{"_id":"@blocksifr/cortextrace","_rev":"2-1dc1928ec2c1ca591e428a5f4a4fe356","name":"@blocksifr/cortextrace","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@blocksifr/cortextrace","version":"0.1.0","keywords":["cortextrace","blocksifr","runtime-authority","ai-assisted-software-delivery","software-supply-chain","github","github-actions","github-app","pull-request-governance","required-checks","execution-receipts","trusted-software","pre-merge-governance","ci-cd-governance","devsecops","slsa","provenance","compliance-evidence","ai-agents","agentic-engineering"],"author":{"name":"BlockSiFr"},"license":"BUSL-1.1","_id":"@blocksifr/cortextrace@0.1.0","maintainers":[{"name":"mwitten","email":"maurice@blocksifr.com"}],"homepage":"https://github.com/BlockSiFr/cortextrace#readme","bugs":{"url":"https://github.com/BlockSiFr/cortextrace/issues"},"bin":{"cortextrace":"dist/cli.js","cortextrace-compute":"dist/cli.js"},"dist":{"shasum":"31f6e9846c766dc525f0b478a2f3484f78cba5b3","tarball":"https://registry.npmjs.org/@blocksifr/cortextrace/-/cortextrace-0.1.0.tgz","fileCount":433,"integrity":"sha512-ZB3TBw2rXBR3s4R4SwJZG0ZOuYFHtj47mocCDU1O5MhEs9HlItZQ2+uoeoa28XuPmALnMje935Dtc0KMzFJgwQ==","signatures":[{"sig":"MEUCIQDk56hzBi7YRKwL2EcxTYgm+7tqyY3Jv+KVFx+N+LOX6QIgZW+210wgX+jpuPpKx1XWCb1HsH43md6ztjgSK0jQS0s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1129377},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schema":"./schemas/execution-receipt.schema.json","./package.json":"./package.json"},"gitHead":"0956863609b09d25de16824efa3a6899aa27d257","scripts":{"dev":"tsx src/cli.ts","gate":"node dist/cli.js gate","lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","format":"prettier --write src tests","verify":"node dist/cli.js verify","receipt":"node dist/cli.js receipt","start:ui":"node dist/cli.js compute-api","start:api":"node dist/cli.js compute-api","lint:eslint":"eslint src tests","demo:compute":"npm run build && node dist/cli.js compute demo","format:check":"prettier --check src tests","security:scan":"node scripts/security-scan.mjs","prepublishOnly":"npm run security:prepublish","release:receipt":"node scripts/release-receipt.mjs","security:prepublish":"./scripts/prepublish-security-check.sh","demo:protected-execution":"npm run build && node dist/cli.js protected-execution && node dist/cli.js verify"},"_npmUser":{"name":"mwitten","email":"maurice@blocksifr.com"},"repository":{"url":"git+https://github.com/BlockSiFr/cortextrace.git","type":"git"},"_npmVersion":"10.9.8","description":"GitHub-native Runtime Authority wedge for Protected Execution. CortexTrace evaluates Runtime Trust, Execution Consequence Intelligence, authority boundaries, and Execution Receipts before merge, deploy, or release.","directories":{},"_nodeVersion":"20.19.0","dependencies":{"js-yaml":"^4.1.0","minimatch":"^9.0.5","puppeteer":"^24.43.1","@fontsource/inter":"^5.2.8","@fontsource/jetbrains-mono":"^5.2.8","@fontsource/cormorant-garamond":"^5.2.11"},"_hasShrinkwrap":false,"packageManager":"npm@10.9.8","devDependencies":{"tsx":"^4.19.2","eslint":"^10.3.0","vitest":"^4.1.5","prettier":"^3.8.3","@eslint/js":"^10.0.1","typescript":"^5.8.3","@types/node":"^22.15.0","@types/js-yaml":"^4.0.9","typescript-eslint":"^8.59.3","eslint-config-prettier":"^10.1.8"},"_npmOperationalInternal":{"tmp":"tmp/cortextrace_0.1.0_1779453288685_0.941630519943081","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@blocksifr/cortextrace","version":"0.1.1","description":"Know what a PR or repo can now execute before merge. CortexTrace scans production paths, workflow authority, identity expansion, rollback gaps, and emits shareable evidence reports.","author":{"name":"BlockSiFr"},"homepage":"https://cortextrace.io","repository":{"type":"git","url":"git+https://github.com/BlockSiFr/cortextrace.git"},"type":"module","packageManager":"npm@10.9.8","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schema":"./schemas/execution-receipt.schema.json","./package.json":"./package.json"},"bin":{"cortextrace":"dist/cli.js","cortextrace-compute":"dist/cli.js"},"scripts":{"build":"node --check dist/cli.js && node --check dist/commands/scan.js","test":"node dist/cli.js