Security and assurance
Review GuardState's technical security evidence, control boundaries, release provenance, and current third-party assurance status without conflating internal testing with independent certification.
Release integrity
GuardState records source and release identity, dependency and SBOM evidence, test results, security-scan results, release manifests, and deployment identity so evaluators can connect public claims to a specific release.
Security controls
The control model includes tenant isolation, role and attribute authorization, approval separation, signature and digest validation, Permit replay resistance, unknown-provider handling, secret minimization, outbound-request controls, evidence integrity, scanner privacy, and scoped sharing.
Operational evidence
Architecture, threat boundaries, access controls, key-domain separation, incident handling, backup and recovery expectations, deployment readiness, and commissioning state are designed to support institutional technical diligence.
Third-party assurance status
GuardState distinguishes internal verification from independent assurance. External penetration testing, SOC 2, ISO 27001, or other third-party attestations are represented only when they have actually been completed and are approved for disclosure.