Published July 29, 2026 | Version 0.3.2

TAP-SEC Reference Implementation M4 v0.3.2: Local-Host Boundary Validation, Fail-Closed Recovery, and Public Evidence

Authors/Creators

  • 1. Independent Researcher, Brussels, Belgium

Description

TAP-SEC Reference Implementation M4 v0.3.2 is a public-safe research software artifact for local-host boundary validation, fail-closed recovery, continuity classification, witness-bound memory updates, formal safe/unsafe profiles, and reproducible public evidence.
 
Status
 
M4_PARTIAL_PASS_WITH_BLOCKED_GATES
M4_LOCAL_HOST_BOUNDARY_PASS=true
M4_FULL_PASS=false
NOT_NORMATIVE
NOT_PRODUCTION_READY
 
The final fixture aggregate is:
 
16 PASS
24 PASS_FAIL_CLOSED
2 BLOCKED_EXTERNAL
0 FAIL
42 fixtures total
 
The tested local-host boundary passed. Four external physical-evidence gates remain explicitly blocked and are not counted as passes:
 
G05 — no distinct pinned remote witness outside the same host.
G06 — no physically separate append-only witness failure domain.
G07 — no physical non-exportable TPM/HSM custody.
G13 — no direct Katy-attributable Joule telemetry.
 
Exact software artifact
 
TAP_SEC_REFERENCE_IMPLEMENTATION_M4_v0_3_2.zip
 
SHA-256:
6760ee89bc92b9d8fea0de6a1642399ae3b126e7fa4508ac8f4921ab3de65942
 
Validation summary
 
The final public artifact passed:
 
183/183 contract-bound tests;
672/672 public checksum records;
671/671 package-manifest records;
143 JSON parsing checks;
154 YAML parsing checks;
40/40 fixture evidence hash bindings;
two clean extractions;
public-safety validation;
release-coherence validation;
byte-identical final ZIP rebuilding.
 
The artifact is public-safe and technically ready for scholarly distribution as an immutable local partial release. It is not a full M4 pass, a production-safety certificate, a normative standard, or an authorization for deployment in a production or safety-critical environment.
 
GitHub resources
 
Repository:
https://github.com/Kot141078/tap-sec-reference-implementation
 
Release:
https://github.com/Kot141078/tap-sec-reference-implementation/releases/tag/m4-v0.3.2
 
Tag:
https://github.com/Kot141078/tap-sec-reference-implementation/tree/m4-v0.3.2
 
Exact commit:
https://github.com/Kot141078/tap-sec-reference-implementation/commit/0e8850e4cde357287764f6c2dc5aec2d950954b9
 
Git commit SHA:
0e8850e4cde357287764f6c2dc5aec2d950954b9
 
DOI
 
10.5281/zenodo.21688521
 
Author and rights holder
 
Ivan Kotov
Independent Researcher, Brussels, Belgium
ORCID: 0009-0009-6002-9845
 
Copyright and licensing
 
Copyright © 2026 Ivan Kotov. All author-owned rights remain vested in Ivan Kotov.
 
Author-owned software, formal specifications, tests, validators, schemas, registries, deployment templates, and other machine-executable materials are licensed under the Apache License 2.0.
 
Author-owned documentation, academic reports, diagrams, publication metadata, and public evidence are licensed under Creative Commons Attribution 4.0 International.
 
Third-party and excluded materials remain under their original terms.
 
AI tools were used under the author’s direction for drafting, implementation assistance, test orchestration, document production, and machine-assisted review. They are not authors, rights holders, independent human peer reviewers, certifiers, or endorsers.
 
Metadata clarification
 
The artifact declares 2026-07-29 as its document and version date. The first public GitHub Release was published on 2026-07-30T20:59:00Z.
 
In Section 7 of the License, Citation, and Reuse Guide, “datacite.json” should read “datacite.xml”.
 
No separate “RELEASE_CLAIMS.json” is distributed. The authoritative machine-readable release claims are provided by “PUBLICATION_STATUS.json” and “PUBLICATION_MANIFEST.json”.
 
The GitHub repository additionally retains “.zenodo.json”.

Files

TAP_SEC_M4_v0_3_2_ACADEMIC_TECHNICAL_REPORT.pdf

Files (2.3 MB)

Name Size Download all
md5:183d7931775f1b6e69076519f536230c
1.2 kB Download
md5:a0d4d16e919430e0d935294217613686
1.1 kB Preview Download
md5:46dea289627e0820c4ef0b95be65c551
1.6 kB Preview Download
md5:eb7ba93f88a5d0abee2e39d1fac92b1d
2.0 kB Preview Download
md5:3b83ef96387f14655fc854ddc3c6bd57
11.4 kB Preview Download
md5:29f6d6758af09d75babd5c4960f7e64d
14.5 kB Preview Download
md5:c1d5d852698b548a52a6a346c1bd6c21
2.3 kB Preview Download
md5:283b3957db24deff633824a9f5290152
879 Bytes Preview Download
md5:98dd18d26311d122d74c3390ce88094a
3.4 kB Preview Download
md5:8c9e71b1eeec797cffec9c2b23c5af04
1.1 kB Preview Download
md5:4af153562d62520b22f9d07569d95f33
676 Bytes Download
md5:4fafb27e7feb39397a720542cece9c56
2.4 kB Preview Download
md5:507d7bbcecefb5c62d7cabc743edd550
30.3 kB Preview Download
md5:0b5f727034380acec8a97a65b6499ec7
313.2 kB Preview Download
md5:630c358834bda7a657b208887f3bdd4d
3.3 kB Preview Download
md5:57e9175b81ee0fb152924b0d837b6dbf
109.1 kB Preview Download
md5:12ea7c264eb03ffa71cae4f694d4529d
4.3 kB Preview Download
md5:56d8430dea8aae61b06c6bfa79b5ddbd
120.7 kB Preview Download
md5:edef45f4c705162261f37bd0d63de957
4.3 kB Preview Download
md5:8ddcf9ac76c93fe565b30f0a75ab09ac
105.8 kB Preview Download
md5:69dbe02a869c8669f1f07516000641c4
8.4 kB Preview Download
md5:643eb53e78347ed76f6b115a00b7fce0
193.1 kB Preview Download
md5:7a8e8d497f40e05c50ff1342b54ba111
1.4 MB Preview Download
md5:0cab52b56b8ef435d24379eff5bc6056
113 Bytes Download

Additional details