Published sample — not live customer evidence
Local server security review
Synthetic public sample package for a read-only local server review. It is not a live customer audit, not a production verification result, and not evidence that any third-party system was tested.
Sample case
Local server security review
Situation: a read-only review of a local server was packaged so a buyer can see posture, findings, a receipt, and hash checks side by side. This sample shows the deliverable shape and honest limits.
Stable sample storage id: offsec-shield-local-server-audit (public fixture path). This sample is not currently verified through WitnessOps /api/verify. Use /verify for supported receipt types; for this sample, inspect the included manifest and sidecars instead.
Run metadata
- Receipt id
- secsvc-local-fixture-a
- Run id
- local-fixture-a
- Module
- local-audit
Download artifacts
- RECEIPT.json
sha256 3ccac6eb0233e907a6ea083536e1aaaee80e4f9383030936d4acf693794ffb12
- evidence_manifest.json
sha256 03696f0eee780f3c9ad4fefc214613715fff6fc18cecd74a88de7a532ccee60a
- MANIFEST.sha256
sha256 481c07604c58b1242e2a8bf48bf7900e3c3c502beddcfa77170f18d52b829b0c
- evidence/posture.json
sha256 63e2d3917b2b9ce3edf28a9e60708a0d1e2004fa95783308e8fe1d074150118a
- evidence/findings.json
sha256 d1c590aa730d5b5bfa1f7c92b7b031b2aab78a16f7e295f712f28102ad44136d
- evidence/authority.json
sha256 f732264f1ae592e4d4e24818c49e734e5ed27b2bbba7b710d998abfebad87db1
- evidence/scope.json
sha256 571823760f1f1d3510e3484527d5c0f6765ce27f12698913ae0d06246cb73f6a
- VERIFY_NOTE.json
sha256 5509b59109f9630cc18cc87f8480d3b5d9f19512a954ad50d832c36164285a90
- README.md
sha256 319cbfbabcc12afa7f851607c4b9ee25e6ad34d28fefdd211d20e73c55a8c653
- proofpack-demo-host-local-fixture-b.zip
Optional portable proof-pack (fixture B drift demo). Verify with the offline operator CLI for this package.
Full suite product sample (OFFSEC-LOCAL-AUDIT)
Complete synthetic product package from the OffSec suite: buyer walkthrough, report, findings, receipt, and downloadable proofpack. Run id pr_lsa_20260710120000_198fd7aceb.
- local-server-audit-pr_lsa_20260710120000_198fd7aceb/BUYER_WALKTHROUGH.md
- local-server-audit-pr_lsa_20260710120000_198fd7aceb/report.md
- local-server-audit-pr_lsa_20260710120000_198fd7aceb/findings.json
- local-server-audit-pr_lsa_20260710120000_198fd7aceb/posture.json
- local-server-audit-pr_lsa_20260710120000_198fd7aceb/receipt.json
- local-server-audit-pr_lsa_20260710120000_198fd7aceb/evidence_manifest.json
- proofpack-pr_lsa_20260710120000_198fd7aceb.proofpack
- proofpack-pr_lsa_20260710120000_198fd7aceb.proofpack.sha256
- proofpack-pr_lsa_20260710120000_198fd7aceb.proofpack.sig.json
Offline product verifier path (suite): witnessops-local-audit verify with the proofpack, detached signature, and a trust registry obtained separately. valid is not a host-security grade.
Proof boundary
- Integrity checks use Shield
MANIFEST.sha256semantics (READY / MISMATCH / MISSING) on the web fixture family. - Does not prove regulatory compliance, EDR coverage, or that your production hosts match this fixture.
- Web fixture receipt is structural; full suite sample uses offline product verify. A public verifier path must be named before any verification claim is made. Neither sample is live customer evidence.
Web fixture id: offsec-shield-local-server-audit. Suite sample id: offsec-local-audit / pr_lsa_20260710120000_198fd7aceb.