{"change_history":[{"change_event_id":"EV-CHG-0056-007","change_type":"ADD","changed_claim_ids":["EVI-INST-0011"],"new_state":"CSRF source fact published with deployment limitation","previous_state":"Security page did not identify the bounded CSRF source fact","public_explanation":"The security page separates source control from deployed-host state.","reason":"Document repository-supported browser-form security controls.","release":"2.0.0-rc.56-WIP","review_boundary":"Source implementation, not actual-host enforcement","source_record":"app/forms.py","supersedes_event_id":null}],"record":{"change_event_id":"EV-CHG-0056-007","claim_class":"REPOSITORY_VERIFIABLE","claim_id":"EVI-INST-0011","claim_text":"The packaged contact form and application stack include CSRF protection when the Flask application is running with required configuration.","claim_title":"Browser forms use a CSRF boundary in source","institutional_page":"security","known_defeaters":["Misconfiguration, disabled extension, mixed deployment, or route bypass."],"last_reviewed":"2026-08-13T00:47:38Z","limitations":["Does not establish the value, rotation, transport, or enforcement of secrets on the actual host."],"observation_environment":"RC57 source tree","observation_time":"2026-08-13T00:47:38Z","public_record_url":"https://evulgare.com/institutional/evidence/EVI-INST-0011/","scope":"Packaged application source","source_digest":"a29d2d47aee0e53ffae02b821dbfcd1af83b8bfa0c90fa59e58293c251a01635","source_path_or_public_url":"app/forms.py","source_release":"2.0.0-rc.57-WIP","source_type":"REPOSITORY_SOURCE","status":"SUPPORTED_WITHIN_SCOPE","superseded_by":[],"supersedes":[],"verification_method":"Form and extension configuration inspection","verification_result":"CSRF-enabled form path present"},"schema":"evulgare.institutional-evidence-record.v1","truth_boundary":"Record integrity and source identity do not establish factual truth beyond the declared scope."}
