audit cycles
Every audit cycle, in full.
14 witnessed cycles on the record. Each one links to a governed engagement, carries the controls held during the run, and the findings and WARD receipts behind it.
index
Jump to a cycle.
cycle 14
v1.8, Resource & Abuse Bounds
Attack with volume. Compute is bounded (per-org + route rate limiters, agent loop cap, connector timeouts, body + result-size caps). Three missing bounds found and fixed: unbounded paid-API spend (gemini/perplexity now propose-first), unbounded ssh exec-time + output (120s timeout + 1MB cap), and an uncapped telegram outbound queue (depth-a fleet host shed). Schedulers carry the triad. Completes the v1.x ladder.
Controls held
- RB1 concurrency/rate: per-org global rate limiter + route toolLimiter + agent loop MAX_ITERATIONS=3.
- RB2 (fixed): gemini_generate + perplexity_research default to propose-first (no unbounded paid-API spend), red-proven pin; live.
- RB3 (fixed): ssh command bounded by EXEC_TIMEOUT_MS=120s + capStreamOutput 1MB/stream, red-proven pin; live. Connector calls already timeout; results truncated.
- RB4 (fixed): telegram outboundQueue depth cap (a fleet host) shed, live. Scheduler triad present across feed/inboxq/quoxseo/reach/reflection/telegram/x pollers.
Findings
3 findings.
- highRB2: paid-API tools (gemini/perplexity) had no spend bound (free-call loop)fixed
- mediumRB3: remote_ssh/ssh_exec unbounded exec time + outputfixed
- mediumRB4: telegramPro outboundQueue no lane depth cap (unbounded in-memory growth)fixed
2 WARD receipts on this cycle.
cycle 13
v1.7, Authorization Depth
Attack the grant lifecycle. Approvals are single-use (atomic claim), expiry is revalidated at use time on both the collector and bastion layers, revocation runs through the same atomic deny gate, capability scope denies unknown agents and binds grants to tool+params+targets, and credentials are declared-type-scoped with JIT leases that expire. Clean exam; the core invariants were already conformance-pinned. Low named debt on the bastion grant layer.
Controls held
- AU1 single-use: atomic claimForResume + bastion nonce (pinned approvalGateGrantSingleUse / qlusterDelegationStore).
- AU2 expiry: use-time revalidation collector + bastion (pinned toolResumeFailClosed 'T-AUTH expiry revalidation').
- AU3 revocation-at-use: explicit deny through the same atomic claim gate (pinned).
- AU4 scope+binding: unknown-agent denies (quox#556); bastion MatchesTool = ToolID+ParamsSHA256+targets; approval fingerprint binds action (pinned approvalGateInputBinding).
- AU5 credential least-privilege + JIT lease: declared-type-scoped resolution; getActiveLease filters expires_at>now + atomic use-increment.
Findings
1 finding.
- lowAU-residuals: bastion grant replay-nonce in-memory + no standalone revoke primitive (low)open_confirmed
2 WARD receipts on this cycle.
cycle 12
v1.6, Evidence Tamper-Evidence
The most on-thesis bar: attack the evidence itself. The WARD chain binds seq + prev_chain_hash + payloadHash; verify detects forgery (CHAIN_HASH_MISMATCH), omission (SEQ_INVALID), reorder/linkage (CHAIN_LINK_BROKEN) and tip tamper (TIP_MISMATCH) with no catch-swallow; no mutation path exists on ward_entries. The witness commitment binds the effective action via payload_commit/canonical_action (the historical payload-exclusion bug is fixed). An independent recompute refuses to publish on mismatch. Clean exam; added the missing gap-detection pin.
Controls held
- ET1 chain completeness/gap-detection: verifyChain returns SEQ_INVALID on a deleted/omitted entry (live throwaway-DB test + new red-proven pin); no DELETE/UPDATE on ward_entries.
- ET2 no silent reorder: ordering hash-bound (seq + prev_chain_hash), not timestamp-trust.
