Evidence vault · claim authority hub
Proof is what survives validation, boundaries, and human review.
The website routes reviewers to proof. It does not authorize claims. Claims either survive the vault — validators, evidence boundaries, and human review — or they stop at the gate.
Evidence Bay
Receipts live here. Claims do not get to float free.
Artifact cards route reviewers from public rendering back to source, validation, proof, and authority surfaces. The wall is searchable by family and keeps proof ceilings attached.
Public Proof
CONTROLLED_TEST_VALIDATEDgovernanceWebsite Rendering Is Not ProofPublic rendering
rendering/reference boundarycase-studyHO-DET-001 Case FilePublic Proof
CONTROLLED_TEST_VALIDATEDproof-recordAWS-DET-001 Proof RecordPublic Proof
CONTROLLED_TEST_VALIDATEDproof-recordHO-DET-001 Private Runtime BoundaryRuntime Truth
CONTROLLED_TEST_VALIDATEDproof-recordPrivate Marker Delivery BoundaryEvidence Truth
CONTROLLED_TEST_VALIDATEDvalidationValidation Report — Controlled-Test ScopeValidation Truth
CONTROLLED_TEST_VALIDATEDvalidationHO-DET-012 Controlled Validation / Runtime BoundaryValidation Truth
CONTROLLED_TEST_VALIDATEDarchitectureHO-PIPE-001 Telemetry Route BoundaryTelemetry route boundary
SOURCE_EXISTS_VALIDATION_PLANNEDarchitectureHO-NDR-001 Security Onion Visibility ContractNDR visibility contract
BOUNDARY_CONTRACT_ONLYpublic-packetProof Loop Reviewer Brief / Review ZIP StandardReviewer packet
REVIEWER_PACKET_STANDARDarchitectureDetection Factory / Validation Factory ControllerGoverned control plane
CONTROL_PLANE_STRUCTUREgovernanceHO-LAB-AUTO / Support-only AI Triage BoundaryAI support boundary
SUPPORT_ONLY_AIgovernanceClaim FirewallPublic claim boundary
rendering/reference boundaryci-verifierBlocked-Claim CI ScannerPublic claim boundary
rendering/reference boundaryarchitectureTruth Surface ModelSystem architecture
rendering/reference boundaryarchitectureRepository Authority MapSystem architecture
rendering/reference boundarygovernanceControl Status MatrixGovernance routing
rendering/reference boundarySealed reviewer package
Proof Pack 001 — a bounded reviewer package.
The receipt states what the package supports and what it does not prove. Raw / private runtime evidence is excluded and public runtime proof stays blocked.
Included · reviewer package (7)
Excluded · blocked from public release (2)
Does not prove
An official direct GitHub Release route exists. Source packet manifest / check-mode language remains source-packet / release-candidate metadata — a route / status distinction, not a stronger proof claim.
Render-only ledger route
Lifetime Case Ledger v1
The website is render-only; the proof repo owns the summary and proof bundle. The badges are workflow-status indicators only. Boundary: no runtime, signal, public-safe runtime proof, SOCaaS, production, autonomous SOC, disposition, or case-closure claim is made.
Runtime boundary
The runtime proof tower — what survives, what stays sealed.
Each level names a stronger runtime status. The public surface holds at controlled validation; higher rungs are sealed gates that require separate evidence and human approval.
View levels as text
| Level | Status | What it does not prove |
|---|---|---|
| 01 · Controlled validation | SUPPORTED | It does not prove runtime activation or any signal observation. |
| 02 · Runtime path initialized | SOURCE-VISIBLE | Source presence is not runtime; nothing here is claimed as executed in production. |
| 03 · Runtime-supported (private) | PARTIAL | Public runtime proof is blocked; the private marker is not a public claim. |
| 04 · Runtime-observed (private) | PARTIAL | Public NDR, cross-source, and signal-observed proof are not claimed from this surface. |
| 05 · Public runtime proof | BLOCKED | Runtime-active, signal-observed, and public-safe runtime proof are blocked and not claimed until a separate promotion gate clears them. |
| 06 · Production / customer / fleet | BLOCKED | Production-ready, customer-validated, partner-endorsed, fleet-wide, and autonomous SOC claims are blocked and not made anywhere on this surface. |
Evidence bay
Proof records — receipts, not a ledger.
The flagship record leads; supporting records follow at lower weight. Each holds its bounded ceiling and a supports / does-not-prove split.
Controlled Validation Receipt · controlled-test validation
Supports
- The public ceiling is stated as CONTROLLED_TEST_VALIDATED.
- Blocked promotions are visible instead of hidden.
- Website rendering remains separated from evidence authority.
- The platform verifier preserves NOT_PUBLIC_SAFE and BLOCKED runtime promotion fields.
- The controlled validation receipt shows source, alert shape, validation, case packet, AI support, and human review as separate stages.
Does not prove
- Runtime activation is not claimed.
- Signal observation is not claimed.
- Public-safe runtime proof is not claimed.
- Live Splunk fired, Cribl-routed status, Wazuh-routed public proof, AWS-live status, production-ready status, fleet-wide coverage, autonomous SOC operation, AI-approved disposition, and analyst-approved disposition are not claimed.
- External-use approval is not claimed.
- Public-safe proof is not claimed.
- Production/customer/SOCaaS deployment, SOCaaS-ready status, FortiSIEM integration proven status, and autonomous production alert resolution are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- Runtime evidence must be promoted separately.
