{
  "schema": "quox.security-audit-log.v1",
  "generated_by": "scripts/export-security-audit.mjs",
  "cycles": [
    {
      "cycle": 1,
      "engagement_id": "ENG_01M2X3HJ2W9PGNTVN5H59PGNTV",
      "name": "trust-proof-self-audit-c1",
      "started_at": "2026-09-19T15:11:18.624Z",
      "last_event_at": "2026-09-20T01:38:40.825Z",
      "scope": [
        "github.com/quoxai/quox",
        "github.com/quoxai/quoxplan",
        "github.com/quoxai/quoxflow",
        "github.com/quoxai/quoxagent",
        "github.com/quoxai/quoxbastion",
        "github.com/quoxai/quoxmcp",
        "github.com/quoxai/quox-repobrain"
      ],
      "method": "Adversarial prompt authored by the owner, run as 9 parallel hostile audit lanes over full local checkouts of every repo in scope: credential theft, phone-home, SSRF and egress, auth boundaries, fleet backdoors, supply chain, plus running-artifact-matches-source checks.",
      "summary": "First witnessed self-audit, and the fix sweep it forced. Findings were filed by nine parallel hostile audit lanes, with several more uncovered during the fix work itself, including two the fixes exposed: our HITL approve path dropped the very grant it existed to mint, and the trust page overclaimed 'no external telemetry'. The counts above are read live from the engagement store; every finding marked fixed was remediated test-first and verified on the running system before being resolved. The rest are published open, on purpose. An audit log that only ever shows green is indistinguishable from no audit at all.",
      "controls_held": [
        "Vault envelope encryption held end to end; no secret values in logs or API responses",
        "Tenant scoping held on vault, memory, HITL and admin paths (queries traced, not assumed)",
        "Privilege-escalation guards held on both role paths",
        "Job-envelope signing fails closed; delimiter injection previously found is fixed",
        "No phone-home beyond the disclosed heartbeat and license check, and the heartbeat is now strictly opt-in",
        "Agent RBAC held during the fix sweep itself: the builder-role agent session was refused allowlist changes and could not approve its own gated actions"
      ],
      "totals": {
        "critical": 2,
        "high": 7,
        "medium": 7,
        "low": 3,
        "fixed": 15,
        "open": 4,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M2X3QVS374X6NTWD9274X6NT",
          "target": "github.com/quoxai/quoxplan",
          "title": "QuoxPlan server accepts unauthenticated LAN read/write of all org roadmap data",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:14:45",
          "resolved_at": "2026-09-19 18:40:18"
        },
        {
          "id": "FND_01M2X3WF346HH7VV9BZJ6HH7VV",
          "target": "github.com/quoxai/quoxbastion",
          "title": "No server-side HITL gate: approval token is UI decoration, exec-scope token executes immediately",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:17:16",
          "resolved_at": "2026-09-19 18:40:20"
        },
        {
          "id": "FND_01M2X3S6GY7JAYB3HFFT7JAYB3",
          "target": "github.com/quoxai/quoxagent",
          "title": "Tool manifest Ed25519 verification is computed but never enforced at execution",
          "severity": "high",
          "status": "confirmed",
          "outcome": "open_confirmed",
          "reported_at": "2026-09-19 15:15:28"
        },
        {
          "id": "FND_01M2X3S90XGQTWP5ZX7DGQTWP5",
          "target": "github.com/quoxai/quox",
          "title": "Sandbox script stdout/stderr returns vault secrets unredacted into chat transcripts",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:15:31",
          "resolved_at": "2026-09-19 18:40:21"
        },
        {
          "id": "FND_01M2X3SB5XVG8XZF7K73VG8XZF",
          "target": "github.com/quoxai/quoxflow",
          "title": "Workflow call executor SSRF: redirects followed unchecked and no DNS resolution in the private-IP check",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:15:33",
          "resolved_at": "2026-09-19 18:51:31"
        },
        {
          "id": "FND_01M2X3SD0Y16D7AFXXVF16D7AF",
          "target": "github.com/quoxai/quoxagent",
          "title": "Installer is curl piped to bash over plain HTTP with no integrity verification",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:15:35",
          "resolved_at": "2026-09-19 21:42:00"
        },
        {
          "id": "FND_01M2XM28PD83SMWYFD1583SMWY",
          "target": "github.com/quoxai/quox",
          "title": "HITL approve bridge drops inbox_item_id: approved bastion actions execute grantless and are 403d by a gate-enabled bastion",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 20:00:03",
          "resolved_at": "2026-09-19 21:07:55"
        },
        {
          "id": "FND_01M2Y1G0BMMNEADZJK5VMNEADZ",
          "target": "github.com/quoxai/quox",
          "title": "Test Lab fabricates pass/fail test numbers (mock on by default, Math.random) and ships hardcoded compliance counts",
          "severity": "high",
          "status": "candidate",
          "outcome": "open_reported",
          "reported_at": "2026-09-19 23:54:44"
        },
        {
          "id": "FND_01M2Y2GXRF1YBV9DJRVE1YBV9D",
          "target": "github.com/quoxai/quox",
          "title": "Cross-tenant leak: GET /volt/runs returns every org's VOLT runs unscoped to authenticated callers (anonymous requests are 401d by the collector auth gate)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-20 00:12:43",
          "title_as_filed": "Cross-tenant leak: GET /volt/runs returns every org's VOLT runs unscoped and unauthenticated",
          "correction_note": "As filed the title said 'unscoped and unauthenticated'. Verification showed anonymous requests are refused (HTTP 401) by the collector auth gate, so the real exposure is cross-tenant reads by any authenticated caller paging the listing, not anonymous access. Corrected here because the engagement store has no amend-title verb; the as-filed title and this note are preserved so the page can be diffed against the store.",
          "resolved_at": "2026-09-20 00:51:24"
        },
        {
          "id": "FND_01M2X3TEGSAPKGESW02DAPKGES",
          "target": "github.com/quoxai/quox",
          "title": "Telemetry heartbeat is opt-out-by-default (pre-ticked in setup)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:16:09",
          "resolved_at": "2026-09-19 21:23:38"
        },
        {
          "id": "FND_01M2X3TG6XBTHD758N6EBTHD75",
          "target": "github.com/quoxai/quox-repobrain",
          "title": "Container publish workflow not tag-gated; latest can be pushed from arbitrary branch state",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:16:11",
          "resolved_at": "2026-09-19 21:44:24"
        },
        {
          "id": "FND_01M2X3THN57136H1XRJK7136H1",
          "target": "github.com/quoxai/quox",
          "title": "No Docker base image digest pinning anywhere; screencap uses :latest",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:16:13",
          "resolved_at": "2026-09-20 01:38:40"
        },
        {
          "id": "FND_01M2X3TKVVDVM97X56FYDVM97X",
          "target": "github.com/quoxai/quox",
          "title": "npm audit: prod-relevant highs in dashboard (sharp CVE-2026-33327/28/35590/91, react-router-dom GHSA high)",
          "severity": "medium",
          "status": "candidate",
          "outcome": "open_reported",
          "reported_at": "2026-09-19 15:16:15"
        },
        {
          "id": "FND_01M2X3WGM0EZZ3PBQ8MCEZZ3PB",
          "target": "github.com/quoxai/quox",
          "title": "Internal signing endpoint accepts caller-supplied org_id under shared INTERNAL_SERVICE_KEY (signing oracle)",
          "severity": "medium",
          "status": "candidate",
          "outcome": "open_reported",
          "reported_at": "2026-09-19 15:17:17"
        },
        {
          "id": "FND_01M2XM4SJHGW46P447XAGW46P4",
          "target": "github.com/quoxai/quox",
          "title": "One native-tool approval mints two inbox items; only the native_tool_approval twin actually resumes the tool",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 20:01:26",
          "resolved_at": "2026-09-19 21:50:50"
        },
        {
          "id": "FND_01M2XPQFK7C3ECZR5JWVC3ECZR",
          "target": "github.com/quoxai/quoxwebsite",
          "title": "Trust page claims 'no external telemetry' while the licensed heartbeat exists (opt-out at the time of writing)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 20:46:35",
          "resolved_at": "2026-09-19 22:59:24"
        },
        {
          "id": "FND_01M2X3TN24G7HPZNDBXYG7HPZN",
          "target": "github.com/quoxai/quox",
          "title": "WARD webhook sink fetches with no egress guard (env-only today, ships pre-broken if ever request-configurable)",
          "severity": "low",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:16:16",
          "resolved_at": "2026-09-19 21:52:14"
        },
        {
          "id": "FND_01M2X3TPFFW31KX6PN17W31KX6",
          "target": "github.com/quoxai/quoxbastion",
          "title": "No CI workflows in Go repos; binaries built ad hoc with no tag provenance",
          "severity": "low",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 15:16:18",
          "resolved_at": "2026-09-19 21:43:47"
        },
        {
          "id": "FND_01M2XGN8YGY9ESE7GYWTY9ESE7",
          "target": "github.com/quoxai/quox",
          "title": "Qlarity browser-level guard blocks org-allowlisted localhost origin (ERR_BLOCKED_BY_CLIENT)",
          "severity": "low",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-19 19:00:31",
          "resolved_at": "2026-09-19 22:59:37"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 2696539,
            "ward_entry_id": "58567dd7-5271-4627-9957-ba8936a7f4e2",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-19T15:11:18.624Z",
            "source_kind": "AEE",
            "source_id": "ENV_MU8IZ2AM_9GP7J2HB",
            "payload_hash": "16c91d42bcf9b166be9669a5a8b03f2fa8bdd612280d65789089f4b3d96a2c08",
            "prev_chain_hash": "7be6869885fbf4beb14a09155795fcaae0abc1b75feaf3f2e882e39f915a7eec",
            "chain_hash": "b59d37a3e28d70e5f5e633127a50dc65570960fd8409f8838216036a2ceceaa4"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 2724319,
            "ward_entry_id": "65832355-9246-4b3a-95a0-1077fea05422",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-20T01:38:40.825Z",
            "source_kind": "AEE",
            "source_id": "ENV_MU95DV7A_J76ZQ9BR",
            "payload_hash": "11305f00199a6a28e6463ddbd19407383217a94ab9785270e2230d707cfb3a43",
            "prev_chain_hash": "4780609f5af7712bb482b17b9c91f04a3118c4e7623bdb73c8baedd0d3c0d3b7",
            "chain_hash": "7d886409d622ed7c6a15fe4bbd21f7ded0a3ee7d9b4ddf30b57799e799c15323"
          }
        ]
      },
      "published": true
    },
    {
      "cycle": 2,
      "engagement_id": "ENG_01M3AWXNJFGWMNDQTHKKGWMNDQ",
      "name": "trust-proof-self-audit-c2",
      "started_at": "2026-09-24T23:44:57.426Z",
      "last_event_at": "2026-09-25T00:22:29.852Z",
      "scope": [
        "quoxai/quox"
      ],
      "method": "A full cross-tenant (multi-tenant isolation) sweep of every org-scoped read and write route across the collector, the tasks engine, the WARD evidence service, and the QuoxFlow executors. Each candidate was checked for a real leak versus a downstream gate, fixed with one canonical org-derivation pattern (a signed-in user is locked to their own org; a client-supplied org id is honoured only for trusted service callers; a record fetched by id is gated on ownership), and then driven as a live two-org request on the running deployment to confirm that org A cannot read or act as org B.",
      "summary": "Second witnessed self-audit: a cross-tenant isolation sweep. Nine families were found where one organisation could read or act as another, including reads of another org's decrypted evidence, fleet inventory, workflow analytics and tool definitions, and a proxy that trusted a spoofable org header. All nine were fixed and then proven on the running system with two real organisations: thirty-two live cross-org checks in which org A is refused org B's data by id, by listing, by write, and with a spoofed org header. Every finding above is resolved. One honest residual remains and is stated on purpose: WARD's read path is now org-scoped and proven, but the evidence hash chain is still a single global chain shared by all orgs, so per-org cryptographic chain isolation is not yet certified. The counts are read live from the engagement store; an audit log that only ever shows green is indistinguishable from no audit at all.",
