Evidence vault · claim authority hub
Proof is what survives validation, boundaries, and human review.
The website routes reviewers to proof. It does not authorize claims. Claims either survive the vault — validators, evidence boundaries, and human review — or they stop at the gate.
Governance Saves · proof of value
Controls Fired Before Bad Truth Shipped
72 public-facing records from GS-001 through GS-080 source range. Private-only records are excluded from this surface.
View as table
| Category | Count | What it covers |
|---|---|---|
| Claim boundary | 16 | Public copy was downgraded, narrowed, or held to match repo-visible evidence — never inflated to runtime, signal, or production wording. |
| Runtime boundary | 7 | Private runtime evidence, mirror traffic, and legacy automation were kept out of public runtime/signal claims. |
| Validator hardening | 8 | Review-thread fixes converted verifier edge cases into deterministic fail-closed paths before merge. |
| AI authority | 2 | AI output stayed support-only. Verifiers enforce human review and block AI-decided disposition. |
| Merge authority | 13 | Green CI never became merge authority. Review, scope, resolved threads, and human approval stayed above checks. |
| Evidence protection | 3 | Non-public evidence, host-local paths, and operator notes were kept off public surfaces and out of public proof. |
| Release gate | 2 | Release wording, checksums, and reviewer-package state were gated before any "approved release" claim could surface. |
| Branch hygiene | 16 | Branch divergence, dirty trees, wrong-branch preflights, and direct-main pushes were stopped before they touched source truth. |
| Workflow hardening | 5 | Required-check rulesets, audit findings, and CODEOWNERS reality were treated as enforcement evidence only when verified. |
Private-only records are excluded from this surface.
Claim firewall
Claims pass, wait, or stop at the gate.
A deterministic scanner, evidence gates, and human review authority sit between a claim and the public surface. Blocked terms stay visible — they describe what this surface does not assert.
View all lanes as text
ALLOWED — Passes the gate
These claims are backed by reviewer-inspectable evidence at the controlled-test ceiling, so they ship to the public surface.
- Controlled validation where supported
- Reviewer-inspectable proof surfaces
- Reviewer-inspectable artifacts
- Governance saves — controls that fired
CAREFUL — Held for review
These describe bounded, private-evidence work. They survive only as summaries and require a separate evidence-backed promotion gate before any stronger wording advances.
- Runtime-supported (private)
- Runtime-observed (private, source-supported only)
- Closed controlled loop
- SOCaaS-style model
- AI triage support (support-only)
BLOCKED · NOT CLAIMED — Stops at the gate
These terms are blocked from public wording. They are not claimed anywhere on this surface and stay blocked until a separate evidence-backed promotion gate changes their state.
- runtime-active
- signal-observed
- public-safe runtime proof
- production-ready
- production/customer/SOCaaS deployment
- SOCaaS-ready
- FortiSIEM integration proven
- fleet-wide
- live Splunk fired
- Splunk-proven Runtime Signal 001
- Cribl-routed
- Wazuh-routed
- AWS-live
- autonomous SOC
- AI-approved disposition
- analyst-approved disposition
- public-safe
- public runtime proof (unless separately promoted)
- production / customer validated
- partner / endorsed
Blocked claims
Kept off the public surface by design
These claims remain blocked unless separate evidence-backed promotion changes their state. Visibility of the blocked list keeps the supported ceiling honest.
- runtime-active
- signal-observed
- public-safe runtime proof
- production-ready
- production/customer/SOCaaS deployment
- SOCaaS-ready
- FortiSIEM integration proven
- fleet-wide
Public-safe runtime proof is not claimed.
Cribl-routed, Wazuh-routed, AWS-live are not claimed.
Autonomous SOC and AI-approved disposition are not claimed.
Sealed reviewer package
Proof Pack 001 — a bounded reviewer package.
The receipt states what the package supports and what it does not prove. Raw / private runtime evidence is excluded and public runtime proof stays blocked.
Included · reviewer package (7)
Excluded · blocked from public release (2)
Does not prove
An official direct GitHub Release route exists. Source packet manifest / check-mode language remains source-packet / release-candidate metadata — a route / status distinction, not a stronger proof claim.
