Sources

Primary evidence and standards

These sources inform the framework. A citation indicates influence or evidence; it does not imply endorsement of this project.

Risk and security

Protocols and authorization

Worked example

Source policy

Use the current published version of a standard where possible. Product claims are pinned to a version or commit. If official documentation and inspected public code differ, the discrepancy should be recorded rather than reconciled by assumption.