      "controls_held": [
        "The collector authentication gate held: unauthenticated requests were refused before any org data was returned on every route checked",
        "A signed-in caller could not widen their scope with a client-supplied org id or org header on any fixed route; the override is honoured only for trusted service callers",
        "The auth service enforced organisation membership as a second, independent gate on the Action Tracker proxy",
        "A route with no resolvable organisation returned an empty result, never a global fallback, and a record owned by another org read as not-found rather than disclosing its existence",
        "The isolation fixes were proven against the deployed containers, not only in unit tests, with the org id read from a verified token rather than any client-supplied value"
      ],
      "totals": {
        "critical": 0,
        "high": 7,
        "medium": 2,
        "low": 0,
        "fixed": 9,
        "open": 0,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3AWZKSFXH5NPV0S2CXH5NPV",
          "target": "quoxai/quox",
          "title": "Cross-tenant read+write in compliance/auditor API (SoA/DPIA/classification/engagements/jobs)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:46:01",
          "resolved_at": "2026-09-24 23:46:55"
        },
        {
          "id": "FND_01M3AX2GP0EETESTWQQBEETEST",
          "target": "quoxai/quox",
          "title": "Cross-tenant read of DECRYPTED AEE envelopes (/aee/:id, /aee/conversation/:corr)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:47:36",
          "resolved_at": "2026-09-24 23:47:39"
        },
        {
          "id": "FND_01M3AX2NWVC0G0DA7K6CC0G0DA",
          "target": "quoxai/quox",
          "title": "Cross-tenant read of VOLT evidence (run events, bundles, /certs) + spoofable /volt/sync write",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:47:41",
          "resolved_at": "2026-09-24 23:47:45"
        },
        {
          "id": "FND_01M3AX2VGA649VSGAJ3F649VSG",
          "target": "quoxai/quox",
          "title": "Cross-tenant read of decrypted QuoxTraces (/traces/:id, simulate, compare)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:47:47",
          "resolved_at": "2026-09-24 23:47:57"
        },
        {
          "id": "FND_01M3AX37ECTK5RC1W9JFTK5RC1",
          "target": "quoxai/quox",
          "title": "Unauthenticated cross-tenant GPU fleet enumeration (/api/v1/gpu/nodes)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:47:59",
          "resolved_at": "2026-09-24 23:48:02"
        },
        {
          "id": "FND_01M3AX3NT2EFTS4C7S84EFTS4C",
          "target": "quoxai/quox",
          "title": "Cross-tenant read of WARD evidence entries (/ward/entries, /entries/:id, /source-breakdown)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:48:14",
          "resolved_at": "2026-09-25 00:22:27"
        },
        {
          "id": "FND_01M3AX3XEAWY64Y7R1J4WY64Y7",
          "target": "quoxai/quox",
          "title": "Unauthenticated cross-tenant analytics in tasks engine (/api/engine/temporal, /dream)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:48:22",
          "resolved_at": "2026-09-25 00:22:29"
        },
        {
          "id": "FND_01M3AX3BV3HB9W0T86DGHB9W0T",
          "target": "quoxai/quox",
          "title": "Cross-tenant read of custom tool definitions (/api/v1/tools/list, /audit)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:48:04",
          "resolved_at": "2026-09-24 23:48:06"
        },
        {
          "id": "FND_01M3AX3FZ9ZQJVK6CSAYZQJVK6",
          "target": "quoxai/quox",
          "title": "Action Tracker proxy honored spoofable x-org-id instead of the JWT org (/api/v1/actions)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-24 23:48:08",
          "resolved_at": "2026-09-25 00:22:26"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 2982615,
            "ward_entry_id": "d1782be4-cc12-43d3-92b5-c03308676aca",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-24T23:44:57.426Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUG6IVKG_PL07GGU4",
            "payload_hash": "3dc4f2b18aed414e390dfc2c0a371cf466e697aa4602d4957ac2d82762bf8dc5",
            "prev_chain_hash": "62490cf545c678c033919c2b533aee3bc69606e6048a4fa62820e56d0b049ef0",
            "chain_hash": "7348034d3304e5a95f34719127a56457594ed3d12262b4d68d36ce7341f92b86"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 2984020,
            "ward_entry_id": "3142be06-bbba-40b0-8f33-d62da72399ff",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-25T00:22:29.852Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUG7V5JT_BDGMKTGV",
            "payload_hash": "f9c0c92d2437c5d6f0960280095364927dfb09eff45c3a4f284d14d9e5af210b",
            "prev_chain_hash": "2344e8b0c42752e9d0fd6f9cf70c60062c69793d8aef7a6c56a8f87c6dec96b4",
            "chain_hash": "c411adcff4d54a6768da7ca11e4fb675e3c70e8347006bf8038add46d0390d28"
          }
        ]
      },
      "published": true
    },
    {
      "cycle": 3,
      "engagement_id": "ENG_01M3BBNJBH0DVJQ4BPX60DVJQ4",
      "name": "trust-proof-self-audit-c3",
      "started_at": "2026-09-25T04:02:40.637Z",
      "last_event_at": "2026-09-25T05:17:46.369Z",
      "scope": [
        "quoxai/quox"
      ],
      "method": "A follow-on adversarial sweep after the cross-tenant isolation cycle, widening from tenant boundaries into governance and into the audit's own evidence pipeline. Fourteen findings across the collector, the screencap and local-inference services, the HITL approval path, per-agent access enforcement, and the /security publish gate itself. Each was traced to a root cause, fixed test-first, and re-verified on the running deployment. The launch-blocking cross-tenant routes were proven live, an unauthenticated request returning another org's data with HTTP 200, before the fix and confirmed refused after it.",
      "summary": "Third witnessed self-audit. Fourteen findings, thirteen fixed and one published open on purpose. The open one is the audit turned on its own publish path: the /security CI gate recomputed each WARD receipt only from fields already committed to this file and never re-queried the live evidence store, so a hand-fabricated finding with a self-consistent fake receipt would have passed the automated gate and been stopped only by human diff review. It is stated here as confirmed, not fixed, and the signing work this cycle ships is the response: the published log is now Ed25519-signed and the signature is verified both in CI and in the production build, so a forged entry needs the signing key, not merely an internally consistent shape. Three of the resolved findings were cross-tenant data-loss launch blockers, unauthenticated collector routes that let any caller read, register or delete another org's data, one of them proven live. The rest span an approval gate that failed open on destructive actions, a HITL path that did not enforce its own declared approvers, a per-agent access check bypassable for up to sixty seconds on a lookup failure, a bulk approve and deny that was a silent no-op, and a real host prefix that leaked into placeholder copy. The counts are read live from the engagement store; an audit log that only ever shows green is indistinguishable from no audit at all.",
      "controls_held": [
        "The fixes were verified test-first and on the running deployment, not only in unit tests; the three launch-blocking routes were re-checked live and refused another org's data after the fix",
        "Where the collector authentication gate was present it held; the cross-tenant findings were routes that lacked the gate or trusted a client-supplied org id, never the gate itself being defeated",
        "The publish-path evidence check held: recomputing each cycle's WARD chain against the live store at publish time is intact, and the allowlist projection that lets only title, severity and status reach the page is unchanged",
        "Once fixed, the approval path and per-agent RBAC refused the escalations they had allowed: an under-approved bulk response and a destructive action on the legacy gate now stop rather than proceed",
        "No secret values were disclosed by the findings above; the one leak was a host prefix in placeholder copy, corrected, not a credential"
      ],
      "totals": {
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "fixed": 13,
        "open": 1,
        "refuted": 0,
        "info": 14
      },
      "findings": [
        {
          "id": "FND_01M3BBQ8AGM2CCYA1A9MM2CCYA",
          "target": "quoxai/quox",
          "title": "Approval gate legacy QuoxFlow check failed OPEN on destructive actions",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:03:35",
          "resolved_at": "2026-09-25 04:05:16"
        },
        {
          "id": "FND_01M3BBRXJZX4AW32GAABX4AW32",
          "target": "quoxai/quox",
          "title": "Per-agent access_mode enforcement bypassed for up to 60s on auth-DB-lookup failure",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:04:30",
          "resolved_at": "2026-09-25 04:05:23"
        },
        {
          "id": "FND_01M3BBRZ50SJ4JK2QCHHSJ4JK2",
          "target": "quoxai/quox",
          "title": "HITL respond/bulk did not enforce declared approvers (multi-member-org privilege escalation)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:04:32",
          "resolved_at": "2026-09-25 04:05:28"
        },
        {
          "id": "FND_01M3BBS11Z5EA9V118HB5EA9V1",
          "target": "quoxai/quox",
          "title": "Bulk approve/deny was a silent no-op (no dispatch, no VOLT witness)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:04:33",
          "resolved_at": "2026-09-25 04:05:31"
        },
        {
          "id": "FND_01M3BBS2H1WHKXQS20BDWHKXQS",
          "target": "quoxai/quox",
          "title": "tests-lab admin routes unauthenticated with no production guard (FALSECLAIM + DoS)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:04:35",
          "resolved_at": "2026-09-25 04:05:34"
        },
        {
          "id": "FND_01M3BBS426MZXZM386PQMZXZM3",
          "target": "quoxai/quox",
          "title": "admin backfill-teams under-gated (readonly tier vs sibling admin)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:04:37",
          "resolved_at": "2026-09-25 04:05:37"
        },
        {
          "id": "FND_01M3BBS5H20PWFJZ4PP90PWFJZ",
          "target": "quoxai/quox",
          "title": "Integration-type placeholders leaked a real host prefix + owner LAN",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:04:38",
          "resolved_at": "2026-09-25 04:05:40"
        },
        {
          "id": "FND_01M3BBS72Q93WGDTBB5M93WGDT",
          "target": "quoxai/quox",
          "title": "Collector rate-limiting is narrow: ~3 buckets across ~462 routes, no global DoS guard",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:04:40",
          "resolved_at": "2026-09-25 05:17:43"
        },
        {
          "id": "FND_01M3BC5NVQ0A9HMS7PJD0A9HMS",
          "target": "quoxai/quox",
          "title": "LIVE cross-tenant + dataloss: screencap ~40/49 routes unauthenticated, trust client org_id, reachable via nginx passthrough",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:11:28",
          "resolved_at": "2026-09-25 04:43:47"
        },
        {
          "id": "FND_01M3BC5QM84C9XDK1A3W4C9XDK",
          "target": "quoxai/quox",
          "title": "Cross-tenant + dataloss: collector /api/v1/users/:userId/data gated only by spoofable x-internal-service header",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:11:30",
          "resolved_at": "2026-09-25 04:43:45"
        },
        {
          "id": "FND_01M3BC5SQ44S79BJHJ8J4S79BJ",
          "target": "quoxai/quox",
          "title": "Cross-tenant + dataloss: collector /api/v1/local-inference/sources has zero auth + no org scoping",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:11:32",
