The Magenta Canon Trust & Security page is the reviewer diligence surface for a private-access reference implementation — not production-hosted infrastructure. It shows how to report a vulnerability, how to verify the evidence independently, and what is proven today versus what is in active development versus what is not built, and it links a machine-readable claims register that maps every public claim to its evidence, limitation, or explicit non-claim. The production multi-tenant Human Plane is in active development and is not production-active; enforcement covers the MCP tools/call method class, and other MCP methods pass through the gateway ungated. An external STH mirror is implemented and detects history rewrite, equivocation, and rollback once a tree head is mirrored, though its value against a dishonest operator depends on independent custody and no hosted third-party mirror service is built.
- Private-access, design-partner evaluation; a reference implementation you run yourself
- Report a vulnerability privately to security@themagentacanon.com (RFC 9116: /.well-known/security.txt)
- Machine-readable claims register published at /claims-register.json
VERIFY, DON'T TRUST
Trust & Security for reviewers.
Everything here is written for the people accountable for agent risk to review, not to take on trust. Magenta Canon is a reference implementation under private-access evaluation — under-claiming is the brand.
Report a Vulnerability
Disclose privately to security@themagentacanon.com with a description, impact, reproduction steps, and the affected version or commit — please do not open a public issue for a vulnerability. Machine-readable contact is published at /.well-known/security.txt (RFC 9116).
Verify It Yourself
The proof surface is executable: from a granted private checkout, run the loop and the standalone verifier yourself, pinning both anchors — the witness key and the ceremony-sourced receipt-issuer key, because the witness key alone is fail-open on receipt provenance. The hosted evidence surface is an evaluation surface running in-memory — its evidence is ephemeral and is not durable production evidence storage.
Claims & Evidence
Every public claim is mapped in a machine-readable claims register at /claims-register.json to its status — proven, supported, design-partner evaluation, roadmap, doctrine, or an explicit non-claim — and to its evidence or limitation. No certification is claimed; it is not broad AI safety; the hosted instance is not durable production evidence storage.
Request Design-Partner Access
Design-partner access and diligence requests: access@themagentacanon.com. Governance questions: governance@themagentacanon.com. Interpretation, compliance determination, and legal judgment remain the responsibility of external reviewers.