Computational · Paper · 2026

Redacted Report Template: Disclosure Control and Release Audit

Daniel Ari Friedman

Zenodo

Download PDF Publication source Paper folder on GitHub Read extracted text

Overview

This exemplar demonstrates a complete disclosure-control pipeline for sanitized public release reports. The methodology combines classification-ceiling enforcement, source-protection validation, mosaic-risk scoring, and TPM-backed sealed sidecars across a sixteen-variant visual proof matrix. Four redaction styles—blackout, whiteout, grayout, and blur—are rendered across four PDF backgrounds—white, gray, black, and blur—yielding sixteen base proof PDFs. Each receives nine steganographic security methods including SHA-256/SHA-512 hash manifests, diagonal watermark overlays, footer provenance stamps, invisible text, QR and Code128 barcodes, PDF Info and XMP metadata, and embedded manifest attachments. Optional Kmyth TPM sealing wraps each hash manifest and steganography PDF in a .ski sidecar sealed against the TPM2-TSS storage hierarchy, bound to PCR selections and policy or-values. The release gate requires three reviewer roles—originator, classification reviewer, and release authority—each providing a non-empty rationale. A source-safe redaction ledger records SHA-256 hashes of each redacted span without exposing source text, and a segment hash manifest compares source and public SHA-256 digests for reproducible audit. The comprehensive release packet combines sanitized text, audit findings, ledger, hashes, review gate status, and paragraph-level audit tables into a single JSON-ready export. This exemplar confirms that visual presentation choices remain orthogonal to the release gate: the same source-safe decisions drive every output variant.

redactiondisclosure controlrelease auditsource protection

Overview source: Curated paper metadata.

Methods and contributions

Read the source for the full argument, qualifications, and evidence.

Findings and contributions

  • On the fixture packet (fourteen segments), the audit reported the packet releasable with redaction coverage 1.0, plus warning-level residual-marker findings.
  • In the verified run, all sixteen variants produced both TPM sidecars, giving thirty-two .ski files.
  • Without the FlushContext patch, the second kmyth-seal invocation fails with an out-of-memory-for-object-contexts error on swtpm.
  • The author reports that visual presentation choices are orthogonal to the release gate: all four redaction treatments yield equivalent source-safe outputs.
  • Stated limitations: fixture data is invented, swtpm lacks hardware tamper resistance, and batch sealing of 32 sidecars takes about thirty seconds via the proxy.

Methods

  • Invented fixture data with synthetic classified segments and reviewers — The pipeline is exercised only on synthetic segments (UNCLASSIFIED to TOP_SECRET//SCI), synthetic redaction decisions and synthetic reviewer records.
  • Text-level release-audit engine with mosaic-risk scoring — Segments are audited against a public classification ceiling, redaction spans checked for overlap, orphan decisions flagged, source-control coverage enforced, and residual markers scored.
  • 4x4 visual redaction proof matrix plus nine steganographic methods — Four redaction styles are rendered on four PDF backgrounds (16 PDFs), each post-processed with hash manifests, watermarks, barcodes, metadata and embedded manifests.
  • Kmyth TPM sealing via swtpm and an mssim-to-swtpm proxy on macOS — Hash manifests and steganography PDFs are sealed into .ski sidecars; on macOS a software TPM and protocol proxy were used, and kmyth-seal was patched to flush contexts.
  • Source-safe SHA-256 redaction ledger and three-role review gate — Redacted spans are recorded only as SHA-256 hashes, and release requires originator, classification reviewer and release authority approvals with rationales.

Summary sources: Paper metadata and evidence · Extracted source text.

PDF downloads

Archived files available directly from this site.

Citation

Citation metadata follows the unified bibliography.

Friedman, Daniel Ari. 2026. Redacted Report Template: Disclosure Control and Release Audit. Zenodo. DOI: 10.5281/zenodo.21298890. URL: https://doi.org/10.5281/zenodo.21298890.
Download bibliography

Catalog details and resources

Catalog row189
Citation keyFriedman2026RedactedReportTemplateDisclosure189

Related in Computational

Other catalogued works in the same domain.

View all Computational works, software & media →