# Security Policy

## Supported release

Security fixes are provided for the current release line. This package is version `1.38.0`. The sole published author, editorial, and security contact is `mike@ns12.com`.

## Reporting

Report a vulnerability privately to the contact configured in `config/site.php`. Include the affected route, expected and observed behavior, browser/runtime, minimal reproduction, and likely impact. Do not include secrets or test against systems outside the supplied application.

## Safe testing scope

Permitted on an authorized local or staging copy:

- static review;
- PHP and JavaScript linting;
- API schema, CSRF, sequence, request-size, and rate-limit tests;
- browser compatibility, accessibility, and rendering-fallback tests;
- attempts to submit non-allowlisted challenge IDs, commands, evidence IDs, hypotheses, controls, or malformed JSON;
- attempts to load non-allowlisted Atlas filter, record, comparison, timeline, or evidence-state values;
- verification that Atlas query text is escaped and never interpreted as markup;
- verification that Human Control result text is constructed through text-only DOM methods, modules reset cleanly, and no interaction is transmitted;
- verification that Evidence Lab source IDs and lineage resolve, challenge codes are allowlisted, answers remain local, no-JavaScript explanations remain visible, and copy/download occurs only after explicit action;
- verification that internal directories and sensitive artifacts are inaccessible;
- canonical, robots, structured-data, FAQ/glossary parity, crawler-policy, feed/index, cache/session, and query-state tests on an authorized copy.

Not permitted:

- denial-of-service against a public host;
- credential attacks or account testing;
- probing unrelated domains, APIs, networks, or infrastructure;
- substituting real targets, live indicators, exploit payloads, malware, or weapon parameters;
- social engineering or collection of visitor data.

## Security architecture

### Request controls

- 16 KiB maximum JSON request body;
- JSON object requirement and bounded decode depth;
- CSRF token validation for state-changing simulation requests;
- per-session command rate limit;
- strict challenge/scenario identifier patterns;
- allowlisted commands and server-side phase preconditions;
- non-negative expected sequence and HTTP 409 resynchronization;
- no arbitrary URL, command, script, file, or state fields.

The Atlas and Source Classification Evidence Lab have no POST endpoint or state-changing API.

### Session controls

- HttpOnly session cookie;
- SameSite=Lax;
- Secure flag under HTTPS;
- server-authoritative simulation state;
- no account database or persistent authentication token;
- separate state keys for each challenge and deterministic seed.

Atlas filtering and comparison and Evidence Lab classification/replay do not use the PHP session.

### Browser controls

- nonce-based Content Security Policy;
- no object embedding or frame ancestors;
- microphone, camera, geolocation, payment, and USB disabled;
- WebXR and fullscreen limited to self;
- external scripts limited to the pinned Three.js CDN when enabled;
- Canvas and semantic HTML fallbacks if that dependency fails;
- Atlas uses local HTML/SVG/JavaScript only and makes no map, geocoder, or dataset request.
- Evidence Lab uses local HTML/CSS/JavaScript and Canvas only; it makes no application network request after page load and uses no persistent browser storage.
- Visual Viewport, orientation, resize, pointer-capability, and device-pixel-ratio values are used only for local presentation sizing and are not transmitted or retained.
- Renderer pixel budgets bound Canvas/WebGL backing-store growth on high-density displays; CSS resizing never grants authority over simulation state.
- Browser zoom remains enabled; compact layouts do not rely on hiding substantive evidence or controls.

### Human Control Lab controls

- all substantive content and case records are server-rendered from curated PHP arrays;
- page interactions are bounded to predefined checkboxes, selects, buttons, fictional timers, and deterministic local event sequences;
- no Human Control POST endpoint, upload, arbitrary JSON loader, external scenario source, account, or persistent user record exists;
- copied summaries are assembled with fixed labels and local numeric counts, not user-authored HTML;
- no raw pose, gaze, voice, identity, geolocation, or biometric data is requested or retained;
- real-world case links resolve only through the curated source registry;
- fictional teaching values are labeled and are not passed to the server;
- the page cannot issue an external action or create an authoritative military, legal, or safety determination.

