Evidence ceiling E3Proof boundary

PUBLIC SITE 80 · INSTITUTIONAL ENGINEERING

Institutional engineering: READY. Customer activation: READY FOR INSTITUTION BINDING.

The source implements the control surface required to onboard an institution without re-architecting the platform: tenant isolation, OIDC/SAML binding contracts, SCIM lifecycle, customer key custody, service credentials, dual approval, governed data use, secure webhooks, tamper-evident audit, recovery evidence, incident kill-switching and a fail-closed customer-live truth gate.

Engineering admission

PASS

This is a seller-controlled source readiness decision, not external validation.

CONTROLS
34/34 BUILT + REFERENCE TESTED
THREAT MAPPINGS
14
BOUNDED MODEL
24 CASES · PASS
CUSTOMER ACTIVATION
READY_FOR_INSTITUTION_BINDING
CUSTOMER LIVE
NO
EVIDENCE CEILING
E3 SELLER-CONTROLLED

Control matrix

34 explicit institutional controls

Every control is named so an evaluator can challenge it independently rather than relying on a generic enterprise-ready label.

01

TENANT_LIFECYCLE

BUILT + REFERENCE TESTED

Tenant creation, suspension, isolation and termination are explicit and fail closed.

02

TENANT_OBJECT_AUTHORIZATION

BUILT + REFERENCE TESTED

Every tenant-bound object operation requires object-level tenant authorization.

03

RBAC_ABAC

BUILT + REFERENCE TESTED

Role and attribute constraints compose; cross-tenant access is denied.

04

SEGREGATION_OF_DUTIES

BUILT + REFERENCE TESTED

High-risk changes support dual authorization by distinct principals.

05

OIDC_FEDERATION

BUILT + REFERENCE TESTED

OIDC issuer/audience/key/signature and freshness validation is implemented.

06

SAML_FEDERATION_CONTRACT

BUILT + REFERENCE TESTED

SAML metadata, entity, signing and audience requirements are modeled as a bindable institutional contract.

07

SCIM_2_LIFECYCLE

BUILT + REFERENCE TESTED

SCIM-style Users/Groups create, read, replace, patch, disable and delete semantics are implemented.

08

PHISHING_RESISTANT_ADMIN_AUTH

BUILT + REFERENCE TESTED

Privileged policy requires phishing-resistant MFA or institution-declared equivalent.

09

SERVICE_CREDENTIALS

BUILT + REFERENCE TESTED

Service credentials are scoped, expiring, hash-only at rest, rotatable and revocable.

10

SENDER_CONSTRAINED_TOKENS

BUILT + REFERENCE TESTED

DPoP proof validation and replay rejection are implemented for high-risk API profiles.

11

IDEMPOTENCY_FINGERPRINT

BUILT + REFERENCE TESTED

Idempotency binds key to request fingerprint and rejects key reuse with a different request.

12

RATE_LIMITING

BUILT + REFERENCE TESTED

Tenant and principal request budgets fail closed without granting authorization.

13

PROBLEM_DETAILS

BUILT + REFERENCE TESTED

Machine-readable API failures have stable problem types and request correlation.

14

KEY_CUSTODY_POLICY

BUILT + REFERENCE TESTED

Customer KMS/HSM, cloud KMS and seller-reference custody are distinct states.

15

CRYPTOGRAPHIC_AGILITY

BUILT + REFERENCE TESTED

Key version, allowed algorithms, rotation and deprecation are policy objects.

16

PQC_MIGRATION_INTERFACE

BUILT + REFERENCE TESTED

PQC migration readiness is explicit without claiming FIPS validation or deployment.

17

DATA_CLASSIFICATION

BUILT + REFERENCE TESTED

Data classification is mandatory for protected workloads.

18

PURPOSE_LIMITATION

BUILT + REFERENCE TESTED

Data use is bound to declared purpose and authorization.

19

DATA_RESIDENCY

BUILT + REFERENCE TESTED

Allowed regions are policy-bound and fail closed.

20

RETENTION_LEGAL_HOLD

BUILT + REFERENCE TESTED

Retention and legal hold override deletion deterministically.

21

CROSS_CUSTOMER_TRAINING_DENY

BUILT + REFERENCE TESTED

Cross-customer model training is denied by default.

22

WEBHOOK_HMAC

BUILT + REFERENCE TESTED

Webhook payloads are secret-authenticated with timestamp and nonce binding.

23

WEBHOOK_REPLAY_DEFENSE

BUILT + REFERENCE TESTED

Duplicate webhook nonce or stale timestamp is rejected.

24

WEBHOOK_SSRF_GUARD

BUILT + REFERENCE TESTED

Webhook targets reject loopback, link-local, private-IP and non-HTTPS destinations.

25

WEBHOOK_RETRY_DLQ

BUILT + REFERENCE TESTED

Retries have bounded exponential backoff and dead-letter state.

26

HASH_CHAINED_AUDIT

BUILT + REFERENCE TESTED

Security and consequential changes produce append-only hash-linked audit evidence.

27

SIEM_EXPORT

BUILT + REFERENCE TESTED

Audit export is redacted, structured and SIEM/OpenTelemetry compatible.

28

BACKUP_INTEGRITY

BUILT + REFERENCE TESTED

Backups carry integrity manifests and reject tampered restore.

