Every figure below was fetched directly from planvivo.org (and Calyx Global's independent case study on V5) for this note. The question is not whether Plan Vivo's community model is real: the revenue-share rule and V5's verified-only retirement answer that. The question is what a vPVC is verified against, and whether a proof-gated field receipt could sit honestly beneath it.
No jargon. Plan Vivo's community model and V5 verification are real and credited below; the one fresh technical gap is worth naming plainly. Here's what closing it is worth.
A real contact in your security.txt → a researcher who finds a bug reaches you, not "[email protected]."
Your security.txt ships, but its Contact line is still the template's placeholder email, so a good-faith reporter has nowhere real to send a finding.
An agent front door (llms.txt / agent card) → AI representing Plan Vivo reads your model, not a guess.
Those files 404 today, so an assistant asked about Plan Vivo's community model and V5 verification has no machine-legible surface and paraphrases from third parties.
Per Calyx Global's independent case study, Plan Vivo's V5 standard introduces three certificate types: fPVCs ("future," ex-ante credits, of which "up to 90% ... can be claimed at any time during the crediting period"), rPVCs ("reported," quantified during monitoring but not yet independently verified), and vPVCs ("verified," the only type eligible for retirement). Calyx states plainly: "The newest version of the Plan Vivo standard does not allow retirement of unverified or ex-ante credits," a direct integrity fix versus V3/V4, where that distinction wasn't enforced at the point of retirement.
Source: calyxglobal.com/research-hub/research/how-moving-to-new-frameworks-improves-quality-faster-a-case-study-of-Plan-Vivo/ (referenced 2026-07-16, exact quotes above)
Plan Vivo is documented across independent sources as the oldest smallholder-focused carbon standard, distinguished from larger registries (Verra, Gold Standard) specifically by requiring that projects be community-led and that a defined majority share of revenue (historically at least 60%) flow directly to smallholder participants and community groups, not project developers or intermediaries. Credits (PVCs) are tracked on the S&P Global registry.
Source: cross-referenced across independent secondary sources (Model Diplomat, TracexTech), 2026-07-16, flagged here as directionally solid, not a direct Plan Vivo quote
www.planvivo.org actually ships a working /.well-known/security.txt (HTTP 200, 536 bytes), a real credit, since most entities we've checked don't have one at all. But the file's own Contact line reads "Contact: [email protected]," the securitytxt.org template's literal placeholder email, evidently never customized. Everything else agent-facing (llms.txt, ai.txt, /.well-known/agent-card.json) returns an honest 404 with an identical branded template (73,302 bytes), matching a nonsense-path control exactly.
Source: www.planvivo.org/.well-known/security.txt, llms.txt, control path (fetched 2026-07-16, contents and byte counts above)
Plan Vivo's V5 vPVC-only-retirement rule is the registry-scale version of a principle EWP already applies at packet scale: don't count what hasn't been proven. But a vPVC is verified against a periodic monitoring report cross-checked on the S&P Global registry, not against a single, dated, GPS-located field task. EWP's photo+GPS+signature+on-chain-settlement receipt is proposed as a candidate primary-evidence layer directly beneath that monitoring report, and Plan Vivo's majority-community-revenue rule is close in spirit to EWP's own worker-paid, no-recruitment design: two systems built around the same instinct (pay the people who actually did the work), applied at different scales.