Skip to content

Commit cf9bf27

Browse files
committed
plan: the standards register opened as a stub
Change 6 of the 2026-09-20 plan, on the owner's decision. One row per control a regulated deployment may ask about, each with where Trinity would satisfy it, the evidence path in the tree or none, a status (tree property, real-world dependency, not claimed, :unknown) and who decides. Every status today is :unknown, not claimed, or a real-world dependency, and the file states the rule it exists to enforce: no README or public page makes a regulatory claim without a row here whose status says the claim is true. plan_check: PASS. trinity.names: OK. Signed-off-by: Ayla Croft <aylacroft@proton.me>
1 parent 2e760d5 commit cf9bf27

1 file changed

Lines changed: 84 additions & 0 deletions

File tree

‎docs/09-standards-register.md‎

Lines changed: 84 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,84 @@
1+
# 09: Standards register
2+
3+
Opened 2026-09-20 as a stub, on the owner's decision. One row per control a regulated deployment may ask
4+
about. The register separates two kinds of statement that are easy to blur: a **tree property**, which a test
5+
or a command in this repository proves, and a **real-world dependency**, which is an act by a deployment, an
6+
assessor or an authority and which no version of this tree can close.
7+
8+
The rule this file enforces by existing: **no README, release note or public page of this project makes a
9+
claim about a regulation, a certification or a government or healthcare requirement unless this register
10+
carries the row, with an evidence path, and the status column says the claim is true.** A row whose status is
11+
`:unknown` or `not claimed` is not a claim. Marketing copy cites this file or says nothing.
12+
13+
Columns: the control; where Trinity satisfies it, or would; the evidence path in the tree (a test name, a
14+
document, a PROOF.md line) or `none`; the status; who decides the status. Statuses: `tree property`,
15+
`real-world dependency`, `not claimed`, `:unknown`.
16+
17+
## Cryptography
18+
19+
| Control | Where Trinity satisfies it | Evidence path | Status | Decider |
20+
|---|---|---|---|---|
21+
| FIPS 140-3 validated cryptography in FIPS mode | OTP built with `--enable-fips` against a validated provider; `crypto:info_fips()` enabled; slice 024's signer selects an approved algorithm or denies | slice 003 (FIPS build leg), slice 024 AC8 | `:unknown` until 003 and 024 land | owner, then an assessor |
22+
| CNSA 1.0 signature suite (ECDSA P-384, SHA-384) | slice 024 amendment 2, FIPS mode selection | slice 024 AC8 | `:unknown` until 024 lands | owner |
23+
| CNSA 2.0 readiness (ML-DSA-87) | slice 024 amendment 6, behind the same seam, compile-conditional on OpenSSL 3.5 or later; never default | none yet | `not claimed` | owner; the word validated waits on the CMVP listing of the provider that carries it |
24+
| FIPS 140-2 certificates on the Historical list from 2026-09-22 | not applicable: Trinity cites no 140-2 module | none | `real-world dependency` (deployment's modules) | deployment |
25+
| TLS floor 1.2 in FIPS mode | one README line and a test pinning it | slice 002 AC3 | `:unknown` until 002 lands | owner |
26+
| Envelope MAC in FIPS mode is an approved algorithm | HMAC-SHA256 or AES-GCM in the MRTR envelope Trinity mints | slice 061 | `:unknown` until 061 lands | owner |
27+
28+
## Records and audit
29+
30+
| Control | Where Trinity satisfies it | Evidence path | Status | Decider |
31+
|---|---|---|---|---|
32+
| NIST SP 800-53 AU family: non-repudiation of every governed act (AU-10) | per-receipt signatures for effect, decision, boot and cap receipts; checkpointed chains for query receipts; standalone verifier | slice 024 AC3, AC7, AC9 | `:unknown` until 024 lands | owner, then an assessor |
33+
| Audit record durability of the last committed receipt | receipts file may run `synchronous: :full` in its own file | slice 010 (file slot), slice 024 | `:unknown` | owner |
34+
