tu8XoRMT/NKZggGEQOX4JdnMWWcQ/kfhHczRDkk
xhny9XrfkjvZoj+zgE7t6OyMW8e645L7VZlQx2Dvijc37/9mqMU5ACVOdfDv
swRbkA5Y33gaZEopxqGN3BE3quz3aeCfXZo1/buf4KrHmSF2l9EcA4VRpmVs
PFUxkhpxGllnLNbFtcpCDA8lhTGvaE1Xza01pTVG7YR+NlnD0CTLC6yhHaRC
HgnBwngxU1U93ExVj4CrZCG7gjZriycQL8CwLlyaJZUHFKcICo42ncDfdMI4
O5J0qjXCFmxWA9iyRxrrKp1rUN+nCSBUNCXzX6hCCS1MWGo+9mWdiIhaHbSW
XeYDSympsxKd7lW5kuMqMD0RE2y2yjAfj2uKvGPq2vVTtaoEnUumeWFLnYRq
VHb8Um2FcNae/DjLL3hKwI5W7ecquYP6+lcElBLf4HoqyL/Nd12SQjdVZCeA
rG6ADIdmKDbUY7xUA/tziZZODNSkrtVZgBUmDtXqLj8o4itVxvDBiRzUmLX4
QrsuGf5XyLiPPkWilwTU0PDy5NlGDP9VqNgmwKR0Ic0GQpYWpiC0mExRf0MK
T0h1C54uHhYM681RIB52jqmeLZfrWxAT05TsiiUG5gsLxLIC18npcl9OJrVK
WuB8ruCbLTWnsUMjfvAfmLtiLktvavUy/z6Sml4ThfAdTfh9yzphJ438Ocdk
sWGMcooWOh2rRJzZBSHx9wrJZMrYIP0OF0VlyoAhf0Swum/iZLMHcyRxB7qb
JX5mJjOBHo06ZG4GhCRkeiab0MyGG5aGicHpLOZEYehnT/jAdNZbkBybz/Kt
EnIMUUjXN8EUVBF9YwRlJlh7PNgTuEwhEiUGW/efjkLBXLqpoWfJ87HiXxLk
SYPHYmEaxrIEnzRVIIafZmbodOZ4YsDa34BLvzRM83xy0dzQqsKqrHFuAjt0
sDNj5FAc11wOG9oloqr+IP6kZf8O0ZFs6nV5u2/j7o4wd+QFB6CbYVZbNedI
+e1wSQSbQspRjCbJ2TBFbIm5lxQrC3UDM+bPcy8lrIDem8ul9Cjb3nYCJ7As
qk1wnoRu01LakQCri0tJMsn0YFeWVN1QwDXohRZfjqxc2xOuj4T9JJPogsxx
PIR+pgp115jjnhS3Ox72MlYmGvhS1YjT83KqzXfozkAckTkMXSDXIUXUVUvD
IlrwApPts1D22Zn6eYR+qw4xYS1JElKMC2sKiPaDD7+iD/No+b4drZaRlFTU
mCN1r2uqL5wZGJkcWXQYEQhIAveZwDLBFK+pIBp4m5xFbkc9BamnINLY12dh
GaBZfCSNsfLzYfxT96dQ14QW4CY4HJFtoVsafY84B9IPQYzczOM6TRR9/F3u
APlI6woH2HZ3HmgpetYGyU/yMwiIk0M+mUKQvnjCu8Fkg4N5HmufaMEwRN/Z
n6Pa/ay2QPuAtBIOceru4cGGYlu5BBywwpOyCoa1toNtEHKXsnFASer8YQSK
O+t6iT2FtwjThVcWSnLEch5JBkxuySWw2ZJ6iLyDk49u888aQuH2JV+NqKnB
n6fcV1oh+Ag4/DjF2AqMe5BVs5asuDhn5mR0SZ2efAqKMLCUPDM8cSilXoVW
a0OUy41P4UcbbaO9b7QaXqqx+Avieql+u6yFCd8EU3FaVaWE3jA8WUHShIcs
