SYSTEM STATUS: INTERNAL / LOCAL / PLUG-IN READYSTAGING STATUS: NOT DEPLOYEDPRODUCTION AUTHORITY: DISABLEDTM-GATE-01: BLOCKED
PUBLIC AUTHORITY

Security architecture

Controls demonstrated in this build, production boundaries, and claims that are intentionally not made.

Canonical recordsFail-closed authorityLifecycle continuity
PROVENANCE VERIFIED™ corporate master mark

Submit an encrypted vulnerability disclosure

Application controls

The build sets CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and X-Frame-Options headers. Input contracts are validated with schemas. Public IDs use a constrained format.

Credential integrity

Deterministic credentials include an integrity hash, signature algorithm, key ID, signature value, version, issuer identity, lifecycle state, and signed event chain. Test signatures are explicitly non-authoritative.

Secret boundary

No production secrets or live credentials are included. Test examples use masked keys. Production integrations require managed secret storage, key rotation, access logging, least privilege, and authorized issuer controls.

Threat boundary

The client is not trusted to calculate certification truth. Tier and lifecycle results originate in the deterministic kernel and canonical state. Renderers are projections only.

Compliance language

This build does not claim certification against an external compliance standard. Public statements describe implemented controls and explicit limitations only.

CANONICAL AUTHORITY

Trust remains inspectable.

Every Test Mode result carries its evidence scope, policy result, signature state, lifecycle state, registry projection, and machine-readable response.

Run verification Quickstart
Deterministic test record loaded. Evidence eligibility and issuance authority are ready for inspection.