### Source Classification Evidence Lab controls

- `data/evidence-lab.php` may reference only stable source IDs already present in `data/sources.php`;
- seven evidence classes and four challenge codes are fixed release allowlists;
- challenge-code query state changes only deterministic card order, receives `noindex,follow,noarchive`, and canonicalizes to the clean route;
- invalid codes fail closed to the default allowlisted sequence;
- all cards, source links, lineages, answers, unknowns, and limitation text are server-rendered before enhancement;
- answers and lineage inspection remain in page-local memory and clear on reload;
- the client is prohibited from using `fetch`, XMLHttpRequest, WebSocket, EventSource, `sendBeacon`, `localStorage`, `sessionStorage`, `innerHTML`, or dynamic code evaluation;
- clipboard and Canvas-PNG output require an explicit control activation and contain only fixed labels and aggregate local counts;
- no result is treated as a credibility score, factual verification, legal conclusion, or assessment of a person, institution, country, manufacturer, or system.

### Technology-provider directory controls

- `data/companies.php` is a fixed release registry; visitors cannot add, edit, rank, rate, or submit providers.
- Server-side query parameters are length-bounded and checked against category, stage, evidence-state, and sort allowlists. Unknown values fall back to safe defaults.
- Client enhancement uses local DOM APIs and `textContent`; it does not use `fetch`, XMLHttpRequest, WebSocket, EventSource, `sendBeacon`, persistent browser storage, `innerHTML`, or dynamic code evaluation.
- Query-state pages are `noindex,follow,noarchive` and canonicalize to the clean directory route.
- Outbound company/product links are curated HTTPS values, open only after an explicit click, and use `noopener noreferrer`. No user-supplied redirect or URL is accepted.
- Every operational statement retains an evidence-state label, source IDs, a human-control boundary, public unknowns, and a review date. A company statement is not promoted to independent verification.
- The directory contains no pricing, lead form, sales representative, RFQ endpoint, affiliate code, sponsored placement, capability score, lethality score, export advice, or procurement recommendation.
- The page is static/public-cacheable and does not start a session or create an analytics, contact, account, or behavioral-profile record.

### KillWebs.com sister-site controls

The sister-site bridge is a read-only publication surface. External destinations are curated in `data/sister-sites.php`, must use the official `https://killwebs.com/` origin, and open only after an explicit visitor action with `noopener noreferrer`. The page performs no iframe embedding, remote-script loading, background fetch, proxying, upload, arbitrary URL acceptance, persistent storage, account creation, or state-changing request. First-party sister-site claims remain labeled as first-party descriptions rather than independent operational verification.

### Atlas data and URL controls

- all publication records are curated in non-public PHP data files;
- record IDs, evidence states, functions, control modes, lifecycle states, regions, event types, and comparison references are validated against allowlists derived from the release dataset;
- unknown URL values fall back to safe defaults instead of creating records or HTML;
- search text is length-bounded and compared as text only;
- embedded JSON uses PHP JSON hex escaping;
- comparison rows and chips are created through `textContent`, not `innerHTML`;
- the comparison list is capped at four entities;
- copied views contain only the current public URL state and are generated after explicit action;
- map positions are abstract percentages and not geographic coordinates;
- source links come only from the curated source registry.


### Author-profile controls

- `data/author.php` is the once-only owner for public author identity; page, footer, structured data, feeds, and discovery outputs consume that record.
- The author page is static, public-cacheable, and does not start a session, process a form, store a message, load a third-party SDK, or collect analytics.
- The approved mail link is `mailto:mike@ns12.com`; the site does not transmit or retain the composed message.
- External profile links use HTTPS and `noopener noreferrer`; the personal URL also receives `rel=me`.
- No telephone number, home address, private profile, portrait, résumé file, client data, credential, or hidden biographical field is copied into the release.
- A self-published professional profile supports the displayed self-description but does not independently validate every career claim.
- Named site authorship does not replace original source attribution or report authorship.

