The same-origin files /xrpl-bridge-directory.json and /xrpl-bridge-incidents.json are the browser-facing curated feeds. Each must supply snapshotType:"complete", normalizationVersion:"XRBC-BRIDGE-NORMALIZATION-2.0", a schema envelope, an unambiguous signed source registry binding every origin to a controllerId, controlGroup (common ownership or control), and sourceClass, plus revision, monotonic revisionSequence, recordCount, canonical recordsSha256, full manifestSha256, and updatedAt. Controller, origin, and control-group diversity are measured separately; favorable corroboration requires at least two control groups, so two domains or brands under common control are not counted as independent. Every removal must retain a structured tombstone with id, removedAt, reason, HTTPS sourceUrl and archiveUrl, controllerId, controlGroup, sourceClass, evidenceSha256, and matching removedRecordSha256/archiveSha256. New tombstones must hash-bind the exact prior accepted record and be dated after the prior snapshot. The manifest covers the normalized records, source registry, tombstones, schema, versions, record count, revision, sequence, and update time. Dynamic v2 route records must use an exact operational state from operational-confirmed, paused-confirmed, incident-confirmed, deprecated-confirmed, unverified-claim, or unknown; operations evidence must bind that exact state, and only operational-confirmed can be rank-eligible. A favorable comparative rank additionally requires a valid Ed25519 signature from a key pinned in this release and durable monotonic replay continuity outside ordinary browser storage. This standalone release keeps a cross-tab synchronized browser guard as a rollback alarm, but deliberately withholds favorable dynamic ranks until an append-only server-side continuity service is implemented. Partial, malformed, truncated, replayed, older, invalidly signed, or non-persistable payloads are rejected or withheld from favorable ranking without erasing the prior safety baseline. The publisher attests the signed control-group mapping; production curation must verify corporate ownership and shared governance before each release. The legacy DefiLlama bridges endpoint is not called: its current documented bridge API is paid and the old URL is not a dependable public integrity source. Bithomp, chain RPCs, government vulnerability feeds, and licensed aggregators may be normalized later by the read-only proxy; no private key belongs in this page.