Governance and Assurance
This is a summary of NeuroCrypt's governing instruments, published as an extract. It is not the instruments themselves. Where a clause is summarized rather than reproduced, the summary is written by this office and has not been reviewed by the office that owns the clause.
1Classification framework
NeuroCrypt operates its own classification scheme. It is not derived from, aligned with, or equivalent to any national scheme, and markings on controlled documents should not be read as claims of governmental authority.
| Marking | Meaning | Release |
|---|---|---|
| OPEN | No restriction on content | Unrestricted |
| RESTRICTED | Internal document; release requires clearance review | Public extracts only |
| TIER 4 | Program-direction material | Abstract only |
| SEALED | Withdrawn from circulation; record of existence retained | none |
| ██████ | ████ | no procedure on file |
The fifth marking appears in the sealing procedure and in two document footers. This office has been unable to locate the instrument that defines it or the authority that applies it. The row is retained because removing it would misrepresent the scheme.
2Independent verification
The witness chain is verifiable by any party holding the public parameters and a copy of the log. Verifying that copy against a root requires no cooperation from NeuroCrypt and cannot be influenced by it, which is a property of the construction rather than a policy commitment. The construction does not establish that the root one party holds is the root another party was shown. Detecting a divergence there would require parties who compare roots with one another, and NeuroCrypt has not arranged for any.
Everything else stated here is asserted by NeuroCrypt about itself. No external body audits NeuroCrypt. No external body has been offered access. Readers should treat the assurance posture accordingly.
3Dual-use and ethics review
Proposals are reviewed against three tests before Ring time is allocated: whether the work requires a subject, whether the subject can withdraw, and whether withdrawal restores the subject's prior position. The third test cannot be satisfied by any attestation-based protocol, since attestations are irrevocable by construction. The review therefore records it as failed in every case and proceeds on a documented exception.
Program proposals that would attempt reconstruction against a living enrolled subject are refused. The prohibition arose from a specific review and is recorded at NC-INC-0012. It is procedural. The substrate would accept such a submission.
4Documentation standard
Every released technical document carries a limitations section stating what the work does not establish. Limitations sections are not abridged on release. Where abridgement would be required, the document is withheld in full instead. This is why the released subset of the technical note series is two notes out of 211.
Every document carries an identifier, a revision, an effective date, a supersession reference, and an availability determination, recorded in the register. A document not in the register is not a controlled document.
Quantities appearing in more than one released document are controlled centrally at NC-REG-0002, with derivations published so that a reader can check them. The schedule was created after five contradictions were found in released documentation by reading rather than by instrument, which this office records as a failure of its own process and not of the documents.
5Supply chain and provenance
Terminal hardware is fabricated to Program specification and inventoried on receipt, on installation, and annually thereafter. Cryptographic primitives are standard and public: SHA3-256 (FIPS 202), Ed25519 (RFC 8032), ML-DSA-65 (FIPS 204). NeuroCrypt does not use primitives of its own design and does not consider itself competent to design them.
The substrate's construction is not public. This is the single largest gap between NeuroCrypt's posture and the posture it would need to make its assurance claims independently checkable.
6Incident handling
An incident is registered when NeuroCrypt's explanation of an event does not survive review, and, by direction rather than by definition, when a matter arises for which no other register is appropriate. Incidents are not closed by administrative finding; the recommendation this practice derives from is minuted at NC-INC-0001-M. An incident with no supportable explanation remains open indefinitely; the oldest has been open 41 years. See NC-INC-INDEX.
This office notes that the practice was adopted to prevent premature closure, and that its effect over four decades has been an incident register in which the open items are the ones that matter and the sealed ones cannot be discussed.
- NC-REG-0001Technical Document Register
- NC-TN-INDEXTechnical Note Series
- NC-SEC-0004Access and clearance policy
- NC-INC-INDEXIncident Register