Security model
Understand boundaries between implementation, runtime, evidence and public claims.
Security & Assurance
XPScerpto separates security posture, disclosure, public advisories and evidence from operational administration while preserving a clear path for technical review.
Understand boundaries between implementation, runtime, evidence and public claims.
Report vulnerabilities through the dedicated controlled intake path.
Published advisories remain distinct from internal investigation material.
Public security claims remain limited by admitted verification and governance state.
Security
Current implementation and verification state for public XPScerpto security controls and claims.
No additional public control statement is published here.
Security administration is capability-gated at HTTP and domain boundaries.
Draft and unapproved advisories are not public.
Security reports can be submitted without an account.
A failed audit write prevents the associated security mutation.
Reporter follow-up uses a short-lived server session rather than browser storage or URL secrets.
Public evidence projections expose receipts and freshness, never raw restricted report evidence.
Security documentation is generated from one canonical multilingual revision set.
security.txt points to the canonical disclosure policy and has a future expiry.