Summary

  • WHOIS began in 1982 as a public network directory for named people. Its simple query-and-response design was not built to preserve a tamper-resistant chain of number-resource control, distinguish public from protected history or authenticate users with different purposes.
  • RDAP improves structured access, transport security, authentication and authorisation. Its event model can state registration, change, transfer and other dates, but a current RDAP response is not necessarily a complete historical ledger or proof of every decision behind the present record.
  • RIR practice already demonstrates that history can be separated from current public data. ARIN's WhoWas provides approved users with reports of formerly public registration information; RIPE saves older operational versions while excluding historical person and role records from ordinary history queries.
  • Retention should attach to event and evidence classes, not one arbitrary number of years. Durable institutional facts may need long preservation; personal contact fields should be minimised, access-controlled and removed or obscured when their purpose expires, subject to lawful holds and claims.
  • Tamper resistance does not require permanent publication. An append-only event sequence, signed checkpoints, trusted timestamps, preserved decision records and auditable corrections can establish integrity while personal payloads remain encrypted, segregated or deleted under an accountable policy.
  • Access should be purpose-based. Holders should be able to inspect their own chain; counterparties should receive the evidence needed for a transaction with authority or consent; adjudicators and competent authorities should have governed routes; researchers should receive minimised or aggregated material.
  • Historical registration evidence supports a chain of control but does not conclusively determine property, contractual priority, route authority or legal title in every jurisdiction. The proof layer should state what the registry verified, what remains uncertain and which event corrected an earlier record.

A current answer proves less than users often think

A current registration response is a snapshot. It can show the name attached to an address block, an identifier for the record, its status, contacts allowed by policy, and dates such as registration or last change. It is valuable because operators need an answer that is current, standardised and easy to retrieve.

The snapshot is weak evidence of a sequence. Suppose a company acquired a network business, changed its legal name, moved the address registration, replaced its technical contacts and later entered insolvency. The current record may show the final name and a recent change date. It may not show the predecessor, the exact resource scope at each stage, the authority accepted for the transfer, a correction made during review or a restraint that applied for part of the period.

That missing sequence matters in ordinary commerce. A buyer needs to know whether the seller's claim connects to the recognised holder history. A lender needs to know whether a notice remained associated with the record after a corporate change. A liquidator needs to distinguish an operational contact update from a transfer of the registered interest. A holder facing a challenge needs to show when and why the RIR accepted its position.

It also matters in abuse and accountability work. An incident occurred at a particular time, not at today's date. The present contact may have had no relation to the resource when the traffic was observed. Treating the current holder as the historic operator can produce a false accusation.

The right response is not to make every old record public. It is to recognise that current publication and historical proof answer different questions. The first supports present coordination. The second supports reconstruction by people with a legitimate purpose.

The chain should be described carefully. Registration history shows what the registry recorded and which evidence or authority it accepted. It does not automatically prove ownership under every law, beneficial control of every company, physical custody of every router or origin of every packet. A reliable limited proof is more useful than an inflated claim.

WHOIS was a white-pages service before it became infrastructure evidence

RFC 812, published in March 1982, described NICNAME/WHOIS as a directory service for ARPANET users. The requested entries included a person's full name, postal address, telephone number and network mailbox. A client connected to port 43, sent a line and received human-readable text.

That history explains much of WHOIS's later difficulty. The service began with a community small enough to imagine a broad directory of identifiable entities. It did not begin as a property register, a transaction ledger or a privacy-preserving evidence system. Its protocol did not define a standard response structure, a differentiated access model or a cryptographic history of changes.

RFC 954 updated the service in 1985. RFC 3912 replaced the earlier protocol descriptions in 2004 while making a blunt observation: WHOIS had no provisions for strong security and lacked access control, integrity and confidentiality. The specification said WHOIS-based services should therefore be used for non-sensitive information intended to be accessible to everyone.

By then, the function had expanded far beyond a directory of research-network users. WHOIS services covered domain names, Internet addresses, autonomous system numbers and related contacts. Registration records were being consulted by operators, investigators, businesses and public authorities. The evidentiary expectations grew while the wire protocol remained spare.

This mismatch produced two common errors. One was to assume that because a field was available publicly it should remain public forever. The other was to assume that because the public service showed only the current field, older states had no legitimate value.