- ET3 action-binding: witness hash binds payload_commit -> canonical_action (tool/tenant/identity/content_commit/outcome); payload-exclusion bug fixed (hooks.js).
- ET4 recompute fails closed: export-security-audit.mjs re-derives + throws on mismatch (exit 1; fail-closed if key unprovisioned); ward-verify EXIT_BROKEN=1.
Findings
1 finding.
- lowET3(b): ward_entries.org_id/tags bare columns not bound into chainHashopen_confirmed
2 WARD receipts on this cycle.
cycle 11
v1.5, Injection / Containment
The premise is a fully-compromised reading model. Containment holds: the single mediateGovernancePolicy chokepoint gates every tool call by EFFECT (not provenance), no model output reaches an interpreter, and approved email recipients are fingerprint-bound. One escalation path found and fixed: browser_navigate allowed a model-controlled URL to reach loopback/private/metadata IPs ungated (SSRF). We explicitly do not certify injection immunity; we certify the gate sits outside the model.
Controls held
- IN1 clean: no eval/Function/vm sink for model output; remote_ssh read-allowlist + approval; db_query parameterised + read-only/gated.
- IN2 clean: email_send always-propose + fingerprint binds to/cc/bcc/subject/body (resume refuses on change); resolveToolOrgId locks org to authenticated ctx.
- IN3 fixed: browserActions.validateUrl blocks loopback/private/link-local/metadata (honours SCREENCAP_ALLOWED_PRIVATE); red-proven pin; deploy-verify in running quox-screencap.
- IN4 clean: single referenceMonitor.mediateGovernancePolicy chokepoint, effect-based gating, untrusted retrieved content cannot trigger an ungated effect.
Findings
1 finding.
- highIN3: browser_navigate SSRF — model-controlled URL reaches private/metadata IPs ungatedfixed
2 WARD receipts on this cycle.
cycle 10
v1.4, Confidentiality & Supply-chain
v1.4 asks whether secrets leak and whether we can prove what runs. The confidentiality core is sound: credentials resolve by reference (never returned), receipts are content-free, mandatory audit always stored. One real leak (CF1: raw tool-input logging, live in prod) and one supply-chain gap (unpinned dep) found and fixed; install integrity already fails closed (CA2). Build-provenance observability (CA1) is named with a precise remediation spec (quoxagent already passes).
Controls held
- CF1 (fixed): collector tool-input logging redacted via summarizeToolInputForLog (secret keys masked, free-text reduced to length, nested to shape), red-proven pin; deployed + verified in running collector.
- CF2 (clean): credentials resolved by credential_id reference, raw secret never in tool input or response; vault tools echo metadata only.
- CF3 (clean): mandatory execution evidence always stored + witnessed regardless of transcript retention; receipts are content-free commitments (digest + per-field hashes).
- CA2 (pass): quoxagent install.sh verifies BINARY_SHA256 and refuses on mismatch (exit 1; bypass needs explicit flag).
- T-ART dep (fixed): @anthropic-ai/claude-code pinned @2.1.197 in the collector Dockerfile.
Findings
3 findings.
- mediumCF1: collector logged raw tool input (secret leak into logs)fixed
- mediumT-ART: collector Dockerfile dependency @anthropic-ai/claude-code unpinnedfixed
- mediumCA1: build provenance not verifiable on collector/auth/dashboard/bastionopen_confirmed
2 WARD receipts on this cycle.
cycle 9
v1.1, Parity & Repeatability
v1.1 asks whether what was AUDITED is what is RUNNING, provably, and whether the v1 PASS REPEATS. The second independent pass (PART B) re-confirmed F6/F7-RR5/fail-closed-gates on the running system AND caught a HIGH cross-tenant hole (PB3) the first pass missed: CommanderQ compliance tools trusted a caller-supplied org_id. Fixed, deployed, verified live, red-proven. Parity itself verified on the collector (running sha == origin/main); the cross-cutting gap is build-provenance observability, with the quoxagent heartbeat half fixed and the rest named.
