{
  "schema_version": "1.0",
  "last_substantive_update": "2026-09-24",
  "product": "1seal publishes security research and a draft model for checking a payload against declared intent before commitment. The semantic toolkit is in private development / pre-release; LMV is a draft, not a mature standard.",
  "pass_boundary": "A PASS means only that the evaluated payload matched declared intent under configured invariants and available evidence. It does not establish safety, legality, compliance, legitimacy or general trustworthiness.",
  "components": {
    "specification": {
      "label": "LMV specification",
      "state": "public draft v0.1",
      "detail": "Public README version; no completed external review or mature standard status is asserted.",
      "url": "https://github.com/1seal/lmv-spec",
      "observed_at": "2026-09-22"
    },
    "evidence_verifier": {
      "label": "Evidence verifier",
      "state": "public documentation; implementation not published there",
      "detail": "The repository describes offline DSSE/JCS verification. Its public tree contains README, SECURITY, LICENSE and .gitignore, not executable verifier code. The site playground checks required fields only.",
      "url": "https://github.com/1seal/verifier/tree/f9030b3b7ecfb64a99dda8ad2395c63174fd2440",
      "observed_at": "2026-09-22"
    },
    "semantic_implementation": {
      "label": "Semantic LMV implementation",
      "state": "private / pre-release",
      "detail": "No public release, independent validation or delivery date is asserted.",
      "url": "/behind-the-work/",
      "observed_at": null
    },
    "design_partners": {
      "label": "Design partners",
      "state": "limited conversations; not broadly open",
      "detail": "No acceptance, existing participation or onboarding date is promised.",
      "url": "/status/#design-partners",
      "observed_at": null
    },
    "services": {
      "label": "Services",
      "state": "by request; separate from product access",
      "detail": "Scope and availability are agreed per engagement.",
      "url": "/services/",
      "observed_at": null
    }
  },
  "research": {
    "snapshot_date": "2026-09-26",
    "counts": {
      "records": 317,
      "projects": 149,
      "cves": 106,
      "ghsas": 10,
      "prs": 29,
      "credited_fixes": 14,
      "engineering_contribs": 5,
      "upstream_contribs": 19,
      "reported_fixes": 153,
      "visible_records": 322,
      "unique_findings": 308
    },
    "url": "/research/",
    "data_url": "/assets/data/portfolio.json",
    "counts_are": {
      "url": "/research/#counting",
      "headline": "counted CVE and GHSA advisory records + security PRs + credited fixes + report-associated fixes + hardening/testing records",
      "roles": "PR and engineering buckets include researcher-opened and vendor-opened work, not an authorship total. PR opener, code authorship and reporting credit are distinct. v4 renames counts.authored_contribs to counts.engineering_contribs without changing membership.",
      "fix_boundary": "Report-associated fixes include conditional mappings and partial mitigations. Their total is not a count of independently reproduced fixes, released fixes or verified deployments; read each record status and limits.",
      "dates": "snapshot_date is the portfolio data revision, not a claim that all upstream facts were rechecked that day. Per-source observations and editorial review dates are separate; deployment revision is in /_build.json.",
      "exclusions": "long-form 1seal advisory pages and historical fixes do not add headline records; advisory exclude_from_counts is respected",
      "visible_records": "Research excludes advisories_detailed as article rows. Each write-up with finding IDs absent from other records contributes one uncounted Documented finding row for its remaining IDs; repeated IDs are not added again. Write-ups remain in this payload and on finding evidence pages. v5 changes visible_records and area/project distributions, not headline membership.",
      "finding_ids": "mechanically deduplicated identifiers, not a deduplicated count of independent vulnerabilities",
      "projects": "distinct repositories in headline sections, including excluded advisory records",
      "cves": "CVE publication state must be PUBLISHED in the source-bound registry snapshot; RESERVED, REJECTED and unverified IDs do not count as CVEs. A published GHSA can still count once in the GHSA bucket."
    }
  },
  "signature": {
    "state": "unsigned",
    "boundary": "The preview DOM hash and build hashes are not signatures or authentication."
  }
}
