Document originDepth and the duress-oracle rejection removal (v1.10.1) Secure-Mode.md: add originDepth floor semantics alongside visibleThroughDepth's ceiling; new Inbound Message Handling section explaining passSecurityControl's removal and the one accepted trade; matching Forensic Deniability bullet. Security-Properties.md: Duress PIN / decoy view moves from "static indistinguishability" (warning) to "static + live-protocol indistinguishability" (fixed) -- the live-protocol test this row's old caveat described is now closed. Threat-Model.md: moves the closed live-protocol test to "Protects Against"; replaces the old vague "ongoing hardening work" line under "Does Not Protect Against" with the two specific, narrower residuals that actually remain.
Correct visibleThroughDepth docs; soften duress-indistinguishability claims Secure-Mode.md described the pre-fix nil-based model and incorrectly said VaultEntry follows the same ceiling rule as contacts - it uses exact-match depth confinement instead, which is what actually prevents duress-created entries from leaking into the real vault. Security-Properties.md and Threat-Model.md asserted unqualified duress/ normal indistinguishability. That's only established for static, at-rest inspection; full indistinguishability under active, extended adversarial testing isn't guaranteed yet and is being worked on - stated as an honest limitation rather than an unqualified claim.
Remove border-crossing-specific language from Secure Mode overview
Add technical documentation wiki pages