Published sample — not live customer evidence

Launch readiness review

Synthetic public sample from the OffSec suite. Deterministic fixture evidence only. Not a live customer launch review, not production verification, and not launch approval.

Sample case

Launch readiness review

Situation: one launch host needs a before-and-after readiness picture against an approved baseline — drift, findings, and open decisions on the package, never automatic launch approval.

Product: OFFSEC-LAUNCH-READYRun: pr_lrr_20260711120000_df6bc5d205Status: Synthetic — not live

How to use this sample

  1. 1. Read the owner signal

    Open review-summary.json for the decision-facing summary of this synthetic run.

  2. 2. Inspect drift

    Read drift.json for admitted changes between baseline and candidate snapshots.

  3. 3. Read findings and report

    Use findings.json and report.md for posture notes and named limits.

  4. 4. Stay inside the boundary

    valid means package and verifier checks passed — not that the launch is secure, ready, or approved.

What you can inspect

  • baseline and candidate snapshot relationship
  • drift notes for admitted v1 changes
  • findings and readiness report
  • receipt, evidence manifest, and hash sidecars
  • buyer walkthrough and offline verification path

Package files

Proofpack bytes are published as a .proofpack file (ZIP-compatible contents). Prefer the listed package files for browser inspection.

Offline verification

Offline product verifier path: witnessops-launch-ready verify with the proofpack ZIP, detached signature, and a separately obtained trust registry. Require exit code 0 and status: valid for the named checks only.

Trust registries for this sample are synthetic and test-only. Obtain any production trust material through a channel separate from the proofpack. /verify is for supported public receipt types; this suite sample is inspected primarily via the package files and offline product verifier.

Boundaries

  • No launch approval, security guarantee, remediation, or arbitrary cloud review.
  • No compliance certification or continuous monitoring.
  • Synthetic trust keys only — not production signing custody.
  • Not live customer evidence, production verification for your environment, or compliance certification.