AER-1 Security Review Package
Status: pending. This is a review package and checklist, not a completed independent security review. No reviewer is claimed.
Threat model
The format protects the integrity and identity of the recorded bytes. It does not make an upstream provider truthful or expose private data safely by itself.
Relevant attack list
- Replay: reviewers should check the stable identifier, creation time, freshness policy, and any anchor evidence.
- Man in the middle: use HTTPS and compare the exact public record, bytes, and digest.
- Denial of service: an unavailable receipt is an availability failure, not proof that the action failed.
Out of scope
Credential protection, provider correctness, business authorization, endpoint availability guarantees, and legal compliance are outside this format's integrity claim.
Reviewer checklist
- Reproduce every vector verdict.
- Check strict UTF-8 and calendar-valid timestamps.
- Compare source, bytes, and hash without reserialization.
- Record findings through the public issue venue.
Findings log
No independent findings are published. Existing relationships only may submit reproducible findings. No cold outreach is requested.