Render-only ledger route
Lifetime Case Ledger v1
The website is render-only; the proof repo owns the summary and proof bundle. The badges are workflow-status indicators only. Boundary: no runtime, signal, public-safe runtime proof, SOCaaS, production, autonomous SOC, disposition, or case-closure claim is made.
Runtime boundary
The runtime proof tower — what survives, what stays sealed.
Each level names a stronger runtime status. The public surface holds at controlled validation; higher rungs are sealed gates that require separate evidence and human approval.
View levels as text
| Level | Status | What it does not prove |
|---|---|---|
| 01 · Controlled validation | SUPPORTED | It does not prove runtime activation or any signal observation. |
| 02 · Runtime path initialized | SOURCE-VISIBLE | Source presence is not runtime; nothing here is claimed as executed in production. |
| 03 · Runtime-supported (private) | PARTIAL | Public runtime proof is blocked; the private marker is not a public claim. |
| 04 · Runtime-observed (private) | PARTIAL | Public NDR, cross-source, and signal-observed proof are not claimed from this surface. |
| 05 · Public runtime proof | BLOCKED | Runtime-active, signal-observed, and public-safe runtime proof are blocked and not claimed until a separate promotion gate clears them. |
| 06 · Production / customer / fleet | BLOCKED | Production-ready, customer-validated, partner-endorsed, fleet-wide, and autonomous SOC claims are blocked and not made anywhere on this surface. |
Evidence bay
Proof records — receipts, not a ledger.
The flagship record leads; supporting records follow at lower weight. Each holds its bounded ceiling and a supports / does-not-prove split.
SOCaaS Pilot Receipt · controlled-test validation
Supports
- The public ceiling is stated as CONTROLLED_TEST_VALIDATED.
- Blocked promotions are visible instead of hidden.
- Website rendering remains separated from evidence authority.
- The platform verifier preserves NOT_PUBLIC_SAFE and BLOCKED runtime promotion fields.
- The SOCaaS Pilot Receipt shows source, alert shape, validation, case packet, AI support, and human review as separate stages.
Does not prove
- Runtime activation is not claimed.
- Signal observation is not claimed.
- Public-safe runtime proof is not claimed.
- Live Splunk fired, Cribl-routed status, Wazuh-routed public proof, AWS-live status, production-ready status, fleet-wide coverage, autonomous SOC operation, AI-approved disposition, and analyst-approved disposition are not claimed.
- External-use approval is not claimed.
- Public-safe proof is not claimed.
- Production/customer/SOCaaS deployment, SOCaaS-ready status, FortiSIEM integration proven status, and autonomous production alert resolution are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- Runtime evidence must be promoted separately.
- Signal evidence must be promoted separately.
- Public proof requires evidence linkage.
- The platform runtime contract does not promote HO-DET-001 beyond CONTROLLED_TEST_VALIDATED.
- Blocked-claim scanner must stay clean before wording changes ship.
Promotion requirements
- Preserved validation output linked to the record.
- Evidence bundle with current trust classification.
- Runtime and signal claims reviewed independently.
- Public wording reviewed against blocked promotions.
CloudTrail-style IAM denial fixture proof card
Supports
- AWS-DET-001 passed fixture-only validation against controlled CloudTrail-style IAM denial fixtures.
- The website renders the public ceiling as CONTROLLED_TEST_VALIDATED.
Does not prove
- AWS-live status is not claimed.
- AWS CloudTrail live evidence is not claimed.
Remaining gates & promotion requirements
Remaining blocked
- AWS-live proof requires separate evidence and Raylee approval.
- Cloud runtime-active proof requires separate deployment evidence.
- Signal-observed public proof requires preserved cloud telemetry.
- Public-safe runtime proof requires evidence linkage and promotion.
Promotion requirements
- Real CloudTrail evidence with sanitization and stale review.
- Cloud deployment evidence linking the rule to an enabled environment.
- Public wording reviewed against the blocked-claim list.
- Raylee approval after evidence and claim review.
Windows Service Creation / Binary Change · bounded summary
Supports
- 17 / 17 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Public runtime proof and public signal-observed proof are not claimed.
- Splunk remains NOT_VERIFIED.
