Skip to main content

Security & Assurance

Security information belongs to a product trust surface.

XPScerpto separates security posture, disclosure, public advisories and evidence from operational administration while preserving a clear path for technical review.

SourceBuildRuntime
XPScerptosecurity
EvidenceReplayVerify

Security model

Understand boundaries between implementation, runtime, evidence and public claims.

Disclosure

Report vulnerabilities through the dedicated controlled intake path.

Advisories

Published advisories remain distinct from internal investigation material.

Assurance

Public security claims remain limited by admitted verification and governance state.

Security sectionsOverview

Security & Trust

Security & Trust

Security information, responsible disclosure and published advisories for XPScerpto.

Published security information

Independent advisory publication

Only approved immutable advisory revisions can become public.

Transactional audit receipts

Security mutations and their audit records commit or roll back together.

Capability-gated security operations

HTTP and domain service layers independently enforce report, evidence and governance authority.

security.txt publication

The well-known security contact record has a future expiry, canonical URL and canonical disclosure policy.

Canonical security documentation

Security documentation is generated from the canonical documentation source and carries publication identity.

Canonical evidence binding

Public security claims bind to normalized evidence registry entries without exposing restricted report evidence.

Anonymous text reporting

A report can be submitted without an account and receives an immutable receipt.

Runtime disclosure policy

The public disclosure policy is projected from the running security domain.

Idempotent report commands

Intake and state-changing commands reject payload conflicts and safe retries do not duplicate work.

Bound follow-up session

A report reference and secret are exchanged for a short-lived HttpOnly session with CSRF binding.