Skip to content

Architecture Decision Records

Decisions that will be questioned later, with the reasoning that produced them. Each record states what was decided, what it cost, and what would make it wrong — so a future change can tell "this was considered and rejected" apart from "nobody thought about it".

Records are immutable once merged. A decision that changes gets a new record superseding the old one, not an edit.

A record whose reasoning turns out to be overstated is the one case that is corrected in place, in a dated section that leaves the original claim visible. Rewriting the argument silently would defeat the point of writing it down; removing the record would lose the fact that the decision was made on a weaker basis than it appeared.

# Decision Status
0001 Unauthenticated probes use a second, credential-free transport Accepted
0002 Every finding cites the requests that produced it; the score is derived from findings Accepted
0003 Secrets are redacted structurally at the recorder, and content types are not trusted Accepted
0004 Only tools declaring readOnlyHint are invoked by default Accepted
0005 The hosted diagnostic is the same binary, and it accepts no credentials Accepted
0006 passmcp contains no client-side telemetry, and 0 bytes uploaded is a product guarantee Accepted
0007 passmcp measures servers and is never in the data path between an agent and one (the line drawn, 2026-09-24) Accepted
0008 passmcp contains no adversarial or exploit probes, in any command Accepted
0009 Token counts are named estimates; no tokenizer vocabulary is embedded Accepted
0010 Provenance is reported from the binary; signatures are verified with cosign or gh Accepted
0011 The attestation schema and rubric are Apache-2.0; the engine stays GPL-3.0 Accepted
0012 No paid tier yet: every roadmap feature is built in the open until adoption says where the line goes Accepted