{
  "schema_version": 1,
  "study_id": "security-verification-2026-09-20",
  "measured_at": "2026-09-20T23:29:30+05:00",
  "product_revision": "301a69f162d03c29a7ba78ffab38ebc61695a183",
  "environment": {
    "operating_system": "Microsoft Windows NT 10.0.22000.0",
    "cpu": "Intel(R) Xeon(R) CPU E5-2680 v4 @ 2.40GHz",
    "memory_bytes": 34278359040,
    "go": "go1.26.5 windows/amd64"
  },
  "method": "Selected developer-authored Go regression tests were run once against archive traversal, recovery encryption and integrity, S3 size limits, mailbox filesystem failure handling, session integrity, security-policy validation, and restore-drill evidence.",
  "top_level_tests": 13,
  "pass_events_including_subtests": 18,
  "failed": 0,
  "package_elapsed_seconds": {
    "hostpanel/cmd/agent": 0.502,
    "hostpanel/internal/store": 0.561,
    "hostpanel/internal/controlplane": 2.406
  },
  "raw_results": "go-test.jsonl",
  "raw_results_sha256": "3dff7fce45d3f702f52f75a586ce74bb951f86059d54450331eb04135fb13832",
  "limitations": [
    "This is developer-run regression verification, not an independent audit, penetration test, formal proof, or claim that the product is free of vulnerabilities.",
    "Only the named controls and test inputs were exercised.",
    "The product security policy still classifies Core Panel as pre-production and identifies unmet production-readiness controls."
  ]
}