Both confuse access with retention. A record can be worth preserving without being worth publishing. A person's old telephone number may be unnecessary and harmful to disclose. The fact that a holder changed from one legal organisation to another on a stated date may remain essential to a dispute years later.

The lesson of 1982 is not that openness was wrong. It is that a white-pages protocol should not silently carry the constitutional burden of historical proof.

RDAP makes differentiated access possible but does not create a complete history by itself

RDAP was designed to remedy important WHOIS shortcomings. It uses HTTP and structured JSON. RFC 7481 provides a framework for access control, authentication, authorisation, confidentiality and data integrity through established security layers. A service can support anonymous public access and offer different information to an authenticated user with a recognised purpose.

RFC 9083 also defines events. An RDAP response can identify actions such as registration, re-registration, last change, deletion, reinstantiation, transfer, locking and unlocking, with a date and sometimes an actor. This is a significant improvement over an unstructured line whose meaning varies by server.

Yet an events array should not be mistaken for a complete ledger. The standard explains how an event can be represented; it does not compel every RIR response to disclose every historical state, underlying document, reviewer or dispute. A current entity may contain registration and last-changed dates while omitting the detailed sequence between them. An actor may not have been captured.

The protocol and the proof service therefore occupy different layers. RDAP can carry a protected historical response. It can authenticate the requester and return structured events. It can link to notices and related records. But the RIR still needs a retention policy, event model, evidence controls, access decisions and audit trail behind the endpoint.

This distinction matters because a technical upgrade can create an illusion of institutional completeness. JSON is easier to parse than traditional WHOIS text. A field named transfer looks authoritative. Neither property proves that every predecessor record was retained, that the date was independently verified or that later correction cannot be hidden.

A historical proof profile could build on RDAP rather than replace it. It would define the requester's purpose, resource scope, time interval, returned event classes, redaction, integrity proof, correction links and response provenance. Public clients could continue receiving a current view. Authorised users could request the historical layer through the same security framework.

The gain from RDAP is not automatic history. It is the ability to stop treating universal publication as the only way to make registration evidence accessible.

Existing RIR services already reject the choice between total secrecy and total publication

The debate is sometimes framed as though registries must choose between publishing every past field and deleting all history. Current RIR practice demonstrates more useful middle positions.

ARIN's WhoWas service gives authorised ARIN Online users access to historical registration information for an IP address or autonomous system number. Access must be requested and approved, and users accept terms. Reports can cover the public history of network, autonomous system, organisation and point-of-contact handles associated with the requested number. ARIN states that the reports contain data that would have been publicly visible in WHOIS.

This model establishes several principles. Historic data can have legitimate operational and research use. Access can require an identified user and stated terms. A report can follow associated records rather than return one flat line. The service can limit high-volume querying rather than make unrestricted collection the price of any access.

RIPE takes a different but related approach. Its documentation states that each old version of an updated entity is saved. Historical queries expose versions and differences for operational entities that still exist, subject to limits around deletion and recreation. Historical person and role data is not available through those queries. The RIPE Database Requirements describe this as a balance between operational or research value and filtering of personal data.

APNIC reported a WhoWas pilot in 2017 that extended RDAP to historical registration queries and highlighted changes between versions. The publication is evidence of an implemented experiment at that time, not proof that every feature remains available today. It nevertheless shows that structured historical retrieval can be built from RIR records.

None of these services supplies a universal answer. ARIN's approval model, RIPE's public operational history and APNIC's reported pilot differ in coverage, access, format and current status. That variation is itself informative. History is being governed as a product of purpose and risk, not simply copied from current WHOIS.

A common baseline could preserve regional discretion while ensuring that every holder can obtain a reliable chain for its own resources and that legitimate disputes do not fail because an old state was discarded or an old contact was overexposed.

The chain of control is a sequence of accepted institutional events

A useful history should not be a pile of full-page snapshots. It should identify the events that connect one recognised state to the next.

The chain begins with a registration or recognised legacy state. It then records consequential changes: allocation or assignment, transfer, merger or succession, legal-name change, account consolidation, subdivision, return, revocation, administrative correction, dispute lock, release of a restraint and movement between competent registration services. Ordinary contact maintenance can be retained at a lower evidentiary tier unless it affects authority.

