This index separates public orientation, normative security contracts, implementation programs, operational evidence, and historical records. A document's title or location does not grant authority.
Use this precedence order and fail closed:
- Frozen protocol specifications and accepted ADRs, including explicit supersession and accepted amendments.
- Accepted phase architecture and implementation contracts.
- Current phase decisions and security-remediation contracts.
- Root security and API documents.
- Conformance specifications and accepted governance records.
- Migration guides and examples.
- Operational evidence, release notes, reviews, and historical plans.
A contradiction between normative records is a release defect. It is not permission to select the more permissive interpretation.
- Project overview
- Host responsibility overview
- FAQ
- Public roadmap
- Contributing
- Security policy
- Support
- Vision
- Architecture
- Security model
- Threat model
- Security invariants
- Public API design
- Public API inventory
- ADR index
- SecureToolKit Authorization Protocol
- Phase 1 decisions
- Phase 2 decisions
- Phase 3 decisions
- Phase 4 decisions
- Phase 5 decisions
- Phase 6 decisions
- Invariant test matrix through Phase 6
- Accepted architecture
- Architecture decisions
- ADR-0042: Human Confirmation Semantics
- Implementation contract
- Test matrix
- Conformance requirements
- Implementation roadmap
- Implementation slices
- Acceptance gates
- S01 structural-checker erratum
Planning documents retain the status metadata of the revision in which they were accepted. Their “implementation not started” wording is historical metadata, not a statement about the current source tree.
Candidate corpus material is not an approved conformance result. Publication status must be determined from the exact corpus identity, its authority record, and its immutable review evidence.
- Examples
- Pre-1.0 migration index
- RC0.1 migration
- RC0.2 migration
- RC0.1 security remediation
- RC0.2 security remediation
Examples are explanatory and non-authoritative. They do not perform Consumption or Execution.
Operational evidence records results for exact historical commits and toolchains. Test counts and platform claims do not automatically apply to the current checkout.
- Keep one H1 heading per document.
- State whether a release, corpus, review, or result is approved, candidate, historical, or informational.
- Never use a candidate result as approved evidence.
- Preserve frozen hashes and explicit supersession records.
- Prefer links from this index over duplicating normative text.
- Keep secrets, customer data, raw prompts, and sensitive arguments out of documentation and evidence.