KRaCiN5YQxG1DfrVZ8HPd7EoKJw7lFUK+j7osUH6WD7g3H6bXcZs6i4szXyd
BJSXL2aOPKqavptRuHIphGhBTx67uAl1s5KYV3gY9v6tePn8TLG61VJ8Olyn
d9Jh7fcAHfCbogmS7pVKfmCL4Azl0SWhZOzIH7JiuZQmyjW3Qw2EcmnMabq3
4IrcH5Exi0DTwnBhdbJoXQPzhXZJSKuoEPOA5biIk0fiss5LKrxIsS0J9m9o
Dcjstkmr1n5kvWgNPywqwTmGcQCRHUUnrgo3flNri5ujeLgKeXo4myM5MOOy
qA4U5rOPYtmITm9lMJcTeoS0cElS86JvsqMblidCYOsu2WkPUbIQosViuKzq
aC7GOCh88iZ6b+SABSuUxwurQrPCu56DuqFxw2TocXj0kNOCU3YGDY45Y3Jh
7JWZXTQR4C/W4iJPFE6OaznxlZANxFOMSwat8dEeULujYJpkB6G4vm9LjBa2
/T3WYpw4LNiaMIcEtm/aRY75bliptdR6xTYXlUiHVfm54Fx3scTp6g3nXirc
XZKDwPlSv9O9Vx+jYLcNGekzaUtuIm9JwUXqZMQiMNS176xRrzPnlDtSIbGg
32xhTQhuPuMrJ9qDqQUOrSOJnnO3ihUncyFNNqDArHaWbKzcdAHfrw9a8SXa
RGZY1cFt6Q4CJRqkKWSaCCaWwD6ngHMxTAY7sqRa4rpLQg1BfBBOdvH3emHA
dcArYqJcILDHcLR01nFnzxK0994UthBRCPNKipemNgD9AdvGyQoUS06ER1S2
2zTV6sxF9r0gWLQk0xmotAJYoOQQitDlfNMXURqmTpnBsVrGEVJ+dsLvRPoi
0uknBZ2tusTxtOSKTq51SyIpvsvXdIa1YFvlXTFNsHSm5p10dxopsy0367U5
WBx2FuMoWrcAXEU89Hkl8eWzezKkgzUvBKVEhBAVViuOtAvO+iEKJcxTSKCE
0RLLapRorSzCa6plLb5CDK51VOlV73LDCA8Ct/i9BQVKLOMMs43wtjD/O10T
9zGcXVJjOXlzgbVBCCUEa6U7AR33RS7EkKIhj4nNJ684vnmoSQpKidKqsFMN
x3Y5x5TbCffCPFbE26U4x9xlJrQGSbaqWubU2pnDXamOQCeuoy2/P7rnBk5A
zpAGU6dgAmoLcspJgPuqZx1GTLSm9famHc1bTmed5w5ThnC3TlbA0Kti4mVN
Nbr5FY9/ap/VCFrvSpMc1qyOcY+VZNTZyk4GOpOpkDR7upViV8WIgmyGgXHz
KL8PIqWpQfQnd1OTAkPlecWsauMvnsSsAfb/YkjPmNMhBLG2g8iiD8KyKXeb
WOEfReUinWqxzWt4KVxWmeJwYAqAL45XRXZeWK8gISx+TktntD0aBkEopCgy
jPqYDD/sUt5Qkg54Ip8gmE+1SKY+xRReGct+B70t9yI9nr4Y6bEtu+vCMCXm
KpTEBD5UrhvLrvCRJQcZM/FXwnHLQIWXlDzT801pFBOw9zZxC9K/UAzGyCjf
GcLbBgPd4Ta3YTknodhJlqO5OstO1CKhGqdheblbKKTE1wPkp0wuV/HJ5Srb
QM4Ouei80OREhc6QxTjXmzNTzhjnzoU0gEGVeT3s7Pa9GfMbSa0z0tWNL0eK
5SvvvYiOTOoruhTlZzGfzvxv2BHyud7gpLyka1bgLb7X9/CHr57849fJZDMs
