Skip to content

Security: FoundLab-PoweredByGoogleCloud/auditable-trust-infrastructure

Security

SECURITY.md

Security Policy

Scope

This repository contains public specifications, category materials, reference architecture, and technical primitives for Auditable Trust Infrastructure.

It does not contain production credentials, customer deployments, private implementation details, security-sensitive operational runbooks, or NDA materials.

Reporting Security Issues

If you believe this repository exposes sensitive information, unsafe claims, implementation vulnerabilities, or security-relevant specification errors, contact FoundLab through official channels.

Do not open a public issue for:

  • suspected credential exposure;
  • customer-specific information;
  • vulnerability details;
  • exploit paths;
  • private deployment architecture;
  • NDA or Private Offer material.

Public Contributions

This repository is currently maintained as a public read-only specification.

Public pull requests are not accepted unless explicitly requested by FoundLab.

Claims Hygiene

Security and compliance claims in this repository must be evidence-bound.

Do not introduce:

  • unconditional legal compliance claims;
  • unconditional erasure claims;
  • production-readiness claims without evidence;
  • latency guarantees without benchmark context;
  • claims that BigQuery alone is terminal WORM storage;
  • claims that crypto-shredding is instantaneous deletion.

Contact

Use FoundLab’s official website or verified institutional contact channels.

There aren't any published security advisories