### Publication and crawler controls

- `data/pages.php` is the reviewed source for public route identity, canonical metadata, breadcrumbs, concise answers, and discovery participation. Generated artifacts are checked against it before packaging.
- Clean public pages emit the same canonical in HTML and the HTTP `Link` header. Query-state pages emit `noindex,follow,noarchive` and canonicalize to the clean route. This reduces duplicate indexing but does not hide the query from the host, browser history, referrer handling, or recipients of a shared URL.
- Static research and answer pages do not start a PHP session. The interactive homepage and APIs retain private, `no-store` session behavior.
- JSON-LD is encoded with JSON hex escaping, created from fixed registries or server-rendered data, and does not ingest arbitrary user HTML, URLs, or scripts. Visible FAQ questions/answers and glossary definitions are the same arrays used for their structured-data entities.
- `content-index.json`, `source-index.json`, sitemap, feeds, and `llms.txt` are derived read-only files. They expose only already-public summaries and source records. They must not include internal report bodies, unpublished evidence, credential locations, session material, or hidden challenge answers.
- `robots.txt` is crawler guidance, not authorization. Internal routes remain protected by web-server denial even when a crawler ignores robots rules. APIs are disallowed from crawling but remain protected by application validation, CSRF, sequence checks, and session boundaries.
- OAI-SearchBot and ChatGPT-User are explicitly permitted for public pages. Training crawlers, search crawlers, and user-triggered fetch agents are distinct policy categories and should be reviewed deliberately during deployment.
- `.well-known/security.txt` publishes only the intended contact and public policy location. No verification token, DNS secret, console credential, IndexNow key, or API secret is included.
- `llms.txt` is nonstandard and cannot override `robots.txt`, HTTP status, canonical signals, or access controls.

### Content controls

- curated static challenge, Evidence Lab, Human Control, and Atlas catalogs only;
- no uploads, remote scenario imports, executable fields, or user-authored markup;
- correct answers and control quality removed from pre-resolution challenge API payloads;
- no real targets, exact coordinates, casualty models, weapon optimization, executable cyber content, or external actions;
- no capability or lethality score generated by the Atlas comparison.


## KillWebs.com external-link boundary

The reciprocal KillWebs.com bridge uses curated HTTPS links only. KillChains.com does not embed, proxy, execute, scrape at runtime, or transmit simulation state to KillWebs.com. External navigation occurs only after a visitor activates a link and uses `noopener noreferrer`. The destination remains an independent origin with its own logs, cookies, availability, content, security controls, and privacy policy.

The sister-site registry and focused audit reject non-HTTPS or off-origin destinations. First-party source records describe the sister site’s public claims but do not create trust in a real military system, authorize operational use, or bypass the site’s evidence and non-operational boundaries.

## Deployment checks

Before production:

1. use HTTPS and a supported patched PHP runtime;
2. confirm PHP session storage is private and writable;
3. verify `/config/`, `/data/`, `/includes/`, `/storage/`, `/tests/`, and `/realtime/` are denied;
4. verify CSP, `nosniff`, frame denial, Referrer-Policy, COOP, and Permissions-Policy headers;
5. run `tests/build-discovery.php --check`, `tests/companies-audit.py`, `tests/seo-aeo-geo-audit.py`, `tests/author-profile-audit.py`, `tests/evidence-lab-audit.py`, `tests/smoke.sh`, `tests/responsive-browser.sh`, and the browser smoke test;
6. test Evidence Lab classification, lineage reveal, keyboard/touch operation, no-JavaScript answers, deterministic replay, and local copy/download;
7. test the provider directory at the clean route and with query filters; verify server-rendered no-JavaScript results, local enhancement, outbound-link attributes, and clean/query-state canonical behavior;
8. test Human Control module reset, filtering, copied summaries, keyboard access, reduced motion, forced colors, 200% text, and compact/mobile layout;
9. test Atlas query manipulation, synchronized table behavior, compact evidence-list mode, and larger-screen map layout;
10. update canonical origin and contact address;
11. verify the clean homepage redirect, canonical/robots parity, query-state noindex, structured data, sitemap, feeds, indexes, `llms.txt`, and `security.txt`;
12. review host access/error log retention, including requested URLs with Atlas query strings;
13. retain the release checksum and source archive.

