# Security and evidence scope

This is a trusted local reference evaluation, using synthetic data and publicly known signing scalars 1001 and 1003. They are visible in the reference source by design. They must never hold funds, identify a real operator or authorize an operational resource.

The tutorial executes deterministic Core authorization, durable local admission, typed acknowledgment and replay. Its default external outcome is simulated. Packet mode really copies two local synthetic files; its signed note records a statement, not incident resolution. No blockchain transaction, AI model, external recipient, institution authentication, production secret or network service participates.

Agents A and B are protocol identities driven in one trusted process, not adversarial programs in separate sandboxes. Protocol termination does not terminate an OS process. Epoch/session fencing denies obsolete requests only at the mediated boundary. Host administrators can alter the local history and fixture keys; local hashes do not resist coordinated malicious replacement or establish a fresh global head. The Linux guide reports a different, recorded native lab scope.

The wrapper appends selected revocations as the trusted single-process operator, after replay validation. It is not a general policy API, concurrent service or secure admin login. The unchanged application uses cooperative locks; it does not repair abandoned locks after a killed process. It preserves uncertain outcomes instead of promising exactly-once effects.

The printed current decision is scoped to a history head and operation. Do not treat it as a capability for a later action. An integration must use the current admission/pre-use checks and completely mediate its protected resource. No privileged decision is delegated to an AI model.

Source integrity checks identify bytes, not correctness, author identity, independence of review or production readiness. Only the documented tutorial behavior and recorded observations are claimed. Experimental deeper APIs are not a compatibility promise.
