Security

Security and trust boundaries

Executive summary of public trust boundaries — not a substitute for the canonical threat model or assurance case.

Verification is distributable

Third parties verify receipts from bytes alone. Platform logs and dashboards are not portable proof.

Fail-closed verifier semantics

Public verifier endpoints reject ambiguous trust inputs. Missing keys, malformed attachments, or profile drift produce explicit failure codes — not silent downgrade.

Recognition is not disclosure

Public recognition surfaces expose anchor facts. Permissioned disclosure and optional attribution require separate authorization — they are not implied by verification.

Demo vs production keys

Proof Lab demo keys are public and rate-limited. Production deployments must use operator-controlled keys with published trust material.

Report issues

See /.well-known/security.txt for coordinated disclosure contact.