ARCHITECTURE VIEW
Trust boundaries
Public evidence. Private execution. This client-safe view explains how public evidence, authority boundaries, protected execution, and bounded public evidence relate without representing a deployment inventory or service entitlement.
CLIENT-SAFE ARCHITECTURE
Public evidence, protected execution
Each step carries its state in text. The diagram remains readable without colour or client JavaScript.
- 01Public evidence surfaceCurrent
Public pages, declared records, and bounded verification material are evidence interfaces. Their presence does not reveal protected operations or create a service entitlement.
- 02Evidence Before AuthoritySpecification
Evidence can support review, but public presentation, a signature, or a capability label cannot grant authority by itself. Authority remains subject to the applicable approval and policy boundary.
- 03Protected private executionProtected
Private execution and protected operational material remain outside public pages, public responses, and ordinary evidence. This view intentionally does not describe their implementation.
- 04Bounded public evidence returnCurrent
Only allowlisted public evidence or verification metadata may return to the public surface. A public record is not an execution receipt, an availability statement, or an authority grant.
- 05Independent review boundaryExternal
No external review, certification, or production approval is implied unless a matching evidence record exists.
- 06Observation boundaryOptional external
A signed observation remains bounded to its declared contract, key, sequence, and freshness state.
Text equivalent: Public evidence surface is current; Evidence Before Authority is specification; Protected private execution is protected; Bounded public evidence return is current; Independent review boundary is external; Observation boundary is optional external.
CURRENT IMPLEMENTATION BOUNDARY
What this view does and does not state
Private infrastructure, signing material, customer environments, and unmeasured runtime behaviour remain outside the public trust boundary. Capability is not authority. Stage 0 architecture evidence note: this package explains the public/private boundary only; it does not assert production readiness, external certification, public tenant availability, or a Stage 0 PASS.
Inspect the claim register and evidence classes for the records that govern public assurance language.