The Contact Initiative treats cybersecurity as an infrastructure-level property, not an add-on, through a defined set of controls:
- Verified, role-based identity for every user, separate from any reassignable number.
- Zero-trust access to the resolution layer — no standing access for any relying party, vendor, or MI agent.
- Non-enumerable, rate-limited query-response verification, preventing bulk scraping of the identity graph.
- Mandatory DNSSEC, SPF, DKIM, and enforced DMARC on every issued domain.
- Aliases that hide the administrative address, shrinking the target for spear-phishing.
- Scoped, short-lived credentials for vendors and MI agents instead of raw record access.
- Persistent, tamper-evident logging at both the institution and national-registry level.
- Mandatory dual control for high-impact actions like bulk data export or identifier retirement overrides.
- A public security-disclosure and bug-bounty commitment for the registry and its reference implementation.
That vendor-focused control matters most: reported research indicates a majority of disclosed K–12 breaches trace back to a compromised vendor, not the district itself. Tokenized, scoped, short-lived vendor credentials are aimed squarely at closing that pathway.