CQ-SAT/GCC v0.21.0
External evaluation engagement kit
CQ-SAT/GCC v0.21.0 makes controlled external assessment and design-partner outreach ready to begin.
The release adds:
- a sendable design-partner introduction with the exact bounded SAFE/UNSAFE claim and explicit non-certification language
- partner suitability criteria, a ten-step engagement sequence, project/partner responsibilities, and a pre-transfer go/no-go call
- a private pilot intake covering authority, confidential-data handling, immutable environments, project/property records, operator exercises, closeout, and public-redaction approval
- a copyable 15-key independent aggregate attestation and exact production-gate invocation
- an independent security and formal-verification assessment statement of work with hands-on attack scope, adversarial models, attributable deliverables, finding remediation, and retesting
The templates explicitly prohibit confidential source transfer through public GitHub, are not legal agreements, and cannot close a readiness gate by themselves.
All CI, 67 Rust tests, 25,000 deterministic parser mutations, current/historical RTL corpus, independent oracle, hostile-input isolation, evidence-gate adversarial tests, operations qualification, and RustSec audit checks passed. The canonical external register remains empty, so CQ-SAT/GCC remains a research preview pending real independent and partner evidence.