## Known architectural limits

- Session state is single-host and not appropriate for a load-balanced deployment without shared session storage.
- The request rate limit is session-based, not a replacement for host-level abuse controls.
- The external Three.js dependency is integrity-pinned by version URL but not bundled locally; the Canvas fallback preserves function if it fails.
- Browser-local challenge progress can be changed by the user and is not an assessment credential.
- Result cards are informational artifacts, not cryptographically signed certificates.
- Atlas saved views and Evidence Lab challenge-code URLs are ordinary URLs, not signed evidence packages. Query strings may appear in browser history, copied messages, referrer handling, and host logs. Evidence Lab answers and scores are not encoded in the URL.
- Atlas, Human Control, and Evidence Lab evidence labels summarize public records and do not eliminate the need to read the source trail, limitations, and unknowns.
- Human Control and Evidence Lab local results are illustrative educational summaries, not validated assessments of a person, organization, real system, or legal compliance.
- Search crawlers, answer engines, structured-data validators, feeds, sitemaps, IndexNow, and generative systems do not guarantee indexing, ranking, rich results, or citation.
- Automated viewport checks do not prove behavior on every physical safe area, virtual keyboard, browser engine, GPU, assistive technology, or WebXR headset; untested combinations remain unverified.

## Repository-memory exposure boundary

The release package contains `AGENTS.md`, `.uai/`, `docs/long-term-memory/`, and `agent-file-handoff/` for repository continuity. They are not public content and must be denied by Apache/LiteSpeed or equivalent Nginx rules. A live proof must confirm they return a denial and do not expose reports, internal paths, handoff material, or credential inventory metadata.


## Company-to-System Relationship Explorer

The relationship explorer reads only release-owned PHP registries. It accepts allowlisted GET filters and at most four released relationship IDs, creates no new relationship, and has no POST endpoint, account, database, upload, analytics, remote data loader, persistent browser storage, or arbitrary HTML insertion. Query-state pages are nonindexable and canonicalize to the clean provider route.


## Human Control replay and share security

- `data/human-control-replays.php` is the once-only owner of the `HC1` schema, compact module IDs, field order, allowlisted values, defaults, cross-field constraints, limitations, and compatibility language.
- The browser serializes no arbitrary DOM state or freeform user value. Unknown, duplicate, reordered, malformed, oversized, unsupported, checksum-invalid, and out-of-allowlist codes fail closed to released module defaults.
- Replay encoding, decoding, accessible text, comparison, and 1200×630 PNG generation are page-local. The feature uses no result API, persistent browser storage, cookie, analytics, background request, service worker, or external action.
- The checksum is an integrity check, not authentication, confidentiality, a digital signature, or an authorization token. Replay URLs should be treated as public links because query values may appear in history, referrers, security appliances, and host logs.
- Query-state pages remain `noindex,follow,noarchive` and canonicalize to `/human-control.php`; that search directive is not a privacy control.

## Anticipatory Intelligence Lab controls

- `data/anticipatory-intelligence.php` is a fixed release registry and accepts no visitor input.
- The page embeds one JSON presentation copy using PHP JSON hex escaping and the active CSP nonce.
- `assets/js/anticipatory-intelligence.js` may use only local DOM state and explicit clipboard access. It is prohibited from using fetch, XHR, WebSocket, EventSource, beacon, cookies, persistent browser storage, `innerHTML`, or dynamic code evaluation.
- The public route is session-free and public-cacheable; no write endpoint exists.
- The lab accepts no uploads, external URLs, live intelligence, names, IDs, travel records, policing data, targets, coordinates, weapon parameters, executable material, or arbitrary scenario definitions.
- All interactive values are fictional and drawn from allowlisted release data.
- The GAITE name and architecture remain explicitly conceptual and cannot be represented as current operational truth by the client.
- Copy output is fixed and aggregate. It contains no identity, location, raw timing, private note, target, real-world recommendation, or real-system score.

