Bound rule 13: audit proves alteration, not omission

audit-core corrected a claim this repository's doctrine also makes. An
append-only archive with a verified hash chain proves records were not altered
or truncated after arrival; it cannot prove one was never sent. A suppressed
event leaves the chain intact and verification reports intact — and the event
an adversary most wants missing is the negative one: a revocation, a denial, a
containment action.

Adds the bound under the Core Rules, replacing "the audit record proves it
happened" with the sound form, and records that completeness is the emitting
system's obligation via atomic emission.

Flags outstanding doctrine work: the ASM Canon's control §27 and tests T-08 and
T-09 are written as though reconstruction from evidence were unconditional.

Also bumps standard references to v0.4.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
tegwick 2026-08-28 22:55:19 +02:00
parent d62d48aba2
commit 94526e44c0
3 changed files with 24 additions and 4 deletions

View file

@ -25,7 +25,7 @@ anything depends on at runtime.
NetKingdom's IT security is layered by determinism and by the kind of artifact
each layer produces — see
[`net-kingdom/canon/standards/security-layer-model_v0.2.md`](../net-kingdom/canon/standards/security-layer-model_v0.2.md).
[`net-kingdom/canon/standards/security-layer-model_v0.4.md`](../net-kingdom/canon/standards/security-layer-model_v0.4.md).
```text
Taxonomy cross-cutting language info-tech-canon, net-kingdom canon