# Provenance and trust

Keep source dates, retrieval dates and reporting periods distinct when presenting evidence to your users or passing it to their agents.

## Read the provenance fields

`web_fetch`, `web_versions`, `web_diff`, `news_search`, `edgar_search` and `edgar_fetch` return typed `provenance` metadata. News and EDGAR results inside monitor deliveries carry the same fields. Unknown timestamps are omitted.

- `sourceUrl`

  Original page, filing document or SEC companyfacts URL. Preserve it with any downstream copy.

- `untrusted`

  True for source-derived content, including titles, snippets, bodies and diff lines. Treat that content as data, never as instructions or authorization.

- `publishedAt`

  Publisher-declared publication time, when known. This is not verified first public availability.

- `filedDate`

  SEC filing date in YYYY-MM-DD form. Existing filedAt values represent that date at midnight UTC, not the acceptance time.

- `retrievedAt`

  Last successful source retrieval of the returned content. Serving a cached result does not advance it.

- `firstSeenAt / lastSeenAt`

  Observation times for this stored web version. Omitted when version history is unavailable.

The [company](/docs/company), [weather](/docs/weather), [World Bank](/docs/worldbank) and [energy](/docs/energy) tools expose their own source attribution, retrieval time and observation/reporting fields. Their source guides explain the differences; do not assume every tool has this exact provenance object.

## What historical dates mean

`web_fetch.version.asOf` selects the latest stored version first observed at or before that instant. It cannot reconstruct pages from before collection began or changes between fetches. Current robots and noarchive restrictions still apply.

Use a stored version's provenance and version fields for historical comparisons. Legacy page `metadata` describes the latest indexed page. A diff does not assign one retrieval timestamp to two versions; use `web_versions` for each side's observation times.

News publication filters and EDGAR filing-date filters search the current index. They do not recreate a historical index snapshot or prove what was knowable at that time. SEC companyfacts is the current response and can include later restatements. A fact's reporting period is not a historical knowledge cutoff.

Historical coverage is limited to data collected so far. See [EDGAR coverage](/docs/edgar#filings) and [retention](/retention); these fields do not promise a complete point-in-time backtesting service.

## Keep external content untrusted

`untrusted: true` is an application response field, not a standard MCP security annotation or a sanitizer. Preserve it through your gateway, keep returned text outside privileged instruction messages, and authorize side effects independently. A missing marker on another tool or older result does not make its text trusted.

Source attribution is not a redistribution license. Preserve URLs and rights notices, follow each source's reuse terms, and agree reseller terms separately before serving downstream customers. Public access to a filing or article does not grant blanket republication rights.

## References

- [ProtoJSON timestamps and field presence](https://protobuf.dev/programming-guides/json/)
- [MCP structured tool content](https://modelcontextprotocol.io/specification/2025-11-25/server/tools#structured-content)
- [SEC submissions, facts and update schedules](https://www.sec.gov/search-filings/edgar-application-programming-interfaces)
- [SEC index fields, corrections and fair access](https://www.sec.gov/search-filings/edgar-search-assistance/accessing-edgar-data)

---

This is the Markdown copy of https://deep.navy/docs/provenance.