## Predictive Enforcement Explorer security boundary

The Predictive Enforcement Explorer accepts bounded GET filters only. It has no write endpoint, account, database, upload, arbitrary URL field, live record connector, runtime crawler, external API, or user-authored program record. Server-side filter values are length-limited and checked against release-defined allowlists. Optional JavaScript uses only the typed records embedded by the server and does not call `fetch`, XHR, WebSocket, EventSource, `sendBeacon`, persistent browser storage, cookies, service workers, dynamic code evaluation, or third-party scripts.

The public data contains no real-person profiles, watchlist identities, passenger records, police targets, operational coordinates, secret thresholds, or evasion guidance. The synthetic feedback-loop lab uses invented aggregate teaching values and cannot accept or produce an individual risk score.

## Source Review Center security boundary — v1.14.0

`/source-review.php` is a read-only, server-rendered publication surface. `data/source-review.php` is repository-owned data and is denied from direct public access with the rest of `data/`.

The optional `assets/js/source-review.js` enhancer:

- performs no fetch, XHR, WebSocket, EventSource, beacon, cookie, or persistent-storage operation;
- accepts no arbitrary URL, upload, HTML, script, or executable expression;
- filters only already rendered records;
- copies only stable internal source-review links after explicit user action.

The correction control is a `mailto:` link to `mike@ns12.com`. The site does not receive, store, parse, or automatically publish the message. A submitted email is not a public edit, authenticated report, confidential channel, or guaranteed response.

External source reachability is not checked at runtime. This prevents public page requests from becoming an SSRF surface, link-scanning proxy, vendor-monitoring service, or availability dependency. All lifecycle changes remain code-reviewed repository changes.


## Daily Challenge command-board boundary — v1.15.0

The command board is a presentation projection over the existing challenge API. It adds no endpoint, command, token, persistence layer, external request, or authoritative browser state. Protected evidence detail, correct-answer flags, control quality, ground truth, and counterfactual outcomes remain server-controlled and phase-gated. The browser may calculate display-only coverage and confidence-comparison values from already released fields; those values are not accepted back as authoritative state.

## Machine Leadership local-only boundary — v1.16.0

The Machine Leadership script operates over embedded released JSON and semantic HTML. It does not call `fetch`, XMLHttpRequest, WebSocket, EventSource, `sendBeacon`, cookies, local storage, session storage, IndexedDB, service workers, `innerHTML`, `eval`, or dynamic `Function`.

The feature has no write API, account, database, upload, arbitrary URL, live company or government data, external control path, or server-side result record. Reloading clears the interaction. The embedded data contains only repository-authored fictional institutions, bounded report descriptions, and governance teaching values.

## Claim Lineage security boundary — v1.17.0

`/claim-lineage.php` is a read-only publication surface. `data/claim-lineage.php` is repository-owned and denied from direct public access.

The optional browser module:

- uses only the JSON presentation copy embedded by the server;
- performs no `fetch`, XHR, WebSocket, EventSource, beacon, cookie, or persistent-storage operation;
- accepts only released filter values and stable claim IDs;
- creates no claim, source, correction, review state, authority assignment, or public record;
- copies only a stable internal URL after an explicit visitor action;
- inserts text through DOM text nodes rather than arbitrary HTML.

The route accepts no upload, arbitrary external URL, executable expression, live intelligence, private identifier, real-person risk input, watchlist entry, target, coordinate, weapon parameter, or operational action. Its Dataset and ItemList structured data describe the visible register; the release intentionally does not emit ClaimReview, Review, Rating, Product, Offer, or Certification schema.

## Institutional Authority Casebook security boundary — v1.18.0
The Authority Casebook is a read-only, session-free publication route. PHP validates query filters against released domain, status, function, and case allowlists and limits comparison to three stable case IDs. The optional browser module performs local filtering and comparison only. It has no network transport, persistent storage, dynamic code execution, public edit, upload, account, database, or factual mutation path.