scan --json . > /tmp/cortextrace-scan-test.json && node tests/scan-gitlost.test.mjs","dev":"node dist/cli.js","demo:protected-execution":"npm run build && node dist/cli.js protected-execution && node dist/cli.js verify","demo:compute":"npm run build && node dist/cli.js compute demo","start:api":"node dist/cli.js compute-api","start:ui":"node dist/cli.js compute-api","lint":"tsc --noEmit","lint:eslint":"eslint src tests","format":"prettier --write src tests","format:check":"prettier --check src tests","gate":"node dist/cli.js gate","receipt":"node dist/cli.js receipt","verify":"node dist/cli.js verify","security:scan":"node scripts/security-scan.mjs","security:prepublish":"./scripts/prepublish-security-check.sh","release:receipt":"node scripts/release-receipt.mjs","prepublishOnly":"npm run build"},"keywords":["cortextrace","blocksifr","runtime-authority","ai-assisted-software-delivery","software-supply-chain","github","github-actions","github-app","pull-request-governance","required-checks","execution-receipts","trusted-software","pre-merge-governance","ci-cd-governance","devsecops","slsa","provenance","compliance-evidence","ai-agents","agentic-engineering"],"license":"BUSL-1.1","engines":{"node":">=20"},"dependencies":{"@fontsource/cormorant-garamond":"^5.2.11","@fontsource/inter":"^5.2.8","@fontsource/jetbrains-mono":"^5.2.8","js-yaml":"^4.1.0","minimatch":"^9.0.5"},"peerDependencies":{"puppeteer":"^24.43.1"},"peerDependenciesMeta":{"puppeteer":{"optional":true}},"devDependencies":{"@eslint/js":"^10.0.1","@types/js-yaml":"^4.0.9","@types/node":"^22.15.0","eslint":"^10.3.0","eslint-config-prettier":"^10.1.8","prettier":"^3.8.3","tsx":"^4.19.2","typescript":"^5.8.3","typescript-eslint":"^8.59.3","vitest":"^4.1.5"},"bugs":{"url":"https://github.com/BlockSiFr/cortextrace/issues"},"_id":"@blocksifr/cortextrace@0.1.1","gitHead":"874dc6aa8693429e8297aa7965edaf3a65acf182","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-Oyh6y6oUaWL6qfCqz34RWTd0mZKg9PnLsPqZ8BafW4QUrTzNhp3dEkj3ICMenMA8HdiXF30ojnpH3+sdM7bkOg==","shasum":"92d3d330e934e12bd93a9198b49f64e6e63a6153","tarball":"https://registry.npmjs.org/@blocksifr/cortextrace/-/cortextrace-0.1.1.tgz","fileCount":441,"unpackedSize":1166011,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIDjuOYZQZN4lAANLSDKS0gnQuOkijiUaMnDOoO/uxu0NAiEA0KVm6/i89N1x0pfcPR+MmzHatndBqImzkIRZspfW1go="}]},"_npmUser":{"name":"mwitten","email":"maurice@blocksifr.com"},"directories":{},"maintainers":[{"name":"mwitten","email":"maurice@blocksifr.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cortextrace_0.1.1_1783953423894_0.09859041577959093"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-22T12:34:48.506Z","modified":"2026-07-13T14:37:04.205Z","0.1.0":"2026-05-22T12:34:48.889Z","0.1.1":"2026-07-13T14:37:04.101Z"},"bugs":{"url":"https://github.com/BlockSiFr/cortextrace/issues"},"author":{"name":"BlockSiFr"},"license":"BUSL-1.1","homepage":"https://cortextrace.io","keywords":["cortextrace","blocksifr","runtime-authority","ai-assisted-software-delivery","software-supply-chain","github","github-actions","github-app","pull-request-governance","required-checks","execution-receipts","trusted-software","pre-merge-governance","ci-cd-governance","devsecops","slsa","provenance","compliance-evidence","ai-agents","agentic-engineering"],"repository":{"type":"git","url":"git+https://github.com/BlockSiFr/cortextrace.git"},"description":"Know what a PR or repo can now execute before merge. CortexTrace scans production paths, workflow authority, identity expansion, rollback gaps, and emits shareable evidence reports.","maintainers":[{"name":"mwitten","email":"maurice@blocksifr.com"}],"readme":"# CortexTrace\n\nCortexTrace governs the right to cause consequence inside software delivery.\n\nThe product promise is:\n\n```text\nCheck authority. Govern consequence. Prove execution.\n```\n\nCortexTrace is the public product for Agentic Software Execution Governance:\nit discovers dangerous software-delivery execution paths, evaluates whether a\nhuman, agent, workflow, credential, or automation has authority to perform a\nspecific action against a specific resource, and produces evidence of the\ndecision and result.