TRQP-TSPP

TRQP Security & Privacy Profile (TSPP) v0.5.0

This document defines a practical security and privacy deployment profile for the Trust Over IP Trust Registry Query Protocol (TRQP).

Goal: convert “security considerations” into ship-stopping requirements and make them testable.

Threat posture

TRQP is a high-leverage primitive: it can become a trust-decision input bus for ecosystems. The dominant risks are not “crypto breaks,” but:

Assurance levels

This repository consumes Assurance Level (AL1–AL4) semantics from the TRQP Assurance Hub.

Normative requirements (summary)

Transport and endpoint integrity

Authentication and authorization

Anti-enumeration and abuse resistance

Freshness and replay controls

Semantic safety

Context privacy

Recognition constraints

How to use this repo

See docs/threat-model.md for deeper adversarial framing and docs/deployment-guidance.md for practical rollout.

Experimental profiles