The casebook cannot create a real-person risk score, watchlist entry, traveler record, military command, target, operational recommendation, or external action. Existing source, Source Review, and Claim Lineage registries remain the authority for evidence identity, lifecycle, and transformation.

## Change Impact and Supersession security boundary — v1.19.0

The Change Impact Explorer is read-only, session-free, and publicly cacheable. Its selector values are resolved only against the released source and claim IDs, and its event values are resolved only against the six typed event definitions in `data/change-impact.php`. Unknown or incompatible values fall back to a released default rather than creating a dynamic record.

The page performs no runtime source crawl, no server-side write, no public correction acceptance, no arbitrary URL fetch, no discovery regeneration, and no factual-state mutation. Client JavaScript can filter already rendered items, hide inapplicable allowlisted event choices, and copy the current public preview URL after an explicit click. It uses no network transport, cookie, persistent storage, service worker, dynamic code evaluation, or `innerHTML`.

A copied URL is not secret. It may appear in browser history, messages, referrers, or ordinary hosting logs, but contains only released source-or-claim identity and event state. Users should not attempt to place private information in the query string; arbitrary values are not accepted.

## Historical Change Ledger security boundary — v1.20.0

The Historical Change Ledger is a read-only, session-free, publicly cacheable publication surface. Event IDs, change types, scopes, statuses, releases, source IDs, claim IDs, route IDs, proof IDs, and decision IDs are resolved only against released typed owners. Unknown or stale references fail during registry load or focused validation.

The browser receives complete public event records and may only filter them, enforce a maximum-three selection, update accessible counts, and copy an allowlisted stable event URL after explicit action. It cannot submit, accept, apply, or persist a correction; edit a source, claim, program, page, decision, or proof; regenerate discovery; or create a new historical event.

The feature uses no account, database, upload, write endpoint, runtime crawler, background link checker, analytics profile, persistent browser storage, arbitrary URL input, dynamic code execution, `ClaimReview` certification, source score, legal conclusion, or operational action. Query states are `noindex,follow,noarchive` and canonicalize to the clean route.



## Ecosystem-link and production-evidence boundary — v1.22.0

The Evulgare integration is an external HTTPS link and typed public identity record. KillChains.com does not iframe Evulgare, load Evulgare JavaScript, transfer session state, receive production telemetry, or expose a production-accountability API. External links use `noopener noreferrer`.

The Research Navigator is session-free and local-only after page delivery. It performs no network request, persistent storage, identity inference, analytics collection, or server-side progress update.

## Cross-Lab Concept Matrix security boundary — v1.23.0

The Concept Matrix is a read-only, session-free, publicly cacheable page. Its client module does not use `fetch`, XHR, WebSocket, EventSource, beacon, cookies, persistent browser storage, service workers, `innerHTML`, `eval`, or dynamic function construction. Query values are bounded and selected IDs are checked against released allowlists.

KillWebs and Evulgare navigation uses explicit HTTPS links with `noopener noreferrer`. KillChains.com does not transmit concept selections, lab state, production telemetry, credentials, or visitor identity to either destination. Live Evulgare source records describe first-party public pages only and do not establish deployment, customer, certification, or production performance.


## Accountability Handoff security boundary — v1.24.0

The public lab is a static, local-only learning surface. The server supplies a bounded fictional scenario and allowlisted internal/external references. The browser can record local radio choices, reveal released routing, reset the DOM, and copy a fixed text summary. It cannot submit production evidence, change publication truth, create a liability determination, call an Evulgare API, or control an external system.

Security review must confirm:

- escaped JSON and text-only DOM construction;
- no `fetch`, XHR, WebSocket, EventSource, beacon, cookies, persistent storage, service worker, `innerHTML`, `eval`, or dynamic function construction;
- all external Evulgare URLs originate from `data/ecosystem.php` and use HTTPS plus `noopener noreferrer`;
- query state is allowlisted and nonindexable;
- clean requests remain session-free and publicly cacheable;
- no guilt, liability, customer, certification, deployment, or operational-performance claim is created from visitor input;
- preserved reports and internal memory remain denied as public routes.


