| Signing implementation | services/gate/src/lib/signing.ts |
| JCS canonicalization | packages/ar-car/src/canonicalize.ts |
| Multi-key store + rotation | services/gate/src/lib/signing.ts, docs/runbooks/06-car-signing-key-incident.md |
| JWKS-shaped public-key feed | services/gate/src/routes/keys.ts (/v1/keys, /.well-known/jwks.json) |
| Public CAR verification | services/gate/src/routes/verify.ts, docs/CAR_VERIFICATION.md |
| Dual-identity model | docs/AUTH_IDENTITY_MODEL.md |
| RLS helper + tenant policies | supabase/migrations/2026050500010*.sql |
| Fail-closed contract tests | services/gate/__tests__/fail-closed.test.ts |
| Fail-open classification | standards/audits/launch-readiness-audit-2026-05-03.md (R-19 closure) |
| CAR durability | docs/CAR_DURABILITY.md |
| Replay / freshness | docs/REPLAY_FRESHNESS.md |
| Failover / failure modes | docs/FAILOVER_SPEC.md, docs/FAILURE_MODES.md |
| Threat model | docs/security/THREAT_MODEL.md |
| Public roadmap | docs/security/ROADMAP.md |