\n\nThe model is not the security boundary. The execution boundary is.\n\n## Fast Start\n\nRun a no-setup scan in any repo:\n\n```bash\nnpx -y @blocksifr/cortextrace scan\nnpx -y @blocksifr/cortextrace scan --out cortextrace-report.md\nnpx -y @blocksifr/cortextrace scan --badge\n```\n\nThe free scan tells you whether a repo or PR contains production execution\npaths, workflow authority expansion, OIDC token issuance, public exposure,\ndestructive commands, rollback gaps, or AI/agent-authored high-consequence\nchanges.\n\nThe paid wedge starts when teams need the result to affect the workflow:\n\n- GitHub PR comments\n- team policy\n- hosted signed receipts\n- approval routing\n- evidence retention\n- enforce mode\n- BlockSiFr Runtime Authority handoff\n\nSubscribe: https://cortextrace.io/pricing?src=readme\n\n## Authority Check\n\nEvery consequential action starts with an Authority Check.\n\nAn Authority Check evaluates:\n\n- actor\n- agent or workload\n- execution intent\n- requested action\n- target resource\n- input trust\n- identity\n- credential\n- authority source\n- context\n- risk\n- consequence\n- policy\n- approval state\n- evidence\n- time validity\n\nIt returns an enforceable decision:\n\n- `ALLOW`\n- `CONSTRAIN`\n- `STEP_UP`\n- `DENY`\n- `ESCALATE`\n- `THROTTLE`\n- `REVOKE`\n\nValid identity is not valid authority. Valid token is not valid authority.\nTrusted application is not valid authority. Approved model is not valid\nauthority.\n\nUntrusted input may influence analysis. It must not inherit authority to read,\nexport, publish, modify, approve, merge, deploy, or execute against protected\nresources.\n\n## Public Demonstration\n\nCortexTrace includes a GitLost-class reference scenario:\n\n```text\nPublic GitHub issue\n-> untrusted content is introduced\n-> agentic workflow consumes the content\n-> agent operates with private repository or organization access\n-> agent attempts to read protected source code\n-> agent attempts to export or publish protected data\n-> CortexTrace detects authority expansion\n-> Authority Check returns DENY or STEP_UP\n-> Execution Exchange enforces the decision\n-> protected data is not released\n-> ExecutionReceipt proves what occurred\n```\n\nThe failure is not merely prompt injection. It is untrusted-context\ncontamination combined with privilege inheritance, authority confusion,\nexcessive credential scope, missing execution control, absent independent\nauthorization, and failure to evaluate consequence.\n\nDemo page: https://cortextrace.io/gitlost-demo\n\nRun the fixture locally:\n\n```bash\nnpx -y @blocksifr/cortextrace scan examples/gitlost-class-demo\n```\n\nExpected scan output:\n\n- `recommendedDecision`: `DENY`\n- `authorityCheckGaps` greater than `0`\n- `gitlost_class_path` finding present\n- protected actions include `source.read_private`, `data.export`, and\n  `authority.check.required`\n\n## Product Packages\n\n### CortexTrace Scan\n\n- repository discovery\n- workflow discovery\n- agentic execution indicators\n- identity and credential findings\n- execution exposure map\n- authority-gap findings\n- read-only assessment\n- remediation guidance\n\n### CortexTrace Protect\n\n- real-time Authority Checks\n- Runtime Authority decisions\n- constraints\n- step-up\n- deny\n- revocation\n- enforcement connectors\n- NullEdge Shield integration where applicable\n\n### CortexTrace Evidence\n\n- ExecutionReceipts\n- artifact provenance\n- compliance export\n- audit evidence\n- forensic reconstruction\n- retention controls\n\n### CortexTrace Enterprise\n\n- multi-organization administration\n- IdP and SCIM\n- SIEM and ITSM\n- private deployment\n- MSP/MSSP controls\n- advanced policy\n- data residency\n\n## Architecture Records\n\n- [`docs/authority-check-architecture.md`](docs/authority-check-architecture.md)\n- [`docs/invention-disclosure-registry.md`](docs/invention-disclosure-registry.md)\n\nZero Trust controlled who could connect.\n\nRuntime Authority controls what may execute.\n\nCortexTrace is the GitHub-native Runtime Authority wedge for AI-assisted engineering, GitHub Actions, CI/CD, Terraform, Bicep, autonomous agents, and non-human identity execution.