Each event needs a stable identifier, resource scope, prior-state reference, resulting-state reference, effective time, recording time, decision authority, evidence class, assurance level and correction status. If the event concerns only part of a prefix, the scope must be exact. If an autonomous system number was included in a broader corporate transaction, its record should not imply that every asset followed the same route.

The event should identify what the RIR decided, not reproduce every assertion made to it. A transfer record might state that the registry accepted a change from recognised organisation A to recognised organisation B under a named policy and evidence class. The supporting file can remain protected. A reviewer can later verify that the required evidence existed and that its integrity has been preserved.

Corrections belong in the sequence. If an effective date was wrong or a transfer was reversed after fraud was established, the original event should not vanish. A linked correction should explain which field or conclusion changed, who authorised the remedy and when the corrected state became effective. Erasing the first state would make the record cleaner and the institution less accountable.

The chain also needs gaps. Early allocations may lack complete documentary evidence. A registry migration may have preserved a current holder but not every intermediate update. Those limits should be represented explicitly. A statement that the earliest verified state begins on a given date is stronger than a seamless story constructed after the fact.

Control, in this context, means the sequence of recognised registration positions. It should never be allowed to imply more than the evidence supports.

Retention should follow the life of a claim, not one fashionable number

How long should history be kept? The attractive answer is a single period: seven years, ten years or the life of the registration. Any universal number conceals more than it resolves.

Different records serve different purposes. The fact that a prefix moved between two legal organisations may remain relevant for as long as the resulting registration exists and for a period after return or transfer. A due-diligence document may be needed through the life of an agreement and any limitation period for claims. Authentication logs may have a much shorter security purpose. A former employee's personal telephone number may cease to be necessary soon after replacement.

Retention should therefore be defined by class. Core institutional events and their integrity commitments can be durable. Evidence supporting title or succession should follow the period in which the registration or a related claim can reasonably be contested, with extensions for a lawful hold. Operational logs should have a stated security and audit period. Personal attributes should be reviewed for necessity and minimised independently of the event they once accompanied.

The European Union's data-protection framework is a useful discipline even though RIRs and holders operate across many jurisdictions. Its principles include data minimisation and storage limitation, while its erasure provisions also recognise circumstances involving legal obligations and the establishment, exercise or defence of legal claims. That is not a global retention rule. It illustrates why privacy and proof cannot be reduced to keep everything or erase everything.

The policy should name the clock's starting point. Is it the date a document was received, an event became effective, the holder relationship ended, a resource was returned or a dispute closed? Different choices can add years. Silent ambiguity benefits the institution holding the records and burdens everyone who relies on them.

Periodic review is as important as the initial period. The RIR should ask whether the purpose still exists, whether the same proof can be preserved with less personal data, whether a hold remains valid and whether obsolete encryption or file formats threaten readability.

A defensible answer is thus a schedule of reasons. History lasts because a defined claim, accountability duty or continuity need lasts, not because indefinite storage feels safer.

Personal information is not the chain

Historic registration records often mix institutional facts with personal data. A company name, resource range and effective transfer date may sit beside the name, address, telephone number and email of an employee who submitted an update years ago. Treating the whole record as one indivisible entity creates a false choice.

The chain can survive the removal of many personal fields. The institution can preserve that an authorised representative acted at a certain assurance level without keeping the person's old public phone number in every accessible snapshot. It can retain a protected identity reference where needed for a dispute while publishing only the role. It can record that notice was sent and acknowledged without exposing the address to every researcher.

RIPE's exclusion of historical person and role records from ordinary historical queries demonstrates this separation. Its privacy statement also explains that historical data and update requests may be kept where necessary for registry purposes and legal obligations, while access to personal information is controlled. The result is not the absence of accountability. It is a decision about which part of the record should be visible to whom.

Redaction must be designed rather than improvised. Removing a name from displayed text while leaving it in a linked handle, free-form remark or difference view is not protection. Historic payloads should be classified field by field, and derived indexes should follow the same access rule.

Nor should a cryptographic digest be assumed anonymous. If the possible values are predictable, a person may be identified by testing guesses. Integrity commitments to personal records require privacy review, access control and sometimes keyed or salted constructions whose verification is limited to authorised parties.

The holder's own rights also matter. An organisation should not be allowed to invoke employee privacy to conceal who had authority for a contested transfer from an adjudicator. The answer is governed disclosure, not universal exposure.

