Claim firewall

Allowed wording, blocked wording, and promotion gates in one public surface.

The firewall keeps a bounded validation result from becoming an unsupported runtime, signal, or public proof claim.

RENDERING_ONLY TEST_VALIDATED_SYNTHETIC_SCOPE NOT_PUBLIC_SAFE

Public inspection layer

source truth separate
runtime truth separate
signal truth separate
evidence truth separate
public proof separate

Controls

Public claim standard

Supported claims must map to proof records. Blocked claims remain blocked unless a separate evidence-backed promotion changes their state.

Allowed claims

  • HawkinsOperations is a public rendering layer.
  • HawkinsOperations separates source truth, runtime truth, signal truth, evidence truth, and public proof.
  • HO-DET-001 has synthetic validation status.
  • HO-DET-001 public proof ceiling is TEST_VALIDATED_SYNTHETIC_SCOPE.
  • Source presence does not prove runtime.
  • Validation does not prove public signal.
  • Public proof requires evidence linkage and explicit promotion.

Blocked / not claimed

runtime-activesignal-observedpublic-safe runtime proofproduction-readyfleet-widelive Splunk firedSplunk-proven Runtime Signal 001Cribl-routedWazuh-routedAWS-liveautonomous SOCAI-approved dispositionanalyst-approved dispositionpublic-safe

Promotion requirements

  • Current source artifact remains reviewable in the owning repository.
  • Validation output is deterministic and linked to the proof record.
  • Runtime state is independently evidenced before runtime claims move forward.
  • Signal state is independently evidenced before signal claims move forward.
  • Evidence linkage is explicit before public proof status changes.
  • Public wording is scanned against the blocked-claim list before release.

Wording examples

Safe wording

  • HO-DET-001 is presented at TEST_VALIDATED_SYNTHETIC_SCOPE.
  • Website pages route reviewers to proof records; they do not replace proof records.
  • Synthetic validation supports the validation surface only.
  • Runtime, signal, evidence, and public proof require separate promotion gates.

Unsafe wording

  • HO-DET-001 is deployed across live systems.
  • The website proves public signal observation.
  • Source presence proves operational coverage.
  • AI has approved the final disposition.