          "resolved_at": "2026-09-25 04:43:44"
        },
        {
          "id": "FND_01M3BC9DKE113327SVN7113327",
          "target": "quoxai/quox",
          "title": "/security CI gate does not re-verify receipts against the live store (forgery caught only by human review)",
          "severity": "info",
          "status": "confirmed",
          "outcome": "open_confirmed",
          "reported_at": "2026-09-25 04:13:31"
        },
        {
          "id": "FND_01M3BD3MQ24GSEA04HBT4GSEA0",
          "target": "quoxai/quox",
          "title": "local-inference chat-time resolveLocalSource() does an unscoped lookup (authed cross-org source reuse)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:27:50",
          "resolved_at": "2026-09-25 05:17:44"
        },
        {
          "id": "FND_01M3BD3XZYTS7F1R2BR9TS7F1R",
          "target": "quoxai/quox",
          "title": "screencap live-stream sessions not org-tagged (authed session-id guess cross-org)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-25 04:27:59",
          "resolved_at": "2026-09-25 05:17:46"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 2992185,
            "ward_entry_id": "ec6fb45d-cd15-4b38-a4f0-a74a391670fe",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-25T04:02:40.637Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUGFQB1Z_KPFDLROU",
            "payload_hash": "5d43228ac03a35d41bda7d4106067ea0df5f48ee8c0a6d0c54625e044e2655fe",
            "prev_chain_hash": "98485f4e2580188fd33b65915e719c1b00385cf8a0de1e8f37b7403a888e0178",
            "chain_hash": "3f27448fc63d8c7875ce6f2a163d0f4d6b1e62092681e0d37e5ce60d4fe3c389"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 2994912,
            "ward_entry_id": "ff097e20-a2f9-4771-8d9f-29d854f11af2",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-25T05:17:46.369Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUGIEVPB_SUPSO2IW",
            "payload_hash": "6040c4a728dfc819df6501b11f490018a845eae49231bcc1eef276cd254dad76",
            "prev_chain_hash": "68f64d1d390ffbe44c050137ffe042d7e468f9e27649af9fcf3db5e14ad4c4a5",
            "chain_hash": "52c0232837efe982e759b8a68cfea922a4ab46f10de216b526c4722c085e1680"
          }
        ]
      },
      "published": true
    },
    {
      "cycle": 4,
      "engagement_id": "ENG_01M3DGGCTA8AX3MZVQJA8AX3MZ",
      "name": "trust-proof-quoxtrust-conformance-c1",
      "started_at": "2026-09-26T00:05:42.924Z",
      "last_event_at": "2026-09-26T00:07:44.309Z",
      "scope": [
        "quoxai/quox"
      ],
      "method": "A conformance cycle, distinct from the hostile-lane self-audits of cycles one through three. Its subject is not an intruder but our own trust guarantees: does each promise hold under a dependency failure, a crash, an exception, and every caller path. It was driven by an unsweetened outside worthiness study that rated the platform four out of ten and proved that trust-invariant violations had shipped undetected, because the checks that existed only asked whether a control was wired, never whether it held. Seven findings across the evidence witness, the governance gate, the audit and execution durability paths, and complete mediation. Each was reproduced with a failing test first, fixed at the root, and re-verified on the running deployment, then pinned by a permanent regression in a required CI gate that is proven to refuse a broken candidate rather than merely to exist.",
      "summary": "Fourth witnessed self-audit, and the first that audits the trust guarantees themselves rather than an attacker. Seven findings, all fixed and all verified on the running deployment. The evidence witness hashed only envelope metadata, so two different commands produced identical intact receipts; it now binds the action payload. The governance gate read a failed policy store as no matching rule and allowed the action; it now fails closed, separating unavailable from no rule, with a positive allowlist so an unknown tool defaults to denied. Audit-envelope write failures were silent; they are now accounted and surfaced on the health and metrics endpoints. A crash mid-dispatch left no record of an in-flight external effect; a durable execution ledger now records intent before dispatch, reconciles in-flight work on restart, and never auto-retries an ambiguous send. Two complete-mediation gaps let an effect run ungated, one in the chat widget on a policy exception and one on every connector path where the org policy check was skipped; both now pass a single reference monitor. The seventh finding is the guardrail against all of the above returning: a new effect-producing tool could previously be added with no gate decision, and the coverage invariant now fails the build unless every effect tool sits in a reviewed gate bucket. What is deliberately not claimed: the coverage invariant pins the tool surface, not every future entry point, and two boundaries are stated open rather than hidden, per-command mediation of a human terminal session and the in-browser behaviour of hostile third-party plugin code, neither of which a backend can witness. The counts are read live from the engagement store; an audit log that only ever shows green is indistinguishable from no audit at all.",
      "controls_held": [
        "Every fix is pinned by a required, non-continue-on-error CI gate that runs the invariant suites across two packages and is proven to exit non-zero on a deliberately broken candidate, so a reopened fail-open gate, an unwitnessed receipt or an ungated effect path goes red before it can merge",
        "The reference monitor now sits at both the native and the connector choke, and a governance deny takes precedence over the entitlement and rate checks, so no connector caller, direct route or delegated agent, can reach an effect the org policy forbids",
        "The durable execution ledger reconciles in-flight effects on boot and refuses to dispatch when its own durable write fails, so an ambiguous external send is recorded as outcome-unknown rather than silently lost or blindly retried",
        "The fixes were verified test-first and on the running deployment, not only in unit tests; each of the six runtime findings was re-checked in the running collector after its fix",
        "No secret values were disclosed by any finding in this cycle; the findings are structural properties of the enforcement path, not leaked credentials",
        "The published log recomputes each WARD receipt at publish time and is Ed25519-signed and verified in CI and in the production build, so a fabricated entry needs the signing key, not merely an internally consistent shape"
      ],
      "totals": {
        "critical": 0,
        "high": 4,
        "medium": 3,
        "low": 0,
        "fixed": 7,
        "open": 0,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3DGJ0JMGYA05NV9FMGYA05N",
          "target": "quoxai/quox",
          "title": "Evidence witness omitted the action payload",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-26 00:06:35",
          "resolved_at": "2026-09-26 00:07:21"
        },
        {
          "id": "FND_01M3DGJ2GCX6K3QX6KJ0X6K3QX",
          "target": "quoxai/quox",
          "title": "Governance gate failed open on policy-store outage",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-26 00:06:37",
          "resolved_at": "2026-09-26 00:07:25"
        },
        {
          "id": "FND_01M3DGJ7RXWXMK593ZGTWXMK59",
          "target": "quoxai/quox",
          "title": "Widget effect gate fell through to execution on policy exception",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-26 00:06:43",
          "resolved_at": "2026-09-26 00:07:35"
        },
        {
          "id": "FND_01M3DGJ97Y3QF5DFH5KA3QF5DF",
          "target": "quoxai/quox",
          "title": "Connector tools bypassed org governance policy",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-26 00:06:44",
          "resolved_at": "2026-09-26 00:07:39"
        },
        {
          "id": "FND_01M3DGJ4CYN00HQQZMYKN00HQQ",
          "target": "quoxai/quox",
          "title": "Audit-envelope write failures were silent",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-26 00:06:39",
          "resolved_at": "2026-09-26 00:07:28"
        },
        {
          "id": "FND_01M3DGJ5TK72E7G9RS1D72E7G9",
          "target": "quoxai/quox",
          "title": "No durable execution intent for external effects",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-26 00:06:41",
          "resolved_at": "2026-09-26 00:07:31"
        },
        {
          "id": "FND_01M3DGJB2A9EBVK4BZJC9EBVK4",
          "target": "quoxai/quox",
          "title": "Effect-producing tools could ship without a gate decision",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-26 00:06:46",
          "resolved_at": "2026-09-26 00:07:44"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3034147,
            "ward_entry_id": "6d10185c-ec37-48cd-92e6-089ed2add876",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-26T00:05:42.924Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUHMPF9K_NPP2YV3M",
            "payload_hash": "cf9a136d4b88b850e99d7d46d05471ba57db79b1b3432eb09b953202e510e940",
            "prev_chain_hash": "25197ae72c3fea315fb412a27f1ac9d9aebb9aa852d6f06c4043b07af61a66ae",
            "chain_hash": "ece58a83d3c8b8e53c740e01aa6a9733f340f8f8b34fb41837636673e82bd9e7"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 3034187,
            "ward_entry_id": "55c062dd-2d66-44ad-956a-65757ebee543",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-26T00:07:44.309Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUHMS0XE_WNSSF1AQ",
            "payload_hash": "3ce4868cb994d5ade8860f898c161df5e527d0e5130ceda8fe730d166dc4176a",
            "prev_chain_hash": "633334b07e716b3766d9d2d4c5f3043fb005f3beae71505c757fc93ca98a29ec",
            "chain_hash": "7a0acf35bebfd38ad6b15444f3d27ecf4baec3ae70bf387e7e37e6819e8a82e4"
          }
        ]
      },
      "published": true
    },
    {
      "cycle": 5,
      "kind": "customer-engagement",
      "engagement_id": "ENG_01M3FZ4KHVNC5JCEYTXTNC5JCE",
      "name": "Governed discovery on real deployments (2026-09)",
      "started_at": "2026-09-26T22:59:54.058Z",
      "last_event_at": "2026-09-27T00:56:11.044Z",
      "scope": [
        "client-a.example",
        "client-b.example",
        "quox.ai"
      ],
      "method": "Per target: proof-of-control first (a DNS TXT record or a .well-known challenge the target must serve), then a governed discovery-tier scan (subfinder host discovery + httpx port/service discovery) executed through the collector's engagement-anchored bastion approval-grant. Discovery tier only: no intrusive, credentialed, or exploit tooling. Findings graded against the actual scan output and confirmed where the evidence was direct.",
      "summary": "The first governed security engagement Quox ran on real customer production sites, not on itself. Three verified production properties were scanned: two external customers (a VPN provider and a hot-tub retailer, redacted here as client-a / client-b) and quox.ai (our own). Every target proved control before any scan ran, every scan passed the same governed approval-grant path as any other risky action, and every step is WARD-witnessed. Findings are published at their honest severity: one low (an internet-exposed hosting control panel with its version disclosed) and two informational (a publicly-discoverable dev subdomain; a customer-named subdomain on our own site). Client identities are redacted; the receipts, scope and severities are not. This band grows over time as more deployments are scanned.",
      "controls_held": [
        "Complete mediation held: every scan minted and presented a bastion approval grant scoped to the exact command and target host; an out-of-scope subdomain probe was refused by the scope gate, not executed.",
        "Fail-closed held under real load: when the grant-mint policy callback timed out, the scan was refused rather than run ungranted.",
        "Proof-of-control enforced before any scan: a target that had not proven control (DNS or well-known challenge) could not be scanned.",
        "Discovery-tier ceiling enforced: production engagements cap at discovery, so no intrusive or exploit tooling ran against a live customer site."
