AER-1 Security Review Package

Status: pending. This is a review package and checklist, not a completed independent security review. No reviewer is claimed.

Threat model

The format protects the integrity and identity of the recorded bytes. It does not make an upstream provider truthful or expose private data safely by itself.

Relevant attack list

Out of scope

Credential protection, provider correctness, business authorization, endpoint availability guarantees, and legal compliance are outside this format's integrity claim.

Reviewer checklist

  1. Reproduce every vector verdict.
  2. Check strict UTF-8 and calendar-valid timestamps.
  3. Compare source, bytes, and hash without reserialization.
  4. Record findings through the public issue venue.

Findings log

No independent findings are published. Existing relationships only may submit reproducible findings. No cold outreach is requested.