METODO DARTAGNAN · VERIFIABLE EVIDENCE
Método D’Artagnan
MÉTODO D’ARTAGNAN · VERIFIABLE CHALLENGE · AUG 22 2026

Challenge accepted.Security is not declared. It is verified.

The hosting AI proposed a test. We froze the defense, audited the real edge, found a flaw, fixed it, retested, and published the generic code, redacted results, and checksums.

100/100in the synthetic lab
17/17proven cases
4equivalent runs
1 → 0real flaw: open → fixed

Two results. No mixing.

Synthetic lab

Three rounds in the sandbox and one in the isolated VPS produced the same signature: 17 proven cases, zero flaws, and a valid audit chain. The 100/100 score belongs solely to this lab.

Method in production

An administrative route responded 200 without visitor credentials. The exposure was removed, the original state was recovered from the backup, and the retest returned 404, preserving legitimate public routes.

REAL FLAW · SEC-MD-01

The test found something that needed to be fixed.

The public edge provided access to an administrative function without visitor authentication. Write actions were not called in the initial audit. The flaw was recorded before the fix and remains in the history.

Before

Administrative read: HTTP 200 without visitor credentials.

Fix

Three administrative routes removed from the public edge, with backup and rollback.

Retest

Administrative routes: HTTP 404. Six legitimate routes: 200. Nine internal ports: blocked.

Reproducible lab score

The score does not automatically approve legacy services or controls that were not demonstrated.

Isolation
25/25
Privileges and sessions
20/20
Files and exports
15/15
Traceability
15/15
Incident response
15/15
AI limits
10/10
100/ 100 · LAB

External criteria A–F

The codes below organize the hosting challenge. They are neither names nor content of the Method's proprietary axioms.

A · Context and scope accompany the decision
B · Only the necessary privilege
C · Identity, role, purpose, and record
D · Absence requires evidence
E · Ambiguity and failure result in denial
F · AI does not self-authorize

Evidence to download and verify

Each public artifact has a SHA-256. Download the package, run it again, or compare the checksums without relying on this page.

SHA-256 verifier in the browser

Select a downloaded file. The calculation occurs locally in your browser; the file is not sent to the server.

No file selected.

The 17 published cases

CaseCategoryExpectedObservedStatus
Loading verifiable results…

What remains unvalidated

Uniform hardening of all legacy services, multi-tenancy in the public infrastructure, session revocation where there is no application session, and use of an external generative model with private data. These items receive zero, not approval by inference.

The challenge was worth it because it found a flaw.

We have no commitment to error. We preserved the evidence, fixed the route, and published what can be reproduced — including the limits.

Back to the Method