Trust
What we do when we do not know.
Most security claims have two states: checked and clean, or checked and failed. The interesting third state is the one a product is tempted to hide, which is that a check did not actually happen. Here is where Bolt carries that state instead, and what it does with it.
Four places the product says unknown
Each of these was built for its own reasons by different people. That they converged on the same discipline is the point.
Why we think this matters more than it sounds
It cannot be adopted retroactively
It is the question you are actually asking
The same rule, applied to this website
A principle that stops at the product boundary is a marketing position. So the Trust Center carries its own unknowns in the same place as its claims rather than in a footnote: the supply chain page lists what our build provenance does not yet cover, the reviewer packet lists the assurance we do not have beside the assurance we do, and the CASA page spends as much space on what the assessment does not prove as on what it does.
Where we are wrong about any of this, we would rather hear it than not. Our disclosure policy commits to a one-business-day acknowledgement and a good-faith safe harbor, and a claim on this site that does not survive contact with the product is as much a finding as a bug is.
Reviewing Bolt?
The reviewer packet states what we have and what we do not, on one page, written to be forwarded without edits.