Skip to content
Radical transparency

The Security Claims Matrix

We refuse to collapse safety into one misleading green badge. This matrix separates what OSDF guarantees cryptographically, what is best-effort, and what no format can promise.

Guaranteed

Cryptographic and design guarantees under stated assumptions.

  • Document-supplied scripts do not execute

    Conforming viewer rejects active objects and isolates legacy PDF input.

  • Unauthorized byte modifications are detected

    Signed manifest and digest verification succeed under hash assumptions.

  • Missing local revisions are detected

    A later revision points to a missing parent in the chain.

  • Unauthorized viewers cannot decrypt confidential payloads

    Keys, endpoint, and implementation remain uncompromised.

Best Effort

Network- or policy-assisted controls that depend on deployment.

  • Rollback to an old authentic copy is detected

    Viewer checks an external log, witness receipt, or cached newer observation.

  • Issuer identity is verified

    Viewer trusts the configured root or directory and checks revocation.

  • Threat & anomaly detection

    Risk scoring and posture signals advise policy; not infallible.

  • Leak investigation

    Copy IDs, telemetry, and watermarks are forensic aids, not proof.

Not Guaranteed

Risks no document format can eliminate. We say so plainly.

  • Authorized user cannot leak visible information

    Camera capture and transcription cannot be absolutely prevented.

  • Endpoint compromise protection

    A fully compromised authorized endpoint can expose an active session.

  • Truthfulness of a signed document

    A signature proves authorization and integrity, not factual correctness.

  • Instant revocation with unlimited offline access

    A disconnected viewer cannot know an authorization was just revoked.

Verification proves origin and integrity - not the truth of every claim a document makes. A ledger proves registered provenance, not factual correctness. Every viewer surfaces which checks passed, which were skipped, and which trust roots were used.

See it in action

Verify a document yourself

Run the full verification pipeline and watch each guarantee resolve - with every check shown in plain language.