Lifted Payments Statement Audit Model v1.1.1
Security and release-engineering patch for the Lifted Payments Payment Statement Audit Model.
- Package and validator: 1.1.1
- Record contract: schema 1.1.0 (unchanged)
- Corpus: 2 accepted + 14 deliberately rejected synthetic vectors
- Publication gate: 11/11 checks passing
- Independent hostile review: no remaining findings
This patch fails closed on pathological numeric tokens, hostile Decimal contexts, malformed or non-object metadata, missing or unregistered corpus vectors, path traversal, symlinked parents, canonical-path aliases, candidate-validator failures, incomplete critical inventories, stale reports, checksum drift, and common credential signatures across every declared source asset. Error output does not echo submitted values or unknown field names.
Read SECURITY.md for the public threat model and non-goals. The model remains a normalization aid—not an accounting opinion, legal determination, interchange-qualification audit, quote, or guarantee of savings.
Zenodo version DOI: https://doi.org/10.5281/zenodo.21762767.
Concept DOI: https://doi.org/10.5281/zenodo.21761714
Canonical guide: https://liftedpayments.com/payment-processing-statement-audit/