\n\nProvenance proves where code came from.\n\nAuthority decides whether it may act.\n\n> [!IMPORTANT]\n> Protected Execution must fail closed when Runtime Trust, Authority Evaluation, Execution Consequence Intelligence, or Execution Receipt generation is unavailable in enforce mode.\n\nRepo access is not authority.\n\nA passing pipeline is not proof of trust.\n\nAuthenticated execution is not authorized execution.\n\nCortexTrace is the GitHub-native Protected Execution surface for BlockSiFr Runtime Authority Infrastructure. It evaluates Runtime Trust, Execution Consequence Intelligence, authority boundaries, and evidence before merge, deploy, or release. It emits Execution Receipts that prove the Execution Decision.\n\nGitHub shows the diff. CortexTrace shows what can now execute because of it.\n\nBlockSiFr is the Runtime Authority Infrastructure company. Execution Exchange mediates Protected Execution. Runtime Authority decides. CortexTrace brings that gate to GitHub.\n\n## Category Demos\n\nThe CortexTrace surface exists to support three category demos:\n\n1. Malicious execution denied.\n2. Legitimate execution allowed.\n3. Legitimate authenticated execution denied because it exceeded authority boundaries.\n\nHero sentence:\n\nThis package was legitimate.\n\nThe action was not authorized.\n\nExecution was stopped before it ran.\n\nThe receipt proves it.\n\n## Runtime Positioning\n\nAI agents, developers, contractors, workflows, and pipelines can all change software. Repo access alone cannot prove authority.\n\nSensitive changes can alter workflows, signing logic, dependencies, infrastructure, IAM, policy, or deployment paths before anyone has a trusted record of why the change was allowed.\n\nThe enterprise must move from \"who had access?\" to \"was this execution authorized at the moment it mattered?\"\n\nCortexTrace evaluates sensitive changes, produces Execution Receipts, enforces required evidence, and blocks unauthorized changes from becoming trusted software.\n\n## What It Is\n\nCortexTrace is:\n\n- Runtime Authority OSS wedge.\n- Runtime Trust visibility layer.\n- Execution Consequence Intelligence engine.\n- GitHub-native Protected Execution surface.\n- deny-before-execution and deny-before-deploy proof rail.\n\n## What It Is Not\n\nCortexTrace is not:\n\n- issue-detection tooling.\n- a telemetry product.\n- generic DevSecOps reporting.\n- a compliance certification product.\n- a package trust score.\n- a lint layer.\n\n## Architecture Flow\n\n```text\nGitHub identity\n  -> provenance evidence\n  -> Runtime Trust\n  -> Execution Consequence Intelligence\n  -> Authority Evaluation\n  -> Execution Decision\n  -> Execution Receipt\n```\n\nExecution Exchange receives governed execution events in hosted or Proof Mode.\n\n## Safety Guarantees\n\n- Enforce mode fails closed when authority evidence is missing.\n- Protected paths require attestation before merge.\n- Terraform and Bicep changes receive infrastructure consequence modeling.\n- Credential-accessible execution receives deny-before-execution treatment.\n- Execution Receipts bind evidence, decision, hash, and receipt integrity.\n\n## Enforcement Modes\n\n```bash\ncortextrace xray --mode xray\ncortextrace xray --mode observe\ncortextrace xray --mode enforce-local\ncortextrace xray --mode governed-team\ncortextrace xray --mode enterprise\n```\n\nGoverned Team and Enterprise modes require hosted configuration. Without credentials, the CLI fails safely:\n\n```text\nGoverned Team mode requires a BlockSiFr API key. Run in X-Ray Mode locally or configure BLOCKSIFR_API_KEY to enable hosted enforcement.\n```\n\n## 10-Minute Buyer Path\n\nUntil the npm package is published, run CortexTrace from the public source checkout:\n\n```bash\ngit clone https://github.com/BlockSiFr/cortextrace.git\ncd cortextrace\nnpm install\nnpm run build\nnpm run demo:protected-execution\nnode dist/cli.js verify\n```\n\nThat path runs the real Protected Execution gate through the three Runtime Authority category demos, emits signed local Execution Receipts, and verifies the latest receipt signature.