Separating the person from the chain improves both aims. Privacy decisions can follow necessity. Institutional events can remain durable. The record no longer depends on preserving an obsolete address merely to prove that a transfer occurred.

Tamper resistance is an institutional property before it is a cryptographic feature

A historical service is valuable only if a later administrator cannot quietly rewrite the past. Cryptography can help, but the first safeguards are institutional: separation of duties, recorded authority, append-only event handling, independent review, controlled correction and preserved evidence.

At the technical layer, each event can include a digest of its canonical record and a reference to the prior accepted event. Periodic signed checkpoints can commit the registry to the sequence known at that time. Trusted timestamps can show that a commitment existed no later than a stated moment. An append-only Merkle tree, of the kind used in transparency systems, can support inclusion and consistency proofs without making every payload public.

RFC 9162's Certificate Transparency design is a comparator, not a ready-made rule for RIR history. It shows how signed tree heads and consistency proofs can make later removal or reordering detectable. Number-resource events have different privacy, correction and authority needs. A registry should borrow the integrity property, not pretend that certificates and address records are interchangeable.

Payloads can remain in a protected evidence store while public checkpoints commit to the event sequence. An authorised reviewer receives the event, permitted supporting material and a proof that the event was included in the checkpoint. A public observer may see aggregate checkpoint information without learning the personal data.

Tamper resistance must include software and key change. If an RIR replaces a signing key, the transition should be cross-referenced and publicly announced. If a defect caused incorrect commitments, the correction should be linked rather than concealed. Backups should be tested for restoration, not merely claimed to exist.

Independent witnesses can strengthen trust. Another RIR, an auditor or a public monitor can retain checkpoints, making silent retrospective alteration harder. Witnesses need not receive protected evidence.

No mechanism proves the original assertion was true. It proves that the institution accepted a stated event, preserved it and did not silently alter its place in the sequence. Truth still depends on evidence, review and challenge. Tamper resistance protects the integrity of institutional memory, not the infallibility of institutional judgement.

Correction and erasure are not opposites

A common objection to append-only history is that privacy and error law may require information to be corrected or removed. A common objection to erasure is that it destroys the chain. Both objections assume that the public payload, protected evidence and integrity sequence must be identical.

They need not be. If a public name is inaccurate, the current record should be corrected promptly. The historical sequence can retain a minimised event stating that an earlier value was corrected, without continuing to display the erroneous personal field. The protected original can be retained only if a defined legal or accountability purpose justifies it.

Where personal data must be erased, the institution can delete the accessible payload and preserve a non-identifying tombstone: event identifier, resource scope, date, reason class, authority and a statement that protected personal content was removed under policy. Whether any digest may remain requires assessment because a digest can still relate to a person.

Where a legal hold applies, access should tighten rather than expand. A hold preserves evidence for a stated matter; it is not permission to keep it public. The record should show the authority, scope, start, review date and release of the hold. Indefinite holds without review are retention by another name.

Corrections also need temporal precision. A later finding that an earlier transfer was invalid does not necessarily mean the registry should pretend the transfer never appeared. The history should distinguish the date of the original action, the date of the finding and the effective consequence. Courts, holders and operators may need to understand what the public record showed during the intervening period.

This layered approach makes accountability possible. The public sees an accurate current record and non-sensitive institutional history. Authorised reviewers can examine the evidence appropriate to their purpose. The integrity mechanism shows that corrections followed earlier states rather than replacing them invisibly.

An institution earns trust not by claiming never to err, but by making error, correction, redaction and lawful removal distinguishable events.

Access should be granted by purpose and relationship

Who may inspect the history? The wrong answers are everyone and only the registry.

The current holder should have broad access to the institutional chain for its resources, including the ability to see which events established its recognised position, subject to protection of unrelated people's data. It should be able to obtain a verifiable statement for due diligence and challenge an error.

A former holder should be able to obtain the portion concerning its period and transfer, especially when defending a claim. Access should not give it continuing visibility into the new holder's later confidential affairs.

A buyer, lender, insurer or auditor can receive evidence with the holder's authority and within the transaction's scope. The response should state what was checked, the date and any gaps. It should not become a transferable dump of historic contact information.

