Application controls
The build sets CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and X-Frame-Options headers. Input contracts are validated with schemas. Public IDs use a constrained format.
Credential integrity
Deterministic credentials include an integrity hash, signature algorithm, key ID, signature value, version, issuer identity, lifecycle state, and signed event chain. Test signatures are explicitly non-authoritative.
Secret boundary
No production secrets or live credentials are included. Test examples use masked keys. Production integrations require managed secret storage, key rotation, access logging, least privilege, and authorized issuer controls.
Threat boundary
The client is not trusted to calculate certification truth. Tier and lifecycle results originate in the deterministic kernel and canonical state. Renderers are projections only.
Compliance language
This build does not claim certification against an external compliance standard. Public statements describe implemented controls and explicit limitations only.