Orientation

Buyer path for a security or operational review

A buyer-facing reading path: start from the situation, inspect the catalogue and samples, understand the verifier boundary, then send a non-secret fit check.

This Page Answers

What should a buyer inspect before starting a WitnessOps review, and what does the request form actually start?

This page gives a buyer-readable path through the public WitnessOps surfaces before submitting a real request.

It is for a reviewer who wants to know:

  • what the public catalogue offers
  • what a sample demonstrates
  • what the verifier can and cannot check
  • what the request form starts
  • what must not be submitted in the first message
  • what remains outside the engagement boundary

1. Start with the situation and the catalogue

WitnessOps delivers bounded security and operational reviews with evidence references, named limits and unresolved items. The public catalogue is six active services (same names, prices and timing terms in English and Polish):

  1. Customer Security Review Sprint
  2. Bounded Workflow Review
  3. One Server Security Check
  4. Launch Readiness Check
  5. Key, Access and Custody Review
  6. Incident Readiness Review

Read View services first. For the questionnaire offer, see Customer Security Review Sprint (from €1,600 after a non-secret fit check; English and Polish one-pagers are linked from that page and the catalogue).

Do not read the catalogue as a broad AI governance program, production deployment claim, legal compliance claim, certification, or whole-environment assurance claim.

2. Inspect a sample before sending secrets

Open AI-agent sample package or other sample cases.

Samples are public illustrations. They demonstrate receipt shape and verifier path only. They are not live customer evidence.

For the pinned AI-agent public sample only, use the table below:

ArtifactWhat to check
ACTION_BOUNDARY.jsonWhat the workflow was allowed to do and what stayed out of scope.
AUTHORITY_MAP.jsonWho approved, acted, observed, reviewed, or challenged the action.
EVIDENCE_MANIFEST.jsonWhich evidence classes are present and which gaps are declared.
RECEIPT.jsonHow approval, action, evidence, result, and limits are bound into one record.
VERIFY_RESULT.jsonWhat the sample verifier result reports and what it does not establish.
CHALLENGE_PATH.mdHow another party can inspect, dispute, or request stronger evidence.
MANIFEST.sha256Whether sample files match the published hash manifest.

3. Understand the verifier boundary

Use Verify a receipt when you have receipt JSON to check — upload or paste, then read the result.

The public console is receipt-first v1. It can check supported receipt JSON. It does not prove the full runtime story, source-system honesty, artifact-byte revalidation, or complete bundle custody.

Read a valid result as receipt-scoped unless a page or bundle names a stronger verifier path and the artifacts needed for that path.

For the full procedure split (public vs offline bundle-complete), read How to Verify a Receipt.

4. Commercial scope

Use Pricing and Commercial Scope and the catalogue for current public prices and ranges. Fee, timing, and evidence handling for a real engagement are confirmed after a non-secret fit check.

5. Submit only the first non-secret fit check

Use Start a review only after you can describe one bounded situation in plain language.

The request form is a non-secret fit check. Start with a general description. Do not send files, credentials, logs, screenshots, private keys, API keys, MFA codes, recovery codes, session tokens or customer evidence during the fit check.

Fallback contact: engage@mail.witnessops.com.

6. Mailbox verification is not review start

After the request form, the mailbox verification step confirms mailbox access only.

The confirmation page means:

  • the mailbox was confirmed for the request
  • no review work has started
  • no customer evidence has been accepted
  • scope, fee, and evidence handling still need to be agreed

7. What happens after the fit check

If the situation fits, WitnessOps confirms the review, scope, authority, price, timing and evidence handling by email before secret material is accepted.

The engagement should make five things easy to see:

  • what the situation was
  • what was authorised and included
  • what was checked or reviewed
  • which material supports the result
  • what remains limited, unknown or unresolved

8. Stop conditions

Stop and do not submit secrets if:

  • the work cannot be bounded to one useful scope
  • no approving authority can be named
  • required evidence cannot be handled safely
  • the goal is a broad compliance certification
  • the goal is a legal audit opinion
  • the request requires production secrets in the first message

9. Minimal buyer reading order

  1. View services
  2. Customer Security Review Sprint (if relevant)
  3. Sample cases
  4. Verify a receipt
  5. Start a review
  6. Verification docs

The key rule: do not rely on a claim unless the evidence reference, receipt, verifier result or named limit that supports it is visible.

Related

Buyer path for a security or operational review | WitnessOps