An adjudicator, court-appointed officer or competent authority needs a route grounded in applicable authority. The registry should verify the request, record the disclosure and limit it to the matter. Notice to affected parties should be the norm where lawful and safe, with delayed notice recorded when immediate notice is prohibited.

Security researchers and network investigators may have legitimate reasons to inspect past operational states. A tiered service can provide minimised data, time-bounded access, query logging and sanctions for republishing personal information. High-volume research may use de-identified sets reviewed for re-identification risk.

The public should retain access to current coordination data and a non-sensitive history of major institutional events. This supports market confidence without exposing every former employee.

Every access class needs an appeal. A holder denied its own chain, or a researcher denied a well-founded request, should receive a reason and a review path. Conversely, a person whose old data was disclosed improperly needs a complaint and remedy route.

Purpose limitation must be enforceable after access. Terms, technical controls and audits should restrict onward use. Perfect prevention is impossible, which is why minimisation before disclosure remains the strongest control.

The goal is not privileged secrecy. It is to make the proof available to the people whose legitimate decision depends on it, while denying curiosity the status of necessity.

Holders need a right to inspect, correct and carry their own chain

Registration institutions often ask holders to maintain accurate data. The reciprocal duty is to let holders see the consequential history attributed to them.

A holder should be able to request a machine-readable and human-readable chain for specified resources. The statement should include event identifiers, dates, recognised organisations, scope, policy basis, assurance, active restraints, corrections and declared gaps. Protected supporting evidence can be listed by class without being reproduced unnecessarily.

Inspection allows the holder to detect a mistaken predecessor, wrong effective date or unexplained discontinuity before a transaction or dispute makes it costly. A correction request should create a review case, preserve the challenged state and link the outcome. The RIR should distinguish a factual correction from an attempt to rewrite an inconvenient but accurate event.

Portability is the harder right. If registration service responsibility changes, the holder's chain should not remain trapped in an old institution. A successor should receive enough verified history to continue the state, while the former service retains proof of its period and fulfils lawful retention duties. The move should have one final cutover and no gap in the chain.

Carrying history does not mean the holder can edit it. The holder receives a verifiable copy and can submit a challenge. Institutional signatures and checkpoints prevent a self-produced document from being mistaken for the canonical record.

The right should also survive account loss. A company in insolvency, a successor after merger or an estate representative may no longer control the original login. Identity and authority recovery procedures need to support lawful succession without lowering protection for ordinary requests.

NRS can articulate this reciprocal compact positively. Holders commit to accurate, timely information and evidence. Registration providers commit to preserving consequential events, protecting people, allowing inspection and supporting a final migration. Each side can be audited against a defined obligation.

Accountability is stronger when the subject of a record is not merely observed by the registry but can verify the chain the registry asks others to rely upon.

Transactions need a closing proof, not unrestricted historical browsing

IPv4 transfers and address-dependent business transactions create a practical use for historical evidence. The parties need to know that the resource described in the agreement connects to the seller's recognised registration position and that the post-closing record connects to the approved change.

A closing proof should identify the exact prefixes or autonomous system numbers, prior recognised holder, new recognised holder, effective event, authority, active conditions and checkpoint. It should say whether the RIR verified legal identity, succession or policy eligibility and state any material limitation. It should not include every old contact field.

This document can reduce ambiguity without declaring universal title. RIR policies and agreements govern registration relationships; applicable property, contract, insolvency and secured-transactions law govern questions the registry may not decide. The proof should avoid words such as owner unless the governing institution and law support them.

Pre-closing diligence can use a protected history view to identify breaks. A legacy block may have moved from an early registration body into an RIR record. A company may have changed names several times. A reorganisation may have altered the legal entity while an operational brand stayed constant. Each transition needs evidence proportionate to the claim.

At closing, the parties should receive a time-bound status statement and later a final event confirmation. If a dispute or restraint is pending, it should be disclosed to authorised parties rather than erased by a clean-looking current response.

After closing, access should narrow. The buyer retains its chain. The seller retains proof of the completed transfer and its former period. Advisers keep only what their legal and professional duties require. Public users see the new current record and the non-sensitive fact of a transfer if policy permits.

This is a historical proof layer, not a public marketplace surveillance tool. It should not expose transaction price, confidential agreements or personal advisers merely because a registration changed.

The institutional benefit is finality with memory. The current record can move cleanly to the new holder while the evidence needed to explain that movement remains verifiable.

