Layered controls, tested at their boundaries
Truenote applies server-side access limits before retrieval, screens content and AI data paths, requires cited answers or refusals, protects browser mutations, and records security-sensitive activity. This page includes only safeguards that have completed repository evidence.
Verified safeguards
“Verified” here means the named repository acceptance check passed. Each card states that evidence scope.
01
Program and clearance isolation
Server-side filters deny cross-program and above-clearance access before protected content reaches ranking, generation, citations, or document reads.
Repository tests passed02
Controlled content activation
Source, file, EICAR, sensitive-content, lifecycle, parsing, and role checks are enforced before knowledge content becomes active.
Repository tests passed03
Hybrid retrieval boundary
Vector, full-text, typo-tolerant, reranking, and neighbor retrieval preserve authorization and lifecycle limits through the complete pipeline.
Repository tests passed04
Zero Data Retention routing policy
Approved answer routes request Zero Data Retention, deny data collection, pin one provider, disable provider fallback, and reject arbitrary routes.
Repository tests passed05
Pre-provider input firewall
Deterministic secret, payment-card, identity, phone, and network-address patterns are redacted before supported embedding, reranking, and model calls.
Boundary tests passed06
Cite or refuse
Missing, malformed, unknown, and out-of-range citations cannot produce a normal answer. Sensitive model output is refused.
Generation tests passed07
Immutable citation receipts
Ordered source snapshots preserve version and anchor context while rejecting stale, revoked, deleted, or unauthorized evidence.
Repository tests passed08
Browser request defense
Trusted same-origin mutations pass while foreign, opaque, malformed, cross-site, and sibling-origin requests are rejected. CSP restricts active content.
Browser-security tests passed09
Redacted diagnostics
Structured error handling removes credentials, complete private keys, Social Security numbers, and payment-card values from covered diagnostic paths.
Redaction tests passed10
Bounded provider failure
Provider operations use explicit deadlines, retry caps, abort propagation, and a fail-closed deadline for the complete ask path.
Failure-path tests passed11
Tamper-evident audit logic
Security events use append-only hash chaining. SIEM delivery tests cover signing, lease fencing, retries, dead-letter handling, and health reporting.
Audit-delivery tests passed12
Evaluation integrity
Evaluation tests cover retrieval, reranking, citations, refusals, faithfulness, durable recovery, cancellation, and protected held-out questions.
Evaluation tests passedSecurity delivery checks
The hosted repository workflow has completed these checks successfully on merged security changes.
Type checking and production build
Workspace TypeScript checks and the production frontend build completed successfully.
Automated test suites
Frontend, API, and security-script suites completed successfully.
Secret scanning
The hosted pull-request secret scan completed successfully.
Dependency audit and SBOM
The production dependency audit and CycloneDX software bill of materials step completed successfully.
CodeQL analysis
Hosted CodeQL analysis and the external alert gate completed successfully.
Security evidence integrity
Machine checks validated evidence links, identifiers, hashes, and required security records.
Source and vulnerability reporting
Inspect the implementation or report privately
The public repository contains the implementation, tests, security policy, and evidence records behind these claims. Suspected vulnerabilities can be submitted through GitHub’s private advisory intake.