EVIDENCE PACK · PUBLIC · NO LOGIN REQUIREDgoverned by Scalarion
Security Questionnaire Triage Agent
SEALED
NOT APPROVEDNot approved — 2 blocking gapsL0 safeguards: 34/34 self-attested · 17 agent-specific · 17 baseline · All required L0 safeguards are self-attested (declared, not independently verified) and no relevant risk is left unaddressed.
- Approved environment
- sandbox · limited tools (α) — a sealed run exists
- Workflow scope
- Triage inbound security questionnaires and draft responses
- Tools in scope
- Email · Knowledge Base · Document Storage · CRM · data confidential
- Autonomy ceiling
- supervised
- Mandatory holds
- every `send` action is held for a human
- Expires
- 2026-11-07 — Bound to version f3a01b2c3d90. Void immediately on any change to the manifest, model, tools or policy; otherwise expires 90 days after compilation.
- Approver
- Not externally approved. This decision was produced from the builder's own attestation plus Scalarion's checks; no independent reviewer has counter-signed it.
GAPS — EVERY ONE DISPOSITIONED
ModelNo base model declared.BLOCKING
MemoryNo retention window declared — long-term memory may persist until deleted (the 'remembers forever' risk).OPEN
Identity / credential scopeA high-severity tool runs as a shared/undeclared service account — scope it to the user.OPEN
Business outcomeNo business outcome declared.OPEN
credential-scopeleast-privilege tokens, no shared secretsBLOCKING
observabilitysigned ledger — this record does not reproduce its seal, so tampering would not be evidentOPEN
memory-isolationorg-scoped; no cross-tenant readsOPEN
live-runtimenot yet offered — behind the red-team gate
This decision approves a sandboxed environment only. Live execution is not granted by it, so the absence of live-runtime evidence does not weaken it — a separate decision is required to run live.NOT APPLICABLE
This decision approves a sandboxed environment only. Live execution is not granted by it, so the absence of live-runtime evidence does not weaken it — a separate decision is required to run live.NOT APPLICABLE
CONDITIONS THIS DECISION CARRIES
- Resolve or formally accept: Memory.
- Resolve or formally accept: Identity / credential scope.
- Resolve or formally accept: Business outcome.
- Resolve or formally accept: observability.
- Resolve or formally accept: memory-isolation.
- live-runtime is out of scope — a separate decision is required to bring it in.
- This decision is void if the manifest, model, tools or policy change — re-prove and re-seal.
PROVENANCE
Audit → Evals → Deploy
full chain, one ledger
full chain, one ledger
GOLDEN SET
Governance eval-set
failing runs named
failing runs named
CONSEQUENCE CAUGHT
1 action(s) held
routed to human, logged
routed to human, logged
HARNESS CONTROLS — SELF-ATTESTED ≠ VERIFIED
dangerous-actions-heldinjected dangerous writes held at the gateVERIFIED
fail-closeddegrades to a hold, never to a guessVERIFIED
reversible-writesundo path or approval queue on every writeVERIFIED
credential-scopeleast-privilege tokens, no shared secretsGAP
observabilitysigned ledger — this record does not reproduce its seal, so tampering would not be evidentGAP
memory-isolationorg-scoped; no cross-tenant readsGAP
live-runtimenot yet offered — behind the red-team gateGAP
pack.signature : kms-ecdsa-p256 · f3a01b2c3d…
ledger.seal : f3a01b2c3d904ead… · hash-chained
integrity : DOES NOT RECOMPUTE — integrity not established (see below)
verification : INDEPENDENT — public key published, checkable without us
runtime.claim : sandboxed run sealed — limited tools (α)
This record does not reproduce its seal hash, so its integrity is NOT established. A defect in this ledger's canonicalisation hashed a non-JSON string containing `undefined`, which the datastore then dropped — so records sealed before the fix cannot be recomputed from what is stored, however untouched they are. That is a limitation of our ledger, not a finding about this document. It also means tampering with such a record would not be detectable by us either. Re-sealing the pack produces a record that verifies.
Signed with an asymmetric key. The public key, the exact bytes that were signed, and a standalone verifier are published below — you can check this pack without contacting us, and without our cooperation.
- Fetch the canonical payload and signature from the verification manifest.
- Fetch the public key. It is a public key: holding it lets you check signatures and does not let you make them.
- Run scripts/verify-pack.mjs, or any library that verifies the named algorithm.
- verification manifest · public key · verifier
What we will not say: “safe,” “certified,” or “verified” for anything without a sealed run behind it — and not “independently verifiable” for anything signed with a key only we hold. What you can do: hand this URL to your security team, along with the disposition of every gap above and the exact version this decision binds to.