K05 assurance architecture
Operations and Verification
Direct answer
K05 separates local deterministic release evidence from deployment evidence and current operation. A valid archive is necessary for deployment but cannot prove what a live server is running.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Operational evidence boundaries
Live-host verification
Deployment-only checks for TLS, redirects, headers, protected paths, caching, compression, body hashes, and exact release identity.
Readiness evidence
Build, provenance, authority, test, incident, uptime, restoration, and independent-verification records.
Assistive-technology evidence
Named environment, tasks, results, defects, remediation, and unresolved limits kept separate from screen-reader claims.
Current deployment state
NOT PERFORMED
The K05 package is built and audited locally. DNS, TLS, live Apache behavior, actual response headers, and deployed body hashes are not claimed.