The whole design is an asymmetry: the decision of whether an inbound authorization is real stands on machine-checked proofs; the weaker outbound edge is fenced by the same quorum acting as a firewall, and named as trusted base rather than dressed up.
Inbound verificationquorum of certificate-covered verify paths
custody-grade · proven
Outbound firewallverify-after-sign, same quorum
custody-grade · proven
Outbound signing itselfthe attested artifact, not a third implementation
trusted base · fenced
SHA-512 · wire parsersoracle / hypotheses inside the theorems
documented boundary
ML-DSA · post-quantumno proven implementation exists
fail-closed