iphTNr6PT+6EsbfbxHxT7jloyC90i2+++nuOB2oE4MUmwq0Vyry1Pt6GwZte
VReqOLopGVO9UfdukxuwRt+d85Miu4BQ3WgLC5v9YPC1hBSRTdh00MCg7N9d
Pn1LjaFajLgTbu7Gmnu4LemFU8JtGeXfor6Z8Ar5sLautKM2jc8fQSnyffGz
hslDak7ZLFrqTKoRpuyWRHnqFYrHyS18J8wkK0dT6vsAMIKCD8GJg1JgXKDA
kAgNKDAnSoH5dt6Lmox0taBwb9i1iH5PrAzjkjuBlN2KV8Z8zpSPDE1yoGYj
XORQ0TG9VITTr8weYQItQ1OJlDsSO+JDR8EOgXJaBKIjBj88wYqFET8KwMRq
KGjAnYNaLTl00kkxtwEIMVNIO6zmTUGxA+zIzcGq++M7mr0RyfmwsXRxvJlC
K5XA+/xrUzfbg9BqtRS1xO7T2xAyHfmEDfawC+X8+H5P3rJyaWNYFPadtoTj
jUnApkZHMVTi4VJE3MwuwPx9AL0n4rGhSv99KjDedGRqFuW2sAZlaQ8vdmK9
nt4klV4FZVnoWqXE3sKEkmDr2PtYoLM60Al4mUydv4L/7ilvJRbkSWf3KFqW
RGxuDi5CKeGOPEmoY2mVa0znbl9GsJ/wUo6O8Gn/6Z99uy/yCqFa6MSnGLY5
UkrIGXKBrV/RsdXYH2GFIX/EsEtEYXbjaF/EVH7wE1aOEwNHnOmZWjZKahgY
Y6rgTV9+PH3O95nY6+Gy+2ojEVJ/tBgAsZT30oWpY8glx5jp/k+nzzg0ofcI
JtGYRUCcqdHT2WKEpsXvg2s0sabgYTDOLrVWTXgOwwgTFcds1umlVDncgQYn
mxkjpj/+9P2zsLUSsYUNXQSWaCQKOL0fqxtuk+LrDnExzbzFhNWvO45BKCMA
UYdwbwOxT8KtYasvKIIImB8aAawuDTZ/pReLvKUKw+XWkajBlqDdJ4gapbGu
RN9NFtji3BkCNJ0GXYfXGyWHYMh2YeVx8faCMt5g/3I0s7OaMPCA6oYfzZeG
S2z3DlXdYcUXADrz91hKCGs+8HNun5a06nDXwas/8olQwfnby11hsTDAWC/Y
EmMRcH/GaaO40fF4H2klrsVe0/VXdNDa+kdrKSxYm2tXsN+dlqhehlvtaO+S
w9o7vY+6NBWXHoZLDTnTtNwSnijACONi7l6njjTbYuShjUgwOvNjvRNv/zAr
Fe7983AgOc3LxIFm9jLrUF8Hfk2/4fJx8K9fP1yCwQUuRME2PFihZS5TRYuY
XgYIq7NvUa7HEjd3HNHt4XXPaDRG0xPEGRPh0UhzjwRFmyw5hW68tH5CeLCd
H0s2MzUrRtpfScmhztQyGQMMt+yUcxrXSfLhy47teAqeh1pZ2C/+/VRiN3O0
InrfmlorG9DhbMWZQk53XOqXCgcGQOKcNGnxNd8SC0u6wcw5F1jJMX0tj7w+
Qf7GIAelBtM9HnwiHuOBGnrDNHOVmRbHCnfkrCCngH81MYJlTlF3qlFO1If1
YonDpfqJk+WEwvU7HOccfp0vSA/XZsZ0nk6Slob0ZcYypTB/vwn1ruKvPaZP
cXVve0wlgSqXXvpmrj6Amb291ZssNKNtTXBmSNAijsCRmgkUJY5qy6vaiiBW
tMfcxfh9e98gX3I4ei+zNxw7ZUGpC5+URiO3odQQCbiPpCCogoK1Vsm15+3F
