Publication / research software
TAP-SEC Reference Implementation M4 v0.3.2
Local-host boundary validation, fail-closed recovery, continuity classification, witness-bound memory updates, formal safe/unsafe profiles, and reproducible public evidence.
Publication state
DOI-backed research software
Truthful status boundary
Partial local-host pass
M4_PARTIAL_PASS_WITH_BLOCKED_GATES
M4_LOCAL_HOST_BOUNDARY_PASS=true
M4_FULL_PASS=false
NOT_NORMATIVE
NOT_PRODUCTION_READY
The tested local-host boundary passed. Four external physical-evidence gates remain explicitly blocked and are not counted as passes.
Evidence summary
Fixture aggregate and validation
16 PASS
24 PASS_FAIL_CLOSED
2 BLOCKED_EXTERNAL
0 FAIL
42 total
The final release tree passed 183/183 contract-bound tests, 672/672 checksum records, 671/671 package-manifest records, and 40/40 fixture evidence bindings.
Validation also completed two clean extractions, public-safety validation, and a byte-identical final ZIP rebuild.
Blocked external gates
Evidence not claimed
- G05 — no distinct pinned remote witness outside the same host.
- G06 — no physically separate append-only witness failure domain.
- G07 — no physical non-exportable TPM/HSM custody.
- G13 — no direct Katy-attributable Joule telemetry.
Immutable artifact
Software release identity
Academic documents
Five approved reports
The approved academic PDFs are linked directly from the immutable m4-v0.3.2 GitHub release. The website does not mirror or modify them.
Licensing
Software and documentation scopes
Author-owned software and machine-executable materials are licensed under the Apache License 2.0.
Author-owned documentation, academic reports, diagrams, publication metadata, and public evidence are licensed under CC BY 4.0.
Third-party and excluded materials retain their original terms.
Copyright © 2026 Ivan Kotov. All author-owned rights remain vested in Ivan Kotov.
Metadata clarification
Authoritative release records
- The reference to
datacite.jsonin Section 7 of the reuse guide meansdatacite.xml. - There is no separate
RELEASE_CLAIMS.json. - The authoritative claim records are
PUBLICATION_STATUS.jsonandPUBLICATION_MANIFEST.json. - The repository retains
.zenodo.json.
Recommended citation
Cite this release
Kotov, I. (2026). TAP-SEC Reference Implementation M4 v0.3.2: Local-Host Boundary Validation, Fail-Closed Recovery, and Public Evidence (Version 0.3.2) [Computer software]. Zenodo. https://doi.org/10.5281/zenodo.21688521
Non-claims
What this release does not establish
This release is not a full M4 pass, normative standard, production-safety certificate, independent human peer review, or authorization for production or safety-critical deployment.
It does not claim physical TPM/HSM custody, a physically independent remote witness, a physically separate append-only witness failure domain, or direct Katy-attributable Joule evidence.