02 Summary
What this page is.
Evidence, not badges
Everything below can be checked from outside, without our files and without trusting us. Where we hold no certification, we say so.
Operator: BlueLabs3, ACN 701 379 964. Accountable person: the Director.
03 Transport
Network and domain.
Transport and domain
TLS 1.3 only; 1.2 and below are refused. HSTS for two years with includeSubDomains and preload, on every 1hbt.com host; submitted to the browser preload list. DNSSEC signed and delegated. CAA limits which authorities may issue certificates. Sender policy is SPF with DMARC at reject.
04 Application
The page and the API edge.
Application security
Content Security Policy that denies everything by default, with every script and stylesheet pinned by hash; violations are reported. COOP, COEP and CORP isolate the document. Every powerful browser feature is switched off. Managed web application firewall rules run in front of the gate.
Requests are size-capped while they stream. Every route is rate-limited; the API window is shared per account across the edge.
05 API access
How clients are admitted.
Identity and access
OAuth 2.0 client credentials from pre.consensor.io, one-hour tokens, issuer, audience and expiry enforced. Per-account scopes limit each client to the routes it needs. Per-account origin allowlists, monthly quotas and idempotency keys. Client-certificate pinning (mTLS) is available per account. Revocation takes effect by account epoch; signing keys rotate with the previous key published for one token lifetime.
06 Verify
Check our claims yourself.
Verifiable releases
Every release publishes the SHA-256 of each module at /claims and /evidence, with an OpenPGP signature over the release manifest. Verify it against the release-signing key, fingerprint DB32 C3CA 903C E8CA 7CC7 3705 D126 7423 30FB 5412.
The audit ledger is hash-chained and its tip is anchored to Sigstore Rekor and OpenTimestamps; see /api/anchor.
07 Testing
For this exact build.
Test report for this release
Every release runs the full test suite against the exact module files it ships, before upload. The result is published as the test report in /claims, bound to the signed release manifest by its SHA-256 and signed with the same key. It lists every test battery, and the false-positive and false-negative counts for the input and output screens.
It also says what was not tested on this build, including mutation testing (last run 19 September 2026 on an earlier tree) and clinical review of the crisis screen. The screen's scope limits are documented and given to named clients and assessors under confidentiality, not published. The test cases are small, fixed and written by us. Passing them is a regression floor, not an error rate, and no third party has reviewed them.
08 Retention
Every layer.
What is kept, and for how long
- Request and answer text. Never written to storage. Held in memory for the life of one request.
- Rate-limit counters. A hash of the caller's IP address and request times, in memory only, for a 60-second window.
- Audit ledger. Event name, coarse counts, time and chain hash. No content and no address. The latest 400 rows are public; older rows move to sealed archive segments in the same storage.
- External anchors. Only the chain digest is published, to Sigstore Rekor and OpenTimestamps. Those public logs are permanent.
- API accounts. Plan, status, tenant, scopes and credential fingerprint for as long as the subscription lasts, plus monthly usage counts.
- Hosting provider logs. Cloudflare keeps request logs (address, path, status, time, errors) for up to 7 days.
- Reports and complaints. Correspondence sent to our addresses is deleted 2 years after the matter closes.
09 Frameworks
What we measure against.
Frameworks
Australian Voluntary AI Safety Standard, read with the Guidance for AI Adoption: transparency and contestability are published on the legal notice. OWASP Secure Headers and Mozilla Observatory (A+). The Privacy Act 1988 and the Notifiable Data Breaches scheme govern incident notification.
10 Operations
How we respond.
Operations
A written incident-response plan with severities, containment and notification. Every release is smoke-tested and read back byte for byte before it counts as live. Failover is drilled: on 24 September 2026 a rollback served worldwide in 5.4 seconds and the roll forward in 1.9 seconds.
11 Documents
What you can read.
Documents
Legal and processing notice, including how to challenge a decision. Security contact and security.txt, with an OpenPGP key for encrypted reports. The full documents and the assurance checklist are provided to named clients and assessors on request.
The BL3 Policy Manual index: fourteen policies and procedures adopted 21 September 2026, with the standard each maps to.
12 Not claimed
Stated plainly.
What we do not hold
No SOC 2 report and no ISO 27001 certificate are held; an independent assessment is the next step. HOURGLASS is patent pending (AU provisional 2026905672); no patent has been granted, and its core functions are not publicly available. There is no public bug-bounty programme and no safe harbour. Module hashes are signed by the operator, not attested by the hosting provider. The test report is the operator's own; no independent review of this release has been done yet.