      ],
      "totals": {
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "fixed": 0,
        "open": 3,
        "refuted": 0,
        "info": 2
      },
      "findings": [
        {
          "id": "FND_01M3G1G6TYKA3WFN5F4RKA3WFN",
          "target": "client-a.example",
          "title": "Plesk admin panel exposed on public port 8443 with version disclosed (Plesk Obsidian 18.0.80)",
          "severity": "low",
          "status": "confirmed",
          "outcome": "open_confirmed",
          "reported_at": "2026-09-26 23:41:11"
        },
        {
          "id": "FND_01M3G3GG3P6CWT0SPZG26CWT0S",
          "target": "client-b.example",
          "title": "Publicly discoverable dev/pre-production subdomain (dev.client-b.example)",
          "severity": "info",
          "status": "candidate",
          "outcome": "open_reported",
          "reported_at": "2026-09-27 00:16:18"
        },
        {
          "id": "FND_01M3G5BW6NSJWYZ6P1Z1SJWYZ6",
          "target": "quox.ai",
          "title": "Client-named subdomain publicly discoverable via passive DNS (info disclosure of a customer relationship + host naming scheme)",
          "severity": "info",
          "status": "candidate",
          "outcome": "open_reported",
          "reported_at": "2026-09-27 00:48:43"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3093939,
            "ward_entry_id": "761d362b-e40a-4866-82d9-7cdcf7c86afa",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-26T22:59:54.058Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUIZSMYW_Y8NZS926",
            "payload_hash": "c1f7cb91832c7331eb44bc3a1df334db6c039ba82c94037378a93be3c4b15bec",
            "prev_chain_hash": "abada37336029a8c078d7f7d562b95c1a0ab82eb388e6bb45994e46b1896b1d7",
            "chain_hash": "fcd7fd57deded5786cd13dbf50c5fad00a7da7a06ab3e1825d000de9cec2e62d"
          },
          {
            "event": "quox.security.target.added",
            "seq": 3099253,
            "ward_entry_id": "02a5431a-ccad-45ce-97a2-58f97d76678b",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-27T00:56:11.044Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUJ3Y6G1_27MII5G1",
            "payload_hash": "88777032279f56b45f098f764008c8553701590de715a637c37c9addcb681880",
            "prev_chain_hash": "c8c86b67f91421e1a2dafa7a3f5cbec68449294498c601feb456eab773753545",
            "chain_hash": "968e1bdd78585c2d32e1a3479e31fc3655848f589143ea8afac57e85dc426720"
          }
        ]
      },
      "published": true
    },
    {
      "cycle": 6,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3R1RVXHFNRB3GF6CAFNRB3G",
      "name": "v1, Release Gate",
      "started_at": "2026-09-30T02:19:50.581Z",
      "last_event_at": "2026-10-01T03:46:06.305Z",
      "scope": {
        "covered": "Trusted first-party platform code: collector tool-execution boundary, connector governed choke, quoxchat widget, quoxagent job/dev-invoke, bastion keys/sudo/exec.",
        "excluded": [
          "Hostile third-party marketplace plugin isolation (thirdPartyPluginHost document injection), deferred to v2.0, stated limit.",
          "Full human-PTY per-command mediation, stated limit.",
          "Universal LLM-injection immunity, stated limit."
        ]
      },
      "method": null,
      "summary": "Bar v1 is the release-blocker gate: an independent adversarial pass (RB1-RB9) over the frozen release surface, with every boundary re-verified on the running collector, auth, quoxagent fleet and bastion. 33 findings were raised in the c4 cycle; the release-blocking set is remediated and deployed. The two deploy-pending blockers at the 2026-09-30 pass, F6 (bastion keys/deploy grant) and F7 (quoxagent job-envelope replay), were DEPLOYED to the live fleet on 2026-10-01 (F6 live on the bastion host; F7 dc25995 on 34/36 quoxagent hosts) and resolved.",
      "controls_held": [
        "Cross-tenant isolation made platform-wide: org derived from authenticated identity, never caller-supplied body/header, across ~8 header-routes + the native-tool route + security/compliance routes + vault-credential path (FND resolved).",
        "Arbitrary shell/SQL (ssh_exec, remote_ssh, db_query writes) and the wider bastion-tool shell-injection class now require human approval and are input-validated (multiple criticals resolved).",
        "Approval cards render the exact effective action (to/cc/bcc/subject/body, command, SQL), no blind-approve (T4).",
        "Fail-closed gates: 4-eyes policy-change gate no longer fails open on audit-write error; WARD witness no longer silently no-ops; GOV-4 store outage denies (T2).",
        "Signature integrity: AEE signature scope now covers HITL gate fields; approval_events chain covers action/actor; offline verifier binds key_id (T8).",
        "F6 DEPLOYED: bastion keys/deploy + sudo/setup gated behind the collector-signed approval grant (parallel path closed).",
        "F7 DEPLOYED: quoxagent /jobs + /dev/invoke replay/freshness guard keyed on the SIGNED CreatedAt (dc25995, 34/36 hosts)."
      ],
      "totals": {
        "critical": 8,
        "high": 13,
        "medium": 6,
        "low": 1,
        "fixed": 30,
        "open": 3,
        "refuted": 0,
        "info": 5
      },
      "findings": [
        {
          "id": "FND_01M3R1TQ7ND2HW6B9QWTD2HW6B",
          "target": "quox",
          "title": "collector native tool route: body org_id overrides authenticated org (cross-tenant credential read)",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:20:51",
          "resolved_at": "2026-09-30 03:50:39"
        },
        {
          "id": "FND_01M3R1TS88AKXVYS36GDAKXVYS",
          "target": "quox",
          "title": "third-party plugin JS injected into dashboard document unsandboxed",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:20:53",
          "resolved_at": "2026-09-30 13:42:44"
        },
        {
          "id": "FND_01M3R1V0K9Y5FSQGAV8TY5FSQG",
          "target": "quoxbastion",
          "title": "keys/deploy + sudo/setup skip requireApprovalGrant (parallel enforcement path)",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:21:00",
          "resolved_at": "2026-10-01 03:46:04"
        },
        {
          "id": "FND_01M3SF9CH1TR2XNHG2XZTR2XNH",
          "target": "quox",
          "title": "Arbitrary shell/SQL executes without human approval: ssh_exec ungated; remote_ssh/db_query approval-path is theatre",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 15:35:17",
          "resolved_at": "2026-09-30 15:48:22"
        },
        {
          "id": "FND_01M3SGFVZDN94PP8F9X0N94PP8",
          "target": "quox",
          "title": "Shell command injection in native bastion tools: system_admin (path/unit/priority/since/user), docker_fleet_logs + docker_fleet_stats (container_id)",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 15:56:18",
          "resolved_at": "2026-09-30 16:04:59"
        },
        {
          "id": "FND_01M3SHGHZQBF8ZT9B4DDBF8ZT9",
          "target": "quox",
          "title": "Shell-injection class is wider than SGFV: 4 more UNGATED callBastion sites (network_check, docker_extended, ssl_certificates, security_audit) + 3 gated (docker_fleet_container_action, proxmox_vm_snapshot, proxmox_vm_clone)",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 16:14:09",
          "resolved_at": "2026-09-30 16:26:45"
        },
        {
          "id": "FND_01M3SK5C5P17ZFQRG05317ZFQR",
          "target": "quox",
          "title": "UNGATED shell injection in bastion_ssh executor (bastionSshExecutor.js) - a parallel shadow of the native fleet tools running off agent args; plus quoxagentExecutor hostId",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 16:43:00",
          "resolved_at": "2026-09-30 16:50:48"
        },
        {
          "id": "FND_01M3SPCJY2PEDNR9PZEHPEDNR9",
          "target": "quox",
          "title": "Org-scope cross-tenant is PLATFORM-WIDE: vault-credential exposure (agents/invoke), cross-org dev-host build/backup/restore/tmux, cross-org read of dev-session events, aee attribution, unauthed GOV-1 policy CRUD",
          "severity": "critical",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 17:39:22",
          "resolved_at": "2026-09-30 18:45:13"
        },
        {
          "id": "FND_01M3R1TTXH3YY97TBBCV3YY97T",
          "target": "quox",
          "title": "plugin tools register globally, not org-scoped (cross-tenant tool exposure)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:20:55",
          "resolved_at": "2026-09-30 04:09:52"
        },
        {
          "id": "FND_01M3R1TX7ES2ZDTR6YBSS2ZDTR",
          "target": "quox",
          "title": "plugin backends share the internal service key",
          "severity": "high",
          "status": "confirmed",
          "outcome": "open_confirmed",
          "reported_at": "2026-09-30 02:20:57"
        },
        {
          "id": "FND_01M3R1TYXZW516YN6TNGW516YN",
          "target": "quox",
          "title": "plugin-backend tools reach execution with no default approval gate",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:20:59",
          "resolved_at": "2026-09-30 12:06:50"
        },
        {
          "id": "FND_01M3R1V2MGS07VB3SATDS07VB3",
          "target": "quoxagent",
          "title": "job envelope has no nonce and optional expiry (replay)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:21:02",
          "resolved_at": "2026-10-01 03:46:06"
        },
        {
          "id": "FND_01M3R1V4865WWCB146PA5WWCB1",
          "target": "quox",
          "title": "approval_events hash chain omits action/actor_type/actor_id",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:21:04",
          "resolved_at": "2026-09-30 03:50:41"
        },
        {
          "id": "FND_01M3R1V6A3DDJDP3YE3VDDJDP3",
          "target": "quoxproof",
          "title": "offline verifier trusts an unbound key_id, diverges from WARD SDK; no agreement test",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:21:06",
          "resolved_at": "2026-09-30 03:33:55"
        },
        {
          "id": "FND_01M3R1V7VHWVMSBY9SD5WVMSBY",
          "target": "quox",
          "title": "AEE signature scope excludes HITL gate fields",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 02:21:08",
          "resolved_at": "2026-09-30 03:50:43"
        },
        {
          "id": "FND_01M3S9DJDBXBYKSB9SW9XBYKSB",
          "target": "quox",
          "title": "4-eyes policy-change gate fails OPEN on an audit-write error (applies unapproved)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 13:52:43",
          "resolved_at": "2026-09-30 14:00:52"
        },
        {
          "id": "FND_01M3SAGZME5S3R531K0B5S3R53",
          "target": "quox",
          "title": "Contactability consent-grant route trusts x-org-id header over authenticated identity (cross-tenant write)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 14:12:03",
          "resolved_at": "2026-09-30 14:19:21"
        },
        {
          "id": "FND_01M3SCFPRGSSP06ZPPYWSSP06Z",
          "target": "quox",
          "title": "remote_ssh (arbitrary shell) and db_query writes execute with no default approval gate",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 14:46:19",
          "resolved_at": "2026-09-30 15:09:43"
        },
        {
          "id": "FND_01M3SM0Q0KHJQYWQGFCVHJQYWQ",
          "target": "quox",
          "title": "Security-engagement/compliance routes derive org as 'req.user?.org_id || req.body/query.org_id' without the req.service gate the safe sibling routes use (potential cross-tenant)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 16:57:56",
          "resolved_at": "2026-09-30 17:15:11"
        },
        {
          "id": "FND_01M3SNE0F59MD0WSV63S9MD0WS",
          "target": "quox",
          "title": "Header-based cross-tenant: ~8 routes derive org as 'req.user?.org_id || req.headers[x-org-id]' with no req.service gate (SM0Q class via header, missed by the body/query fix); + toolsmith sandbox route bypasses GOV-4",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 17:22:40",
          "resolved_at": "2026-09-30 17:29:58"
        },
        {
          "id": "FND_01M3SQJPK91CMB37A8M51CMB37",
          "target": "quox",
          "title": "WARD witness degradation is silent: /health reports ready:true when witnessing is dead (initWardHooks failed), runtime witness errors uncounted, unsigned tips unaccounted (T3/T8 evidence-integrity)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 18:00:11",
          "resolved_at": "2026-09-30 18:09:54"
        },
        {
          "id": "FND_01M3S8Q874M0DSZK1CV2M0DSZK",
          "target": "quox",
          "title": "Outbound telephony + notification (tripwire) bypasses the GOV-4 governance choke",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 13:40:32",
          "resolved_at": "2026-09-30 13:50:34"
        },
        {
          "id": "FND_01M3S9XRKKR7K8TFH2ZVR7K8TF",
          "target": "quox",
