How It Works

Proof Model

How External Attack Surface Review declarations, evidence bytes, signatures, trust policy, and verifier checks form separate assurance layers.

WitnessOps proof is layered. A workflow declaration, evidence package, signature, signer policy, and verifier result answer different questions and must not be collapsed into one badge.

1. Current sequence

  1. The approved External Attack Surface Review produces source records within its frozen scope and method.
  2. The bounded OffSec adapter exports eligible records, stages actual files, and derives real manifest artifact IDs.
  3. The proof engine normalizes records, compares workflow claims, builds the package, and signs the receipt when an authorized signing input is supplied.
  4. A separate verifier can recompute package bytes, evidence support, signature, workflow checks, and explicit trust policy.
  5. The public web adapter accepts receipt JSON only and reports which receipt-profile checks ran and which required checks did not.

2. Assurance layers

LayerInputWhat a successful check can establish
Receipt profilewitnessops.receipt.v0 + legacy public_exposure_review contextSubmitted JSON preserves the expected product fields, claims, limitations, method, and relationships
Evidence integrityManifest and referenced artifact bytesSupplied files match declared hashes and references resolve
Evidence supportClaims plus independently inspected artifactsSupplied artifacts support the recorded claim status under the declared method
SignatureCanonical receipt bytes, Ed25519 signature, public keyThe signature matches that key
Production signer policyPinned registry revision/hash, allowlist, validity, usage, custody, revocationThe key was accepted for this production workflow under that policy
Workflow verificationRequest, authority, frozen schedules, execution recordsThe recorded work stayed within the accepted workflow contract

Passing one row does not imply the others passed.

3. Producer and verifier results

The proof engine's verification_result.json is deterministic producer-side output. It records build and comparison checks and preserves unresolved states. It is not proof that a separate party reran those checks.

An independent result requires a separate verifier invocation with the package and reviewer- or server-owned trust inputs. The canonical full verifier is currently internal and is not a supported public distribution.

4. Public result today

The public adapter checks receipt structure and the exact legacy-named public_exposure_review profile. It does not receive package bytes or an active production trust snapshot. A conforming receipt using that profile therefore returns indeterminate; a profile conflict returns invalid.

For the legacy public_exposure_review profile described here, the documented production signing policy is draft and allowlists no keys. This is not a statement about the separate Local Audit trust policy. Signature syntax is not signature verification, and a key included in a package is not automatically trusted.

5. Optional compatibility layers

Some retained or compatibility formats declare timestamps, DSSE envelopes, predecessor chains, Merkle roots, checkpoints, or inclusion proofs. Those layers are testable only when the specific artifacts and trust roots are supplied and the selected verifier implements that profile. They are not universal public_exposure_review receipt fields.

6. Limits

Even a fully verified package does not prove tool correctness, uncompromised source hosts, perfect human judgment, system security, absence of vulnerabilities, or completeness outside the approved scope.

7. Next-page handoff

Read Evidence Bundles, Verification, and Receipt Specification for the executable contracts.

Related technical reference: Anchored replay and Standards. These are profile-specific concepts, not additional app features.

Proof Model | WitnessOps