Skip to main content

Trust Lifecycle Evidence

See the Trust Lifecycle Evidence Pack v1 for the complete summary.

Trust Proof Status

ProofCapabilityStatus
TRUST-PROOF-001Enrollment happy pathlocal/mock proven
TRUST-PROOF-002Enrollment rejection / fail-closedlocal/mock proven
TRUST-PROOF-003HMAC valid/invalid/stale/rotatedlocal/mock proven
TRUST-PROOF-004mTLS/cert baseline (cert-manager, auto-renewal)implementation_present
TRUST-PROOF-005ZenLock secret authority (ciphertext-only)local/mock proven
TRUST-PROOF-006mTLS cert rejection (5 scenarios)local/mock proven
TRUST-PROOF-007Canary cert rotation (ingester)local/mock proven
TRUST-PROOF-008Trust bundle rotationblocked (no implementation)
TRUST-PROOF-009ZenLock secret rotationlocal/mock proven
TRUST-PROOF-010Revocation/expirylocal/mock proven (sub-scenarios)

Verification

make trust-lifecycle-evidence-pack-v1-check
make trust-proof-replay-verify
make trust-lifecycle-state-machine-check
make trust-lifecycle-readiness-report-check
make zero-trust-proof-matrix-check
make trust-lifecycle-evidence-map-check

Scope

  • No generic zero-trust claim.
  • No production zero-trust or production mTLS/cert rotation claim.
  • No SVID/SPIFFE rotation — SPIRE not deployed.
  • No secret values printed in any artifact.
  • No Merkle auth/replay/identity/delivery claim.