| Disconnected operation without loss of audit | store-and-forward receipts, hybrid logical clocks, Merkle merge | slice 026 | `not claimed`; 026 is blocked on an external answer | owner |
35+
| Trusted time for receipts | none in software; a deployment supplies a trusted time source | slice 026 risk line | `real-world dependency` | deployment |
36+
37+
## Data at rest and keys
38+
39+
| Control | Where Trinity satisfies it | Evidence path | Status | Decider |
40+
|---|---|---|---|---|
41+
| Encryption of data at rest with deployment-controlled keys | volume or page level below SQLite (documented baseline); envelope encryption for blobs; keys through the custody seam | slice 025 | `:unknown` until 025 lands | owner, then an assessor |
42+
| Exclusive deployment control of encryption keys | `Trinity.Keys` behaviour; local adapter first; KMS, HSM and PKCS#11 as later adapters | slice 025 AC1, AC3 | `:unknown` | deployment |
43+
44+
## Identity
45+
46+
| Control | Where Trinity satisfies it | Evidence path | Status | Decider |
47+
|---|---|---|---|---|
48+
| Non-person entity identity from the deployment's PKI, with an accountable sponsor | X.509 per instance; sponsor field in the boot receipt; SPIFFE as an issuance path only | slice 062 amendment note | `not claimed`; no criterion yet | owner |
49+
| Identity is not authority | OAuth and EMA answer who; the gate and the authority adapter answer whether | slice 062, slice 024 | `:unknown` until both land | owner |
50+
51+
## Supply chain
52+
53+
| Control | Where Trinity satisfies it | Evidence path | Status | Decider |
54+
|---|---|---|---|---|
55+
| Software bill of materials on every release | CycloneDX from the gate, attached to releases | slice 002 AC1, AC2 | `:unknown` until 002 lands | owner |
56+
| Build provenance on release artifacts | GitHub attestation, verified in the workflow | slice 002 AC2 | `:unknown` until 002 lands | owner |
57+
| Signed releases, Scorecard, SLSA level | slice 121 | none yet | `not claimed` | owner |
58+
| Cryptography bill of materials | none until the minimum elements are published | none | `not claimed` | owner |
59+
60+
## Architecture arguments a deployment may ask for
61+
62+
| Control | Where Trinity satisfies it | Evidence path | Status | Decider |
63+
|---|---|---|---|---|
64+
| Independence from other systems that share the Jido library | shared library, not shared runtime; not on the path a finding takes | ADR-0009 appended decision | `tree property` once 012 lands with the boundary tests | owner |
65+
| Standalone operation with no authority plane and no outbound connection | `TRINITY_AUTHORITY=local`, the standalone assertion | slice 024 AC2 | `:unknown` until 024 lands | owner |
66+
| Nothing fails open | signing unavailable denies; unknown tool denies; unknown effect denies; adapter unresolvable refuses to start | slice 024 AC5, ADR-0010 | `:unknown` until 024 lands | owner |
67+
68+
## Real-world dependencies that no tree change closes
69+
70+
An authorization to operate, a provisional authorization, a FedRAMP package, a business associate agreement
71+
with every downstream model provider, a CMMC level, a device submission. Each is a deployment's act with a
72+
sponsor and a date. They are listed here so nobody mistakes a green gate for one of them.
73+
74+
| Item | Status | Decider |
75+
|---|---|---|
76+
| Any authorization to operate | `real-world dependency` | deployment and its authorizing official |
77+
| Business associate agreements with model providers | `real-world dependency` | deployment |
78+
| CMMC assessment | `real-world dependency` | deployment and its assessor |
79+
| Device submission with a change-control plan | `real-world dependency` | deployment and its regulator |
80+
81+
## How rows change
82+
83+
A row's status moves only with an evidence path a stranger can follow. A row is never deleted; a control that
84+
stops applying keeps its row with the reason. Corrections append below the table they correct, dated.

0 commit comments

Comments
 (0)