Security Operations
ENTITY security operations focus on preserving authority boundaries, key custody, evidence integrity, recovery and provider independence.
Daily/continuous controls
- Protect identity/recovery key material with least privilege.
- Monitor failed signature, authority and rights verification.
- Retain tamper-evident evidence/incident logs.
- Verify backups and exports can actually be restored.
- Keep dependencies and release provenance pinned to supported versions.
- Do not run current deployments on superseded v3.4.1.
High-risk events
Key exposure, unauthorized authority delegation, corrupted provenance, backup failure, external-anchor substitution, provider lockout, altered release material and unexpected BTDU state-root change should trigger incident handling.
Dependency security
The v3.4.2 release process included dependency review. Deployment operators must continue patch management outside the immutable tag by qualifying a new application environment or subsequent release rather than modifying the tagged release in place and pretending it is unchanged.
Vulnerability reporting
Use the repository's SECURITY.md and private reporting path for exploitable findings. Public issues are appropriate for non-sensitive design criticism and reproducible specification ambiguities.