Published sample — not live customer evidence
Launch readiness review
Synthetic public sample from the OffSec suite. Deterministic fixture evidence only. Not a live customer launch review, not production verification, and not launch approval.
Sample case
Launch readiness review
Situation: one launch host needs a before-and-after readiness picture against an approved baseline — drift, findings, and open decisions on the package, never automatic launch approval.
How to use this sample
1. Read the owner signal
Open review-summary.json for the decision-facing summary of this synthetic run.
2. Inspect drift
Read drift.json for admitted changes between baseline and candidate snapshots.
3. Read findings and report
Use findings.json and report.md for posture notes and named limits.
4. Stay inside the boundary
valid means package and verifier checks passed — not that the launch is secure, ready, or approved.
What you can inspect
- baseline and candidate snapshot relationship
- drift notes for admitted v1 changes
- findings and readiness report
- receipt, evidence manifest, and hash sidecars
- buyer walkthrough and offline verification path
Package files
- BUYER_WALKTHROUGH.md
- review-summary.json
- drift.json
- findings.json
- report.md
- receipt.json
- evidence_manifest.json
- verification_result.json
Proofpack bytes are published as a .proofpack file (ZIP-compatible contents). Prefer the listed package files for browser inspection.
Offline verification
Offline product verifier path: witnessops-launch-ready verify with the proofpack ZIP, detached signature, and a separately obtained trust registry. Require exit code 0 and status: valid for the named checks only.
Trust registries for this sample are synthetic and test-only. Obtain any production trust material through a channel separate from the proofpack. /verify is for supported public receipt types; this suite sample is inspected primarily via the package files and offline product verifier.
Boundaries
- No launch approval, security guarantee, remediation, or arbitrary cloud review.
- No compliance certification or continuous monitoring.
- Synthetic trust keys only — not production signing custody.
- Not live customer evidence, production verification for your environment, or compliance certification.