Evidence ceiling E3Proof boundary

INSTITUTIONAL CONTROL MATRIX

Inspect the controls. Challenge the assumptions.

Public Site 80 exposes the Site 77-originated control baseline as historical engineering provenance rather than using customer-ready as an unbounded claim.

Controls

34/34 seller-controlled engineering controls

External effectiveness must still be demonstrated by institution-owned operation and outside evaluation.

01

TENANT_LIFECYCLE

REFERENCE TESTED

Tenant creation, suspension, isolation and termination are explicit and fail closed.

02

TENANT_OBJECT_AUTHORIZATION

REFERENCE TESTED

Every tenant-bound object operation requires object-level tenant authorization.

03

RBAC_ABAC

REFERENCE TESTED

Role and attribute constraints compose; cross-tenant access is denied.

04

SEGREGATION_OF_DUTIES

REFERENCE TESTED

High-risk changes support dual authorization by distinct principals.

05

OIDC_FEDERATION

REFERENCE TESTED

OIDC issuer/audience/key/signature and freshness validation is implemented.

06

SAML_FEDERATION_CONTRACT

REFERENCE TESTED

SAML metadata, entity, signing and audience requirements are modeled as a bindable institutional contract.

07

SCIM_2_LIFECYCLE

REFERENCE TESTED

SCIM-style Users/Groups create, read, replace, patch, disable and delete semantics are implemented.

08

PHISHING_RESISTANT_ADMIN_AUTH

REFERENCE TESTED

Privileged policy requires phishing-resistant MFA or institution-declared equivalent.

09

SERVICE_CREDENTIALS

REFERENCE TESTED

Service credentials are scoped, expiring, hash-only at rest, rotatable and revocable.

10

SENDER_CONSTRAINED_TOKENS

REFERENCE TESTED

DPoP proof validation and replay rejection are implemented for high-risk API profiles.

11

IDEMPOTENCY_FINGERPRINT

REFERENCE TESTED

Idempotency binds key to request fingerprint and rejects key reuse with a different request.

12

RATE_LIMITING

REFERENCE TESTED

Tenant and principal request budgets fail closed without granting authorization.

13

PROBLEM_DETAILS

REFERENCE TESTED

Machine-readable API failures have stable problem types and request correlation.

14

KEY_CUSTODY_POLICY

REFERENCE TESTED

Customer KMS/HSM, cloud KMS and seller-reference custody are distinct states.

15

CRYPTOGRAPHIC_AGILITY

REFERENCE TESTED

Key version, allowed algorithms, rotation and deprecation are policy objects.

16

PQC_MIGRATION_INTERFACE

REFERENCE TESTED

PQC migration readiness is explicit without claiming FIPS validation or deployment.

17

DATA_CLASSIFICATION

REFERENCE TESTED

Data classification is mandatory for protected workloads.

18

PURPOSE_LIMITATION

REFERENCE TESTED

Data use is bound to declared purpose and authorization.

19

DATA_RESIDENCY

REFERENCE TESTED

Allowed regions are policy-bound and fail closed.

20

RETENTION_LEGAL_HOLD

REFERENCE TESTED

Retention and legal hold override deletion deterministically.

21

CROSS_CUSTOMER_TRAINING_DENY

REFERENCE TESTED

Cross-customer model training is denied by default.

22

WEBHOOK_HMAC

REFERENCE TESTED

Webhook payloads are secret-authenticated with timestamp and nonce binding.

23

WEBHOOK_REPLAY_DEFENSE

REFERENCE TESTED

Duplicate webhook nonce or stale timestamp is rejected.

24

WEBHOOK_SSRF_GUARD

REFERENCE TESTED

Webhook targets reject loopback, link-local, private-IP and non-HTTPS destinations.

25

WEBHOOK_RETRY_DLQ

REFERENCE TESTED

Retries have bounded exponential backoff and dead-letter state.

26

HASH_CHAINED_AUDIT

REFERENCE TESTED

Security and consequential changes produce append-only hash-linked audit evidence.

27

SIEM_EXPORT

REFERENCE TESTED

Audit export is redacted, structured and SIEM/OpenTelemetry compatible.

28

BACKUP_INTEGRITY

REFERENCE TESTED

Backups carry integrity manifests and reject tampered restore.

29

RPO_RTO_POLICY

REFERENCE TESTED

Recovery point and recovery time objectives are explicit policy objects.

30

RECOVERY_DRILL_EVIDENCE

REFERENCE TESTED

Recovery drills produce attributable receipts; seller drills do not become customer evidence.

31

INCIDENT_KILL_SWITCH

REFERENCE TESTED

Incident state can suspend high-risk mutation while preserving read/audit access.

32

SECURE_BUILD_PROVENANCE

REFERENCE TESTED

SBOM, source identity, build provenance and verification are required publication inputs.

33

CUSTOMER_ACTIVATION_TRUTH_GATE

REFERENCE TESTED

Customer-live status requires externally signed activation evidence and cannot self-promote.

34

NO_EXTERNAL_EVIDENCE_SELF_PROMOTION

REFERENCE TESTED

Seller evidence cannot mint E4/E5/E6, customer-live, certification or adoption.

Threats

14 explicit threat mappings

Fail-closed states are documented so reviewers can falsify the intended protections.

01

cross-tenant object access

TENANT_OBJECT_AUTHORIZATION

TENANT_BOUNDARY_DENIED

02

stolen bearer token replay

SENDER_CONSTRAINED_TOKENS

DPOP_REPLAY_OR_BINDING_DENIED

03

privileged single-actor control change

SEGREGATION_OF_DUTIES

SELF_OR_INCOMPLETE_APPROVAL_DENIED

04

identity lifecycle drift

SCIM_2_LIFECYCLE

INACTIVE_IDENTITY_REMOVED_FROM_ACTIVE_GROUP_USE

05

webhook replay or forgery

WEBHOOK_HMAC

SIGNATURE_OR_NONCE_REJECTED

06

webhook SSRF

WEBHOOK_SSRF_GUARD

PRIVATE_LOOPBACK_OR_NON_HTTPS_TARGET_DENIED

07

idempotency-key semantic collision

IDEMPOTENCY_FINGERPRINT

KEY_REUSE_WITH_DIFFERENT_REQUEST_DENIED

08

unsafe data reuse

PURPOSE_LIMITATION

PURPOSE_OR_CROSS_CUSTOMER_USE_DENIED

09

legal-hold bypass

RETENTION_LEGAL_HOLD

DELETE_DENIED_WHILE_HOLD_OR_RETENTION_ACTIVE

10

audit erasure or silent rewrite

HASH_CHAINED_AUDIT

CHAIN_VERIFICATION_FAILS_ON_MUTATION

11

backup tamper or untested recovery

BACKUP_INTEGRITY

RECOVERY_READINESS_FAILS

12

incident-time unsafe mutation

INCIDENT_KILL_SWITCH

HIGH_RISK_MUTATION_HALTED

13

unsupported customer-live claim

CUSTOMER_ACTIVATION_TRUTH_GATE

CUSTOMER_LIVE_FALSE_UNTIL_ALL_EXTERNAL_GATES_PASS

14

supply-chain artifact substitution

SECURE_BUILD_PROVENANCE

PUBLICATION_GATE_DENIED

Public knowledge index

Search Finality Group

Protected, owner-only and legacy content is excluded.