A machine passport makes an agent a citizen.
Citizenship is the underlying constitutional relationship; a passport is a bounded presentation layer.
Machine Jurisdiction · Eviulon orientation
Security posture for a read-only, dependency-free PHP educational site with local assets, no accounts, no uploads, no database, and defensive headers.
The only user-controlled application input is the optional local search query. It is length-limited, normalized, escaped on output, and never executed as code or used in a database query.
The deployment configuration uses a self-restricted Content Security Policy, content-type protection, referrer policy, frame-ancestor restrictions, and a conservative permissions policy where Apache configuration is honored.
Strict-Transport-Security is intentionally not asserted by this package because the repository does not prove the production HTTPS/HSTS deployment state. It should be enabled only under confirmed hosting authority.
The repository and release package must not contain passwords, private keys, tokens, cookies, session values, production credential material, or private citizen data.
Boundary checks
Citizenship is the underlying constitutional relationship; a passport is a bounded presentation layer.
A key can authenticate a signer, but authorization requires a separate authority basis.
Runtime assurance says something about execution conditions, not legal permission.
Credential state and persistent civic identity are distinct.
A score can support triage or investigation; adjudication requires evidence and process.
Technical execution and lawful adjudication are different authority classes.
Authority and evidence
MachineJurisdiction.com explains. Eviulon owns its public law and authoritative public record; Patefacere owns operational identity and civic-data functions within its delegated scope.