Vault record model.
| Field | Public-safe statement | Boundary |
|---|---|---|
| Inputs | Owned-system recovery paths, rotation metadata, redacted diagnostics, and local runbook state. | No credential values. |
| Outputs | Path-only receipts, rotation reminders, diagnostic summaries, and human recovery checklist state. | No credential recovery instructions are published. |
| Use | Local operational continuity and evidence hygiene. | No bypass guidance. |
Release boundary.
The vault does not contain the secret.
Kun records where recovery authority lives and how to audit the process. It does not publish or retain raw keys, tokens, passwords, seed phrases, private browser state, or protected content.