Controls held
- PB3 (must-fix): commanderq compliance/governance tools route org through resolveToolOrgId(ctx,input) (authenticated org wins), verified LIVE in quox-collector (0 inverted patterns, resolveToolOrgId present).
- PB1 F6 bastion key grant fail-closed (origin/main).
- PB2 F7/RR5 quoxagent replay freshness + durable seen-set (origin/main).
- PB4 fail-closed collector gates, running container sha byte-identical to origin/main.
- PA5 half: quoxagent heartbeat reports the real build version (Options.AgentVersion wired; red-proven pin).
Findings
2 findings.
- highPB3: CommanderQ compliance tools trusted caller-supplied org_id (cross-tenant read+write)fixed
- mediumPA5: fleet cannot observe running build generation (heartbeat hardcoded 0.1.0)open_confirmed
2 WARD receipts on this cycle.
cycle 8
v1.3, Resilience
Bar v1.3 is the resilience bar: a bounded adversarial sweep fault-injected every mandatory dependency across 5 surfaces and asked whether each gate still holds when its dependency is down, slow, or the process dies mid-effect. The collector's fail-closed evidence/policy gates, durable executionLedger (crash -> outcome_unknown, no retry), and atomic single-use claim were verified LIVE in the running container. One real code must-fix (quoxagent replay seen-set was in-memory only) was fixed with a durable seen-set, red-proven-pinned, and deployed.
Controls held
- RR5 (the must-fix): quoxagent replay seen-set is now DURABLE (persisted to DataDir atomically, restored at boot), a restart no longer reopens the 15-min replay window on /jobs or /dev/invoke. Best-effort write so a disk fault cannot DoS the agent. Deployed as v84780f4.
- RR1 evidence/WARD store down: collector counts + surfaces audit-write failures (recordAuditWriteFailure, /health + /metrics) instead of a silent skip, verified in the running quox-collector.
- RR2 policy store down: collector fails closed on storeResult.unavailable (approvalGate) and returns policy_unavailable on governance exception (quoxchat), verified in the running container.
- RR3 external-effect crash-after-send: executionLedger durable claim before dispatch; reconcileOnBoot flips dispatched -> outcome_unknown, no retry, states enumerated, verified live.
- RR4 restart mid-dispatch: toolApprovalStore single atomic claim (SQLite-durable, replay -> null), reconciled at boot, verified live.
- RR2-bastion grant verification: fails closed on zero trusted keys / verify error (internal/approval/grant.go).
Findings
1 finding.
- highRR5: quoxagent replay seen-set was in-memory only (replay window reopens on restart)fixed
2 WARD receipts on this cycle.
cycle 7
v1.2, Complete Mediation
Bar v1.2 is the complete-mediation bar: a bounded adversarial sweep enumerated every effect path across 5 surfaces vs origin/main, and the T9 conformance pin now proves every effect-verb tool sits in exactly one reviewed bucket. Four must-fixes closed the gaps the sweep found; all are deployed to the running systems with red-proven CI pins.
Controls held
- MF-1: bastion DELETE /keys/{id} revoke now requires the collector-signed approval grant (F6 sibling closed), live the bastion host, running-exe verified.
- MF-2: native externalEffect tools (alerts_manage silence, backup_run, keeper_backup_create, deploy_template) default to HITL via AGENT_ALWAYS_PROPOSE + withApprovalGate, with non-blind T4 cards, NOT blanket-gated, live in the running collector.
- MF-3: github-proxy write routes routed through the executeConnectorTool governance choke (policy/approval/ledger/WARD); generate-notes via mediateGovernancePolicy + WARD, live in the running collector.
- MF-4: quoxagent /dev/invoke verifies signature before freshness (loopback pre-consumption DoS closed), live 34/36 fleet.
- hat_load_bundle classified (QuoxHat P4, option A: within-envelope capability selection, witnessed, not an external effect), T9 pin green.
