# Security verification note — 2026-09-20

This note records a selected developer-run regression suite against Core Panel product revision 301a69f162d03c29a7ba78ffab38ebc61695a183.

## Result

All 13 selected top-level tests passed. The raw Go stream contains 18 pass events because one filesystem-security test has five named subtests.

## Covered controls

- cPanel and Core Panel archive traversal rejection
- Mail-backup traversal rejection
- Recovery-manifest path confinement
- Authenticated recovery encryption, wrong-key rejection, and tamper rejection
- Recovery-download size limiting
- Mailbox filesystem failure handling
- Signed session cookie attributes, tamper rejection, and expiry
- Invalid website-security network rejection
- Clean-restore evidence invalidation after a failed drill

## Reproduce

Use the exact test names present in go-test.jsonl with Go 1.26.5 at the recorded product revision. The raw stream includes package names, test names, timestamps, elapsed times, and pass states. Its SHA-256 digest is 3dff7fce45d3f702f52f75a586ce74bb951f86059d54450331eb04135fb13832.

## Limitation

This is not independent security research or a penetration test. A passing regression suite only establishes that the selected tests passed on the disclosed revision and environment. Review the current Core Panel security policy and production-readiness status before evaluating deployment.
