Comparison matrix
Red-team evidence vs Exploit disclosure
One-sentence distinction
Red-team evidence and Exploit disclosure answer different questions and must not be collapsed.
Side-by-side matrix
| Dimension | Red-team evidence | Exploit disclosure |
|---|---|---|
| Primary question | What evidence establishes the first property for a named purpose? | What separate evidence or authority establishes the second property? |
| Evidence | Purpose-specific technical, factual, or institutional records. | Independent records appropriate to the second category. |
| Authority | May be descriptive or technical and may not require legal authority. | May require a competent legal, constitutional, organizational, or operational decision-maker. |
| Currentness | Can be current, stale, disputed, unknown, or unavailable. | Must be assessed separately; the first status does not transfer. |
| Failure condition | Evidence may be authentic but incomplete or unsuitable. | Authority may exist but rely on wrong or stale facts. |
Why the distinction matters
Red-team evidence and Exploit disclosure answer different questions and must not be collapsed. Systems and institutions fail when one side is used as a shortcut for the other. The distinction determines what evidence is collected, who may decide, what can be appealed, and which failure modes must be controlled.
Common failure caused by conflation
Treating these categories as equivalent can turn a bounded reference record into an unsupported authority, compliance, readiness, deployment, or operation claim.
This error can create false confidence, unauthorized status, misattributed liability, silent loss of correction rights, or an operational claim based only on descriptive material.
Implementation consequences
- Use different fields, identifiers, and claim-status records for each side.
- Require separate evidence and currentness checks.
- Do not let a user-interface label silently merge the categories.
- Preserve correction and supersession history for both.
- Route decisions to the ecosystem authority that owns the relevant function.
Legal consequences
Legal admissibility and weight depend on jurisdiction, procedure, foundation and purpose; technical validity is not a universal admissibility rule.
Technical evidence can inform a legal decision but cannot replace jurisdiction, legal basis, procedural authority, due process, or remedy. Conversely, a lawful decision does not make the underlying technical record accurate if the evidence is stale or defective.
Examples
- A valid signature demonstrates control over a key and payload integrity; it does not establish the truth of every signed statement.
- A registry can record a citizenship decision; the registry operator does not thereby acquire constitutional power to create citizenship.
- A static release can show that software exists; it does not prove the service is currently operating.
Sources
- PROV-O: The PROV Ontology — W3C; W3C Recommendation 30 April 2013; W3C Recommendation. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
- RFC 3161: Time-Stamp Protocol — IETF; RFC 3161 with RFC 5816 update; Proposed Standard. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
- C2PA Technical Specification v2.4 — Coalition for Content Provenance and Authenticity; C2PA Technical Specification 2.4; Published technical specification. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
- in-toto Attestation Framework — in-toto project; Current project framework; Open standard; CNCF graduated project. Exact claim-support entries: 1. Revalidated 2026-08-14T22:04:09Z.
Comparison claim record
Each proposition has a stable ID, status, scope, owning route, evidence relationship, currentness qualification, correction state, and synchronized JSON record. Record completeness does not make the proposition true.
Red-team evidence versus Exploit disclosure
Red-team evidence and Exploit disclosure answer different questions and must not be collapsed.
Support relationship
SRC-W3C-PROV-O· Abstract and status · DIRECT OR QUALIFYING SOURCE SUPPORTSRC-RFC-3161· RFC status and update chain · DIRECT OR QUALIFYING SOURCE SUPPORTSRC-C2PA· Version history — 2.4 · DIRECT OR QUALIFYING SOURCE SUPPORT