          "title": "/chat/resolve-plan swallows a pre-LLM gate throw and proceeds (fail-open)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 14:01:34",
          "resolved_at": "2026-09-30 14:07:27"
        },
        {
          "id": "FND_01M3SB5J4FQY704DHWR7QY704D",
          "target": "quox",
          "title": "WARD witness hooks silently no-op when not initialised (evidence receipts vanish untraced)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 14:23:18",
          "resolved_at": "2026-09-30 14:31:49"
        },
        {
          "id": "FND_01M3SC1WEZ9BAZ6R4M8Z9BAZ6R",
          "target": "quox",
          "title": "VOLT GOLD certifies a self-signed (embedded-key) signature as identity-verified",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 14:38:46",
          "resolved_at": "2026-09-30 14:42:56"
        },
        {
          "id": "FND_01M3SJS9FY5GC1ZW7NPH5GC1ZW",
          "target": "quox",
          "title": "docker_extended 'restart' is an ungated container MUTATION duplicating the gated docker_fleet_container_action (parallel-enforcement bypass)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 16:36:24",
          "resolved_at": "2026-09-30 16:50:46"
        },
        {
          "id": "FND_01M3SRMADJ54NH52VFJ154NH52",
          "target": "quox",
          "title": "T-AUTH expiry gap: the inbox-driven approval resume path executes without re-checking approval expiry / current policy (stale approval still fires)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 18:18:33",
          "resolved_at": "2026-09-30 18:44:22"
        },
        {
          "id": "FND_01M3ST59E9252CVE8C6F252CVE",
          "target": "quox",
          "title": "HARDENING: GOV-1 policy routes trust org_id from query/body for internal authorization (beyond route-level auth)",
          "severity": "low",
          "status": "candidate",
          "outcome": "open_reported",
          "reported_at": "2026-09-30 18:45:17"
        },
        {
          "id": "FND_01M3R8JM243HJQ7FTE193HJQ7F",
          "target": "quoxproof",
          "title": "receipt-write failure masks the successful tool outcome and corrupts the chain",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 04:18:45",
          "resolved_at": "2026-09-30 04:21:49"
        },
        {
          "id": "FND_01M3R93CPZCFQCF38Y5HCFQCF3",
          "target": "quoxflow",
          "title": "workflow maxConcurrency has no upper ceiling (unbounded per-workflow admission)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 04:27:55",
          "resolved_at": "2026-09-30 04:35:43"
        },
        {
          "id": "FND_01M3R9GG5G58Q3S9FZBH58Q3S9",
          "target": "quoxflow",
          "title": "call executor persists request headers verbatim into the evidence store (secret leak)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 04:35:05",
          "resolved_at": "2026-09-30 04:42:27"
        },
        {
          "id": "FND_01M3R9X647CMRA4NBBXFCMRA4N",
          "target": "quoxbastion",
          "title": "bastion risky-mode 403s a live fleet log-collection loop (read-only journalctl requires a human grant)",
          "severity": "info",
          "status": "candidate",
          "outcome": "open_reported",
          "reported_at": "2026-09-30 04:42:00"
        },
        {
          "id": "FND_01M3RA5R9KKEZVVJ9Y0ZKEZVVJ",
          "target": "quoxflow",
          "title": "public /webhooks route has no rate limit (comment claims 10/s, never wired)",
          "severity": "info",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-09-30 04:46:41",
          "resolved_at": "2026-09-30 04:54:57"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3282885,
            "ward_entry_id": "3cf23638-0036-4cfe-b649-3f3e60d2311d",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-09-30T02:19:50.581Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUNH9BJN_ZJGTT7LY",
            "payload_hash": "c6e07fcbaa2c7c03674fe55fddf746b075ed52c73ff7ed28fe1c6cfdf36b0c45",
            "prev_chain_hash": "108ce986a31655a3a6eaf260c7fe0a038fa7c900b8fa222783578cffd33ec844",
            "chain_hash": "dd94be611349cd5a2b51220fd09ce0107fe305970104e8f4eeed3017a7a611ba"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 3342385,
            "ward_entry_id": "00cb6c82-b64e-48e4-bd21-79a1bfa8256f",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-01T03:46:06.305Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUOZS3TP_9CLSQBVS",
            "payload_hash": "82a6fe49bec4a28414511865e27b515679d372cca2c9f18838e0026eb6eacf4c",
            "prev_chain_hash": "36a1c79640e5c66875797bbb5f4fa78840fdf707708319f67dcf625b700fb731",
            "chain_hash": "3e41d3e63df59f8e39bcd591c37b86fb80d22fa0ee06fb5d8a6e42cf29b2f569"
          }
        ]
      },
      "published": true,
      "version": "v1",
      "bar_name": "Release Gate",
      "properties_raised": [
        "T1 evidence-commits-to-effective-action",
        "T2 fail-closed-gates",
        "T3 durable-intent-and-recovery",
        "T4 reviewable-authority (approval cards render recipients/command/SQL)",
        "T-AUTH authorization-lifetime-and-single-use",
        "T7 tenant-and-resource-isolation (platform-wide org-scope)",
        "T8 signature-integrity (AEE/approval-events/offline-verifier)",
        "T9 complete-mediation-and-default-denied-capabilities (frozen surface)",
        "T-CONF secret-confidentiality"
      ],
      "verdict": "PASS",
      "known_debt": [
        "F4 plugin backends share the internal service key (confirmed, documented), carried to a higher bar.",
        "GOV-1 policy routes trust org_id from query/body (low hardening, candidate), carried to v1.2 hardening.",
        "The v1.2 Complete-Mediation Brutaloop (2026-10-01) surfaced further items for v1.2/v1.3, see ~/QUOXTRUST_V1_2_FINDINGS.md."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-09-30",
      "criterion": "No bypassable release-blocker on the frozen release surface; every trust-property boundary verified on the RUNNING systems, not just the source."
    },
    {
      "cycle": 7,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3WC959AS5XWEGCGVBS5XWEG",
      "name": "v1.2, Complete Mediation",
      "started_at": "2026-10-01T18:40:27.951Z",
      "last_event_at": "2026-10-02T00:44:45.759Z",
      "scope": {
        "covered": "Trusted first-party platform effect paths across collector, connectors, quoxchat widget, quoxagent, bastion.",
        "excluded": [
          "Hostile third-party marketplace plugin isolation, deferred to v2.0 (stated limit).",
          "Full human-PTY per-command mediation, stated limit.",
          "Universal LLM-injection immunity, stated limit."
        ]
      },
      "method": null,
      "summary": "Bar v1.2 is the complete-mediation bar: a bounded adversarial sweep enumerated every effect path across 5 surfaces vs origin/main, and the T9 conformance pin now proves every effect-verb tool sits in exactly one reviewed bucket. Four must-fixes closed the gaps the sweep found; all are deployed to the running systems with red-proven CI pins.",
      "controls_held": [
        "MF-1: bastion DELETE /keys/{id} revoke now requires the collector-signed approval grant (F6 sibling closed), live the bastion host, running-exe verified.",
        "MF-2: native externalEffect tools (alerts_manage silence, backup_run, keeper_backup_create, deploy_template) default to HITL via AGENT_ALWAYS_PROPOSE + withApprovalGate, with non-blind T4 cards, NOT blanket-gated, live in the running collector.",
        "MF-3: github-proxy write routes routed through the executeConnectorTool governance choke (policy/approval/ledger/WARD); generate-notes via mediateGovernancePolicy + WARD, live in the running collector.",
        "MF-4: quoxagent /dev/invoke verifies signature before freshness (loopback pre-consumption DoS closed), live 34/36 fleet.",
        "hat_load_bundle classified (QuoxHat P4, option A: within-envelope capability selection, witnessed, not an external effect), T9 pin green."
      ],
      "totals": {
        "critical": 0,
        "high": 3,
        "medium": 1,
        "low": 0,
        "fixed": 4,
        "open": 0,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3WCAG0WSTRF2FKBR4STRF2F",
          "target": "quoxai/quox",
          "title": "MF-1: bastion DELETE /keys/{id} revoke was ungated (F6 sibling)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-01 18:41:11",
          "resolved_at": "2026-10-01 18:42:02"
        },
        {
          "id": "FND_01M3WCB9QP0KFY9ZJ7CW0KFY9Z",
          "target": "quoxai/quox",
          "title": "MF-2: native externalEffect tools had no default HITL",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-01 18:41:38",
          "resolved_at": "2026-10-01 18:42:06"
        },
        {
          "id": "FND_01M3WCBBNA0MNKQ4ZK5Z0MNKQ4",
          "target": "quoxai/quox",
          "title": "MF-3: github-proxy write routes bypassed the governance choke",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-01 18:41:40",
          "resolved_at": "2026-10-01 18:42:09"
        },
        {
          "id": "FND_01M3WCBE2FST2677X7C2ST2677",
          "target": "quoxai/quox",
          "title": "MF-4: quoxagent /dev/invoke verified freshness before signature",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-01 18:41:42",
          "resolved_at": "2026-10-01 18:42:13"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3365217,
            "ward_entry_id": "ca6f76e4-496c-4048-b200-efcaa797972c",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-01T18:40:27.951Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUPVQ9F0_ZSDCW5L6",
            "payload_hash": "024aaf4b23368b9b1c771ffa14aed4f8712476db0eec25f9a486b9b795617235",
            "prev_chain_hash": "239045c88494f79a9e10b7f4508fcf1195eaa83826cab16b1dc6efc3dd51b9f4",
            "chain_hash": "224dc71482bef30f2e5f32f11b3efe4b63d44ec8dd543a1732898a4073cad1ac"
          },
          {
            "event": "quox.security.finding.verified",
            "seq": 3375542,
            "ward_entry_id": "8915f69b-909f-4bfe-aae2-9eb2752b3e04",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T00:44:45.759Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQ8QR0C_R1MDWEP4",
            "payload_hash": "4fa057a5fcd1a5b47e16378bfb433916205ad6d37d582252c7786fb79fbf32a8",
            "prev_chain_hash": "1b3e2f038b4af639720c2862e4f95719823f87f2ed6de6e7365e020bb6a1efc7",
            "chain_hash": "455c59b001cbfc7d62fb18e389ff9bb0fbaf22d7408f5777dc22be333eee583a"
          }
        ]
      },
      "published": true,
      "version": "v1.2",
      "bar_name": "Complete Mediation",
      "properties_raised": [
        "T9 complete-mediation & default-denied capabilities (the headline)",
        "T4 reviewable-authority (non-blind approval cards for the newly-gated native effect tools)",
        "T2 fail-closed gates (native effect tools default to HITL, no reliance on an absent org policy)",
        "T3 durable-intent/replay ordering (dev/invoke signature-before-freshness)"
      ],
      "verdict": "PASS",
      "known_debt": [
        "MF-2(b): gemini_generate/perplexity_research have no per-org cost-budget gate (no budget infra exists; honest TODO, carried forward).",
        "tool-def install fails open on unset INTERNAL_SERVICE_KEY (WEAK, v1.2 hardening).",
        "plugin-declared effect:'read' on a non-verb-named tool escapes the F5 default gate (WEAK).",
        "bastion PUT /hosts + registry import re-target the fleet without a grant (MEDIUM, v1.2 hardening).",
        "LATENT: quoxagent internal/protocol handleExecute/handleInvoke unsigned/unfresh, no live caller; guard before wiring.",
        "v1.3 Resilience: quoxagent seen-set is in-memory only (replay window reopens on restart)."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-10-01",
      "criterion": "Every effect-producing entry point across ALL surfaces (collector tool executors, connector HTTP routes, quoxchat widget, plugin tools, quoxagent jobs/dev-seams, bastion key/exec paths) passes exactly ONE reviewed gate. Enforced by the T9 conformance pin (test/w-t9-effect-coverage.test.js), GREEN on origin/main 9f010160."
    },
    {
      "cycle": 8,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3WS3FTHXGWC5A3RASXGWC5A",
      "name": "v1.3, Resilience",
      "started_at": "2026-10-01T22:24:33.626Z",
      "last_event_at": "2026-10-02T00:58:32.658Z",
      "scope": {
        "covered": "Resilience under dependency failure + restart across collector (evidence/policy/dispatch), quoxagent (replay seen-set), and bastion (grant verification).",
        "excluded": [
          "Secret/data confidentiality sweeps (T-CONF), v1.4.",
          "Supply-chain / artifact integrity (T-ART), v1.4.",
          "Prompt-injection / untrusted-model containment (T5/T6), v1.5.",
          "Hostile third-party plugin runtime isolation, v2.0.",
          "Performance/latency SLOs under load (this bar is correctness-under-fault, not throughput)."