Findings
4 findings.
- highMF-1: bastion DELETE /keys/{id} revoke was ungated (F6 sibling)fixed
- highMF-2: native externalEffect tools had no default HITLfixed
- highMF-3: github-proxy write routes bypassed the governance chokefixed
- mediumMF-4: quoxagent /dev/invoke verified freshness before signaturefixed
2 WARD receipts on this cycle.
cycle 6
v1, Release Gate
Bar v1 is the release-blocker gate: an independent adversarial pass (RB1-RB9) over the frozen release surface, with every boundary re-verified on the running collector, auth, quoxagent fleet and bastion. 33 findings were raised in the c4 cycle; the release-blocking set is remediated and deployed. The two deploy-pending blockers at the 2026-09-30 pass, F6 (bastion keys/deploy grant) and F7 (quoxagent job-envelope replay), were DEPLOYED to the live fleet on 2026-10-01 (F6 live on the bastion host; F7 dc25995 on 34/36 quoxagent hosts) and resolved.
Controls held
- Cross-tenant isolation made platform-wide: org derived from authenticated identity, never caller-supplied body/header, across ~8 header-routes + the native-tool route + security/compliance routes + vault-credential path (FND resolved).
- Arbitrary shell/SQL (ssh_exec, remote_ssh, db_query writes) and the wider bastion-tool shell-injection class now require human approval and are input-validated (multiple criticals resolved).
- Approval cards render the exact effective action (to/cc/bcc/subject/body, command, SQL), no blind-approve (T4).
- Fail-closed gates: 4-eyes policy-change gate no longer fails open on audit-write error; WARD witness no longer silently no-ops; GOV-4 store outage denies (T2).
- Signature integrity: AEE signature scope now covers HITL gate fields; approval_events chain covers action/actor; offline verifier binds key_id (T8).
- F6 DEPLOYED: bastion keys/deploy + sudo/setup gated behind the collector-signed approval grant (parallel path closed).
- F7 DEPLOYED: quoxagent /jobs + /dev/invoke replay/freshness guard keyed on the SIGNED CreatedAt (dc25995, 34/36 hosts).
Findings
33 findings.
- criticalcollector native tool route: body org_id overrides authenticated org (cross-tenant credential read)fixed
- criticalthird-party plugin JS injected into dashboard document unsandboxedfixed
- criticalkeys/deploy + sudo/setup skip requireApprovalGrant (parallel enforcement path)fixed
- criticalArbitrary shell/SQL executes without human approval: ssh_exec ungated; remote_ssh/db_query approval-path is theatrefixed
- criticalShell command injection in native bastion tools: system_admin (path/unit/priority/since/user), docker_fleet_logs + docker_fleet_stats (container_id)fixed
- criticalShell-injection class is wider than SGFV: 4 more UNGATED callBastion sites (network_check, docker_extended, ssl_certificates, security_audit) + 3 gated (docker_fleet_container_action, proxmox_vm_snapshot, proxmox_vm_clone)fixed
- criticalUNGATED shell injection in bastion_ssh executor (bastionSshExecutor.js) - a parallel shadow of the native fleet tools running off agent args; plus quoxagentExecutor hostIdfixed
- criticalOrg-scope cross-tenant is PLATFORM-WIDE: vault-credential exposure (agents/invoke), cross-org dev-host build/backup/restore/tmux, cross-org read of dev-session events, aee attribution, unauthed GOV-1 policy CRUDfixed
- highplugin tools register globally, not org-scoped (cross-tenant tool exposure)fixed
- highplugin backends share the internal service keyopen_confirmed
- highplugin-backend tools reach execution with no default approval gatefixed
- highjob envelope has no nonce and optional expiry (replay)fixed
- highapproval_events hash chain omits action/actor_type/actor_idfixed
- highoffline verifier trusts an unbound key_id, diverges from WARD SDK; no agreement testfixed
- highAEE signature scope excludes HITL gate fieldsfixed
