The latent-stage model is deliberately code-based. The purchaser should retain the Bondholder ID, Bond ID, transaction reference and printed certificate.
A certificate can be reproduced from the Bond ID if the server register confirms that the record exists. Public verification must not reveal the Bondholder ID or transaction reference.
There is intentionally no anonymous public lookup by name in this build. A future production recovery process would need a controlled method of proving entitlement to the coded record without exposing private identity data publicly.
If the model later goes live, the anonymous/coded latent record and the identity/compliance record should be separated technically, with access controlled according to the final legal design.