xXwXVMzXv/qSd6XcQgGCly8xfZk2FngQ2x3RQouvRF06VgF2lBuPnk3B93eN
TC2JlwkZg220zqF7UOU79uRCGFJdWpi9kM9x10hlV1JVzPLlNsquqVTTmQJN
98X/KHooLJXyH4VL45xax9QUMcu0pAe9aTzvJfPrcB6dRAelb/P1VwlmSgJJ
4WoFF8If4phyVGZuRjOrrND7INmmLh2ffOk/Hs/r4m6uznImu4Y6LKfdREyS
31iZi2qP5WGZa+2SSdyRC0ulUzHYI8w5vaWYJfmDECH91X63a7nOtiTYTbKh
/RE2dKwjhHo5JLpNhXa+pS6Ps1eUD3jOZqeZWke21rDQyGcVNng6iPd3MmxP
SIJwg5gnGWsAhTEn9Sh4pDfgjhRfhhHcJDLs9nX+JS+rUPshv4H/b+oBNYsc
+OnmDPObcu0wzCa31ijORRyT8TJ1karokuKkSPrJ67rge8FYC9gwbQK4BmpU
AUZnJehWRBFM+W745p7MXVPImzl2tBfCTN6A9hlS02ImT8hBwQMLW/tcyLXP
udMV40gjr1lfGMGU5CsWd5byids/KJUMDoNS68vdF7TDOGV3pLyBMzXgcTay
QeUCLbM/qA/vTUfQM5/ZDFJRHZtGpRO/ZS5Kj7VnkFMwt60MCtahMVygHRHC
Q/LGw06XSuzcWDqSPmIrpJOLD8dyDyfuqtwzZOZGKSQyRIbB+YJEe/lR+O7c
DKuRa7FkOFaLOrnQh8mRJgNnDUcxlbjQS8Uezoaau8jLrxtHh6jlB8ZGmRJ4
T+BSgzJlJyUfkF2G07SQaUI37Nam9hFb+DXo9ks1QuRCoWkKfjwB8P4MWT6i
xC3gpwWyfx1M6kqYvfaye3XPB6o01GbcErcMi/1XsJOc/WwnFETyitCWvCdj
wg3dl3iE6Y1QhgE+wf4O94rx3VGTDPDZi0hlpAg1RI74kI9eJHdtztDBXbTB
ocnk7nrhhxseuy3nRHFfywofE8FNoUZjgEppDb44na4OZSLMt3uumNZWMoJG
HcgZm4vUIwWSz5nJMcxO4iw+eVgd3SD2ie8Jmguxrx9++vH5R2bxqLOEgGge
brxGQ0euk58qTUbIn9Zw0ZAqD1ECawJYhG7ZSyV75qDz26Zo2cirEiii8YOr
Rk2t4acnaYkWJRh2lgVDRbUeszvDdVhjct+WFOZjqXuMCSN43JLZbPIgHw/K
nzFQUGtZBJtzaI2AYeGzu00pGeN4TNmKcAaqnTHAYs0z2+R51Babpm72bWdT
tgTrGYbO5yx02gPLpgLnJFyPFNvJ2Gce9JpjG3Z1YlU4/ns1vp2r6HTLmViv
sDDc8AaykQhNJLaznJLhsKDLyT8EWg58aCJD09wne20Ih/fcKDadehnuUBte
BW/IQY8CdEk2xveZ//Pp8xMJRusIadqw/pSmKo/qFOhKsZVTN+kFHHPQyuAm
cntNl/sWZsqoCtLEtUnJ4Y9F4Qb1hTOJNTPSXpr7eIdGJYaHZXuIBhikocfk
8xu20sjookp0eoVLjCTxJVvm7GOC8Ka5QzMvVuiKlyHHYaKH3XotXTC8jXYv
WQCBjDB/BRep6Hp0wZezhqte4Ryh/yromFh1DqsnvafqSRwXSC5GvqdSlZ8q
dJVWrXJJ1apkG08qDCnla47faF0fKVaVVovH2GdS4spN1YnSg9bUidBajpbr