- high4-eyes policy-change gate fails OPEN on an audit-write error (applies unapproved)fixed
- highContactability consent-grant route trusts x-org-id header over authenticated identity (cross-tenant write)fixed
- highremote_ssh (arbitrary shell) and db_query writes execute with no default approval gatefixed
- highSecurity-engagement/compliance routes derive org as 'req.user?.org_id || req.body/query.org_id' without the req.service gate the safe sibling routes use (potential cross-tenant)fixed
- highHeader-based cross-tenant: ~8 routes derive org as 'req.user?.org_id || req.headers[x-org-id]' with no req.service gate (SM0Q class via header, missed by the body/query fix); + toolsmith sandbox route bypasses GOV-4fixed
- highWARD witness degradation is silent: /health reports ready:true when witnessing is dead (initWardHooks failed), runtime witness errors uncounted, unsigned tips unaccounted (T3/T8 evidence-integrity)fixed
- mediumOutbound telephony + notification (tripwire) bypasses the GOV-4 governance chokefixed
- medium/chat/resolve-plan swallows a pre-LLM gate throw and proceeds (fail-open)fixed
- mediumWARD witness hooks silently no-op when not initialised (evidence receipts vanish untraced)fixed
- mediumVOLT GOLD certifies a self-signed (embedded-key) signature as identity-verifiedfixed
- mediumdocker_extended 'restart' is an ungated container MUTATION duplicating the gated docker_fleet_container_action (parallel-enforcement bypass)fixed
- mediumT-AUTH expiry gap: the inbox-driven approval resume path executes without re-checking approval expiry / current policy (stale approval still fires)fixed
- lowHARDENING: GOV-1 policy routes trust org_id from query/body for internal authorization (beyond route-level auth)open_reported
- inforeceipt-write failure masks the successful tool outcome and corrupts the chainfixed
- infoworkflow maxConcurrency has no upper ceiling (unbounded per-workflow admission)fixed
- infocall executor persists request headers verbatim into the evidence store (secret leak)fixed
- infobastion risky-mode 403s a live fleet log-collection loop (read-only journalctl requires a human grant)open_reported
- infopublic /webhooks route has no rate limit (comment claims 10/s, never wired)fixed
2 WARD receipts on this cycle.
cycle 5
Governed discovery on real deployments (2026-09)
The first governed security engagement Quox ran on real customer production sites, not on itself. Three verified production properties were scanned: two external customers (a VPN provider and a hot-tub retailer, redacted here as client-a / client-b) and quox.ai (our own). Every target proved control before any scan ran, every scan passed the same governed approval-grant path as any other risky action, and every step is WARD-witnessed. Findings are published at their honest severity: one low (an internet-exposed hosting control panel with its version disclosed) and two informational (a publicly-discoverable dev subdomain; a customer-named subdomain on our own site). Client identities are redacted; the receipts, scope and severities are not. This band grows over time as more deployments are scanned.
Controls held
- Complete mediation held: every scan minted and presented a bastion approval grant scoped to the exact command and target host; an out-of-scope subdomain probe was refused by the scope gate, not executed.
- Fail-closed held under real load: when the grant-mint policy callback timed out, the scan was refused rather than run ungranted.
- Proof-of-control enforced before any scan: a target that had not proven control (DNS or well-known challenge) could not be scanned.
- Discovery-tier ceiling enforced: production engagements cap at discovery, so no intrusive or exploit tooling ran against a live customer site.
Findings
3 findings.