Disputes need evidence of what the registry knew at each decision point

When a registration is contested, parties often argue from different dates. One relies on an old letter. Another relies on the current RDAP response. The RIR relies on a case decision. An operator points to live routing. Without a chronological record, each item can be made to look decisive.

The history should show what the registry received, verified and decided at each material point. It should distinguish submission time from effective time, provisional status from final status, and notice from consent. If a lock was placed during the dispute, the event should state its scope and release.

Evidence must remain challengeable. A signed event proves that the RIR recorded a decision, not that a forged corporate document became genuine. The opposing party needs a route to present contrary evidence, and the adjudicator needs to see assurance levels and review notes appropriate to the matter.

The chain should also identify uncertainty. Early registration records may have incomplete provenance. The RIR may have verified a company name but not beneficial ownership. An inter-RIR transfer may rely on an attestation from the counterpart registry. Those boundaries help a court or arbitrator assign weight.

Access in disputes must be symmetrical enough for fairness while respecting unrelated data. One party should not receive a full archive that the other cannot inspect. A disclosure schedule can list withheld classes and the basis for withholding. An independent reviewer can resolve contested redactions.

Preservation notices should be narrow and timely. Once a dispute is reasonably anticipated, relevant records, access logs and checkpoints should be protected from routine deletion. When the matter and applicable claim period end, the hold should be reviewed and released.

A historical proof service can reduce the temptation to litigate through public WHOIS. Parties no longer need to demand that every old personal field remain online merely to preserve evidence. They can rely on governed disclosure from a record whose integrity is independently testable.

The right to prove a chain is ultimately a right to a fair chronology: the same events, dates, limitations and corrections available to the decision-maker and the parties whose registration position is at stake.

Legacy allocations require honesty about missing links

Internet number history did not begin with today's five RIRs. Early address registrations were made through predecessor institutions and later transferred into regional administration. APNIC describes historical resources that came through early registration transfers or predecessor arrangements such as AUNIC. ARIN's WhoWas coverage includes legacy addresses within its service region.

These records can have commercial significance, but age does not create complete evidence. A current RIR may have inherited a state without every original application, letter, contact or organisational change. Conversions between record formats may have preserved fields while losing context.

A proof layer should identify the earliest verified state and the provenance class of earlier material. It can say that a registration was present in a named predecessor record at a known date, that responsibility moved to the RIR under a documented transition, and that later events are preserved at a higher assurance. It should not invent a continuous chain back to 1982 where none can be demonstrated.

Legacy holders also need a correction path that does not make historical status depend on old contact data that can no longer be maintained. Corporate succession evidence, archived public filings and prior registry correspondence may be more relevant than an obsolete personal mailbox.

The same restraint applies to absence. A missing old entry is not proof that the present holder's claim is invalid. It is a gap whose significance depends on policy, evidence and law. The history service should make gaps visible rather than convert them into automatic adverse conclusions.

Market entities should price that uncertainty. A transaction involving a well-documented recent transfer differs from one relying on an early allocation with a partial chain. The registry can describe assurance without valuing the resource or deciding the transaction.

NRS advocacy can be useful if it defends holders against confiscatory assumptions while demanding honest evidence. Legacy status should not mean permanent suspicion, but neither should it become a substitute for a provable chain.

The legitimate objective is continuity across institutional generations, with confidence labels that reflect what survived rather than what later users wish had survived.

Public history should describe institutions, not expose former workers

A minimum public history can improve accountability. It might show that a resource was first recorded in a given period, moved between named legal organisations, entered or left a disputed state, and transferred between competent registry relationships. Dates can be rounded where precision would create risk and exactness is unnecessary for public use.

The public layer should generally omit former employees' names, direct contact details, authentication events, identity documents, signatures and correspondence. Those fields rarely help a member of the public understand the institutional chain. They can expose people long after their role ended.

Organisation names require care too. A sole trader or natural-person holder may be identifiable from the registered name. Publication must follow applicable policy and law, and a protected proof may be more appropriate than a public timeline. Even corporate history can reveal confidential restructuring before it is otherwise public.

The test is purpose. Does publication help current network coordination, accountability for a consequential registry action or informed reliance on the present state? If the answer is only that the data once appeared in WHOIS, that is not enough. Past publicity does not make perpetual republication harmless.

