Hash, schema, signature, and artifact consistency.
Security model
The verifier reports evidence integrity, attribution, capture coverage, independent readback, and public availability as separate dimensions.
The enterprise retains action authority, credentials, signing-key custody, and deployment controls.
Assurance dimensions
Each dimension is evaluated from the supplied artifact, trust policy, deployment evidence, and optional readback.
Declared key control or policy-backed enterprise identity.
Evidence observed at the declared ingress, without claiming coverage of the external action.
Not evaluated, inapplicable, source-reported, pending, confirmed, contradicted, or unresolved.
Local artifact, registry record, or optional public anchor.
| Surface | Claim |
|---|---|
| Execution Receipt | Represents one domain-neutral lifecycle statement without defining or controlling the external action. |
| Append-only local journal | Preserves record order and lifecycle links; external ordering and completeness are evaluated separately. |
| Receipt Commitment | Binds an Execution Receipt hash to its declared-signer signature; source identity and factual truth remain policy-evaluated dimensions. |
| Receipt Bundle | Packages lifecycle-linked Execution Receipts and Receipt Commitments for offline verification. |
| Local MCP and HTTP ingress | Accepts evidence submissions locally while external action authority stays with the enterprise. |
| Verified backup and restore | Semantically verifies a credential-free single-host snapshot and refuses to overwrite a restore target. |
| Deployment preflight | Exercises the external signer and verifies live evidence, outbox state, and a retained backup inside the evidence boundary. |
| Bounded OpenMetrics export | Projects fixed capacity, backlog, readiness, and reason-code series without scope, policy, evidence, or private-data labels. |
| Signed readiness bundle | Requires the exact clean source HEAD, records its Git tree, and binds both with a fresh preflight and redacted deployment-profile hash to the enterprise signer. |
| Independent review | Review binds target-environment controls, identity policy, and operational evidence. |
Verifier trust inputs
- Source identity and authentication policy.
- Purpose-specific signer authorization and status.
- KMS/HSM custody, rotation, revocation, and recovery.
- Independent cryptographic, identity-policy, and privacy review.
Operational deployment controls
- Authenticate the local ingress and protect signing keys.
- Keep the external action system outside ChoiceProof.
- Define retention, backup, recovery, and access policy.
- Collect the bounded OpenMetrics snapshot and test staleness, paging, acknowledgement, and escalation.
- Create and independently verify the signed readiness bundle for the reviewed clean source commit and Git tree.
- Run privacy, tamper, conflict, restart, and recovery tests.
Security references
Review SECURITY.md, docs/THREAT_MODEL.md, docs/SECURITY_REVIEW_SUMMARY.md, docs/KNOWN_LIMITATIONS.md, and docs/PRODUCT_ARCHITECTURE.md in the repository.
Factual truth, legal status, regulatory approval, observation coverage, and external-action authority remain separate trust and policy dimensions.