- lowPlesk admin panel exposed on public port 8443 with version disclosed (Plesk Obsidian 18.0.80)open_confirmed
- infoPublicly discoverable dev/pre-production subdomain (dev.client-b.example)open_reported
- infoClient-named subdomain publicly discoverable via passive DNS (info disclosure of a customer relationship + host naming scheme)open_reported
2 WARD receipts on this cycle.
cycle 4
trust-proof-quoxtrust-conformance-c1
Fourth witnessed self-audit, and the first that audits the trust guarantees themselves rather than an attacker. Seven findings, all fixed and all verified on the running deployment. The evidence witness hashed only envelope metadata, so two different commands produced identical intact receipts; it now binds the action payload. The governance gate read a failed policy store as no matching rule and allowed the action; it now fails closed, separating unavailable from no rule, with a positive allowlist so an unknown tool defaults to denied. Audit-envelope write failures were silent; they are now accounted and surfaced on the health and metrics endpoints. A crash mid-dispatch left no record of an in-flight external effect; a durable execution ledger now records intent before dispatch, reconciles in-flight work on restart, and never auto-retries an ambiguous send. Two complete-mediation gaps let an effect run ungated, one in the chat widget on a policy exception and one on every connector path where the org policy check was skipped; both now pass a single reference monitor. The seventh finding is the guardrail against all of the above returning: a new effect-producing tool could previously be added with no gate decision, and the coverage invariant now fails the build unless every effect tool sits in a reviewed gate bucket. What is deliberately not claimed: the coverage invariant pins the tool surface, not every future entry point, and two boundaries are stated open rather than hidden, per-command mediation of a human terminal session and the in-browser behaviour of hostile third-party plugin code, neither of which a backend can witness. The counts are read live from the engagement store; an audit log that only ever shows green is indistinguishable from no audit at all.
Controls held
- Every fix is pinned by a required, non-continue-on-error CI gate that runs the invariant suites across two packages and is proven to exit non-zero on a deliberately broken candidate, so a reopened fail-open gate, an unwitnessed receipt or an ungated effect path goes red before it can merge
- The reference monitor now sits at both the native and the connector choke, and a governance deny takes precedence over the entitlement and rate checks, so no connector caller, direct route or delegated agent, can reach an effect the org policy forbids
- The durable execution ledger reconciles in-flight effects on boot and refuses to dispatch when its own durable write fails, so an ambiguous external send is recorded as outcome-unknown rather than silently lost or blindly retried
- The fixes were verified test-first and on the running deployment, not only in unit tests; each of the six runtime findings was re-checked in the running collector after its fix
- No secret values were disclosed by any finding in this cycle; the findings are structural properties of the enforcement path, not leaked credentials
- The published log recomputes each WARD receipt at publish time and is Ed25519-signed and verified in CI and in the production build, so a fabricated entry needs the signing key, not merely an internally consistent shape
Findings
7 findings.
- highEvidence witness omitted the action payloadfixed
- highGovernance gate failed open on policy-store outagefixed
- highWidget effect gate fell through to execution on policy exceptionfixed
- highConnector tools bypassed org governance policyfixed
- mediumAudit-envelope write failures were silentfixed
- mediumNo durable execution intent for external effectsfixed
- mediumEffect-producing tools could ship without a gate decisionfixed
2 WARD receipts on this cycle.
cycle 3
trust-proof-self-audit-c3
Third witnessed self-audit. Fourteen findings, thirteen fixed and one published open on purpose. The open one is the audit turned on its own publish path: the /security CI gate recomputed each WARD receipt only from fields already committed to this file and never re-queried the live evidence store, so a hand-fabricated finding with a self-consistent fake receipt would have passed the automated gate and been stopped only by human diff review. It is stated here as confirmed, not fixed, and the signing work this cycle ships is the response: the published log is now Ed25519-signed and the signature is verified both in CI and in the production build, so a forged entry needs the signing key, not merely an internally consistent shape. Three of the resolved findings were cross-tenant data-loss launch blockers, unauthenticated collector routes that let any caller read, register or delete another org's data, one of them proven live. The rest span an approval gate that failed open on destructive actions, a HITL path that did not enforce its own declared approvers, a per-agent access check bypassable for up to sixty seconds on a lookup failure, a bulk approve and deny that was a silent no-op, and a real host prefix that leaked into placeholder copy. The counts are read live from the engagement store; an audit log that only ever shows green is indistinguishable from no audit at all.
