Skip to content
CUNICULA

Primary sources

Original records, exact passages, retrieval dates, and pinned archive hashes.

Each citation below identifies the original document and the exact provision or passage supporting a published claim. A primary document does not automatically earn the strongest evidence tier. Official records resolve to third-party reporting, provider publications remain self-reported, audits require an independent audit report, and directly tested evidence requires a Cunicula test record.

Machine-readable records are available from /api/v1/primary-sources and the site feed.

Releases: GrapheneOS 2026091000, 2026091700 and 2026091900

Issuing body
GrapheneOS
Publication date
Retrieved
Document type
transparency-report
Evidence tier
SELF-REPORTED
Content hash
sha256:91e8f131994ffa0517c761d638abb92f5bcc09f2bcbd114767a403c151b6a2d8
Copies
Official document · Archived copy

Supported claims

GrapheneOS release 2026091000 reports the full 2026-09-01 security patch level.

Location: 2026091000: Changes since the 2026090700 release (included in September 19 release history), PDF page 1

full 2026-09-01 security patch level

Attached to: Article: grapheneos-privacy-phone-guide

GrapheneOS release 2026091700 reports a Pixel cellular modem firmware backport from Android 17 QPR1.

Location: 2026091700: Changes since the 2026091000 release, PDF page 1

Pixels: backport cellular modem firmware from Android 17 QPR1

Attached to: Article: grapheneos-privacy-phone-guide

License Plate Reader Policy

Issuing body
Flock Safety
Publication date
Retrieved
Document type
transparency-report
Evidence tier
SELF-REPORTED
Content hash
sha256:c92398d62608b2c249021bbf86484959b6f0191c26b215f6cc83d26a114d3182
Copies
Official document · Archived copy

Supported claims

Flock's LPR policy says queries are stored for auditing with user, date, time, purpose and search elements; this is not verification of OS Investigate logging.

Location: Authorized Users and Access, PDF page 1

All queries of the LPR system are stored for auditing purposes, including: Username Date Time Purpose of query License plate and other elements used to query the system

Attached to: Article: license-plate-readers-traffic-enforcement

Flock states a seven-day default deletion period with customer law or policy exceptions; the policy expressly governs its LPR system, not every investigative record.

Location: Data Retention and Privacy (page labelled June 30; wording retrieved September 21), PDF page 1

LPR data is hard deleted on a rolling 7-day basis by default; this may be increased or decreased on a case-by-case basis if a different schedule is required by a customer’s law or policy. Privacy: This policy governs the LPR system provided by Flock Safety.

Attached to: Article: license-plate-readers-traffic-enforcement

Security incident at Brevo, our third-party email provider

Issuing body
Trezor
Publication date
Retrieved
Document type
transparency-report
Evidence tier
SELF-REPORTED
Content hash
sha256:e174a3abc49460f24aea0ff048e281a6d6b9fe7949cf5b00b7b550ccdc369bb4
Copies
Official document · Archived copy

Supported claims

Trezor's September 17 update reports 347,149 marketing email contacts exported through Brevo's API.

Location: Updated September 17, 2026, PDF page 1

Brevo has confirmed that 347,149 marketing email contacts were exported from our list through the API during this incident.

Attached to: Service: trezor, field incidents

Trezor says its product, wallet and account systems were not affected by the Brevo incident.

Location: Was Trezor itself hacked?, PDF page 1

No Trezor product, wallet, or account system was affected.

Attached to: Service: trezor, field incidents

Trezor describes a phishing email linking to an app that asked for a wallet backup, not a verified hardware repair.

Location: Phishing email description, PDF page 1

The phishing email sent from our account contained a malicious link that prompted users to download an app that asked users to enter their wallet backup.

Attached to: Service: trezor, field incidents

Recent customer data exposed in shipping provider incident

Issuing body
Trezor
Publication date
Retrieved
Document type
transparency-report
Evidence tier
SELF-REPORTED
Content hash
sha256:53efa089aabc2bf3bea34d06df8eb646a961acc81560c98da1a8d38d621d568f
Copies
Official document · Archived copy

Supported claims

Trezor's updated ShipMonk disclosure states that 80,689 customers are affected by that incident.

Location: How many customers are affected by this incident? (September 4 update; header August 12, body says original August 13), PDF page 1

80,689 customers are affected.

Attached to: Service: trezor, field incidents

Trezor's September 4 update adds approximately 67,000 US customers with full name, email, phone, shipping-address and order-number exposure.

Location: Updated September 4, 2026, PDF page 1

This leaked data affects another approximately 67,000 US customers and includes full exposure (name, email, phone number, shipping address, order number).

Attached to: Service: trezor, field incidents

Trezor says ShipMonk retained data despite confirmation of deletion; this is the customer's account, not an independent audit.

Location: Updated September 4, 2026, PDF page 1

We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.

Attached to: Service: trezor, field incidents

Attacker gained access to client accounts

Issuing body
Brevo
Publication date
Retrieved
Document type
transparency-report
Evidence tier
SELF-REPORTED
Content hash
sha256:47425f4490e004f7bbb073bc6302773f31c6271e59f2eacaabbcb0d67a1fd6f9
Copies
Official document · Archived copy

Supported claims

Brevo's postmortem reports 138 platform accounts accessed, distinct from Trezor's exported newsletter-contact count.

Location: What happened, PDF page 1

On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts.

Attached to: Service: trezor, field incidents

Brevo says the phishing messages passed ordinary email authentication because they used legitimate sending infrastructure.

Location: If you have received some of these emails, PDF page 1

These messages were sent through legitimate infrastructure, so they passed the usual email authentication checks and looked genuine.

