SITEBORNEUNIFIED SEMANTIC SYSTEM VCMgoverned release
Trust / Security

Authority is explicit.
Proof is evidence.

SITEBORNE separates who or what is acting, what it may do, how payment is authorized, whether execution may proceed, what proof says happened, who may access a sensitive result, and whether settlement may complete.

Identity, mandate, policy, payment authorization, execution authority, assurance/PCC evidence, Result Authorization, and Settlement Authority remain distinct. Release 3 candidate semantics strengthen these boundaries without promoting candidate controls to live-v2 production.

Security model

Do not let metadata become authority.

External identity, policy, payment, protocol, and trust systems can contribute evidence. No login, payment receipt, signature, provider capability, PCC, or model output automatically grants every other kind of authority.

Security Authority evaluates governed evidence; metadata and LLM output cannot silently mint privilege. In Release 3 candidate semantics, result release is separately governed and sensitive document/verification results use buyer-authorized handling.

High-risk authorization and integrity failures should fail closed unless a governed requirement says otherwise.

identity≠mandate
mandate≠policy decision
payment authorization≠execution authority
execution success≠contract satisfaction
PCC / proof≠result authorization
result existence≠result authorization
payment receipt≠settlement authority
supplier capability≠qualification
Evidence

Observed state beats narrative.

Security claims should be backed by source, runtime behavior, boundary tests, exact-version specifications, or independently reproducible evidence.

Disclosure

Public interoperability, private advantage.

The public site explains what customers and integrators need to know while keeping private security controls, supplier scoring, credentials, and competitive internals private.

Vulnerability disclosure

Report security issues through
one governed channel.

Security reports should go to security@alerts.siteborne.net. The build now includes the canonical RFC 9116 /.well-known/security.txt projection for the product surface.

Authorized contact: mailto:security@alerts.siteborne.net. RFC 9116 Expires: 2027-08-31T23:59:59Z. Policy: https://siteborne.com/security. Configuration is authorized; deliverability and live publication are not claimed verified.

CONFIGURED · DELIVERY CHECK PENDING

The authorized reporting identity and RFC 9116 projection are configured for this release. Mail delivery, reply behavior, active monitoring, and live publication remain unverified until externally tested and read back.

CONTACTCONFIGUREDAUTHORITYAUTHORIZEDDELIVERYUNVERIFIEDLIVE FILEVERIFY AFTER DEPLOYEXPIRES2027-08-31
LIVE PROJECTION DRIFT · 2026-09-24 UTC: the runtime RFC 9116 file at utility.siteborne.net/.well-known/security.txt still publishes security@siteborne.net. This release keeps security@alerts.siteborne.net as the governed next-release contact, but does not claim convergence until product/network/runtime files are deployed and independently read back. The product security.txt endpoint was not independently retrievable in this sweep.
Security standards horizon

Use standards as adapters,
not silent authority.

Standards can make systems work together more easily, but a listed standard is not necessarily active in production.

OAuth 2.0 / OIDCAUTHENTICATION EVIDENCE · STANDARD DPoPPROOF OF POSSESSION · ADAPTER mTLSTRANSPORT AUTH · ADAPTER HTTP Message SignaturesREQUEST INTEGRITY · WATCH AuthZENPOLICY DECISION API · PRIORITY OPA / CedarPOLICY ECOSYSTEM · ADAPTER MCP EMA / ID-JAGDELEGATED AUTHORITY · ROADMAP AP2 / Verifiable IntentDELEGATED INTENT · WATCH OWASP ACSRUNTIME HOOKS · ROADMAP WIMSE / SPIFFEWORKLOAD IDENTITY · WATCH CAEP / Shared SignalsSECURITY EVENTS · WATCH RATSATTESTATION · WATCH OpenTelemetryOBSERVABILITY · PREFERRED OCSFSECURITY TELEMETRY · WHERE FIT SCITTGENERIC AUDIT · WATCH C2PACONTENT PROVENANCE · ADAPTER Sigstore-style bundlesPORTABLE PROOF · WATCH security.txt / RFC 9116DISCLOSURE SURFACE · BUILD CONFIGURED