K05 assurance architecture

Operations and Verification

Direct answer

K05 separates local deterministic release evidence from deployment evidence and current operation. A valid archive is necessary for deployment but cannot prove what a live server is running.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Operational evidence boundaries

Live-host verification

Deployment-only checks for TLS, redirects, headers, protected paths, caching, compression, body hashes, and exact release identity.

Readiness evidence

Build, provenance, authority, test, incident, uptime, restoration, and independent-verification records.

Assistive-technology evidence

Named environment, tasks, results, defects, remediation, and unresolved limits kept separate from screen-reader claims.

Current deployment state

NOT PERFORMED

The K05 package is built and audited locally. DNS, TLS, live Apache behavior, actual response headers, and deployed body hashes are not claimed.