Entry Surface

FAQ

Free signup, workspace creation and invitations, browser and CLI access, reports, pricing and support.

Accounts and app access

Is signup free? Do I need a card?

Creating an account is free. No card or subscription is required. The pricing page now lists the published one-off review offers. Signup does not grant a paid app plan.

Do I need an invitation after signup?

No invitation is needed to create your own workspace after verifying your email. To join someone else’s workspace, its Owner invites you through Members; accept using the matching verified email. Existing Early Access invitations retain their activation prompt. For missing or paused access, use Support.

Do I have to install the app?

No. Use the browser app. The optional CLI currently runs from an approved source checkout with Node.js 22; do not assume a published npm installer exists.

Does a free check require signup?

No. The public free check, its result and download require no account. It does not automatically import into a workspace or authorize further checks.

Why can I not start a check or find a report?

Owners and Contributors can authorize supported checks; Viewers can read and export accessible workspace results. Owners manage membership and report publication. Reports require saved observations. Start with Your first observation or Account and CLI help.

Are reports signed proof?

A report is a derived presentation. External Exposure snapshots are unsigned. Local Audit Proofpacks use a separate signed-receipt and ZIP-signature checking path. Read Understand results and reports; no format proves whole-system security or source-system truth.

Can AI solve an account issue or submit a ticket?

AI can explain public guidance but cannot access your workspace, issue invitations or submit tickets. Use Contact support and verify your email for a human request. You do not need a paid review for ordinary product support.

Expert help and technical reference

The remaining questions describe separately scoped reviews and the documented governed-workflow model. They are not additional app features or permissions.

Commercial Entry Point

What is the primary paid entry point?

Agent Action Security Review reviews one consequential agent or automation action across authority, identity, permissions, tools, execution, and evidence. It covers one action for €2,500 fixed · excluding VAT, begins with a non-secret fit check, and is delivered within 10 working days after evidence rules are agreed. Agent Workflow Reconstruction is the delivery method underneath the buyer-facing security review.

Scope limit: the default mode is read, inspect, reconstruct, and report. It does not include production modification, destructive testing, exploitation, credential changes, persistence, continuous monitoring, certification that an agent is safe, platform installation, custom protocol development, or multi-workflow programmes. External Attack Surface Review remains separate secondary catalogue work at €1,900 · excluding VAT with its existing caps, start conditions, and retest. It is not a penetration test.

Execution, Proof, and Presentation

Is WitnessOps a scanner?

The app offers bounded observations, and expert services provide separately scoped reviews. The technical governed-execution model describes tool orchestration; it is not a promise that every documented scanner or runbook is available in the app.

Scope limit: finding quality still depends on the underlying tool and its configuration. See Governed Execution and Runbooks.

What is the difference between execution and proof?

Execution is runtime control (executed, denied, paused, failed). Proof is post-execution verification of supplied artifacts and trust inputs (valid, invalid, indeterminate).

Scope limit: successful execution is not automatically a successful proof result, and proof validity is not a claim about business impact. See Governed Execution, Proof Model, and How to Verify a Receipt.

What is the difference between proof and presentation?

Proof artifacts are verification-bearing materials, such as receipts, manifests, trust material, and continuity artifacts. Presentation is operator-facing display: dashboards, summaries, and status views.

Scope limit: presentation can summarize proof, but it is not proof-bearing on its own. See Proof Model and Evidence Bundles.

Does a receipt prove a finding is true?

No. A receipt declares a governed claim, a manifest digest, evidence references, and signature material. Cryptographic binding is established only when the matching bytes, signature, and trusted signer policy are independently checked.

Scope limit: receipt validity does not prove exploitability, severity, remediation quality, or organizational risk acceptance. See Receipts, Receipt Spec, and What Evidence Is Required?.

Authority and Runtime Boundaries

Who has authority to let a step run?

In the documented operator workflow model, runtime gates evaluate policy-bound principals (operator, approver, system) and permit or deny execution accordingly.

Scope limit: WitnessOps enforces the configured authorization contract; it does not independently guarantee upstream identity sources are truthful. See Authorization Model and Policy Gates.

Can an operator bypass policy gates?

In that model, a failed required gate blocks the step. Confirm the actual implementation before claiming a deployed control enforced it. A tool may still be run outside WitnessOps, but that action is outside governance and outside the WitnessOps receipt chain.

Scope limit: without a verified WitnessOps receipt, available evidence does not establish governed execution for that action. It does not prove that no action happened elsewhere. See Governed Execution and Lab Mode and Scope Bypass.

What verification is public today?

Public receipt-only checks run at /verify (or /api/verify for the same path). Upload or paste supported receipt JSON and read the adapter, named checks, limitations, and verdict. The legacy-named public_exposure_review receipt profile, created under the former Public Exposure Review name, remains indeterminate when conforming because the full evidence and production trust inputs are not independently checked there.

Scope limit: /verify does not accept proof bundles or caller-supplied trust material, recompute artifact bytes, or rerun tools against live targets. Full package verification is a separate internal path and is not currently a supported public distribution. See How to Verify a Receipt and Evidence Bundles.

Evidence Sufficiency and Decisions

How much evidence is enough?

Enough means sufficient for the current decision (proceed, close, escalate), not maximum artifact volume.

Scope limit: more artifacts do not automatically strengthen a claim; sufficiency depends on claim relevance, quality, and reviewability. See What Evidence Is Required? and Do I Need to Escalate?.

Does WitnessOps replace reviewer judgment?

No. WitnessOps makes execution and proof artifacts reviewable; humans still interpret risk, context, and acceptable action.

Scope limit: governance and proof reduce ambiguity but do not remove outside trust assumptions. See Three-Layer Stack and Threat Model and Trust Boundaries.

Need term definitions first?

Use the Glossary for canonical definitions before deep review or dispute handling.

FAQ | WitnessOps