Customer-controlled evidence
Detailed source, prompts, private context, and findings stay offchain by default.
Security and trust
Public operating boundaryVerShep is designed to support trustworthy review; it does not claim to guarantee security, replace audits, create compliance automatically, or remove the need for Human judgment.
Detailed source, prompts, private context, and findings stay offchain by default.
Capabilities must be explicit, purpose-limited, revocable, and separate from identity.
The producer should not be the only evaluator of its own consequential work.
Passing automation cannot silently become business acceptance.
Not assessed, stale, skipped, and unresolved states remain visible.
Evidence and accepted corrections should remain useful across model and provider changes.
The VerShep read app is limited to selected repository metadata, contents, pull requests, checks, releases, and tags. DEP retains the installation relationship and bounded source manifest; it does not retain the temporary GitHub user token used to validate installation ownership.
Draft pull requests use a separate write-tier app. The endpoint additionally requires DEP Pro, a blocker-free Human-accepted outcome, an unchanged pinned source revision, and an exact Human confirmation. Merge, deployment, signing, and publication remain outside DEP authority.
DEP can export a provider-neutral Trust Envelope that records the source, Digital Entity identities, Human sponsor, authorized purpose, delegated actions, denied actions, containment references, evidence state, and Human acceptance state.
The export supports operational audit readiness. It is not a security certification, legal opinion, or automatic compliance determination. Identity, connectivity, execution, evidence, and acceptance remain separate concepts.
Accessibility
The public site targets WCAG AA contrast, semantic landmarks, visible keyboard focus, reduced-motion preferences, and non-color status labels.
Automated checks and Human Operator QA support each release. Accessibility feedback can be sent to admin@vershep.com.