# TSEM v1.0 Initial Calibration Record

- **Artifact ID:** CHQ-EX-2026-005
- **Public record:** https://record.cybersecurityhq.com/methods/chq-ex-2026-005
- **Machine-record SHA-256:** `f058651dca5b2560cdc33b48eca114c00a642d2759ba9f6566a2a3fa72513c37`

## Complete structured record

```json
{
  "id": "CHQ-EX-2026-005",
  "title": "TSEM v1.0 Initial Calibration Record",
  "subtitle": "Gate inputs, classification outcomes, and discriminating function observations from the first three incidents evaluated under the Trust Surface Escalation Model during its initial operational period",
  "classification_notice": [
    "This document is published as a CHQ Exhibit. It records operational outputs of the Trust Surface Escalation Model (TSEM) v1.0 during its initial calibration period. This Exhibit documents gate inputs, gate results, and classification outcomes as they were produced during evaluation.",
    "This document does not assess TSEM's predictive validity, recommend gate adjustments, or declare model readiness. No evaluative conclusions about the model's fitness for institutional use are present. Classification outcomes recorded here are calibration data, not authoritative determinations.",
    "CHQ Exhibits are not superseded by later artifacts unless explicitly invalidated for factual error."
  ],
  "metadata": {
    "artifact_class": "METHOD_CALIBRATION_RECORD",
    "temporal_scope": "OPERATIONAL (2026-02-25 THROUGH 2026-02-27)",
    "authority_level": "NON-JUDGMENTAL",
    "reliance_status": "CONTEXT ONLY",
    "update_policy": "ERRATA ONLY",
    "temporal_start": "2026-02-25",
    "temporal_end": "2026-02-27"
  },
  "sections": [
    {
      "heading": "I. TSEM v1.0 Architecture as Deployed",
      "content": [
        "The Trust Surface Escalation Model v1.0 was ratified on February 25, 2026 as a three-gate classification instrument. The model distinguishes between exploit-based compromises and trust channel inversion events where authenticated systems execute adversarial input through compliant workflows.",
        "Gate 1: Trust Channel Inversion Test (TCIT). Evaluates whether the incident occurred through an authenticated channel, followed a compliant workflow, and the system behaved as designed. All three conditions must hold simultaneously for passage.",
        "Gate 2: Intent Dislocation Gate (IDG). Evaluates whether organizational intent was violated despite system compliance. The gate distinguishes between system malfunction and correct system behavior producing unauthorized outcomes.",
        "Gate 3: Productivity Surface Exposure Flag (PSEF). Evaluates whether the compromise propagates inherited trust downstream without requiring independent authentication compromise at each subsequent layer.",
        "Classification outcomes: Operational (fails TCIT), Trust Channel Inversion Event or TCIE (passes TCIT and IDG), Systemic Trust Surface Event or STSE (passes all three gates).",
        "TSEM v1.0 operates in retrospective-only mode. No forward-looking classifications are permitted until the model demonstrates discriminating value through a minimum of eight calibrated incidents. Gate definitions are frozen during calibration. No adjustments to gate language or passage criteria are permitted before the eight-incident threshold."
      ]
    },
    {
      "heading": "II. Incident 1: Flagstar Bancorp Citrix Breach and SEC Enforcement",
      "content": [
        "Date evaluated: February 25, 2026. Source incident: Flagstar Bancorp breach via Citrix vulnerability exploitation, subsequent SEC enforcement action.",
        "Gate 1 (TCIT) inputs: The compromise involved exploitation of a known Citrix vulnerability. The attacker did not use authenticated access. The workflow was not compliant. The system did not behave as designed.",
        "Gate 1 result: FAIL.",
        "Classification: Operational.",
        "Calibration observation: This incident qualifies under CHQ-ACJ-2026-001 scope (U.S. public financial institution with SEC enforcement). ACJ scope qualification does not imply TSEM escalation. The model correctly distinguished between an incident relevant to CHQ's institutional focus and an incident that represents trust channel inversion. These are independent classifications."
      ]
    },
    {
      "heading": "III. Incident 2: Google Sheets Command-and-Control via UNC2814",
      "content": [
        "Date evaluated: February 27, 2026. Source incident: UNC2814 deployed GRIDTIDE backdoor using Google Sheets API as command-and-control infrastructure across 53 organizations.",
        "Gate 1 (TCIT) inputs: The adversary used authenticated Google Sheets API access. The API calls followed compliant workflows. Google Sheets operated as designed, executing read and write operations from authorized API clients. The command-and-control channel was indistinguishable from legitimate collaboration traffic at the protocol level.",
        "Gate 1 result: PASS.",
        "Gate 2 (IDG) inputs: Organizational intent for Google Sheets API access was collaborative document workflows, not command-and-control relay. The system executed the organizational workflow correctly while simultaneously serving adversary objectives. Intent was dislocated from execution.",
        "Gate 2 result: PASS.",
        "Classification: TCIE (Trust Channel Inversion Event).",
        "Calibration observation: Detection required external disruption by Google, not routine post-admission monitoring. The trust channel (Google Sheets API) carried both legitimate and adversarial traffic simultaneously without protocol-level differentiation. Gate 3 (PSEF) was not evaluated because TCIE classification does not require Gate 3 passage."