Controls held
- The fixes were verified test-first and on the running deployment, not only in unit tests; the three launch-blocking routes were re-checked live and refused another org's data after the fix
- Where the collector authentication gate was present it held; the cross-tenant findings were routes that lacked the gate or trusted a client-supplied org id, never the gate itself being defeated
- The publish-path evidence check held: recomputing each cycle's WARD chain against the live store at publish time is intact, and the allowlist projection that lets only title, severity and status reach the page is unchanged
- Once fixed, the approval path and per-agent RBAC refused the escalations they had allowed: an under-approved bulk response and a destructive action on the legacy gate now stop rather than proceed
- No secret values were disclosed by the findings above; the one leak was a host prefix in placeholder copy, corrected, not a credential
Findings
14 findings.
- infoApproval gate legacy QuoxFlow check failed OPEN on destructive actionsfixed
- infoPer-agent access_mode enforcement bypassed for up to 60s on auth-DB-lookup failurefixed
- infoHITL respond/bulk did not enforce declared approvers (multi-member-org privilege escalation)fixed
- infoBulk approve/deny was a silent no-op (no dispatch, no VOLT witness)fixed
- infotests-lab admin routes unauthenticated with no production guard (FALSECLAIM + DoS)fixed
- infoadmin backfill-teams under-gated (readonly tier vs sibling admin)fixed
- infoIntegration-type placeholders leaked a real host prefix + owner LANfixed
- infoCollector rate-limiting is narrow: ~3 buckets across ~462 routes, no global DoS guardfixed
- infoLIVE cross-tenant + dataloss: screencap ~40/49 routes unauthenticated, trust client org_id, reachable via nginx passthroughfixed
- infoCross-tenant + dataloss: collector /api/v1/users/:userId/data gated only by spoofable x-internal-service headerfixed
- infoCross-tenant + dataloss: collector /api/v1/local-inference/sources has zero auth + no org scopingfixed
- info/security CI gate does not re-verify receipts against the live store (forgery caught only by human review)open_confirmed
- infolocal-inference chat-time resolveLocalSource() does an unscoped lookup (authed cross-org source reuse)fixed
- infoscreencap live-stream sessions not org-tagged (authed session-id guess cross-org)fixed
2 WARD receipts on this cycle.
cycle 2
trust-proof-self-audit-c2
Second witnessed self-audit: a cross-tenant isolation sweep. Nine families were found where one organisation could read or act as another, including reads of another org's decrypted evidence, fleet inventory, workflow analytics and tool definitions, and a proxy that trusted a spoofable org header. All nine were fixed and then proven on the running system with two real organisations: thirty-two live cross-org checks in which org A is refused org B's data by id, by listing, by write, and with a spoofed org header. Every finding above is resolved. One honest residual remains and is stated on purpose: WARD's read path is now org-scoped and proven, but the evidence hash chain is still a single global chain shared by all orgs, so per-org cryptographic chain isolation is not yet certified. The counts are read live from the engagement store; an audit log that only ever shows green is indistinguishable from no audit at all.
Controls held
- The collector authentication gate held: unauthenticated requests were refused before any org data was returned on every route checked
- A signed-in caller could not widen their scope with a client-supplied org id or org header on any fixed route; the override is honoured only for trusted service callers
- The auth service enforced organisation membership as a second, independent gate on the Action Tracker proxy
- A route with no resolvable organisation returned an empty result, never a global fallback, and a record owned by another org read as not-found rather than disclosing its existence
- The isolation fixes were proven against the deployed containers, not only in unit tests, with the org id read from a verified token rather than any client-supplied value
Findings
9 findings.
