published synthetic receipts

oops db8c301d.

tenant a received tenant b's invoice with http 200. the boundary check caught the cross-tenant read; a tested repair was shipped and verified on the public endpoint.

recovered
request identitytenant a
target invoiceinv_b
expected http403
observed http200
published recovery receipt

the rollback trap, resolved.

oops db8c301d
legacy rollbackrejectedguard pattern absent; failed executable checks
prior rollbackrejectedamount and current schema, positive access for b
akash forward 1rejectedguard pattern absent; failed executable checks
akash forward 2rejectedguard pattern absent; failed executable checks
akash forward 3rejectedproposal accesses an unapproved attribute
openai forward repairshippedopenai proposal
verified 2026-10-09 20:36:03 UTCartifact sha256 edbb1a2a91d45ab8bacefdacb714df47870786c9b1b125b58f271ddb3c9f9449

the unchanged recovery floor.

the same five watchpoints were run for each candidate. blank cells mean the candidate was stopped before execution.

candidateamount and current schematenant boundarypositive access for bunauthenticated denialunknown invoice denial
legacy rollbackrejected
prior rollbackrejected
openai forward repaireligible

swipe across the table to see all five checks →

listen to the recovery.

an evidence-backed briefing generated after the verified gateway switch.

check the receipt chain.

recompute the hash over redacted incident events recorded before publication. save this head independently to notice later server-side changes.

published head 8700542eb35b847682fb1daeb2d6b86dfd78fb0a4aaf75bfe431a94c09433e68

detects edits relative to the published head. it is not a signature and does not prove the events were true.

this report uses synthetic data. the vulnerable release was a synthetic fixture, not recorded model output. it contains no customer identities, access tokens, or source code.