Security and trust

Public operating boundary

Evidence-qualified claims. Explicit boundaries.

VerShep is designed to support trustworthy review; it does not claim to guarantee security, replace audits, create compliance automatically, or remove the need for Human judgment.

Customer-controlled evidence

Detailed source, prompts, private context, and findings stay offchain by default.

Bounded authority

Capabilities must be explicit, purpose-limited, revocable, and separate from identity.

Independent checks

The producer should not be the only evaluator of its own consequential work.

Human acceptance

Passing automation cannot silently become business acceptance.

Honest uncertainty

Not assessed, stale, skipped, and unresolved states remain visible.

Portable records

Evidence and accepted corrections should remain useful across model and provider changes.

Current public boundary

What VerShep does not claim or perform by default.

  • Hold private keys or customer funds
  • Sign or submit production transactions
  • Deploy or upgrade programs autonomously
  • Place private evidence onchain by default
  • Represent a professional security audit
  • Guarantee that assessed work is free of defects
Connected-project beta

Observation and mutation use separate gates.

The VerShep read app is limited to selected repository metadata, contents, pull requests, checks, releases, and tags. DEP retains the installation relationship and bounded source manifest; it does not retain the temporary GitHub user token used to validate installation ownership.

Draft pull requests use a separate write-tier app. The endpoint additionally requires DEP Pro, a blocker-free Human-accepted outcome, an unchanged pinned source revision, and an exact Human confirmation. Merge, deployment, signing, and publication remain outside DEP authority.

Available in DEP Early Access

Export the trust boundary, not only the result.

DEP can export a provider-neutral Trust Envelope that records the source, Digital Entity identities, Human sponsor, authorized purpose, delegated actions, denied actions, containment references, evidence state, and Human acceptance state.

The export supports operational audit readiness. It is not a security certification, legal opinion, or automatic compliance determination. Identity, connectivity, execution, evidence, and acceptance remain separate concepts.

Accessibility

Trust includes usable access.

The public site targets WCAG AA contrast, semantic landmarks, visible keyboard focus, reduced-motion preferences, and non-color status labels.

Automated checks and Human Operator QA support each release. Accessibility feedback can be sent to admin@vershep.com.