      ]
    },
    {
      "heading": "IV. Incident 3: Claude Code Remote Code Execution via Prompt Injection",
      "content": [
        "Date evaluated: February 27, 2026. Source incident: Check Point Research disclosed that Claude Code executed shell commands from prompt-injected content before trust dialogs rendered. Administrative file transfer interfaces converted privilege into root execution across four simultaneous attack paths.",
        "Gate 1 (TCIT) inputs: The adversary delivered payloads through content that Claude Code processed as part of its designed workflow. The system ingested and executed instructions from sources it was designed to process. No authentication bypass occurred. The execution followed the system's intended input processing pipeline.",
        "Gate 1 result: PASS.",
        "Gate 2 (IDG) inputs: Organizational intent for Claude Code was assisted software development, not arbitrary shell command execution from untrusted content. The system processed adversarial instructions identically to legitimate instructions. Intent was dislocated from execution at zero latency: privilege preceded monitoring.",
        "Gate 2 result: PASS.",
        "Classification: TCIE (Trust Channel Inversion Event).",
        "Calibration observation: This incident surfaces a degenerate condition. Detection latency is not merely long. It is structurally zero because privilege is granted before any monitoring or trust dialog can intervene. The system's design grants execution authority at the moment of input ingestion, prior to any verification layer. This condition was flagged as a potential TSEM subclass for future revision without modifying gate definitions during calibration."
      ]
    },
    {
      "heading": "V. Incident Not Evaluated: Cisco SD-WAN CVE-2026-20127",
      "content": [
        "The Cisco SD-WAN authentication bypass (CVE-2026-20127, exploited by UAT-8616 for approximately three years) was considered for TSEM evaluation but was not classified.",
        "Reason: The compromise involved authentication bypass. The attacker circumvented the authentication mechanism rather than satisfying it. Gate 1 (TCIT) requires that the incident occur through an authenticated channel where the system behaves as designed. Authentication bypass means the system did not behave as designed. The incident is Operational under TSEM classification.",
        "This exclusion is recorded because the post-admission behavior (three years of undetected operations through legitimate administrative interfaces) pressures the assumption that monitoring constrains dwell time. The incident is relevant to CHQ's analytical concerns but does not represent trust channel inversion as defined by TSEM v1.0."
      ]
    },
    {
      "heading": "VI. Incident Not Evaluated: SolarWinds Serv-U CVE-2025-40538",
      "content": [
        "The SolarWinds Serv-U critical vulnerability was considered for TSEM evaluation but was not classified.",
        "Reason: The vulnerability requires pre-existing administrative privileges. No confirmed exploitation in the wild was documented at the time of evaluation. Insufficient operational data to evaluate gate inputs. Evaluation deferred pending exploitation evidence."
      ]
    },
    {
      "heading": "VII. Calibration Summary",
      "content": [
        "Total incidents evaluated: 3. Classifications: 1 Operational, 2 TCIE, 0 STSE. Gate adjustment threshold: 8 incidents (not reached). Gate definitions: Frozen. No modifications permitted. Next review: After 5 additional evaluated incidents or 60 days, whichever comes first.",
        "The model's discriminating function produced non-uniform classifications across the initial three incidents. Flagstar (exploit-based, authentication bypass) classified differently from Google Sheets and Claude Code (trust channel inversion through compliant workflows). This non-uniformity is a positive calibration signal. A model that classifies all inputs identically provides no discriminating value.",
        "The two TCIE classifications share a structural property: in both cases, the adversary operated within the system's designed input processing workflow. The system did not malfunction. It executed correctly and produced unauthorized outcomes. The distinction between system failure and system compliance producing unauthorized results is the core discriminating boundary TSEM v1.0 is designed to test.",
        "Whether this boundary holds across a broader incident population remains unknown. Three incidents do not constitute validation. They constitute initial calibration data."
      ]
    }
  ],
  "closing_statement": "This Exhibit records calibration outputs from the period February 25 through February 27, 2026. No present applicability beyond calibration documentation. No evaluative conclusions.",
  "hash_scope": "Full exhibit content body",
  "hash_generated": "2026-02-27",
  "canonical_artifact_class": "EXHIBIT"
}
```
