Published sample — not live customer evidence
Access removed proof
Synthetic method sample from the OffSec suite. Not a public buyer product card on the catalogue. Not live customer evidence, not access mutation, and not universal access-elimination.
Method sample
Access removed proof
Situation: prove one named access-removal event with sanitised before/after observations — without claiming every shadow path is gone or that a credential can never still be used.
How to use this sample
1. Read the walkthrough
Open BUYER_WALKTHROUGH.md for the inspection order of this synthetic access-removal package.
2. Compare before and after
Inspect sanitised before/after observations for the admitted opaque subjects and access paths.
3. Read findings
Findings name remaining or unresolved scope — not that every possible path was discovered.
4. Stay inside the boundary
This sample does not revoke access, validate credentials, or prove compromise absence.
What you can inspect
- sanitised before/after observations for one named event
- findings for remaining or unresolved scope
- receipt, evidence manifest, and hash sidecars
- buyer walkthrough and offline verification path
Package files
- BUYER_WALKTHROUGH.md
- receipt.json
- evidence_manifest.json
- findings.json
- report.md
- verification_result.json
Proofpack bytes are published as a .proofpack file (ZIP-compatible contents). Prefer the listed package files for browser inspection.
Offline verification
Offline product verifier path: witnessops-access-removed verify with the proofpack ZIP, detached signature, and separately obtained trust registries. Require status: valid for named checks only.
Trust registries for this sample are synthetic and test-only. Obtain any production trust material through a channel separate from the proofpack. /verify is for supported public receipt types; this suite sample is inspected primarily via the package files and offline product verifier.
Boundaries
- No access mutation, credential validation, secrets, or universal access-elimination claim.
- Not a public catalogue product card — method/example only.
- Not a compromise claim or compliance certification.
- Synthetic trust keys only — not production signing custody.
- Not live customer evidence, production verification for your environment, or compliance certification.