the rollback trap, resolved.
edbb1a2a91d45ab8bacefdacb714df47870786c9b1b125b58f271ddb3c9f9449published synthetic receipts
tenant a received tenant b's invoice with http 200. the boundary check caught the cross-tenant read; a tested repair was shipped and verified on the public endpoint.
edbb1a2a91d45ab8bacefdacb714df47870786c9b1b125b58f271ddb3c9f9449the same five watchpoints were run for each candidate. blank cells mean the candidate was stopped before execution.
| candidate | amount and current schema | tenant boundary | positive access for b | unauthenticated denial | unknown invoice denial |
|---|---|---|---|---|---|
| legacy rollbackrejected | |||||
| prior rollbackrejected | |||||
| openai forward repaireligible |
swipe across the table to see all five checks →
an evidence-backed briefing generated after the verified gateway switch.
recompute the hash over redacted incident events recorded before publication. save this head independently to notice later server-side changes.
published head 8700542eb35b847682fb1daeb2d6b86dfd78fb0a4aaf75bfe431a94c09433e68
detects edits relative to the published head. it is not a signature and does not prove the events were true.
this report uses synthetic data. the vulnerable release was a synthetic fixture, not recorded model output. it contains no customer identities, access tokens, or source code.