29

RPO_RTO_POLICY

BUILT + REFERENCE TESTED

Recovery point and recovery time objectives are explicit policy objects.

30

RECOVERY_DRILL_EVIDENCE

BUILT + REFERENCE TESTED

Recovery drills produce attributable receipts; seller drills do not become customer evidence.

31

INCIDENT_KILL_SWITCH

BUILT + REFERENCE TESTED

Incident state can suspend high-risk mutation while preserving read/audit access.

32

SECURE_BUILD_PROVENANCE

BUILT + REFERENCE TESTED

SBOM, source identity, build provenance and verification are required publication inputs.

33

CUSTOMER_ACTIVATION_TRUTH_GATE

BUILT + REFERENCE TESTED

Customer-live status requires externally signed activation evidence and cannot self-promote.

34

NO_EXTERNAL_EVIDENCE_SELF_PROMOTION

BUILT + REFERENCE TESTED

Seller evidence cannot mint E4/E5/E6, customer-live, certification or adoption.

Hostile boundary

Fail closed

The threat model is part of the engineering surface, including tenant-object authorization, replay, SSRF, raw-secret rejection, privilege separation, recovery failure and customer-live inflation.

01

cross-tenant object access

TENANT_OBJECT_AUTHORIZATION

TENANT_BOUNDARY_DENIED

02

stolen bearer token replay

SENDER_CONSTRAINED_TOKENS

DPOP_REPLAY_OR_BINDING_DENIED

03

privileged single-actor control change

SEGREGATION_OF_DUTIES

SELF_OR_INCOMPLETE_APPROVAL_DENIED

04

identity lifecycle drift

SCIM_2_LIFECYCLE

INACTIVE_IDENTITY_REMOVED_FROM_ACTIVE_GROUP_USE

05

webhook replay or forgery

WEBHOOK_HMAC

SIGNATURE_OR_NONCE_REJECTED

06

webhook SSRF

WEBHOOK_SSRF_GUARD

PRIVATE_LOOPBACK_OR_NON_HTTPS_TARGET_DENIED

07

idempotency-key semantic collision

IDEMPOTENCY_FINGERPRINT

KEY_REUSE_WITH_DIFFERENT_REQUEST_DENIED

08

unsafe data reuse

PURPOSE_LIMITATION

PURPOSE_OR_CROSS_CUSTOMER_USE_DENIED

09

legal-hold bypass

RETENTION_LEGAL_HOLD

DELETE_DENIED_WHILE_HOLD_OR_RETENTION_ACTIVE

10

audit erasure or silent rewrite

HASH_CHAINED_AUDIT

CHAIN_VERIFICATION_FAILS_ON_MUTATION

11

backup tamper or untested recovery

BACKUP_INTEGRITY

RECOVERY_READINESS_FAILS

12

incident-time unsafe mutation

INCIDENT_KILL_SWITCH

HIGH_RISK_MUTATION_HALTED

13

unsupported customer-live claim

CUSTOMER_ACTIVATION_TRUTH_GATE

CUSTOMER_LIVE_FALSE_UNTIL_ALL_EXTERNAL_GATES_PASS

14

supply-chain artifact substitution

SECURE_BUILD_PROVENANCE

PUBLICATION_GATE_DENIED

Standards baseline

Reference mapping only

The engineering surface is mapped to current identity, OAuth, provisioning, API, telemetry and software-supply-chain references without claiming certification or conformance.

01

NIST_SP_800_63_4

REFERENCE_MAPPING

digital identity proofing, authentication and federation baseline

02

NIST_SP_800_63C_4

REFERENCE_MAPPING

federation and assertions baseline

03

RFC_9700

REFERENCE_MAPPING

OAuth 2.0 security BCP and sender-constrained-token preference

04

RFC_9449

REFERENCE_IMPLEMENTATION

DPoP proof-of-possession profile

05

RFC_7644

REFERENCE_IMPLEMENTATION

SCIM 2.0 user and group lifecycle model

06

RFC_9457

REFERENCE_IMPLEMENTATION

machine-readable HTTP problem details

07

RFC_9421

REFERENCE_MAPPING

HTTP message-signature interoperability reference

08

OPENTELEMETRY_SEMANTIC_CONVENTIONS

REFERENCE_MAPPING

trace, metric and log naming reference

09

NIST_SP_800_218_SSDF

REFERENCE_MAPPING

secure software development lifecycle reference

10

SLSA_1_2

REFERENCE_MAPPING

build provenance and hardened build-level reference

11

CISA_SECURE_BY_DESIGN

REFERENCE_MAPPING

secure defaults, MFA, SSO and customer-accessible logging reference

12

OWASP_API_SECURITY_TOP_10_2023

REFERENCE_MAPPING

API authorization, authentication, resource-consumption and SSRF threat reference

13

OWASP_ASVS_5_0

REFERENCE_MAPPING

application security verification and procurement-control reference

14

NIST_CSF_2_0

REFERENCE_MAPPING

govern, identify, protect, detect, respond and recover cybersecurity-outcome reference

15

OWASP_AGENT_CONTROL_STANDARD_2026

REFERENCE_MAPPING

agent transparency and control hook reference upstream of outcome closure

Public knowledge index

Search Finality Group

Protected, owner-only and legacy content is excluded.