Evidence limitation

Build provenance is not runtime evidence

Direct limitation

It does not prove deployment, service availability, current authorization, correct runtime behavior, uptime, or institutional action.

Artifact or claim that may be supported

How an artifact was produced and whether exact bytes match an expected release.

What the evidence does not establish

It does not prove deployment, service availability, current authorization, correct runtime behavior, uptime, or institutional action.

Additional evidence required

Runtime identity, deployment record, endpoint observations, signed state transitions, incident history, and verification window.

Mitigation

Runtime identity, deployment record, endpoint observations, signed state transitions, incident history, and verification window.

Supporting sources

No public source record is assigned; the claim remains bounded by project doctrine, a governed report, or an explicitly unresolved evidence requirement.

Related topic

Security and Resilience