VeriTrace is an offline evidence and conformance tool. It does not execute agent tools, grant permissions, contact model providers, or store credentials. The security boundary is the parsing, evaluation, reporting, and verification of potentially untrusted trace and policy artifacts.
Do not place live secrets, access tokens, personal data, or unredacted tool output in fixtures or evidence bundles. Treat generated HTML reports as sensitive if the source trace contains confidential metadata. Use the unknown verdict as a signal that evidence is incomplete, not as proof of safety.
Please do not open a public issue for a suspected security vulnerability. Use GitHub's private vulnerability reporting for the repository, including a minimal reproduction, affected version, expected behavior, and whether an input artifact is required. Maintainers will acknowledge reports and coordinate a fix and disclosure timeline.
The verifier proves integrity and deterministic consistency of the supplied artifact; it cannot prove that the original runtime truthfully recorded every event, that a policy expresses an organization's intent, or that an action is safe in the real world. These limitations are intentional and should be stated in downstream audit materials.