Executive summary
Configured Hiro's Phase 1 observation policy for three explicitly approved public sources: one exact IANA control page, the Python 3 documentation tree, and one exact PyPI Simple Index project page.
Added host-bound exact-URL and path-prefix enforcement so approval of a hostname no longer authorizes unrelated paths on that host. Request, elapsed-time, and cumulative-byte budgets now persist across every capture made by one observer session.
Passed 55 focused adversarial tests and the complete 382-test Hiro suite before making any public request.
The authorized shadow session then completed exactly three direct, read-only GET requests: all returned HTTP 200, no redirect occurred, and 81,403 response bytes were retrieved in 0.754 seconds. Each response was sanitized and frozen with a verified SHA-256 companion.
The observation lane was re-disabled immediately after the session. Stage 6 remained disabled, and the session granted no promotion, deployment, credential, or state-changing authority.