## Machine Answerability Replay security boundary — v1.25.0

The replay is server-rendered and enhanced locally. It uses no account, database, upload, write API, analytics service, persistent browser storage, runtime crawler, arbitrary external URL, production telemetry, cross-site session, or external action. Query state is allowlisted, length-bounded, nonindexable, and canonicalized to the clean route. The client cannot modify the fixed event, ground truth, source state, claim state, authority state, assurance state, or publication truth.

## Machine Answerability Remediation security boundary — v1.26.0

The remediation route is read-only and session-free. It accepts only allowlisted safeguard IDs and presets, enforces a six-control limit, renders a complete no-JavaScript result, and stores no account, profile, production evidence, or persistent browser state. Its enhancement script performs no `fetch`, XHR, WebSocket, EventSource, beacon, cookie, `localStorage`, `sessionStorage`, IndexedDB, service-worker, arbitrary-URL, HTML-injection, or dynamic-code operation.

The browser cannot mutate the fixed replay, certify a safeguard, submit real evidence, control a deployed system, allocate blame, or invoke Evulgare or KillWebs services. External ecosystem links are ordinary allowlisted HTTPS navigation after deliberate visitor action.



## Machine Answerability Assurance security boundary — v1.27.0

The Assurance Case and Invalidation Lab is a public, read-only, local-only synthetic exercise. It accepts only allowlisted claim, safeguard, assumption, owner, and change-event IDs. Query state cannot create a claim, alter evidence, accept a correction, certify a product, modify the Orison history, mutate remediation effects, ingest production evidence, or call an external system.

The client module performs no network request and uses no cookie, persistent browser storage, service worker, dynamic code execution, arbitrary URL, upload, telemetry, or cross-site session. Evulgare and KillWebs links are resolved through the typed ecosystem registry and open only after explicit visitor navigation.

Evidence-integrity and factual-support outputs are educational states. They are not authentication, cryptographic attestation, certification, compliance, legal approval, safety proof, product rating, procurement advice, or liability allocation.

## Machine Answerability Assurance Review security boundary — v1.28.0

The review route is read-only, session-free, and fully server rendered. It accepts only allowlisted prior/current snapshot IDs, enforces deterministic packet identity, and creates no account, database, upload, write API, signature authority, production evidence store, analytics profile, persistent browser state, runtime crawler, arbitrary external URL, or external action.

The optional client performs only local selector swap, copy, and JSON download. It cannot alter packet contents, claim states, evidence, versions, owners, review completion, operational release authority, fixed event history, or publication truth. Evulgare and KillWebs links are ordinary allowlisted HTTPS navigation after deliberate visitor action.

## Machine Answerability Evidence Contract security boundary — v1.29.0

`/answerability-contract.php` is a read-only synthetic review-ownership lab. It accepts only allowlisted contract, packet, arrangement, and comparison identifiers. It creates no account, upload, write API, signature authority, certificate, operational release, external action, or production evidence record.

The client enhancement is page-local and must not use network transport, persistent browser storage, dynamic code execution, arbitrary URLs, or HTML-string insertion. Download and clipboard output occur only after explicit visitor action and contain synthetic registry state. All six source packet hashes remain immutable.


## Evidence-Gap Escalation security boundary — v1.30.0

The route accepts only allowlisted GET identifiers, caps remediation selection at six, remains read-only, starts no session, and performs no upload, write API, external fetch, persistent storage, analytics, source crawl, production-evidence ingestion, or arbitrary URL handling. JavaScript only enhances local selection, copy, and JSON download. No browser action can assign authority, modify a packet, accept a correction, suspend a real system, or initiate an external action.