zokMU7Wt5M+kUrTKVzJJkg6rLxNxQ8LLanDmyRRTBMhUSMlDwy6dfZjPB5xT
oh9WbuH2wAJP/rV54AGX5nyQJn4FpzjXYo0RxWbbmGd9e3Ax/WLUtPFFYjmG
oJjVKXFSZT8WXMtC9b/MzCpJzGgJYWdMLCE2uKe4mFZNETZDYGsMSyi6aNnA
aDQpIrGSY/FnYuXb27fJpiCbXGGUW2Ql4yklN2wcscsedpaleSzE6FI2tnKI
LGpKe4xyUVUmOEQoGpO4MsQ9xthNL5sD/BhM6IxsTcnNI3LALy/ff/hIqdOB
53Q20EfiLx5JWN6ZW9QskKGEV7moE/a59L3QKggEg0CvmPEfmTJdvJ4P0bC/
72ETrEo5++yJL6sFPdiA8wq/hrM9L42WQV3o9LdLXq7OP+KSgWwlK/2PWsAh
Mynq91e/XlxevLj+iPYu2AnCDw7KuCZSEHGE+Ro0mAMh7Bc99rw78d2G/CeM
BcdUkVkiRK6isoD2tJCbzUIBnRTcYfEzY91JmyhhRnOW/snZgcJ/CiQf3+bt
iqjWSUVarYwXVj2WuXJKABwpFXPKIk+I3D4JGdhpLlbWwt1jnGHTWxRfMuXK
3mIeKbMld3bIoTC3ZaWBzULrg1U7hhlRCMXAvMI/kLqZxKHT76xR/71pwG0D
aV5Q3tOB3Pa2LvrFyxbccDQdFSIjmLFSFw9+s7jJEcCKnB51BU22qCCYNMGK
xw+mNgakpvE6r3idS6rYh27Fw1IKNozvHNLYrPrjDta+ym+KisZnaUHJGONF
FYGJZC5SjDe805mqzrGkeudbMZrmOyQsJ7XxsSvmIsmkJ5NXUHq9gtISw2do
YwkKGK6gVEkYMqioppaTGyv1Jkp7caU/csXkLPhVHL9i0qIR6ejvTW5HsZdw
3fFs9f4bkSg3yo2f8wpjWr7m439TOj60BFNcKiM1SbiPGIyAVrrOoSThzIHM
T6OpU53ekw45YDcsm1VCZOo1VwTpYntzDbHS0/LOMNRCeZIzFAZ70YcUf5sm
YBrskfUV7pOO+3II/GzPPeCaZHo5auLwh88nd47pnQrUfQL66L5yqRkxvFgg
omchoA5q9aXSkP5aItx8cG6FWnGxVaU5HNcCx7V48sQ/egNG6LMnz344oXLV
lxR5rnCdJXcCyza/xNhYYagpU1DAI/aLsnGILXNT90/HS47K7RZdXLlddx04
CQ+TMt9e7x5ZCLlfd92UFskTkn8kgSJAM3kZtiGaDdtP4rCWpzZBxhu/PU09
wfuYBtUys4Sa4kOI5cQfpakkH5zLRLAYUD2yM0LlWPb1EhwoO8IxGg92BGpy
2sxEFcDxVVrj1mYUYJJ9P2Q6+oSyT232uaZkMlc85N5yqgEhYcmBHrjg0Fpg
g3eR+52SzGHbLBb+BiPoWCxo+blu7iqs2EDHh/u/Z8yeKlb/88EaDuHiwf+z
lg5I0B3aX17pgIO6/MjzwSQoidyGFB4wifFqgnyaiXsAn2Wrxi/fHpLmE8aM
QTdIo+LQUyxYcyRNMaH0QFtVrNY9Z2nHupQdp7Lr3dCDJDd97mxciCoWAiVi
TcdRGJNUyJUeKhzcIfpLtoggyw87RZScuaxYvwkSRwo/7wdXoloKH/ouZDGD
g16SPFr/leXi/wPXExCzObMAAA==

-->

</rfc>

