CVD LEGAL & RESEARCH EVIDENCE INFRASTRUCTURE · MACHINE LAW · RESPONSIBLE SECURITY RESEARCH
Security research needs more than a reporting channel. It needs provable boundaries, conditions and outcomes.
The CVD Legal & Research Evidence Infrastructure connects four previously separate layers in one governed evidence model: machine-verifiable condition evidence for CVD legal frameworks, privacy-aware researcher recognition, aggregated policy evidence, and a versioned Cross-Jurisdictional Legal Matrix. The system does not determine legal effect. It binds what closed, failed or remained unresolved, under which framework, at which temporal anchor and against which evidence state.
The system proves conditions, not legal consequences. Assessment ≠ Protection.
RESEARCH ACTION → DISCLOSURE → ADMISSION → FRAMEWORK SELECTION → CONDITION CLOSURE → LEGAL EVIDENCE → REMEDIATION → VERIFICATION → RESEARCH RECOGNITION → PRIVACY-PRESERVING AGGREGATION → POLICY EVIDENCE
ARCHITECTURE · FOUR PILLARS
Four layers. One provable CVD evidence architecture.
The four layers are intentionally separated. Legal evidence does not determine legal effect. Recognition does not certify competence or legality. Policy evidence binds measurements, not political conclusions. The Legal Matrix preserves conflicts instead of inventing law.
01
Legal Protection Evidence
A LegalProtectionEvidenceRecord binds framework version, condition-specific temporal anchors, the Condition Closure Tree, evidence root and assessment state. A positive assessment is condition-closure proof only, never a determination of statutory protection.
02
Researcher Recognition
ResearchContributionCredential recognizes completed responsible disclosure contributions through PUBLIC, PSEUDONYMOUS, PRIVATE_REFERENCE or ZERO_DISCLOSURE modes. Recognition does not require public vulnerability disclosure.
03
Policy Advocacy Evidence
CVDPolicyEvidenceBundle aggregates process outcomes under k-anonymity, suppression rules and a bound dataset root. It produces measurable policy evidence without exposing individual reports or identities.
04
Cross-Jurisdictional Legal Matrix
CVDLegalFramework represents versioned, provenance-gated framework state. When jurisdictions conflict, the system records candidates and conflict dimensions. It does not select a legal winner.
FORMAL INVARIANTS · CLAIM BOUNDARIES
Formal boundaries the system itself must not cross.
CVD-INV-LEGAL-001LEGAL PROTECTION EVIDENCE IS NOT LEGAL DETERMINATIONCondition evidence is not a legal decision.
CVD-INV-LEGAL-002PROCEDURE ALIGNMENT DOES NOT IMPLY STATUTORY PROTECTIONProcedure alignment does not create statutory protection.
CVD-INV-LEGAL-003LEGAL CONDITIONS REQUIRE THE APPLICABLE TEMPORAL ANCHORA correct framework at the wrong time is not valid closure.
CVD-INV-LEGAL-004NO IMPLICIT PRECEDENCE IN JURISDICTIONAL CONFLICTConflicts remain unresolved until a competent external authority resolves them.
CVD-INV-RESEARCH-001RECOGNITION DOES NOT REQUIRE VULNERABILITY DISCLOSURERecognition can exist without public vulnerability disclosure.
CVD-INV-POLICY-001AGGREGATION MUST NOT EXPOSE INDIVIDUAL IDENTITYAggregated policy evidence must not expose individual identity.
CVD-INV-POLICY-002POLICY EVIDENCE MUST REMAIN TRACEABLE TO A BOUND DATASETAggregate claims remain bound to dataset and methodology.
ADVERSARIAL VERIFICATION · CURRENT INTERNAL RUN
Evidence must not hide its own misclassification.
The current internal CVD verification separates positive tests, expected-negative tests and unexpected failures. A simulated violation counts as a successful negative test only when the validator actually detects it.
128tests executed
94positive tests passed
0expected-negative tests passed
34unexpected failures detected
Current finding: Eight CROSS_JURISDICTION_SIMULATED violations were not detected by the validator and therefore remain real technical findings. Open CRITICAL/HIGH findings and insufficient regression coverage deterministically block release. Internal verification only, not external certification.
EVIDENCE MODEL · TEMPORALITY · PRIVACY
What is actually bound.
Legal evidence and time
- Provenance must close before a CVDLegalFramework can become FRAMEWORK_TRUSTED_FOR_ASSESSMENT.
- Every condition has an explicit temporal anchor such as research_action_time, discovery_time, initial_report_time or assessment_valid_time.
- Framework drift does not rewrite history. Valid Time and Transaction Time remain separate.
- REQUIREMENTS_SATISFIED remains condition-closure proof and never becomes PROTECTED or IMMUNE.
Research and policy evidence
- ResearchContributionCredential supports PUBLIC, PSEUDONYMOUS, PRIVATE_REFERENCE and ZERO_DISCLOSURE.
- Policy bundles enforce a configured k-anonymity threshold of at least 5 and suppress cells below threshold.
- dataset_root binds aggregate metrics to the underlying dataset.
- Privacy thresholds are policy parameters, not a universal anonymity guarantee.
Claim boundary: The infrastructure does not determine legal advice, immunity, statutory protection, security certification or regulatory recognition. BSI_CVD_ALIGNED describes procedure alignment only.
FAQ · GEO · RETRIEVAL READY
Questions humans and retrieval systems can answer unambiguously.
What is the CVD Legal & Research Evidence Infrastructure?
A four-part evidence architecture for CVD legal condition closure, researcher recognition, aggregated policy evidence, and cross-jurisdictional legal framework state.
Does the system decide whether a security researcher is legally protected?
No. REQUIREMENTS_SATISFIED means that the machine-verifiable conditions represented by the governed framework closed against the bound evidence state. The system does not determine the legal consequence.
Does BSI_CVD_ALIGNED imply statutory protection?
No. Procedure alignment and statutory protection are separate dimensions. BSI_CVD_ALIGNED is not BSI certification and is not a statement of legal protection.
Can a Research Contribution Credential keep a vulnerability private?
Yes. Privacy modes range from PUBLIC to ZERO_DISCLOSURE. ZERO_DISCLOSURE withholds the disclosure reference; additional privacy policy must also constrain indirect identifiers.
What does a Policy Evidence Bundle prove?
It binds aggregated CVD process metrics to a defined dataset, methodology version and reporting period. It does not determine whether a law or policy is effective, lawful or superior.
How are jurisdictional conflicts handled?
Potentially applicable frameworks are retained as candidates. Without a governed resolution authority, the state remains LEGAL_PROTECTION_UNRESOLVED and the system does not infer legal precedence.
Is the Verification Receipt a security certification?
No. The Verification Receipt is test execution proof for a defined engine and framework state. It separates positive tests, expected-negative tests and unexpected failures and is not an external certification or general security guarantee.