Skip to main content

Public Docs Claim Audit

Audit ID: PUBLIC-DOCS-CLAIM-AUDIT-001 Date: 2026-05-24 Source Repo: ~/zenmesh/zen-platform @ 7d41a92b1 Docs Repo: ~/zenmesh/docs @ 3bd3ef3

Audit Results by Doc

docs/architecture/security-model.md

ClaimClassificationAction
mTLS certs issued via SPIFFE/SPIREneeds_scopecert-manager issues workload certs with SPIFFE URI SAN; SPIRE NOT_YET_BUILT
SPIFFE/SPIRE workload identity / auto-rotationsupported_but_missing_evidence_refscert-manager auto-renewal is COMPLETE; SPIRE SVID rotation NOT_YET_BUILT
HMAC: "Duplicate events are detected and rejected"needs_scopeHMAC provides integrity/tamper protection, not dedup
Enrollment flowsupported_as_writtenTRUST-PROOF-001/002 match
ZenLock/zero-knowledge secretssupported_as_writtenTRUST-PROOF-005/009 match
Encryption layerssupported_as_writtenmTLS enforcement confirmed

docs/architecture/delivery-modes.md — All claims supported_as_written

docs/guides/cluster-enrollment.md — All claims supported_as_written

docs-zen-lock/security-properties.md — All claims supported_as_written

Changes Applied

  1. security-model.md: Scoped SPIFFE/SPIRE claim to cert-manager issuance, marked SPIRE as planned.
  2. security-model.md: Clarified HMAC provides integrity/tamper protection; dedup handled by idempotency layer.
  3. Remaining docs: no changes needed — claims match current evidence.

Non-Claims

  • No changes introduced new claims.
  • No content removed where implementation exists but proof is local/mock.
  • No production/live proof claimed.