Security
Security model
ProvableCORE is fail-closed by design and keeps signing under controlled, authoritative handling.
Fail-closed operation
ProvableCORE is fail-closed by design: when a proof cannot be properly constructed, signed, or preserved, the system withholds a positive result rather than issuing an unverified one. AI and automated systems act under human and institutional authority — ProvableCORE records that authority; it does not replace it.
Key handling
Proofs are signed under controlled, authoritative signing so that a record's origin can be established. Signing is operated as a controlled capability. The site makes no unconditional assertion about hardware modules or key custody.
Preservation
Signed, content-bound proofs are preserved as durable evidence records. The locked-retention trust tier describes proofs held under a locked-retention regime for a defined preservation window when configured; it is not a claim that every record is kept for an unlimited time or is impossible to remove.
Responsible disclosure
If you believe you have found a security issue, contact contact@agrocapitalstandard.eu. Please provide enough detail to reproduce the issue and allow reasonable time for remediation before public disclosure.