ARCHITECTURE VIEW

Trust boundaries

Public evidence. Private execution. This client-safe view explains how public evidence, authority boundaries, protected execution, and bounded public evidence relate without representing a deployment inventory or service entitlement.

CLIENT-SAFE ARCHITECTURE

Public evidence, protected execution

Each step carries its state in text. The diagram remains readable without colour or client JavaScript.

  1. 01
    Public evidence surface

    Public pages, declared records, and bounded verification material are evidence interfaces. Their presence does not reveal protected operations or create a service entitlement.

    Current
  2. 02
    Evidence Before Authority

    Evidence can support review, but public presentation, a signature, or a capability label cannot grant authority by itself. Authority remains subject to the applicable approval and policy boundary.

    Specification
  3. 03
    Protected private execution

    Private execution and protected operational material remain outside public pages, public responses, and ordinary evidence. This view intentionally does not describe their implementation.

    Protected
  4. 04
    Bounded public evidence return

    Only allowlisted public evidence or verification metadata may return to the public surface. A public record is not an execution receipt, an availability statement, or an authority grant.

    Current
  5. 05
    Independent review boundary

    No external review, certification, or production approval is implied unless a matching evidence record exists.

    External
  6. 06
    Observation boundary

    A signed observation remains bounded to its declared contract, key, sequence, and freshness state.

    Optional external

Text equivalent: Public evidence surface is current; Evidence Before Authority is specification; Protected private execution is protected; Bounded public evidence return is current; Independent review boundary is external; Observation boundary is optional external.

CURRENT IMPLEMENTATION BOUNDARY

What this view does and does not state

Private infrastructure, signing material, customer environments, and unmeasured runtime behaviour remain outside the public trust boundary. Capability is not authority. Stage 0 architecture evidence note: this package explains the public/private boundary only; it does not assert production readiness, external certification, public tenant availability, or a Stage 0 PASS.

Inspect the claim register and evidence classes for the records that govern public assurance language.