Sample work

Illustrative reviews, findings and evidence.

Inspect the evidence, findings and limits of a bounded review. Published sample, not live customer evidence. No production verification or certification.

Sample cases

External Exposure assessment

Synthetic sample reportExternal Exposure

Situation

A bounded external review is documented in a synthetic sample report.

What you can inspect

The existing report, findings, evidence references and limits. Not a live assessment of your environment.

Open example →

Local server security review

Full sample packageSynthetic host

Situation

A read-only local server security review was packaged for inspection.

What you can inspect

How posture and findings sit next to a receipt and hash manifest, and what /verify does and does not confirm for this sample.

Open example →

Launch readiness review

Full sample packageOFFSEC-LAUNCH-READY

Situation

One launch host needs a before-and-after readiness picture against an approved baseline.

What you can inspect

Baseline/candidate relationship, drift notes, findings, proofpack ZIP, and named limits, not launch approval.

Open example →

Customer Security Review Sprint

Synthetic demoCSR

Situation

A security questionnaire is holding up a deal.

What you can inspect

Synthetic answer matrix shape, evidence references, open items, and ownership of final submission.

Open example →

Compromised API key rotation

Signed synthetic runBrowser + offline verifier

Situation

A synthetic compromise signal triggers one bounded API-key rotation.

What you can inspect

The signed authority, exact evidence, browser verification, one-byte tamper challenge, and network-free offline verifier.

Open example →

Witnessed synthetic CRM action

Recorded synthetic runReplay + unsigned receipt

Situation

A recorded bounded action changes only Acme from NEW to REVIEWED.

What you can inspect

Original run authority, replay-only consent, the fixed action sequence, independent read-back, and an unsigned exact-byte demonstration receipt.

Open example →

Custody / wallet-ops review

Full sample packageOFFSEC-CUSTODY-OPS

Situation

A proof-backed review of custody or wallet-operations controls without keys or fund movement.

What you can inspect

Sanitised posture, findings, proofpack, and hard boundaries, no solvency or custody-of-funds claim.

Open example →

Incident readiness review

Full sample packageOFFSEC-INCIDENT-READY

Situation

A bounded readiness record for one named incident scenario and environment.

What you can inspect

Sanitised readiness observations, open decisions, and proofpack limits, not live IR command.

Open example →

Access removed proof (method sample)

Method sampleNot a product card

Situation

One named access-removal event with sanitised before/after observations.

What you can inspect

Package shape and limits. Not a public product card and not universal access-elimination.

Open example →

SBOM field checklist (method sample)

Method sampleNot a product card

Situation

A labelled synthetic package shows how a field checklist can sit inside a delivery, not a public product card.

What you can inspect

Generation context, present/partial gaps, and limits. Not compliance certification and not a catalogue SKU promotion.

Open example →

Privileged access grant

Access pathExplanatory example only

Situation

Someone requested time-bounded administrative access for one task.

What you can inspect

How approval, provisioning, and entitlement evidence should connect and where replay often stays weak.

Open example →

Approval-gated containment

Control pathExplanatory example only

Situation

A containment action must not run until approval is recorded.

What you can inspect

Gate enforcement, target-state evidence, and what a portable inspection path should include after the event.

Open example →

Limits that always apply

  • Not live customer evidence or a claim of completed verification for your environment.
  • Not a legal compliance claim, certification, or audit opinion.
  • Not a production deployment claim or complete AI governance program.
  • A public receipt-only result names the checks that ran and remains indeterminate whenever required evidence or trust inputs were not independently checked.

Next steps

Expert help

Request path: /review/request

Fallback contact: engage@mail.witnessops.com

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

Sample work | WitnessOps