K08 · traceable Machine Intelligence knowledge infrastructure

Compromised Supplier Signing Key

Direct answer

This defensive reference playbook defines internal evidence, containment, and recovery actions. It does not authorize action against a supplier or third party.

Authority and evidence boundary. K08 publishes governed research, synthetic reference traces, non-certifying workbooks, acquisition evaluation structures, offline planning records, and bounded protocol experiments. It does not prove historical authority, facility truth, compliance, certification, contract award, deployment, current operation, or authorization for external effects.

Scenario

SCIP-K08-001 · compromised supplier signing key

Detect

  • revocation or supplier notice
  • signature anomaly
  • unexpected key fingerprint

Contain

  • block new artifacts from affected key
  • freeze promotion
  • preserve installed-state evidence

Recover

  • obtain independently verified successor key
  • revalidate artifacts from trusted source
  • rotate trust stores

Evidence

  • notice
  • key history
  • affected artifact inventory
  • decision and retest results

Machine record

Download this playbook