Remaining gates & promotion requirements
Remaining blocked
- Raw Wazuh lines, Windows event payloads, command output, host/user details, private paths, internal network details, service markers, correlation markers, and private hashes remain excluded.
- Public runtime proof requires a separate approval beyond this bounded summary.
Promotion requirements
- Separate proof/index vocabulary and approval before any stronger runtime or signal claim.
- Fresh wording review before publishing any evidence anchor or private hash.
Suspicious Scheduled Task Creation · bounded summary
Supports
- 8 / 8 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Public runtime proof and public signal-observed proof are not claimed.
- Splunk remains NOT_VERIFIED.
Remaining gates & promotion requirements
Remaining blocked
- Raw Wazuh lines, Windows event payloads, command output, host/user details, private paths, internal network details, task markers, correlation markers, and private hashes remain excluded.
- Public runtime proof requires a separate approval beyond this bounded summary.
Promotion requirements
- Separate proof/index vocabulary and approval before any stronger runtime or signal claim.
- Fresh wording review before publishing any evidence anchor or private hash.
Suspicious identity session context · no proof record
Supports
- 10 / 10 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Live IdP / SIEM / NDR coverage is not claimed.
- Production identity coverage and autonomous / AI disposition are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- A proof record must be created before public proof status.
Promotion requirements
- Proof record authored and linked to validation output.
MFA fatigue / repeated MFA failure · no proof record
Supports
- 10 / 10 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Live IdP and live SIEM / NDR are not claimed.
- Proof promotion and public-safe state are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- A proof record must be created before public proof status.
Promotion requirements
- Proof record authored and linked to validation output.
Privileged role / admin group change · no proof record
Supports
- 10 / 10 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Live IdP / SIEM coverage is not claimed.
- Production coverage and AI / analyst disposition are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- A proof record must be created before public proof status.
Promotion requirements
- Proof record authored and linked to validation output.
Impossible travel / anomalous session · no proof record
Supports
- 10 / 10 fixtures pass deterministically.
- 0 missed positives and 0 false-positive negatives.
Does not prove
- Impossible-travel and session-hijacking completeness are not claimed.
- Live IdP and public-safe state are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- Completeness is blocked; a proof record must be created before public proof status.
Promotion requirements
- Proof record authored and linked to validation output.
Security Onion visibility contract · boundary scaffold
Supports
- A cross-source corroboration contract is defined.
Does not prove
- Security Onion runtime, Splunk search, and Cribl / Wazuh routes are not claimed.
- Zeek / Suricata quality and public-safe proof are not claimed.
Remaining gates & promotion requirements
Remaining blocked
- Cross-source corroboration contract is defined, not promoted to proof.
Promotion requirements
- Fixtures authored and validated before any proof record.
Each record holds its bounded ceiling and routes reviewers to source and validation. Website rendering is not proof.
Promotion gates
What must hold before stronger wording ships.
The ladder is sequential — no rung is skipped. Stronger runtime, signal, and public proof wording cannot ship until its gate clears.
- G·01Current source artifact remains reviewable in the owning repository.
- G·02Validation output is deterministic and linked to the proof record.
- G·03Runtime state is independently evidenced before runtime claims move forward.
- G·04Signal state is independently evidenced before signal claims move forward.
- G·05Evidence linkage is explicit before public proof status changes.
- G·06Public wording is scanned against the blocked-claim list before release.
Governed work · Snapshot as of 2026-05-18
Recent governed proof-repo work
Recent governed work on the proof repo. Reviewer-visible cards that do not change the public claim ceiling. Stronger wording requires a separate evidence-backed promotion gate.
- DOCS_ARTIFACT2026-05-17
AI Governance Control Layer case study merged
Context-only case study describing the governed AI-assisted proof routing model. Not pipeline proof.
proof · #37Open review → - MERGED_PR2026-05-17
Proof Pack 001 reviewer-package wording hardened
Reviewer-package wording for Proof Pack 001 tightened. Wording only.
proof · #36Open review →
Routes
Where to inspect next.
Rendering is not proof.
Evidence, validators, and human review authorize claims. The website routes reviewers to proof; it does not author it.
