V0.1

Security and privacy considerations

IP-SEC-01 — Fail closed. Missing trusted association, invalid proof, stale or unavailable authoritative state, expired/revoked evidence, or uncertain validation commit cannot produce success. A bounded version conflict may retry; missing authority or uncertainty is not converted to permit. [ADRs 8G–8H, 8K-A–8M-A, 8S-A–8U-A.]

IP-SEC-02 — Limit disclosure. Return only the exact opaque consumer reference after successful resolve. Keep response and telemetry from revealing hidden targets, Root/sibling relationships, account links, grant paths, or identity keys. [ADRs 7P, 8D–8G, 8R-A.]

IP-SEC-03 — Resist replay. Bind evidence to audience, purpose, challenge, actor, operation, target, state/generation, and authoritative expiry; enforce one-time acceptance and context-bound idempotency. [ADRs 8S-A, 9F-A.]

IP-SEC-04 — Bound work. Admission, asynchronous waiting, blocking execution, connections, deadlines, retries, and cancellation must be bounded so timed-out work remains accounted for until safely stopped. Numeric limits and runtime mechanisms are deployment/profile choices. [Resolver contract, Bounded asynchronous scheduling and execution; ADR 8H.]

IP-SEC-05 — Independent data ownership. Passport and a consumer own their separate records and transactions. This draft makes no claim of a cross-database transaction. Credentials, migrations, and audit stores are operational matters, not universal identity semantics. [ADR 8H.]

Issuer compromise, trust-anchor/key rotation, independently auditable fresh authentication, public error/timing policy, and deployment integration remain open questions. These gaps block production and interop claims; they do not silently alter the candidate semantic rules.