## Dispute Ledger security boundary — v1.31.0

`/answerability-disputes.php` is read-only, session-free, and publicly cacheable. The server accepts only allowlisted record, scope, state, search, and comparison values and caps comparison at three records. The client performs no network request or persistent storage and cannot submit evidence, create a dispute, accept a correction, alter a packet, infer a missing owner, or affect an external system. JSON output is generated locally after explicit action and contains only released synthetic state.

## Corrective Action Effectiveness Audit security boundary — v1.32.0

`/answerability-effectiveness.php` is read-only, session-free, and publicly cacheable. The server accepts only allowlisted audit, state, result, action, search, and comparison values and caps comparison at three records. The client performs no network request or persistent storage and cannot upload evidence, create an audit, alter a dispute, infer missing authority, certify effectiveness, authorize operation, or affect an external system.

Clipboard and JSON output occur only after explicit visitor action and contain released synthetic registry state. External KillWebs and Evulgare destinations are allowlisted ordinary HTTPS links; no cross-site session, iframe, remote script, production evidence, or API connection exists.



## Corrective Action Monitoring security boundary — v1.34.0

The monitoring lab is synthetic, read-only, and page-local. It accepts only allowlisted branch/filter/comparison state, creates no account or database record, performs no network request, ingests no production evidence, and cannot alter earlier audits or accepted history. Local JSON output is generated only after explicit visitor action. Missing evidence or competent ownership remains effectiveness unknown or no authority to infer.


## Monitoring Coverage security boundary — v1.35.0

The Coverage Lab accepts only allowlisted query identifiers. It cannot ingest telemetry, upload evidence, create a dispute, change an assurance state, accept a correction, authorize operation, or call Evulgare or KillWebs at runtime. Optional JavaScript is page-local and uses no network transport, cookie, persistent browser storage, dynamic code execution, or remote content loader.

Branch and source hashes are integrity identities for synthetic records. They are not signatures, certificates, proof of truth, or release authority. Missing ownership fails closed instead of being inferred from the nearest human event.


## Coverage Remediation Validation security boundary — v1.36.0

The validation route accepts only allowlisted branch, remediation, implementation-state, condition, preset, and failure-injection identifiers. Server evaluation caps failure injections at three, rejects unknown or branch-ineligible remediations, sorts inputs deterministically, and preserves the immutable source branch and predecessor hashes.

The optional client uses no network transport, cookie, persistent browser storage, service worker, dynamic code execution, remote content loader, account, database, upload, public edit, or cross-site session. Copy and local JSON actions require explicit visitor input. The page cannot configure a real monitor, send an alert, suspend reliance, correct or retire a real claim, create a dispute, sign a record, or authorize deployment.

## v1.37.0 exception/retest security boundary

The exception/retest route accepts only bounded allowlisted GET state and creates no server write, account, upload, arbitrary URL, code execution, persistent profile, production evidence, or external action. JavaScript uses no network or storage primitive. Treat query strings and downloaded JSON as synthetic presentation state, not authenticated evidence, a signature, a certificate, or a production release record.

## v1.38.0 exception recurrence pattern-review security boundary

The pattern-review route is read-only, session-free, and publicly cacheable. The server accepts only released branch, preset, admission-policy, observation-window, dimension, dependency-hypothesis, and competing-explanation identifiers; enforces two-to-three branch selection; caps dimensions at six and competing explanations at four; sorts bounded inputs deterministically; and rejects unknown state. It creates no account, database record, upload, public edit, arbitrary URL, production-evidence record, analytics profile, external action, or cross-site session.

The optional client performs no network request, cookie write, persistent storage, service-worker registration, dynamic code execution, remote content loading, HTML-string insertion, or runtime crawl. Clipboard and JSON output occur only after explicit visitor action and contain released synthetic state. Query strings and downloaded files are not authenticated evidence, signatures, certificates, production records, or release decisions.

Source IDs and SHA-256 values establish deterministic identity and predecessor continuity inside the released package; they do not prove truth, completeness, fixture comparability, real recurrence, common cause, production causation, safety, legality, or institutional authority. Missing or excluded observations remain unknown. Missing competent ownership remains no authority to infer rather than being assigned to the nearest visible operator.

