Published sample — not live customer evidence

External Exposure Assessment

Synthetic worked example — not customer evidence. Local fixture observations only; no public company or customer was assessed.

Synthetic sample

External Exposure Assessment

A concise, buyer-safe example of the authority summary, exposure map, evidence-linked findings, handover, focused retest, manifest, and verifier result produced for a bounded synthetic target.

How to inspect the sample

  1. 1. Start with authority and scope

    Read the assessment and exposure map to see the synthetic target boundary, fixed caps, allowed checks, exclusions, and unknowns.

  2. 2. Trace findings to evidence

    Compare the synthetic findings with the evidence register. Each finding should name the observation that supports it.

  3. 3. Inspect closure

    Use the handover agenda and focused retest result to see what was explained, rechecked, and left unresolved.

  4. 4. Check package integrity

    Use MANIFEST.sha256 and the recorded verifier result for the named file and hash checks only. Integrity is not proof that a system is secure.

Sample package files

These files are sanitized synthetic artifacts. They are published for buyer inspection, not as evidence about WitnessOps or any customer.

What the integrity result means

MANIFEST.sha256 checks the files in this public sample. The published verifier result is preserved from the complete internal signed synthetic bundle and names the verifier, schema, trust set, and checks that ran; it is not a receipt for this smaller web copy. Neither result proves that observations are complete, that findings are universally correct, or that any system is secure.

Boundaries

  • Synthetic worked example — not customer evidence.
  • Not a live customer artifact or production verification result.
  • No public company or customer was assessed to produce this package.
  • This is not a penetration test, certification, attestation, or security guarantee.
  • The package does not prove that a target is secure, complete, compliant, accepted, or free of vulnerabilities.
  • The verifier result supports only the checks and files it names; it does not prove observation completeness or system security.