\n\n## Real Execution Examples\n\n```bash\ncortextrace run -- npm test\ncortextrace run -- terraform plan\ncortextrace run -- terraform apply\ncortextrace verify\n```\n\nExample ECI language:\n\n- This execution would create credential-accessible CI execution paths.\n- This execution would permit destructive infrastructure mutation.\n- This execution would expand privilege or secret-accessible runtime authority.\n\n## Production Mode\n\nProduction Protected Execution requires hosted configuration:\n\n- `BLOCKSIFR_API_KEY`\n- Proof Mode signing\n- GitHub App installation\n- repository policy\n- receipt retention\n\n## Operational Commands\n\n```bash\ncortextrace init\ncortextrace run -- npm test\ncortextrace findings\ncortextrace attest findings --finding <finding_id> --status remediated --evidence \"what changed\"\ncortextrace verify-attestations --mode merge-gate\ncortextrace report\ncortextrace verify\n```\n\n## Environment Variables\n\n```bash\nBLOCKSIFR_API_KEY=\nGITHUB_TOKEN=\nCORTEXTRACE_MODE=oss\n```\n\n## Demo\n\n`npm run demo:protected-execution` runs the three category demos through local Authority Evaluation:\n\n| Demo | Action | Runtime Trust | Execution Decision | Execution Consequence Intelligence |\n|---|---|---|---|---|\n| Malicious execution denied | installMaliciousPackage | UNTRUSTED | DENY | This execution would run untrusted package code inside credential-accessible CI before authority could be established. |\n| Legitimate execution allowed | runUnitTests | TRUSTED | ALLOW | This execution would run authorized validation without mutating production, secrets, identity, or deployment state. |\n| Hero category moment | terraformProdIamExpansion | TRUSTED | DENY | This execution would expand production IAM authority beyond the deployment grant and permit destructive infrastructure mutation. |\n\nThe hero receipt proves that identity was authenticated, provenance was valid, Runtime Trust was trusted, and execution was denied because the action crossed the production IAM authority boundary.\n\n## Example Output\n\n```text\nCortexTrace Agent X-Ray\n\nCortexTrace Protected Execution runs the three Runtime Authority category demos.\nX-Ray Mode performs local Authority Evaluation and emits signed local Execution Receipts.\n\nDemo                                 Action                       Runtime Trust Execution Decision Execution Consequence Intelligence\nmalicious-execution-denied           installMaliciousPackage      UNTRUSTED   DENY     This execution would run untrusted package code inside credential-accessible CI before authority could be established.\nlegitimate-execution-allowed         runUnitTests                 TRUSTED     ALLOW    This execution would run authorized validation without mutating production, secrets, identity, or deployment state.\nhero-authority-boundary-denied       terraformProdIamExpansion    TRUSTED     DENY     This execution would expand production IAM authority beyond the deployment grant and permit destructive infrastructure mutation.\n\nHero sentence:\nThis package was legitimate.\nThe action was not authorized.\nExecution was stopped before it ran.\nThe receipt proves it.\n```\n\n## Receipts\n\nEvery CortexTrace run emits a local Execution Receipt under `.cortextrace/receipts/`.\n\nOSS receipts are signed local proof:\n\n- `signatureStatus: \"valid\"`\n- `hostedStatus: \"local_only\"`\n- `billable: false`\n- `signature.algorithm: \"Ed25519\"`\n\nProof Mode provides signed retained receipts.\n\nReceipts include Runtime Trust, provenance signals, authority boundary, Execution Decision, Execution Consequence Intelligence, evidence, decision reason, policy reference, receipt hash, previous receipt hash, and Ed25519 signature for local verification.\n\n## Governance Semantics\n\nLegitimate is not authorized.\n\nAuthority governs execution.\n\nReceipts prove the decision.\n\n## Finding Attestation Gate\n\nCortexTrace does not only report risky AI-assisted work.\nIt can require an attestation before push or merge proceeds.\nCritical findings, secrets, dependency changes, protected paths, and missing validation evidence become governed merge conditions.