Security

Security model

The verifier reports evidence integrity, attribution, capture coverage, independent readback, and public availability as separate dimensions.

The enterprise retains action authority, credentials, signing-key custody, and deployment controls.

Independent result

Assurance dimensions

Each dimension is evaluated from the supplied artifact, trust policy, deployment evidence, and optional readback.

Evidence integrityINDETERMINATE

Hash, schema, signature, and artifact consistency.

AttributionNOT_EVALUATED

Declared key control or policy-backed enterprise identity.

Capture coverageNOT_CLAIMED

Evidence observed at the declared ingress, without claiming coverage of the external action.

Independent readbackNOT_EVALUATED

Not evaluated, inapplicable, source-reported, pending, confirmed, contradicted, or unresolved.

Public availabilityLOCAL_ONLY

Local artifact, registry record, or optional public anchor.

SurfaceClaim
Execution ReceiptRepresents one domain-neutral lifecycle statement without defining or controlling the external action.
Append-only local journalPreserves record order and lifecycle links; external ordering and completeness are evaluated separately.
Receipt CommitmentBinds an Execution Receipt hash to its declared-signer signature; source identity and factual truth remain policy-evaluated dimensions.
Receipt BundlePackages lifecycle-linked Execution Receipts and Receipt Commitments for offline verification.
Local MCP and HTTP ingressAccepts evidence submissions locally while external action authority stays with the enterprise.
Verified backup and restoreSemantically verifies a credential-free single-host snapshot and refuses to overwrite a restore target.
Deployment preflightExercises the external signer and verifies live evidence, outbox state, and a retained backup inside the evidence boundary.
Bounded OpenMetrics exportProjects fixed capacity, backlog, readiness, and reason-code series without scope, policy, evidence, or private-data labels.
Signed readiness bundleRequires the exact clean source HEAD, records its Git tree, and binds both with a fresh preflight and redacted deployment-profile hash to the enterprise signer.
Independent reviewReview binds target-environment controls, identity policy, and operational evidence.
Externally supplied

Verifier trust inputs

  • Source identity and authentication policy.
  • Purpose-specific signer authorization and status.
  • KMS/HSM custody, rotation, revocation, and recovery.
  • Independent cryptographic, identity-policy, and privacy review.
Deployment scoped

Operational deployment controls

  • Authenticate the local ingress and protect signing keys.
  • Keep the external action system outside ChoiceProof.
  • Define retention, backup, recovery, and access policy.
  • Collect the bounded OpenMetrics snapshot and test staleness, paging, acknowledgement, and escalation.
  • Create and independently verify the signed readiness bundle for the reviewed clean source commit and Git tree.
  • Run privacy, tamper, conflict, restart, and recovery tests.
Security references

Review SECURITY.md, docs/THREAT_MODEL.md, docs/SECURITY_REVIEW_SUMMARY.md, docs/KNOWN_LIMITATIONS.md, and docs/PRODUCT_ARCHITECTURE.md in the repository.

Factual truth, legal status, regulatory approval, observation coverage, and external-action authority remain separate trust and policy dimensions.