Observed state beats narrative.
Security claims should be backed by source, runtime behavior, boundary tests, exact-version specifications, or independently reproducible evidence.
SITEBORNE separates who or what is acting, what it may do, how payment is authorized, whether execution may proceed, what proof says happened, who may access a sensitive result, and whether settlement may complete.
Identity, mandate, policy, payment authorization, execution authority, assurance/PCC evidence, Result Authorization, and Settlement Authority remain distinct. Release 3 candidate semantics strengthen these boundaries without promoting candidate controls to live-v2 production.
External identity, policy, payment, protocol, and trust systems can contribute evidence. No login, payment receipt, signature, provider capability, PCC, or model output automatically grants every other kind of authority.
Security Authority evaluates governed evidence; metadata and LLM output cannot silently mint privilege. In Release 3 candidate semantics, result release is separately governed and sensitive document/verification results use buyer-authorized handling.
High-risk authorization and integrity failures should fail closed unless a governed requirement says otherwise.
Security claims should be backed by source, runtime behavior, boundary tests, exact-version specifications, or independently reproducible evidence.
The public site explains what customers and integrators need to know while keeping private security controls, supplier scoring, credentials, and competitive internals private.
Security reports should go to security@alerts.siteborne.net. The build now includes the canonical RFC 9116 /.well-known/security.txt projection for the product surface.
Authorized contact: mailto:security@alerts.siteborne.net. RFC 9116 Expires: 2027-08-31T23:59:59Z. Policy: https://siteborne.com/security. Configuration is authorized; deliverability and live publication are not claimed verified.
The authorized reporting identity and RFC 9116 projection are configured for this release. Mail delivery, reply behavior, active monitoring, and live publication remain unverified until externally tested and read back.
utility.siteborne.net/.well-known/security.txt still publishes security@siteborne.net. This release keeps security@alerts.siteborne.net as the governed next-release contact, but does not claim convergence until product/network/runtime files are deployed and independently read back. The product security.txt endpoint was not independently retrievable in this sweep.Standards can make systems work together more easily, but a listed standard is not necessarily active in production.