Security model
Understand boundaries between implementation, runtime, evidence and public claims.
Security & Assurance
XPScerpto separates security posture, disclosure, public advisories and evidence from operational administration while preserving a clear path for technical review.
Understand boundaries between implementation, runtime, evidence and public claims.
Report vulnerabilities through the dedicated controlled intake path.
Published advisories remain distinct from internal investigation material.
Public security claims remain limited by admitted verification and governance state.
Security & Trust
Security information, responsible disclosure and published advisories for XPScerpto.
Only approved immutable advisory revisions can become public.
Security mutations and their audit records commit or roll back together.
HTTP and domain service layers independently enforce report, evidence and governance authority.
The well-known security contact record has a future expiry, canonical URL and canonical disclosure policy.
Security documentation is generated from the canonical documentation source and carries publication identity.
Public security claims bind to normalized evidence registry entries without exposing restricted report evidence.
A report can be submitted without an account and receives an immutable receipt.
The public disclosure policy is projected from the running security domain.
Intake and state-changing commands reject payload conflicts and safe retries do not duplicate work.
A report reference and secret are exchanged for a short-lived HttpOnly session with CSRF binding.