- Signal evidence must be promoted separately.
- Public proof requires evidence linkage.
- The platform runtime contract does not promote HO-DET-001 beyond CONTROLLED_TEST_VALIDATED.
- Blocked-claim scanner must stay clean before wording changes ship.
Promotion requirements
- Preserved validation output linked to the record.
- Evidence bundle with current trust classification.
- Runtime and signal claims reviewed independently.
- Public wording reviewed against blocked promotions.
CloudTrail-style IAM denial fixture proof card
Supports
- AWS-DET-001 passed fixture-only validation against controlled CloudTrail-style IAM denial fixtures.
- The website renders the public ceiling as CONTROLLED_TEST_VALIDATED.
Does not prove
- AWS-live status is not claimed.
- AWS CloudTrail live evidence is not claimed.
Remaining gates & promotion requirements
Remaining blocked
- AWS-live proof requires separate evidence and Raylee approval.
- Cloud runtime-active proof requires separate deployment evidence.
- Signal-observed public proof requires preserved cloud telemetry.
- Public-safe runtime proof requires evidence linkage and promotion.
Promotion requirements
- Real CloudTrail evidence with sanitization and stale review.
- Cloud deployment evidence linking the rule to an enabled environment.
- Public wording reviewed against the blocked-claim list.
- Raylee approval after evidence and claim review.
Windows Service Creation / Binary Change · bounded summary
Supports
- 17 / 17 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Public runtime proof and public signal-observed proof are not claimed.
- Splunk remains NOT_VERIFIED.
Remaining gates & promotion requirements
Remaining blocked
- Raw Wazuh lines, Windows event payloads, command output, host/user details, private paths, internal network details, service markers, correlation markers, and private hashes remain excluded.
- Public runtime proof requires a separate approval beyond this bounded summary.
Promotion requirements
- Separate proof/index vocabulary and approval before any stronger runtime or signal claim.
- Fresh wording review before publishing any evidence anchor or private hash.
Suspicious Scheduled Task Creation · bounded summary
Supports
- 8 / 8 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Public runtime proof and public signal-observed proof are not claimed.
- Splunk remains NOT_VERIFIED.
Remaining gates & promotion requirements
Remaining blocked
- Raw Wazuh lines, Windows event payloads, command output, host/user details, private paths, internal network details, task markers, correlation markers, and private hashes remain excluded.
- Public runtime proof requires a separate approval beyond this bounded summary.
Promotion requirements
- Separate proof/index vocabulary and approval before any stronger runtime or signal claim.
- Fresh wording review before publishing any evidence anchor or private hash.
Suspicious identity session context · no proof record
Supports
- 10 / 10 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Live IdP / SIEM / NDR coverage is not claimed.
- Production identity coverage and autonomous / AI disposition are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- A proof record must be created before public proof status.
Promotion requirements
- Proof record authored and linked to validation output.
MFA fatigue / repeated MFA failure · no proof record
Supports
- 10 / 10 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Live IdP and live SIEM / NDR are not claimed.
- Proof promotion and public-safe state are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- A proof record must be created before public proof status.
Promotion requirements
- Proof record authored and linked to validation output.
Privileged role / admin group change · no proof record
Supports
- 10 / 10 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Live IdP / SIEM coverage is not claimed.
- Production coverage and AI / analyst disposition are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- A proof record must be created before public proof status.
Promotion requirements
- Proof record authored and linked to validation output.
Impossible travel / anomalous session · no proof record
Supports
- 10 / 10 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Impossible-travel and session-hijacking completeness are not claimed.
- Live IdP and public-safe state are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- Completeness is blocked; a proof record must be created before public proof status.
Promotion requirements
- Proof record authored and linked to validation output.
Security Onion visibility contract · boundary scaffold
Supports
- A cross-source corroboration contract is defined.
Does not prove
- Security Onion runtime, Splunk search, and Cribl / Wazuh routes are not claimed.
- Zeek / Suricata quality and public-safe proof are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- Cross-source corroboration contract is defined, not promoted to proof.
Promotion requirements
- Fixtures authored and validated before any proof record.
Each record holds its bounded ceiling and routes reviewers to source and validation. Website rendering is not proof.
Promotion gates
What must hold before stronger wording ships.
The ladder is sequential — no rung is skipped. Stronger runtime, signal, and public proof wording cannot ship until its gate clears.
- G·01Current source artifact remains reviewable in the owning repository.
- G·02Validation output is deterministic and linked to the proof record.
- G·03Runtime state is independently evidenced before runtime claims move forward.
- G·04Signal state is independently evidenced before signal claims move forward.
- G·05Evidence linkage is explicit before public proof status changes.
- G·06Public wording is scanned against the blocked-claim list before release.
Governed work · Snapshot as of 2026-05-18
Recent governed proof-repo work
Recent governed work on the proof repo. Reviewer-visible cards that do not change the public claim ceiling. Stronger wording requires a separate evidence-backed promotion gate.
- DOCS_ARTIFACT2026-05-17
AI Governance Control Layer case study merged
Context-only case study describing the governed AI-assisted proof routing model. Not pipeline proof.
proof · #37Open review → - MERGED_PR2026-05-17
Proof Pack 001 reviewer-package wording hardened
Reviewer-package wording for Proof Pack 001 tightened. Wording only.
proof · #36Open review →
Routes
Where to inspect next.
Rendering is not proof.
Evidence, validators, and human review authorize claims. The website routes reviewers to proof; it does not author it.
