# audit-core — NetKingdom security layer declaration # # Framework: net-kingdom/canon/standards/security-layer-model_v0.7.md # Assent: AUDIT-IN-0001 (audit-core's own voice, per §11 "who must declare") # history/2026-08-28-approval-evidence-assent.md # history/2026-08-29-security-layer-model-v0.6-review.md # history/2026-08-29-v0.7-alignment-and-scope-assessment.md # # Reference form offered by ops-warden and adopted here, so §11's declaration # check is mechanical rather than a reader's judgment about prose. audit-core # raised that defect; adopting the form is the other half of raising it. schema_version: "0.1" framework: netkingdom-security-layer-model standard_version: "0.7" repository: audit-core layer: engine role: evidence # §3.3 engine typing declared_by: intakes/intakes.md AUDIT-IN-0001 declared_at: "2026-08-29" # §3.3: an Evidence engine records what happened and proves integrity of what # it holds. It is explicitly not a decision point (§6, §9.4). decision_surfaces_exposed: none # §9.4 — normative and permanent. audit-core exposes no verdict on whether an # approval is still valid; a consumer branching on such an answer would route an # authorization decision through the audit fabric. approval_validity_query: forbidden # §5 applies to Staff. audit-core is an Engine and holds no §4 Tooling contact # (key-cape, OpenBao). Companion §4 asks that UNCATALOGUED infrastructure be # listed anyway so the check is total, and that carve-out sunsets within two # review intervals for a store another layer reads. Completing this list and # adding a conformance test is AUDIT-WP-0009-T10. tooling_contacts: [] uncatalogued_infrastructure: - id: platform-pg system: CNPG PostgreSQL on railiance01 role: audit-core's own operational custody store read_by_other_layers: true # subject to the companion §4 sunset note: >- Not a §4 Tooling row. Listed for totality, not as a declared gap. # §9.6 — the bound audit-core delivers, stated so no doctrine rests on more. evidence_bound: proves: - records held were not altered after arrival - records held were not truncated after arrival does_not_prove: - that a record was ever sent - absence of a record as evidence of non-occurrence conditional_on: - external chain-head attestation stored outside platform-pg contract: docs/integrity.md not_claimed: [WORM, object-lock, archival-custody]