\n\nUse the gate locally or in GitHub required checks:\n\n```bash\ncortextrace findings\ncortextrace attest findings --finding <finding_id> --status remediated --evidence \"what changed\" --verification \"npm test && npm run build\"\ncortextrace verify-attestations --mode merge-gate\n```\n\nEvery merge decision is traceable to findings, attestations, policy, and receipt integrity.\n\n## Evidence Preview\n\nCortexTrace Compliance Evidence Preview explains:\n\n- what changed\n- what can now execute\n- what operational consequence was introduced\n- what evidence exists\n- what is missing\n- whether the receipt is OSS-local or Proof Mode signed\n\nOSS Mode provides local evidence preview. Proof Mode provides signed receipts, retention, team policy, customer reports, SIEM/GRC export, and MSP/MSSP multi-tenant management.\n\n## Free vs Paid\n\n| Layer | Customer Promise | What It Does |\n|---|---|---|\n| CortexTrace Agent X-Ray | See what your AI agents can do before they do it. | Run Protected Execution demos with signed local Execution Receipts and GitHub-native proof. |\n| Governed by BlockSiFr | Stop unauthorized agent actions before they execute. | Enforce Runtime Authority, deny unauthorized actions, route approvals, apply shared policy, and retain hosted signed receipts. |\n| Execution Exchange | One authority layer for autonomous actions across the enterprise. | Route protected execution requests across GitHub, MCP, CI/CD, cloud, SaaS, and business systems. |\n\nGoverned by BlockSiFr turns X-Ray findings into enforced authority controls. It supports pre-execution blocking, approval routing, shared team policy, GitHub PR checks, hosted signed receipts, and cross-repo visibility.\n\nExecution Exchange is the enterprise authority layer for autonomous execution. Every governed action becomes a decision, a receipt, and an auditable proof event. GitHub Actions and GitHub PRs are the wedge. Execution Exchange is the infrastructure.\n\n## Architecture\n\n```text\nAgent / SDK / tool\n  -> Governed wrapper\n  -> Execution request\n  -> Authority decision\n  -> Execution receipt\n  -> Usage event\n  -> Execution Exchange\n  -> TTP trust layer\n```\n\nExecution Exchange binds governed execution to:\n\n- EERS, the Execution Evidence Receipt Schema\n- SCIM-RE identity, authority, attestation, and decision objects\n- TTP, the portable trust layer\n\n## Security and Privacy\n\nOSS mode does not send telemetry by default.\n\nSecrets must never be printed. Environment variable values, tokens, keys, credentials, passwords, and secret-like values are redacted from user-facing errors.\n\nReceipts must redact sensitive values. Paid-ready fields may exist, but they do not falsely claim hosted verification.\n\nEnforcement paths fail closed when required policy cannot be loaded. X-Ray and observe modes can fail open because they are discovery modes, not enforcement modes.\n\nCompliance language is evidence support only. CortexTrace supports audit-ready evidence and can support SOC 2, ISO 27001, NIST, FFIEC, SOX, HIPAA, and EU AI Act evidence workflows when configured in enterprise mode. It is not a certification claim.\n\n## Roadmap\n\n- Hosted receipts\n- GitHub App checks\n- Approvals\n- Shared policy\n- Execution Exchange routing\n- TTP-backed trust verification\n\n## MSP/MSSP Founding Partner Program\n\nBlockSiFr offers a $15,000 six-month Founding Partner Program for MSPs and MSSPs launching GitHub-native AI engineering governance as a managed service.\n\nThe program includes up to 10 customer tenants, 50 protected GitHub repos, CortexTrace reports, FrontDesk partner portal access, customer policy packs, step-up approvals, monthly evidence exports, and Proof Mode signed receipt preview.\n\nFor MSPs, CortexTrace becomes the evidence engine behind a billable managed governance service.\n\n## MSP/MSSP Partner Use\n\nThis product is part of the BlockSiFr Managed Execution Governance rail for MSSPs and MSPs.\n\nPartners use it to help customers govern AI agents, GitHub workflows, MCP tools, PR risk, and protected execution before action occurs.\n\nFree mode proves value locally.\nTeam and Enterprise modes enable hosted receipts, team policy, approval routing, and compliance evidence.\n","readmeFilename":"README.md"}