Security posture
Security
A bounded overview of security design without certification, immunity, or service-level guarantees.
Pre-publication draft: this document is not an approved public-beta contract. Publication and open registration remain disabled.
Document: security
Version: 2026-07-22-beta-readiness-1
Effective date: 2026-07-22
Canonical localized-content SHA-256: e9d86fb7ad29bfa09e25925503a8cbc3ab63f8663a92ca7dbe1889c6ce16e4da
Approved multilingual document SHA-256: 4c75fce9f34db6c3e376f33c6c5a889f172cc791b8d2337703ddb47cbb8e9d3c
Security: security@gutmask.xyz
Current design
GutMask separates human control-plane, human runtime-plane, and Portal machine-channel authority. Authentication, session, ACL, audit, and release controls are designed as layered safeguards rather than absolute guarantees.
- Sensitive reports should use the private security contact.
- Do not place credentials, private keys, or unrelated personal data in a report.
Assurance boundaries
No certification, compliance status, penetration-test coverage, uptime, or incident-response time is claimed unless separately published with current evidence.
- See the Vulnerability Disclosure Policy for authorized testing boundaries.