{"change_history":[{"change_event_id":"EV-CHG-0056-008","change_type":"QUALIFY","changed_claim_ids":["EVI-INST-0012"],"new_state":"Source and actual-host boundaries separated","previous_state":"Header behavior described generally","public_explanation":"Application middleware evidence does not substitute for final response evidence.","reason":"Describe security-header logic without claiming final proxy output.","release":"2.0.0-rc.56-WIP","review_boundary":"Final public headers require host observation","source_record":"app/security.py","supersedes_event_id":null}],"record":{"change_event_id":"EV-CHG-0056-008","claim_class":"REPOSITORY_VERIFIABLE","claim_id":"EVI-INST-0012","claim_text":"The packaged application defines security-header behavior, but reverse proxies and host configuration can alter the final public response.","claim_title":"Restrictive response-header logic exists in source","institutional_page":"security","known_defeaters":["Proxy rewriting, stale release, route fallback, configuration drift, or middleware registration failure."],"last_reviewed":"2026-08-13T00:47:38Z","limitations":["Final actual-host headers were unavailable in the build environment."],"observation_environment":"RC57 source tree","observation_time":"2026-08-13T00:47:38Z","public_record_url":"https://evulgare.com/institutional/evidence/EVI-INST-0012/","scope":"Application-generated responses in the packaged source","source_digest":"ab2f62c3f3bcc9fb3c1fecb8af080a960fb2437d76f4baf1cd747b4f4287bc7d","source_path_or_public_url":"app/security.py","source_release":"2.0.0-rc.57-WIP","source_type":"REPOSITORY_SOURCE","status":"SUPPORTED_WITHIN_SCOPE","superseded_by":[],"supersedes":[],"verification_method":"Security middleware inspection","verification_result":"Header construction and response hook present"},"schema":"evulgare.institutional-evidence-record.v1","truth_boundary":"Record integrity and source identity do not establish factual truth beyond the declared scope."}
