Verification is distributable
Third parties verify receipts from bytes alone. Platform logs and dashboards are not portable proof.
Security
Executive summary of public trust boundaries — not a substitute for the canonical threat model or assurance case.
Third parties verify receipts from bytes alone. Platform logs and dashboards are not portable proof.
Public verifier endpoints reject ambiguous trust inputs. Missing keys, malformed attachments, or profile drift produce explicit failure codes — not silent downgrade.
Public recognition surfaces expose anchor facts. Permissioned disclosure and optional attribution require separate authorization — they are not implied by verification.
Proof Lab demo keys are public and rate-limited. Production deployments must use operator-controlled keys with published trust material.
See /.well-known/security.txt for coordinated disclosure contact.