Skip to content

Repository policies

Ziggurat keeps its normative documents in the repository rather than on this site, so that a reader of the source always has the authoritative text alongside the code it describes.

DocumentGoverns
ARCHITECTURE.mdAssets, actors, capabilities, trust boundaries, state transitions, and enforcement points
SECURITY.mdThreat model, attack mapping, fail-closed behaviour, residual risks, and vulnerability reporting
docs/authorization-protocol.mdThe byte-level canonicalization and signing contract
CONTRIBUTING.mdDevelopment workflow and the boundary rules a change must not break
SUPPORT.mdWhere to ask questions
CODE_OF_CONDUCT.mdExpected conduct in project spaces
LICENSEMIT licence terms

docs/release-checklist.md is a maintainer gate list rather than user documentation. It lives in the repository and is not reproduced here.

Where this site and a repository document disagree, the repository document wins. Site pages are task-oriented explanations of the specifications, not replacements for them. Report any disagreement you find as a documentation bug.