PUBLIC TAXONOMY
Eleven bounded evidence classes
The taxonomy separates specification, test, build, release, runtime, operational, observation, incident, independent reproduction, external review, and regulatory or compliance evidence.
specification
Specification evidence
Defines an intended public contract, model, interface, or boundary.
- Authority
- Authoritative for the stated design and boundary only.
- Integrity
- Versioned repository path and any published content hash or revision.
- Freshness
- Bound to its reviewed date and superseded by a later identified revision.
- Disclosure
- May describe public contracts without exposing secrets, private topology, or customer data.
Does not prove: Runtime deployment Production safety External assurance
test
Test evidence
Records a repeatable check of a declared behavior or fixture.
- Authority
- Authoritative only for the exercised behavior, environment, and result scope.
- Integrity
- Versioned test source, fixture identifiers, and retained output when published.
- Freshness
- Fresh only for the tested revision and declared environment.
- Disclosure
- Do not expose protected inputs, secrets, or customer data in public fixtures.
Does not prove: Unexercised behavior Production operation Complete security
build
Build evidence
Connects a generated artifact or tool capture to a declared source revision or build process.
- Authority
- Authoritative for the named artifact or version capture, not for a broader runtime state.
- Integrity
- Content hashes, source revision bindings, and deterministic generation checks where available.
- Freshness
- Fresh only for the declared source revision and captured environment.
- Disclosure
- Never publish build secrets, private environment values, or provider internals.
Does not prove: Production deployment Runtime health Security of an installed tool
release
Release evidence
Binds a public release record to listed artifacts and stated validation scope.
- Authority
- Authoritative only for the disclosed static artifact set and stated release boundary.
- Integrity
- Source commit, content digests, and a release-manifest record.
- Freshness
- Point-in-time at the release record timestamp and invalid after a different release is promoted.
- Disclosure
- Does not disclose provider credentials, project internals, or protected runtime surfaces.
Does not prove: Live API state Protected-system behavior Future availability
runtime
Runtime evidence
Describes a bounded observation of an executing system in a declared environment.
- Authority
- Authoritative only for the recorded environment, time, and measured signal.
- Integrity
- Authenticated collection, timestamping, and integrity checks appropriate to the runtime source.
- Freshness
- Short-lived and explicitly timestamped.
- Disclosure
- Must not disclose private endpoints, secrets, personal data, or protected topology.
Does not prove: All runtime behavior Security of unrelated systems Perpetual availability
operational
Operational evidence
Records a declared operating process, ownership boundary, or service state.
- Authority
- Authoritative only for the declared operating boundary and review date.
- Integrity
- Versioned source, owner, review date, and route or document binding.
- Freshness
- Reviewed at the stated cadence and revised when operating scope changes.
- Disclosure
- Public records exclude secrets, private incident detail, and customer-specific operations.
Does not prove: SLO attainment Production safety Contract terms not published
observation
Observation evidence
Describes a bounded public observation with declared source and failure semantics.
- Authority
- Authoritative only for the disclosed observation field set and time.
- Integrity
- Declared signature, key metadata, canonicalization, and freshness controls where present.
- Freshness
- Explicitly timestamped and subject to the route's freshness state.
- Disclosure
- Never exposes signing keys, private gateway addresses, peers, or administrative controls.
Does not prove: Contract safety Bytecode identity Reserve state Chain-wide finality
incident
Incident evidence
Records a scoped issue report, impact statement, and handling path.
- Authority
- Authoritative only for the explicitly recorded issue and handling scope.
- Integrity
- Case identifier, protected evidence handling, and documented reproduction scope.
- Freshness
- Changes as investigation, remediation, or disclosure state changes.
- Disclosure
- Protect secrets, customer information, and exploitable details until disclosure is approved.
Does not prove: Absence of vulnerabilities Complete remediation Security certification
independent-reproduction
Independent reproduction evidence
Records an independently repeated result against a stated procedure and scope.
- Authority
- Authoritative only for the reproduced procedure, artifact, and declared environment.
- Integrity
- Independent actor identity, versioned procedure, and retained result receipt.
- Freshness
- Bound to the reproduced revision and environment.
- Disclosure
- Do not disclose protected inputs or third-party confidential materials.
Does not prove: Formal correctness Production safety Universal reproducibility
external-review
External review evidence
Records an externally scoped review with a named method and conclusion boundary.
- Authority
- Authoritative only for the named reviewer, scope, method, and finding date.
- Integrity
- Reviewer identity, immutable report reference, and scope/version binding.
- Freshness
- Bound to the reviewed version and report date.
- Disclosure
- Publish only approved findings without exposing protected systems or confidential report material.
Does not prove: Coverage outside scope Future security Regulatory approval
regulatory-compliance
Regulatory or compliance evidence
Records a regulator, registry, or compliance-source fact with stated jurisdiction and date.
- Authority
- Authoritative only for the cited authority, jurisdiction, record date, and stated fact.
- Integrity
- Official authority reference, lookup identifier, and retained verification date.
- Freshness
- Bound to the authority's current record and the stated verification date.
- Disclosure
- Do not publish private registry material, personal data, or legal advice.
Does not prove: Legal advice Product approval Compliance outside the cited scope