Settled under the ceiling you saw first.

Every call to the metered route (POST /v1/metered/chat/completions) is quoted from its own body before payment. A buyer whose client speaks the upto scheme, or who pays by card or credits, settles what the call actually used, times 1.15, never more than the quote. The ledger records both numbers per settlement; the settle transaction is on-chain. Machine-readable: /api/proof.

LATEST EXTERNAL SETTLEMENT (a buyer that is not us)

No settlement recorded yet. The metered route is new; this row fills in with the first outside buyer's settlement.

LATEST INTERNAL SETTLEMENT (our own daily canary, paying with our own wallet)

No settlement recorded yet. Internal by construction: the CI canary buys this route every day from our burner wallet to prove the settle-actual path, and the ledger files it as ours, never as revenue.

Nothing here identifies a buyer. The rest of the proof lives on /status (uptime observed from outside production), /revenue (transactions by rail and wire) and the source.