K08 · traceable Machine Intelligence knowledge infrastructure
Compromised Supplier Signing Key
Direct answer
This defensive reference playbook defines internal evidence, containment, and recovery actions. It does not authorize action against a supplier or third party.
Authority and evidence boundary. K08 publishes governed research, synthetic reference traces, non-certifying workbooks, acquisition evaluation structures, offline planning records, and bounded protocol experiments. It does not prove historical authority, facility truth, compliance, certification, contract award, deployment, current operation, or authorization for external effects.
Scenario
SCIP-K08-001 · compromised supplier signing key
Detect
- revocation or supplier notice
- signature anomaly
- unexpected key fingerprint
Contain
- block new artifacts from affected key
- freeze promotion
- preserve installed-state evidence
Recover
- obtain independently verified successor key
- revalidate artifacts from trusted source
- rotate trust stores
Evidence
- notice
- key history
- affected artifact inventory
- decision and retest results