        ]
      },
      "method": null,
      "summary": "Bar v1.3 is the resilience bar: a bounded adversarial sweep fault-injected every mandatory dependency across 5 surfaces and asked whether each gate still holds when its dependency is down, slow, or the process dies mid-effect. The collector's fail-closed evidence/policy gates, durable executionLedger (crash -> outcome_unknown, no retry), and atomic single-use claim were verified LIVE in the running container. One real code must-fix (quoxagent replay seen-set was in-memory only) was fixed with a durable seen-set, red-proven-pinned, and deployed.",
      "controls_held": [
        "RR5 (the must-fix): quoxagent replay seen-set is now DURABLE (persisted to DataDir atomically, restored at boot), a restart no longer reopens the 15-min replay window on /jobs or /dev/invoke. Best-effort write so a disk fault cannot DoS the agent. Deployed as v84780f4.",
        "RR1 evidence/WARD store down: collector counts + surfaces audit-write failures (recordAuditWriteFailure, /health + /metrics) instead of a silent skip, verified in the running quox-collector.",
        "RR2 policy store down: collector fails closed on storeResult.unavailable (approvalGate) and returns policy_unavailable on governance exception (quoxchat), verified in the running container.",
        "RR3 external-effect crash-after-send: executionLedger durable claim before dispatch; reconcileOnBoot flips dispatched -> outcome_unknown, no retry, states enumerated, verified live.",
        "RR4 restart mid-dispatch: toolApprovalStore single atomic claim (SQLite-durable, replay -> null), reconciled at boot, verified live.",
        "RR2-bastion grant verification: fails closed on zero trusted keys / verify error (internal/approval/grant.go)."
      ],
      "totals": {
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "fixed": 1,
        "open": 0,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3WSZK7CX10CBBSY7HX10CBB",
          "target": "quoxai/quox",
          "title": "RR5: quoxagent replay seen-set was in-memory only (replay window reopens on restart)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-01 22:39:54",
          "resolved_at": "2026-10-01 23:50:14"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3371095,
            "ward_entry_id": "1cfc85ea-5f11-47be-8278-a5610525cb9b",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-01T22:24:33.626Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQ3QG5X_F9GS0SJX",
            "payload_hash": "ccf9754bdeebf240b3a4e11364be264dfde9c224adc6b7df9cc45abeab70f209",
            "prev_chain_hash": "eb0b3a4f6424ecd1d5e3abf3c08fe2ff483fabf0ac2754e7168a238bbf6c2878",
            "chain_hash": "417c88b1cf90d1f9d6bcc9b075179edf1cdf2c07661888c4090ba6bdfce8e864"
          },
          {
            "event": "quox.security.target.added",
            "seq": 3376822,
            "ward_entry_id": "5938cbbd-286c-4589-886f-62e6f2ad91d5",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T00:58:32.658Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQ98H1S_DWWSB5L6",
            "payload_hash": "e4afadee244cfafc3449c4ebcf47f2f3c705ff2446024ad21877f9f7ca4698d9",
            "prev_chain_hash": "281859d560abd751287057b7ea55265cc697d3b40f5a726fe6fca0bcf3f45cd8",
            "chain_hash": "8de9f0a6b6fc71658f19db5cbda966373d4308accceb692f017a83c133371629"
          }
        ]
      },
      "published": true,
      "version": "v1.3",
      "bar_name": "Resilience",
      "properties_raised": [
        "T2 fail-closed gates under dependency failure (policy-store-down, evidence-store-down)",
        "T3 durable intent + recovery (crash-after-send -> outcome_unknown, no retry; restart reconciliation)",
        "T10 bounded/durable-across-restart (replay seen-set survives restart, the headline fix)",
        "VISIBLE degradation (dependency failure counted distinctly from empty, surfaced on health/metrics)"
      ],
      "verdict": "PASS",
      "known_debt": [
        "RR5 residual: persist is best-effort, a persist FAILURE followed by a restart could still reopen the window (rare compound case). Deliberate: fail-closed-on-persist-error would couple job acceptance to disk health. A fail-closed flag is available if wanted.",
        "RR2 residual (collector): approvalGate checkStorePolicies !_voltDb pre-init branch returns allow-posture not 'unavailable'. UNREACHABLE at runtime (setApprovalGateDb precedes server.listen; running container passed RR2). v1.3 hardening: distinguish pre-init from intentionally-no-GOV-4-store.",
        "RR1 residual (collector): effect executes before the receipt is guaranteed (re-emit recovery, by design). Ordering -> v1.4.",
        "RR6 residual (quoxagent): heartbeat loop counts+logs failures (visible) but has no backoff (fixed ticker). Scheduler-triad backoff leg missing. Hardening.",
        "Process: shared quox-dashboard working tree (gtm-p2-topbar, e0213cca) is ~142 commits behind origin/main on collector files, merge-regression risk; the DEPLOYED collector is current."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-10-01",
      "criterion": "Every mandatory-dependency fault (evidence/WARD store down, policy service down/null, external-effect crash-after-send, collector restart mid-dispatch, quoxagent restart) leaves the effect path FAIL-CLOSED (or durably queued), with VISIBLE degradation, NO double-effect, and RECOVERABLE incomplete executions. Rungs RR1-RR6 of ~/QUOXTRUST_BAR_V1_3_RUBRIC.md."
    },
    {
      "cycle": 9,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3X057C151EGY8PMZE51EGY8",
      "name": "v1.1, Parity & Repeatability",
      "started_at": "2026-10-02T00:27:50.535Z",
      "last_event_at": "2026-10-02T12:57:23.224Z",
      "scope": {
        "covered": "Parity of release-critical platform components (collector verified live; quoxagent/bastion parity by exe-sha/deploy + named observability); repeatability of v1's RB invariants on the running system.",
        "excluded": [
          "Reaching all 17 unreached quoxagent hosts this cycle (deploy-tooling plumbing; gripe filed).",
          "Container git-stamp + collector fleet-view display (the collector half of observability), named remediation, next.",
          "Website (separate deploy surface).",
          "Resilience (v1.3, banked), confidentiality (v1.4), injection (v1.5), hostile plugins (v2.0)."
        ]
      },
      "method": null,
      "summary": "v1.1 asks whether what was AUDITED is what is RUNNING, provably, and whether the v1 PASS REPEATS. The second independent pass (PART B) re-confirmed F6/F7-RR5/fail-closed-gates on the running system AND caught a HIGH cross-tenant hole (PB3) the first pass missed: CommanderQ compliance tools trusted a caller-supplied org_id. Fixed, deployed, verified live, red-proven. Parity itself verified on the collector (running sha == origin/main); the cross-cutting gap is build-provenance observability, with the quoxagent heartbeat half fixed and the rest named.",
      "controls_held": [
        "PB3 (must-fix): commanderq compliance/governance tools route org through resolveToolOrgId(ctx,input) (authenticated org wins), verified LIVE in quox-collector (0 inverted patterns, resolveToolOrgId present).",
        "PB1 F6 bastion key grant fail-closed (origin/main).",
        "PB2 F7/RR5 quoxagent replay freshness + durable seen-set (origin/main).",
        "PB4 fail-closed collector gates, running container sha byte-identical to origin/main.",
        "PA5 half: quoxagent heartbeat reports the real build version (Options.AgentVersion wired; red-proven pin)."
      ],
      "totals": {
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 0,
        "fixed": 1,
        "open": 1,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3X138J7MG75JM4TCPMG75JM",
          "target": "quoxai/quox",
          "title": "PB3: CommanderQ compliance tools trusted caller-supplied org_id (cross-tenant read+write)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-02 00:44:14",
          "resolved_at": "2026-10-02 00:44:43"
        },
        {
          "id": "FND_01M3X13AE5F0CZER6Z93F0CZER",
          "target": "quoxai/quox",
          "title": "PA5: fleet cannot observe running build generation (heartbeat hardcoded 0.1.0)",
          "severity": "medium",
          "status": "confirmed",
          "outcome": "open_confirmed",
          "reported_at": "2026-10-02 00:44:16"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3375109,
            "ward_entry_id": "651cc11a-4848-4330-9f4a-90bec424b78f",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T00:27:50.535Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQ84ZNO_PB0N8Y8G",
            "payload_hash": "069161995c2b5c486aab6e69cb50e9c8c1bf036e883de498d30096e22e302a05",
            "prev_chain_hash": "c2d156992360c132a234a056ac2948deece3ffb2d8b8563b1549336c2826c50f",
            "chain_hash": "14daf2424e37aff14267cd480c7b4aeda49aadbea07087d04d067824fef464a9"
          },
          {
            "event": "quox.security.finding.verified",
            "seq": 3397051,
            "ward_entry_id": "e9573b1e-180e-4a84-b32e-6d5db8236cb6",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T12:57:23.224Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQYWWT2_K7LGXS1X",
            "payload_hash": "e70dd748f155151787f2929a61c6e1822a120a4c1eabe382b3b214d2317b1864",
            "prev_chain_hash": "b7ae1e4d07c252b67b52b7a04c98f80d191cdd223bf2f0bd99de0614d7c6cc50",
            "chain_hash": "f1038eb798a708abc8f298bfbd6769a8f692491ee7a9770ac787ef70b6c65ba9"
          }
        ]
      },
      "published": true,
      "version": "v1.1",
      "bar_name": "Parity & Repeatability",
      "properties_raised": [
        "T7 tenant isolation (the repeatability pass caught a HIGH cross-tenant regression and closed it)",
        "Parity: source == artifact == running, verified on the collector by byte-identical sha + live fix check",
        "Observability: the running build generation is reportable (quoxagent heartbeat now carries the real version)"
      ],
      "verdict": "PASS",
      "known_debt": [
        "PA5 collector half: fleet-view/CLI should display agent.version (ingested server-side), observability not complete until shipped + quoxagent redeployed. Finding FND_01M3X13AE5F0CZER6Z93F0CZER left CONFIRMED (partial).",
        "No container git-sha label (collector/auth/dashboard) + bastion --version prints nothing, provenance stamps are the full observability remediation.",
        "quoxagent fleet 20/37 at current generation; 17 unreached (deploy-tooling gripe).",
        "Shared quox-dashboard working tree ~142 commits behind origin/main (parity hazard; deployed collector is current)."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-10-02",
      "criterion": "Every release-critical component at 3-way parity (github==artifact==running) OR the gap NAMED with a remediation path; running generation observable; a SECOND independent pass over v1's invariants (PB1-PB4) clean on the running system."
    },
    {
      "cycle": 10,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3X1XBG75GX72VJCVA5GX72V",
      "name": "v1.4, Confidentiality & Supply-chain",
      "started_at": "2026-10-02T00:58:30.058Z",
      "last_event_at": "2026-10-02T02:14:07.924Z",
      "scope": {
        "covered": "Secret confidentiality in logs/responses/transcripts across collector + auth; install integrity + dependency pinning; artifact provenance observability.",
        "excluded": [
          "Injection / untrusted-model containment (T5/T6) -> v1.5.",
          "Hostile third-party plugin isolation -> v2.0.",
          "HSM/key-ceremony hardening of the license signing key (owner-only).",
          "Autonomous rotation of any secret (owner-gated; flag only)."
