Documentation
7 committed documents, rendered from the repository rather than rewritten for the web. Each is the file the project itself works from.
- The control language 236 lines
What a control is: its subject, the byte-exact span it cites, its adapter, operator and expected value, and the period it is in force for. - Threat model 361 lines
What can go wrong, what the design stops, and the residual risks that remain open with their identifiers. - Limitations 306 lines
Every target that was missed, recorded as missed, and every claim the system cannot support. - USDY retrieval 144 lines
What was measured when the 260 MB suspension was re-examined, including the two shortcuts that turned out to be closed. - AI usage 102 lines
Where a model is used, what it may propose, what it may never decide, and the measured outcome of every compilation in this repository. - Source audit 347 lines
Every candidate issuer source that was examined, what it returned, and why it was kept or set aside. - Roadmap 599 lines
The build plan, the product principles, and the security and governance ladder.
Documents recording host paths, environment variable names or key custody are deliberately not published. Stating in a threat model that there is no HSM is accountability; publishing where the keys live is something else.