Attached to: Service: trezor, field incidents

Shutting down our public encrypted DNS servers and sponsoring Quad9 instead

Issuing body
Mullvad VPN
Publication date
Retrieved
Document type
transparency-report
Evidence tier
SELF-REPORTED
Content hash
sha256:3a5d9c626cb8eedba19547f3afc90fa9bdb09e8f43c25f1825f517d8dc97a6aa
Copies
Official document · Archived copy

Supported claims

Mullvad asks manually configured public DoH users to switch before November 2, 2026.

Location: Migrating to Quad9, PDF page 1

If you have manually configured our DoH servers, switch before November 2nd 2026.

Attached to: Service: mullvad-dns, field privacyWarning

Mullvad distinguishes its VPN internal DNS from the public encrypted DNS service being retired.

Location: Opening paragraph, PDF page 1

They are unnecessary when using Mullvad VPN — traffic is already encrypted and Mullvad VPN's internal DNS handles all queries.

Attached to: Article: private-dns-setup-guide

Mullvad Browser default and included ad-blocking DoH settings will automatically migrate to Quad9.

Location: Mullvad Browser, PDF page 1

Mullvad Browser users who have kept the default DoH settings or the included ad blocking one, will automatically be migrated to Quad9.

Attached to: Article: private-dns-setup-guide

Mullvad says customized browser DoH settings will not be changed automatically.

Location: Mullvad Browser, PDF page 1

If you have customized the DoH, we will not change them.

Attached to: Article: private-dns-setup-guide

Implementation Rules for Article 43 of the Law of the People's Republic of China on Safeguarding National Security in the Hong Kong Special Administrative Region

Issuing body
Chief Executive in conjunction with the Committee for Safeguarding National Security of the Hong Kong Special Administrative Region
Hosting body
Legislative Council of the Hong Kong Special Administrative Region
Publication date
Retrieved
Document type
regulation
Evidence tier
THIRD-PARTY REPORTED
Content hash
sha256:409c3acb01c81a53a4ffac029c7a63ffb40919bf8979416fea64864d680b104a
Copies
Official document · Archived copy

Supported claims

The 2026 amendments to Instrument A303 commenced on 23 March 2026.

Location: Rule 1, Editorial Note, PDF page 6

For the commencement arrangements under the subsequent amendments to these Implementation Rules, please see L.N. 166 of 2023 (commencement date: 15 December 2023) and L.N. 27 of 2026 (commencement date: 23 March 2026).

Attached to: Article: hong-kong-device-password-law

A police officer exercising the electronic-equipment search power may require a specified person to provide a necessary password or decryption method.

Location: Schedule 1, Part 1, section 4(2)(a), PDF page 11

(a) require a specified person to provide the police officer with any password, or other decryption method, that is necessary;

Attached to: Article: hong-kong-device-password-law

The same power may require other reasonable and necessary information or assistance.

Location: Schedule 1, Part 1, section 4(2)(b), PDF page 11

(b) require a specified person to provide the police officer with any other reasonable and necessary information or assistance,

Attached to: Article: hong-kong-device-password-law

Failure to comply can result in a HK$100,000 fine and one year of imprisonment on conviction on indictment.

Location: Schedule 1, Part 1, section 5(1), PDF page 12

If a person fails to comply with a requirement imposed under section 4(2) of this Schedule, the person commits an offence and is liable on conviction on indictment to a fine of $100,000 and to imprisonment for 1 year.

Attached to: Article: hong-kong-device-password-law

A person charged with the noncompliance offence may establish a defence by showing a reasonable excuse for failing to comply.

Location: Schedule 1, Part 1, section 5(3), PDF page 12

It is a defence for a person charged with an offence under subsection (1) to establish that the person had a reasonable excuse for failing to comply with the requirement.

Attached to: Article: hong-kong-device-password-law

Knowingly or recklessly providing materially false or misleading information can result in a HK$500,000 fine and three years of imprisonment on conviction on indictment.

Location: Schedule 1, Part 1, section 6, PDF page 13

(a) provides any information, or makes a statement, that the person knows to be false or misleading in a material particular; or (b) recklessly provides any information, or recklessly makes a statement, that is false or misleading in a material particular, the person commits an offence and is liable on conviction on indictment to a fine of $500,000 and to imprisonment for 3 years.

Attached to: Article: hong-kong-device-password-law

The ordinary warrant route requires a police officer to apply to a magistrate by information on oath.

Location: Schedule 1, Part 1, section 2(1), PDF page 8

A police officer may, for investigation of an offence endangering national security, apply to a magistrate by information on oath for a warrant under this section.

Attached to: Article: hong-kong-device-password-law

The section 3(1) warrantless route requires satisfaction by a police officer not below the rank of Assistant Commissioner.

Location: Schedule 1, Part 1, section 3(1), PDF page 10

If a police officer not below the rank of Assistant Commissioner of Police is satisfied that

Attached to: Article: hong-kong-device-password-law

The section 3(1) warrantless route also requires that obtaining a warrant would not be reasonably practicable.

Location: Schedule 1, Part 1, section 3(1)(c), PDF page 10

for any reason it would not be reasonably practicable to obtain a warrant, the police officer, or another police officer authorized by the police officer, may exercise one or more of the powers under section 2(3) of this Schedule for investigation of an offence endangering national security without a warrant.

Attached to: Article: hong-kong-device-password-law

Rule 2(3) adds Customs and Excise Service members to the officials who may exercise Schedule 3 property freezing, restraint, confiscation, and forfeiture powers.

Location: Rule 2(3), PDF page 6

The Secretary for Justice, the Secretary for Security, a member of the Customs and Excise Service or a police officer may, in accordance with Schedule 3, exercise the power to freeze, restrain, confiscate and forfeit property relating to the commission of an offence endangering national security.

Attached to: Article: hong-kong-device-password-law