        ]
      },
      "method": null,
      "summary": "v1.4 asks whether secrets leak and whether we can prove what runs. The confidentiality core is sound: credentials resolve by reference (never returned), receipts are content-free, mandatory audit always stored. One real leak (CF1: raw tool-input logging, live in prod) and one supply-chain gap (unpinned dep) found and fixed; install integrity already fails closed (CA2). Build-provenance observability (CA1) is named with a precise remediation spec (quoxagent already passes).",
      "controls_held": [
        "CF1 (fixed): collector tool-input logging redacted via summarizeToolInputForLog (secret keys masked, free-text reduced to length, nested to shape), red-proven pin; deployed + verified in running collector.",
        "CF2 (clean): credentials resolved by credential_id reference, raw secret never in tool input or response; vault tools echo metadata only.",
        "CF3 (clean): mandatory execution evidence always stored + witnessed regardless of transcript retention; receipts are content-free commitments (digest + per-field hashes).",
        "CA2 (pass): quoxagent install.sh verifies BINARY_SHA256 and refuses on mismatch (exit 1; bypass needs explicit flag).",
        "T-ART dep (fixed): @anthropic-ai/claude-code pinned @2.1.197 in the collector Dockerfile."
      ],
      "totals": {
        "critical": 0,
        "high": 0,
        "medium": 3,
        "low": 0,
        "fixed": 2,
        "open": 1,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3X2HGKA090E3JQ21J090E3J",
          "target": "quoxai/quox",
          "title": "CF1: collector logged raw tool input (secret leak into logs)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-02 01:09:30",
          "resolved_at": "2026-10-02 01:19:05"
        },
        {
          "id": "FND_01M3X2HJ4Z6ZTAR92J4M6ZTAR9",
          "target": "quoxai/quox",
          "title": "T-ART: collector Dockerfile dependency @anthropic-ai/claude-code unpinned",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-02 01:09:31",
          "resolved_at": "2026-10-02 01:19:07"
        },
        {
          "id": "FND_01M3X2HMA7BZD68KFGWPBZD68K",
          "target": "quoxai/quox",
          "title": "CA1: build provenance not verifiable on collector/auth/dashboard/bastion",
          "severity": "medium",
          "status": "confirmed",
          "outcome": "open_confirmed",
          "reported_at": "2026-10-02 01:09:34"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3376821,
            "ward_entry_id": "bba4929f-1a51-4f0b-98ef-d0f3a7774734",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T00:58:30.058Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQ98F1J_KRD2874O",
            "payload_hash": "b684183989c8c3cf18a90ce7f7b0c0027972c5651073b26b34042325eb83168b",
            "prev_chain_hash": "079e138d3e9dd046d6693094bedd7ce5cf3af8ab7b32b57b8ab62f962d66ab0a",
            "chain_hash": "281859d560abd751287057b7ea55265cc697d3b40f5a726fe6fca0bcf3f45cd8"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 3378927,
            "ward_entry_id": "882fcd7c-7dd4-451d-8cd4-267393a72f51",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T02:14:07.924Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQBXOHD_24QPQR53",
            "payload_hash": "1c2bfeed37aa4a414316f48513645ffb5b0f5deba4279639ab521e50e20ea74b",
            "prev_chain_hash": "4509c8fc0e06ef704491b24a0ede2705531ecc93cd6b54cf4de56ca02af160d3",
            "chain_hash": "8371fd58b0e3c3af51b541284931dcaac34b5c04bdf65b034bf310ec3a400482"
          }
        ]
      },
      "published": true,
      "version": "v1.4",
      "bar_name": "Confidentiality & Supply-chain",
      "properties_raised": [
        "T-CONF secret/data confidentiality (no secret in logs/responses/transcripts)",
        "T-ART artifact/runtime integrity (install integrity fail-closed; provenance observability)"
      ],
      "verdict": "PASS",
      "known_debt": [
        "CA1 build-provenance observability: collector/auth /health return semver not git-sha; dashboard no version; bastion no Makefile/ldflags. quoxagent passes (MF-P1). Remediation spec: ARG GIT_SHA + ENV + /health git_sha via --build-arg (collector/auth), LABEL+/version.json (dashboard), Makefile+ldflags (bastion). Build-pipeline change for a SUPERVISED mini-cycle, not unsupervised overnight. Finding FND_01M3X2HMA7... left CONFIRMED (partial).",
        "CF1 free-text allowlist is heuristic (key-name based); a secret in an unlisted non-free-text string key >64 chars is truncated+shown. Low residual; widen the free-text key set if needed."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-10-02",
      "criterion": "No secret or cross-tenant data leaks into logs/responses/transcripts (T-CONF); every deployed artifact's provenance is verifiable OR named with a remediation path, and install integrity fails closed (T-ART)."
    },
    {
      "cycle": 11,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3X30DKDFJB6D76W1FFJB6D7",
      "name": "v1.5, Injection / Containment",
      "started_at": "2026-10-02T01:17:38.805Z",
      "last_event_at": "2026-10-02T02:14:07.924Z",
      "scope": {
        "covered": "Interpreter reach, authority/recipient/credential expansion, egress destination bounds, untrusted-content-as-authority, across the collector tool surface + the screencap browser pipeline.",
        "excluded": [
          "Universal LLM prompt-injection immunity, STATED non-goal, not a rung.",
          "Evidence tamper-evidence (T8) -> v1.6; Authorization depth (T-AUTH) -> v1.7; Resource bounds (T10) -> v1.8; hostile plugins -> v2.0."
        ]
      },
      "method": null,
      "summary": "The premise is a fully-compromised reading model. Containment holds: the single mediateGovernancePolicy chokepoint gates every tool call by EFFECT (not provenance), no model output reaches an interpreter, and approved email recipients are fingerprint-bound. One escalation path found and fixed: browser_navigate allowed a model-controlled URL to reach loopback/private/metadata IPs ungated (SSRF). We explicitly do not certify injection immunity; we certify the gate sits outside the model.",
      "controls_held": [
        "IN1 clean: no eval/Function/vm sink for model output; remote_ssh read-allowlist + approval; db_query parameterised + read-only/gated.",
        "IN2 clean: email_send always-propose + fingerprint binds to/cc/bcc/subject/body (resume refuses on change); resolveToolOrgId locks org to authenticated ctx.",
        "IN3 fixed: browserActions.validateUrl blocks loopback/private/link-local/metadata (honours SCREENCAP_ALLOWED_PRIVATE); red-proven pin; deploy-verify in running quox-screencap.",
        "IN4 clean: single referenceMonitor.mediateGovernancePolicy chokepoint, effect-based gating, untrusted retrieved content cannot trigger an ungated effect."
      ],
      "totals": {
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "fixed": 1,
        "open": 0,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3X3JQP7CK17WA9REZCK17WA",
          "target": "quoxai/quox",
          "title": "IN3: browser_navigate SSRF — model-controlled URL reaches private/metadata IPs ungated",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-02 01:27:38",
          "resolved_at": "2026-10-02 01:38:55"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3377382,
            "ward_entry_id": "e4fedd92-226f-4c82-89c9-c49b64c66a33",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T01:17:38.805Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQ9X1F4_51V0HP6G",
            "payload_hash": "8bc66627abb02d9237202cbfbe06e030e0d5e8c03bbfd74aa197c50dcc587f9f",
            "prev_chain_hash": "a6c29cac50481ae3e051b3f18698cc5116fc02144ccf2a490110503ec7b570fb",
            "chain_hash": "dba145b7e185309aa3ee306dec6278b4edb80ed2c7f6ed9356e1abb3aa669a00"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 3378927,
            "ward_entry_id": "882fcd7c-7dd4-451d-8cd4-267393a72f51",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T02:14:07.924Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQBXOHD_24QPQR53",
            "payload_hash": "1c2bfeed37aa4a414316f48513645ffb5b0f5deba4279639ab521e50e20ea74b",
            "prev_chain_hash": "4509c8fc0e06ef704491b24a0ede2705531ecc93cd6b54cf4de56ca02af160d3",
            "chain_hash": "8371fd58b0e3c3af51b541284931dcaac34b5c04bdf65b034bf310ec3a400482"
          }
        ]
      },
      "published": true,
      "version": "v1.5",
      "bar_name": "Injection / Containment",
      "properties_raised": [
        "T5 untrusted-input/model-output containment (no interpreter reach; authority enforced outside the model)",
        "T6 egress/exfil bounds (destination-bounded consequential sinks)"
      ],
      "verdict": "PASS",
      "known_debt": [
        "IN3 residual: DNS-rebinding (hostname resolving to a private IP) not blocked, literal-IP + metadata-hostname only, same as the sibling guard. Full fix: resolve-then-check / egress proxy pinned to resolved IP.",
        "Two validateUrl implementations (browserActions + browserObjective), unify into one shared validator + agreement test (deferred; avoided touching the working objective path).",
        "IN2 permissions self-escalation not exhaustively traced (no path found; revisit)."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-10-02",
      "criterion": "Assume the reading model is compromised: it cannot reach an interpreter (IN1), expand recipients/credentials/permissions (IN2), exfiltrate to an unbounded destination (IN3), or let untrusted content carry authority (IN4). NOT a claim of universal injection immunity (stated non-goal), a claim that the enforcement boundary is outside the model."
    },
    {
      "cycle": 12,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3X425XKMGQPRS5PCYMGQPRS",
      "name": "v1.6, Evidence Tamper-Evidence",
      "started_at": "2026-10-02T01:36:06.478Z",
      "last_event_at": "2026-10-02T02:14:07.924Z",
      "scope": {
        "covered": "WARD evidence chain integrity + ordering + action-binding + independent recompute, across the running collector/ward artifact and the /security export.",
        "excluded": [
          "Authorization depth (T-AUTH) -> v1.7; resource bounds (T10) -> v1.8; hostile plugins -> v2.0.",
          "Throughput of verify at scale (bounded-verify wedge already fixed; this bar is detection-correctness)."
        ]
      },
      "method": null,
      "summary": "The most on-thesis bar: attack the evidence itself. The WARD chain binds seq + prev_chain_hash + payloadHash; verify detects forgery (CHAIN_HASH_MISMATCH), omission (SEQ_INVALID), reorder/linkage (CHAIN_LINK_BROKEN) and tip tamper (TIP_MISMATCH) with no catch-swallow; no mutation path exists on ward_entries. The witness commitment binds the effective action via payload_commit/canonical_action (the historical payload-exclusion bug is fixed). An independent recompute refuses to publish on mismatch. Clean exam; added the missing gap-detection pin.",
      "controls_held": [
        "ET1 chain completeness/gap-detection: verifyChain returns SEQ_INVALID on a deleted/omitted entry (live throwaway-DB test + new red-proven pin); no DELETE/UPDATE on ward_entries.",
        "ET2 no silent reorder: ordering hash-bound (seq + prev_chain_hash), not timestamp-trust.",
        "ET3 action-binding: witness hash binds payload_commit -> canonical_action (tool/tenant/identity/content_commit/outcome); payload-exclusion bug fixed (hooks.js).",
        "ET4 recompute fails closed: export-security-audit.mjs re-derives + throws on mismatch (exit 1; fail-closed if key unprovisioned); ward-verify EXIT_BROKEN=1."
