/** * AgentGuard(TM) Spend: External timestamp anchoring. * * The signed decision log proves *internal* order and integrity: each entry * binds the previous entry's hash and is Ed25519-signed. But those signatures * are produced inside the operator's own environment, so on their own they * cannot prove the chain was not re-generated (backdated / reordered) later. * * A `TimestampAnchor` closes that gap by binding the chain head's SHA-256 to an * EXTERNAL clock: a public timestamp calendar (e.g. OpenTimestamps -> Bitcoin). * After anchoring, "this hash existed no later than