ARIN's WhoWas statement that reports contain formerly public WHOIS data is an important boundary on what that service returns, but it does not establish a universal rule that all such data must remain openly available. The service itself requires approval.

Aggregate publication can support research. RIRs can report counts of transfer events, corrections, locks, history requests, approvals, denials and retention reviews with explicit periods and denominators. Researchers studying individual chains can apply for minimised records under defined criteria.

This separation improves public debate. Observers can assess whether an institution corrects errors, how long disputes remain locked and whether migrations preserve history without browsing a former engineer's home address.

Institutional transparency is not measured by the volume of personal information released. It is measured by whether consequential decisions, authority, timing, correction and performance can be examined.

Audit should cover access as rigorously as alteration

A tamper-resistant history can still become a surveillance asset if access is weak. Every protected query should therefore leave its own auditable record.

The access log should identify the requesting account, verified role, stated purpose, authority or consent, resource scope, time range, fields disclosed, decision, reviewer where required and expiry of the permission. It should distinguish interactive inspection from bulk retrieval. It should record denied attempts without retaining unnecessary query content indefinitely.

Holders should be able to see a useful access history for their resources, subject to lawful limits. A delayed-notice mechanism can protect an investigation while ensuring that secrecy does not become permanent by default. Staff access should be included; privileged administration is not outside the accountability perimeter.

Independent audits should sample both grants and denials. Grants reveal overbroad disclosure. Denials reveal whether the institution is withholding legitimate proof. Auditors should test whether personal fields were redacted consistently across current records, historical versions, differences, indexes and backups.

Metrics need denominators. A report can state that a named service received a stated number of history requests during a defined period, approved a stated number by access class and recorded a stated number of policy violations. It cannot infer the worldwide demand for history from one RIR's users.

Access abuse requires remedies. Credentials can be suspended, onward disclosure investigated and affected people notified. Institutional users should not escape consequences because their purpose initially appeared legitimate. Repeated high-volume use deserves review even where each query could be defended individually.

Audit records themselves contain sensitive information. A law-enforcement request, planned transaction or dispute may be revealed by the query. Access logs need their own retention, security and disclosure rules.

Integrity and privacy meet here. The institution must prove not only that the history was not rewritten, but that it was not opened casually. A chain of control worthy of reliance includes a chain of custody for every protected view.

NRS can turn holder rights into a reciprocal evidence standard

NRS argues for accurate registration, operator rights and bounded authority. Historical proof offers a concrete programme in which those principles can reinforce, rather than weaken, registry stewardship.

The society can propose a minimum holder-history statement: exact resource scope, recognised states, consequential events, active restraints, corrections, gaps, assurance and integrity proof. It can insist that every holder has a route to obtain and challenge that statement without requiring old personal information to be public.

It can also define portability requirements. When a qualified registration relationship changes, the event sequence, evidence references, access restrictions and unresolved disputes must move or remain verifiably linked. The old provider cannot hold the chain hostage; the new provider cannot start history at a convenient clean date.

Reciprocity matters. Holders seeking strong proof must provide accurate legal identity, authority evidence and timely change information. They must accept that a valid adverse event or dispute cannot be deleted merely because it complicates a transaction. Privacy protects people; it does not create a right to falsify institutional history.

NRS could sponsor inter-service test cases using consenting holders and reserved data. Reviewers could check whether a name change, merger, partial-prefix transfer, correction and access revocation remain provable after migration. Results should identify the tested cases rather than claim universal performance.

The society should avoid promising legal title. Its standard can attest registration continuity and evidence quality while reserving property and priority questions for competent law and agreements. That restraint will make the product more credible to RIRs, holders, lenders and courts.

The positive institutional vision is neither a public dossier nor a secret registry vault. It is a portable proof service in which the holder can demonstrate its recognised chain, the registry can demonstrate its decisions, and affected people can expect their obsolete details to remain protected.

Rights become durable when they arrive with evidence duties on both sides.

No global retention claim can be inferred from partial services

Public materials establish that some RIRs preserve and expose forms of history. They do not establish a complete global denominator of retained events, deleted records, WhoWas users, dispute requests or transaction reliance.

ARIN's service documents its own coverage and approval conditions. RIPE's documentation describes its own version history and exclusions. APNIC's 2017 article describes a pilot at that time. These sources cannot support a claim that every RIR retains equivalent data, that every historic address has a complete chain or that a common retention period already exists.

