K07 · evidence-bundled critical-infrastructure assurance

Existing nuclear-plant colocation digital-twin evidence contract

Direct answer

Support bounded design, consequence, control, autonomy, timing, recovery, and evidence testing without exposing or commanding a live facility.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

Purpose and facility pattern

Support bounded design, consequence, control, autonomy, timing, recovery, and evidence testing without exposing or commanding a live facility.

Facility pattern: FP-K06-001.

Required model facts

  • declared system boundary
  • model version and hash
  • represented and omitted functions
  • physical assumptions and validity range
  • time resolution and uncertainty
  • sensor and actuator abstractions
  • failure and degraded modes
  • calibration source
  • data provenance
  • known divergence from site

Safe synthetic-data rules

  • use synthetic identifiers and non-routable addresses
  • remove site coordinates, credentials, keys, serial numbers and real protection settings
  • preserve physical relationships only at the fidelity needed for the named test
  • label generated, transformed, sampled and withheld fields
  • prevent synthetic records from being imported as operating evidence

Allowed uses

  • architecture trade study
  • contained fault injection
  • recovery sequence test
  • control and evidence schema validation
  • model and agent assurance

Prohibited uses

  • target development
  • production command
  • real facility access
  • weapon or destructive-procedure development
  • claiming site fidelity beyond validated range
  • certification without competent authority

Acceptance evidence

  • model manifest
  • calibration record
  • validation cases
  • known-limit register
  • fidelity statement by function
  • independent challenge
  • reset and artifact-removal test

Invalidators

  • unrecorded site change
  • unknown calibration source
  • hidden production connection
  • real credential or key material
  • unsafe command path
  • unbounded model extrapolation

Source relationships