- highCross-tenant read+write in compliance/auditor API (SoA/DPIA/classification/engagements/jobs)fixed
- highCross-tenant read of DECRYPTED AEE envelopes (/aee/:id, /aee/conversation/:corr)fixed
- highCross-tenant read of VOLT evidence (run events, bundles, /certs) + spoofable /volt/sync writefixed
- highCross-tenant read of decrypted QuoxTraces (/traces/:id, simulate, compare)fixed
- highUnauthenticated cross-tenant GPU fleet enumeration (/api/v1/gpu/nodes)fixed
- highCross-tenant read of WARD evidence entries (/ward/entries, /entries/:id, /source-breakdown)fixed
- highUnauthenticated cross-tenant analytics in tasks engine (/api/engine/temporal, /dream)fixed
- mediumCross-tenant read of custom tool definitions (/api/v1/tools/list, /audit)fixed
- mediumAction Tracker proxy honored spoofable x-org-id instead of the JWT org (/api/v1/actions)fixed
2 WARD receipts on this cycle.
cycle 1
trust-proof-self-audit-c1
First witnessed self-audit, and the fix sweep it forced. Findings were filed by nine parallel hostile audit lanes, with several more uncovered during the fix work itself, including two the fixes exposed: our HITL approve path dropped the very grant it existed to mint, and the trust page overclaimed 'no external telemetry'. The counts above are read live from the engagement store; every finding marked fixed was remediated test-first and verified on the running system before being resolved. The rest are published open, on purpose. An audit log that only ever shows green is indistinguishable from no audit at all.
Controls held
- Vault envelope encryption held end to end; no secret values in logs or API responses
- Tenant scoping held on vault, memory, HITL and admin paths (queries traced, not assumed)
- Privilege-escalation guards held on both role paths
- Job-envelope signing fails closed; delimiter injection previously found is fixed
- No phone-home beyond the disclosed heartbeat and license check, and the heartbeat is now strictly opt-in
- Agent RBAC held during the fix sweep itself: the builder-role agent session was refused allowlist changes and could not approve its own gated actions
Findings
19 findings.
- criticalQuoxPlan server accepts unauthenticated LAN read/write of all org roadmap datafixed
- criticalNo server-side HITL gate: approval token is UI decoration, exec-scope token executes immediatelyfixed
- highTool manifest Ed25519 verification is computed but never enforced at executionopen_confirmed
- highSandbox script stdout/stderr returns vault secrets unredacted into chat transcriptsfixed
- highWorkflow call executor SSRF: redirects followed unchecked and no DNS resolution in the private-IP checkfixed
- highInstaller is curl piped to bash over plain HTTP with no integrity verificationfixed
- highHITL approve bridge drops inbox_item_id: approved bastion actions execute grantless and are 403d by a gate-enabled bastionfixed
- highTest Lab fabricates pass/fail test numbers (mock on by default, Math.random) and ships hardcoded compliance countsopen_reported
- highCross-tenant leak: GET /volt/runs returns every org's VOLT runs unscoped to authenticated callers (anonymous requests are 401d by the collector auth gate)fixed
- mediumTelemetry heartbeat is opt-out-by-default (pre-ticked in setup)fixed
- mediumContainer publish workflow not tag-gated; latest can be pushed from arbitrary branch statefixed
- mediumNo Docker base image digest pinning anywhere; screencap uses :latestfixed
- mediumnpm audit: prod-relevant highs in dashboard (sharp CVE-2026-33327/28/35590/91, react-router-dom GHSA high)open_reported
- mediumInternal signing endpoint accepts caller-supplied org_id under shared INTERNAL_SERVICE_KEY (signing oracle)open_reported
- mediumOne native-tool approval mints two inbox items; only the native_tool_approval twin actually resumes the toolfixed
- mediumTrust page claims 'no external telemetry' while the licensed heartbeat exists (opt-out at the time of writing)fixed
- lowWARD webhook sink fetches with no egress guard (env-only today, ships pre-broken if ever request-configurable)fixed
- lowNo CI workflows in Go repos; binaries built ad hoc with no tag provenancefixed
- lowQlarity browser-level guard blocks org-allowlisted localhost origin (ERR_BLOCKED_BY_CLIENT)fixed
2 WARD receipts on this cycle.