The age of WHOIS is not a denominator either. A protocol dating to 1982 does not mean every record has been continuously retained since 1982. Institutions, formats, policies and service regions changed. Some old records were converted; some context may be unavailable.

Evaluation should therefore use declared populations. A registry can select all consequential events recorded during a period and report how many have complete prior-state references, assurance labels, integrity proofs and review outcomes. A transaction pilot can report the number of participating chains, gaps found, correction time and user assessments. A privacy audit can report the sampled fields and violations.

Negative findings should remain visible. If deleted-and-recreated entities break an accessible RIPE history, that limit should be stated. If WhoWas access is inappropriate for a class of high-volume research, denial is not evidence that the history lacks value. If a legacy chain begins with an inherited state, the result is partial, not worthless.

A mature standard should invite null results. Better history may not reduce transaction time where legal uncertainty dominates. Tamper-resistant commitments may not help a user who cannot obtain authorised access. A shorter personal-data period may have no effect on institutional proof if fields were properly separated already.

Precision protects reform from advocacy inflation. The case for a proof layer rests on identifiable transaction, dispute, accountability and continuity needs. It does not require invented worldwide percentages.

The right policy preserves events longer than exposure

The central mistake in historical registration policy is to give retention and visibility the same clock. If a field disappears from public view, institutions fear losing evidence. If a record must be preserved, privacy advocates fear permanent publication. A layered system gives each concern its own answer.

Consequential institutional events can be preserved for long periods, potentially for the life of the recognised registration and relevant claims beyond it. Their public representation can be minimised. Supporting personal evidence can have a narrower retention period, protected access and lawful holds. Operational logs can expire earlier. Integrity checkpoints can remain while payloads are removed where policy permits and privacy risk is addressed.

The policy should be legible. A holder should know what event classes are kept, for how long, from which date and for what purpose. A former contact should know when personal fields leave accessible history and how to request review. A relying party should know which historical statement can be obtained and what it proves.

Institutions should publish changes to these rules and assess their effect on existing records. A new privacy requirement may require redaction of old versions, not just better collection from tomorrow. A new transaction service may justify preserving an event class, not every document in the file.

The technology should support selective action. A system that can only keep or delete a whole snapshot forces bad governance choices. Event-level classification, separate evidence stores, protected identity references and integrity proofs make the policy executable.

Review should include cost and security. Indefinite archives accumulate breach risk and migration burden. Premature deletion shifts cost to holders and courts that must reconstruct a chain from weaker private documents. The institution should publish the trade-off rather than hide it in storage defaults.

Preserving events longer than exposure is not a compromise halfway between openness and privacy. It is a more accurate account of what each piece of information is for.

A historical proof layer would make present registration more credible

Current WHOIS and RDAP services remain essential. Operators need to know which organisation is recorded now and how to contact the right role. The historical proof layer should strengthen that current answer, not turn every query into an archival investigation.

It does so by making the present state explainable. The holder can show the accepted events connecting it to a predecessor. A counterparty can verify a transaction without collecting unrelated personal records. A court can inspect a chronological record whose integrity and corrections are visible. A former worker can leave a role without remaining a permanent public exhibit.

The reform also narrows institutional power. An RIR can no longer rely on the clean surface of a current record if a past decision is challenged. Its event history and correction record can be examined. At the same time, it gains protection against fabricated screenshots and selective private archives because it can provide a canonical proof.

NRS can advance holder rights without weakening uniqueness or accuracy. A holder receives inspection, challenge and portable continuity. In return, it supplies evidence and accepts that valid history cannot be erased for convenience.

The remaining legal limits should be stated plainly. Registration history is strong evidence of the registry relationship. It may support a chain of control. It does not settle every claim to property, contract priority, route use, beneficial ownership or liability. Different jurisdictions and agreements can assign different consequences.

That modesty is not a weakness. It allows the service to be exact about what it knows: this institution recorded this resource in this state, accepted this event under this authority, preserved this evidence class, corrected this error and disclosed this history under this rule.

The right to prove a chain of control is therefore paired with a right not to have every human detail exposed forever. The two rights depend on the same design choice: preserve institutional memory as structured evidence, rather than preserving old public pages as though publication itself were proof.

Sources