Security

Security model

ProvableCORE is fail-closed by design and keeps signing under controlled, authoritative handling.

Fail-closed operation

ProvableCORE is fail-closed by design: when a proof cannot be properly constructed, signed, or preserved, the system withholds a positive result rather than issuing an unverified one. AI and automated systems act under human and institutional authority — ProvableCORE records that authority; it does not replace it.

Key handling

Proofs are signed under controlled, authoritative signing so that a record's origin can be established. Signing is operated as a controlled capability. The site makes no unconditional assertion about hardware modules or key custody.

Preservation

Signed, content-bound proofs are preserved as durable evidence records. The locked-retention trust tier describes proofs held under a locked-retention regime for a defined preservation window when configured; it is not a claim that every record is kept for an unlimited time or is impossible to remove.

Responsible disclosure

If you believe you have found a security issue, contact contact@agrocapitalstandard.eu. Please provide enough detail to reproduce the issue and allow reasonable time for remediation before public disclosure.

Request institutional access