      ],
      "totals": {
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "fixed": 0,
        "open": 1,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3X4JCBHM63HPTH6F9M63HPT",
          "target": "quoxai/quox",
          "title": "ET3(b): ward_entries.org_id/tags bare columns not bound into chainHash",
          "severity": "low",
          "status": "confirmed",
          "outcome": "open_confirmed",
          "reported_at": "2026-10-02 01:44:55"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3377858,
            "ward_entry_id": "1e967f9e-c873-4392-b019-fb255c0b7c99",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T01:36:06.478Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQAKR0Y_LINX64XW",
            "payload_hash": "1dd613c86ae7c3602771936340e02726f7d6a0677806d39d358b2f2d41dd13e0",
            "prev_chain_hash": "18c2bbaf932502e4b2fb4e9555d5edb4186ee3b61c065ec1bb119e5ca944a966",
            "chain_hash": "33212803b60fbfc454ac5dc4843430dc2ca6af40d2156893be3313e0732417e0"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 3378927,
            "ward_entry_id": "882fcd7c-7dd4-451d-8cd4-267393a72f51",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T02:14:07.924Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQBXOHD_24QPQR53",
            "payload_hash": "1c2bfeed37aa4a414316f48513645ffb5b0f5deba4279639ab521e50e20ea74b",
            "prev_chain_hash": "4509c8fc0e06ef704491b24a0ede2705531ecc93cd6b54cf4de56ca02af160d3",
            "chain_hash": "8371fd58b0e3c3af51b541284931dcaac34b5c04bdf65b034bf310ec3a400482"
          }
        ]
      },
      "published": true,
      "version": "v1.6",
      "bar_name": "Evidence Tamper-Evidence",
      "properties_raised": [
        "T8 evidence integrity / tamper-evidence (chain completeness, ordering, action-binding, fail-closed recompute)"
      ],
      "verdict": "PASS",
      "known_debt": [
        "ET3(b) (low, FND_01M3X4JCBHM63HPTH6F9M63HPT): ward_entries.org_id + tags are bare columns outside chainHash; a DB rewrite mis-attributes tenant-scoped visibility without breaking chain verify (authoritative org is hash-bound in payload_commit). Supervised fix: verifyChain cross-checks the columns against the hash-committed values, do NOT change the chainHash recipe (breaks all historical chains)."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-10-02",
      "criterion": "The audit trail cannot be forged, omitted, reordered, or edited without detection; the commitment binds the effective action (no attacker-writable field verifies green); an independent recompute (ward verify + /security --check) fails closed on tamper."
    },
    {
      "cycle": 13,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3X4VXWXPVCBZF1PVVPVCBZF",
      "name": "v1.7, Authorization Depth",
      "started_at": "2026-10-02T01:50:09.076Z",
      "last_event_at": "2026-10-02T02:14:07.924Z",
      "scope": {
        "covered": "Grant/approval lifecycle (single-use/expiry/revocation), capability scope + grant binding, credential least-privilege + JIT lease, collector + auth + bastion.",
        "excluded": [
          "Resource/abuse bounds (T10) -> v1.8; hostile plugins -> v2.0.",
          "A standing-grant revocation model (bastion grants are short-TTL + synchronously minted; no standing window today)."
        ]
      },
      "method": null,
      "summary": "Attack the grant lifecycle. Approvals are single-use (atomic claim), expiry is revalidated at use time on both the collector and bastion layers, revocation runs through the same atomic deny gate, capability scope denies unknown agents and binds grants to tool+params+targets, and credentials are declared-type-scoped with JIT leases that expire. Clean exam; the core invariants were already conformance-pinned. Low named debt on the bastion grant layer.",
      "controls_held": [
        "AU1 single-use: atomic claimForResume + bastion nonce (pinned approvalGateGrantSingleUse / qlusterDelegationStore).",
        "AU2 expiry: use-time revalidation collector + bastion (pinned toolResumeFailClosed 'T-AUTH expiry revalidation').",
        "AU3 revocation-at-use: explicit deny through the same atomic claim gate (pinned).",
        "AU4 scope+binding: unknown-agent denies (quox#556); bastion MatchesTool = ToolID+ParamsSHA256+targets; approval fingerprint binds action (pinned approvalGateInputBinding).",
        "AU5 credential least-privilege + JIT lease: declared-type-scoped resolution; getActiveLease filters expires_at>now + atomic use-increment."
      ],
      "totals": {
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "fixed": 0,
        "open": 1,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3X59AD9G0KX1TBS03G0KX1T",
          "target": "quoxai/quox",
          "title": "AU-residuals: bastion grant replay-nonce in-memory + no standalone revoke primitive (low)",
          "severity": "low",
          "status": "confirmed",
          "outcome": "open_confirmed",
          "reported_at": "2026-10-02 01:57:27"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3378249,
            "ward_entry_id": "8dc68e39-3855-438e-a843-10ed471feb70",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T01:50:09.076Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQB2U9C_H3N48AOI",
            "payload_hash": "d78d0d98ed61739231c2cf7cd46939cafe6e6ccf0f6d1cef4dd75b450b1888dd",
            "prev_chain_hash": "b42dccb6c76a8f4f99eeaea6cd98c2cf54e823089ef36376030618f3fdbc4ead",
            "chain_hash": "517a56ccf6f8dad24b612d87575579e8d60694a4c0e9aa021da4d5a7a1d0361b"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 3378927,
            "ward_entry_id": "882fcd7c-7dd4-451d-8cd4-267393a72f51",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T02:14:07.924Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQBXOHD_24QPQR53",
            "payload_hash": "1c2bfeed37aa4a414316f48513645ffb5b0f5deba4279639ab521e50e20ea74b",
            "prev_chain_hash": "4509c8fc0e06ef704491b24a0ede2705531ecc93cd6b54cf4de56ca02af160d3",
            "chain_hash": "8371fd58b0e3c3af51b541284931dcaac34b5c04bdf65b034bf310ec3a400482"
          }
        ]
      },
      "published": true,
      "version": "v1.7",
      "bar_name": "Authorization Depth",
      "properties_raised": [
        "T-AUTH authorization lifetime, single-use, least privilege (expiry, revocation-at-use, capability scope, grant binding, credential JIT-lease)"
      ],
      "verdict": "PASS",
      "known_debt": [
        "Bastion replay-nonce (v.seen) is in-memory, restart inside the TTL reopens a replay window (echoes v1.3 RR5; persist the set). Low.",
        "Bastion Grant has no standalone revoke primitive, structurally mitigated (short TTL, synchronous mint). Add if a standing-grant model appears.",
        "Vault lease enforcement is per-org opt-in (advisory/off still releases), consider default-closed.",
        "putPending ON CONFLICT reopens a terminal row, informational, not exploitable (fresh approval.id per call)."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-10-02",
      "criterion": "An authorization cannot be stretched (expiry), replayed (single-use), used after revocation, or widened (capability scope / grant binding / credential scope), proven under adversarial reuse."
    },
    {
      "cycle": 14,
      "kind": "trust-bar",
      "engagement_id": "ENG_01M3X5EAMEKZYA6YZX53KZYA6Y",
      "name": "v1.8, Resource & Abuse Bounds",
      "started_at": "2026-10-02T02:00:12.144Z",
      "last_event_at": "2026-10-02T02:14:07.924Z",
      "scope": {
        "covered": "Spend (paid-API tools), concurrency/rate, exec-time/output/payload, queue depth + loop triad across the collector tool surface + schedulers + telegram queue.",
        "excluded": [
          "Hostile third-party plugin isolation -> v2.0 (design).",
          "Network-layer DDoS / edge rate limiting (infra concern).",
          "Load/throughput benchmarking (bar is bound-existence + durability, not perf)."
        ]
      },
      "method": null,
      "summary": "Attack with volume. Compute is bounded (per-org + route rate limiters, agent loop cap, connector timeouts, body + result-size caps). Three missing bounds found and fixed: unbounded paid-API spend (gemini/perplexity now propose-first), unbounded ssh exec-time + output (120s timeout + 1MB cap), and an uncapped telegram outbound queue (depth-a fleet host shed). Schedulers carry the triad. Completes the v1.x ladder.",
      "controls_held": [
        "RB1 concurrency/rate: per-org global rate limiter + route toolLimiter + agent loop MAX_ITERATIONS=3.",
        "RB2 (fixed): gemini_generate + perplexity_research default to propose-first (no unbounded paid-API spend), red-proven pin; live.",
        "RB3 (fixed): ssh command bounded by EXEC_TIMEOUT_MS=120s + capStreamOutput 1MB/stream, red-proven pin; live. Connector calls already timeout; results truncated.",
        "RB4 (fixed): telegram outboundQueue depth cap (a fleet host) shed, live. Scheduler triad present across feed/inboxq/quoxseo/reach/reflection/telegram/x pollers."
      ],
      "totals": {
        "critical": 0,
        "high": 1,
        "medium": 2,
        "low": 0,
        "fixed": 3,
        "open": 0,
        "refuted": 0
      },
      "findings": [
        {
          "id": "FND_01M3X65GVMGPQ8Y5CZHQGPQ8Y5",
          "target": "quoxai/quox",
          "title": "RB2: paid-API tools (gemini/perplexity) had no spend bound (free-call loop)",
          "severity": "high",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-02 02:12:51",
          "resolved_at": "2026-10-02 02:14:05"
        },
        {
          "id": "FND_01M3X65PVJZQB66DSBGGZQB66D",
          "target": "quoxai/quox",
          "title": "RB3: remote_ssh/ssh_exec unbounded exec time + output",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-02 02:12:57",
          "resolved_at": "2026-10-02 02:14:06"
        },
        {
          "id": "FND_01M3X65RZFGAJ2NF42RYGAJ2NF",
          "target": "quoxai/quox",
          "title": "RB4: telegramPro outboundQueue no lane depth cap (unbounded in-memory growth)",
          "severity": "medium",
          "status": "resolved",
          "outcome": "fixed",
          "reported_at": "2026-10-02 02:13:00",
          "resolved_at": "2026-10-02 02:14:07"
        }
      ],
      "ward": {
        "chain_id": "ward:org/quox/env/production",
        "hash_recipe": "sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex",
        "receipts": [
          {
            "event": "quox.security.engagement.created",
            "seq": 3378502,
            "ward_entry_id": "8f0afc88-ba00-4a29-b0fb-10bf54cde39f",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T02:00:12.144Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQBFRL9_TGN0AQMP",
            "payload_hash": "d04107e52c405441da39daf58bc0f6498948c5e321fe36eae7512d15ff34dca2",
            "prev_chain_hash": "52f9c78f6fdad28cc8eccc4cf541aed63d105fe83b12fc496e58413d2c0b6cfa",
            "chain_hash": "68c6f9a3619473d0718eb4039284fcef09d615879746614a6e7a3892da61fe84"
          },
          {
            "event": "quox.security.finding.resolved",
            "seq": 3378927,
            "ward_entry_id": "882fcd7c-7dd4-451d-8cd4-267393a72f51",
            "chain_id": "ward:org/quox/env/production",
            "witnessed_at": "2026-10-02T02:14:07.924Z",
            "source_kind": "AEE",
            "source_id": "ENV_MUQBXOHD_24QPQR53",
            "payload_hash": "1c2bfeed37aa4a414316f48513645ffb5b0f5deba4279639ab521e50e20ea74b",
            "prev_chain_hash": "4509c8fc0e06ef704491b24a0ede2705531ecc93cd6b54cf4de56ca02af160d3",
            "chain_hash": "8371fd58b0e3c3af51b541284931dcaac34b5c04bdf65b034bf310ec3a400482"
          }
        ]
      },
      "published": true,
      "version": "v1.8",
      "bar_name": "Resource & Abuse Bounds",
      "properties_raised": [
        "T10 bounded resource consumption (spend, concurrency/rate, exec-time/output/payload, queue depth, loop triad)"
      ],
      "verdict": "PASS",
      "known_debt": [
        "RB2: no REAL per-org cost-budget/spend-ceiling infra yet (propose-first is interim). Build the budget gate for unattended paid-tool use.",
        "RB4: outbound queue in-memory (not durable across restart), depth cap bounds the live process; persist lane state for cross-restart durability. Depth-cap pin DEFERRED (trivial synchronous guard; module hides lane internals for a non-flaky test).",
        "securityScanScheduler is cadence-driven; backoff/retirement N/A by design (noted)."
      ],
      "contract_version": "1.0.0",
      "passed_date": "2026-10-02",
      "criterion": "A compromised or runaway caller cannot exhaust money (spend), compute (concurrency/rate/time/output), or queues; bounds are durable; every recurring loop carries the failure-accounting + backoff + retirement triad."
    }
  ],
  "sig": "ED25519:In/NQFLoC0rUhQesDEnYcfC57b9TdbjSUSKy6bA8wHMR4DS0wPhd0glq2D2HsFuQaNeI1ALvghNTOxWsXMblBQ=="
}
