control
hoxline
ProofOps control plane
Owns claim boundary packaging, Gauntlet runner, output contract, and website-ready data; does not own proof authority.
Evidence vault · claim authority hub
The website routes reviewers to proof. It does not authorize claims. Claims either survive the vault — validators, evidence boundaries, and human review — or they stop at the gate.
Evidence Bay
Artifact cards route reviewers from public rendering back to source, validation, proof, and authority surfaces. The wall is searchable by family and keeps proof ceilings attached.
Public Proof
CONTROLLED_TEST_VALIDATEDgovernanceWebsite Rendering Is Not ProofPublic rendering
rendering/reference boundarycase-studyHO-DET-001 Case FilePublic Proof
CONTROLLED_TEST_VALIDATEDproof-recordAWS-DET-001 Proof RecordPublic Proof
CONTROLLED_TEST_VALIDATEDproof-recordHO-DET-001 Private Runtime BoundaryRuntime Truth
CONTROLLED_TEST_VALIDATEDproof-recordPrivate Marker Delivery BoundaryEvidence Truth
CONTROLLED_TEST_VALIDATEDvalidationValidation Report — Controlled-Test ScopeValidation Truth
CONTROLLED_TEST_VALIDATEDvalidationHO-DET-012 Controlled Validation / Runtime BoundaryValidation Truth
CONTROLLED_TEST_VALIDATEDarchitectureHO-PIPE-001 Telemetry Route BoundaryTelemetry route boundary
SOURCE_EXISTS_VALIDATION_PLANNEDarchitectureHO-NDR-001 Security Onion Visibility ContractNDR visibility contract
BOUNDARY_CONTRACT_ONLYpublic-packetProof Loop Reviewer Brief / Review ZIP StandardReviewer packet
REVIEWER_PACKET_STANDARDarchitectureDetection Factory / Validation Factory ControllerGoverned control plane
CONTROL_PLANE_STRUCTUREgovernanceHO-LAB-AUTO / Support-only AI Triage BoundaryAI support boundary
SUPPORT_ONLY_AIgovernanceClaim FirewallPublic claim boundary
rendering/reference boundaryci-verifierBlocked-Claim CI ScannerPublic claim boundary
rendering/reference boundaryarchitectureTruth Surface ModelSystem architecture
rendering/reference boundaryarchitectureRepository Authority MapSystem architecture
rendering/reference boundarygovernanceControl Status MatrixGovernance routing
rendering/reference boundaryHoxline rendering reference
Gauntlet v0 output is useful reviewer context for HO-DET-001, but it does not make Hoxline or the website proof authority. Runtime and signal promotion still require separate evidence and review records.
authority_surface_chart
Hoxline is the control route. It does not replace proof, source, validation, platform, website, or org routing boundaries.
control
ProofOps control plane
Owns claim boundary packaging, Gauntlet runner, output contract, and website-ready data; does not own proof authority.
claim_decision_chart
Toggle the decision families. Blocked claims are visible as boundaries, not as product claims.
allowed
One allowed controlled-validation claim is present in the visual data pack.
Governance Saves · proof of value
72 public-facing records from GS-001 through GS-080 source range. Private-only records are excluded from this surface.
| Category | Count | What it covers |
|---|---|---|
| Claim boundary | 16 | Public copy was downgraded, narrowed, or held to match repo-visible evidence — never inflated to runtime, signal, or production wording. |
| Runtime boundary | 7 | Private runtime evidence, mirror traffic, and legacy automation were kept out of public runtime/signal claims. |
| Validator hardening | 8 | Review-thread fixes converted verifier edge cases into deterministic fail-closed paths before merge. |
| AI authority | 2 | AI output stayed support-only. Verifiers enforce human review and block AI-decided disposition. |
| Merge authority | 13 | Green CI never became merge authority. Review, scope, resolved threads, and human approval stayed above checks. |
| Evidence protection | 3 | Non-public evidence, host-local paths, and operator notes were kept off public surfaces and out of public proof. |
| Release gate | 2 | Release wording, checksums, and reviewer-package state were gated before any "approved release" claim could surface. |
| Branch hygiene | 16 | Branch divergence, dirty trees, wrong-branch preflights, and direct-main pushes were stopped before they touched source truth. |
| Workflow hardening | 5 | Required-check rulesets, audit findings, and CODEOWNERS reality were treated as enforcement evidence only when verified. |
Private-only records are excluded from this surface.
Claim firewall
A deterministic scanner, evidence gates, and human review authority sit between a claim and the public surface. Blocked terms stay visible — they describe what this surface does not assert.
These claims are backed by reviewer-inspectable evidence at the controlled-test ceiling, so they ship to the public surface.
These describe bounded, private-evidence work. They survive only as summaries and require a separate evidence-backed promotion gate before any stronger wording advances.
These terms are blocked from public wording. They are not claimed anywhere on this surface and stay blocked until a separate evidence-backed promotion gate changes their state.
Blocked claims
These claims remain blocked unless separate evidence-backed promotion changes their state. Visibility of the blocked list keeps the supported ceiling honest.
Public-safe runtime proof is not claimed.
Cribl-routed, Wazuh-routed, AWS-live are not claimed.
Autonomous SOC and AI-approved disposition are not claimed.
Sealed reviewer package
The receipt states what the package supports and what it does not prove. Raw / private runtime evidence is excluded and public runtime proof stays blocked.
An official direct GitHub Release route exists. Source packet manifest / check-mode language remains source-packet / release-candidate metadata — a route / status distinction, not a stronger proof claim.
Render-only ledger route
The website is render-only; the proof repo owns the summary and proof bundle. The badges are workflow-status indicators only. Boundary: no runtime, signal, public-safe runtime proof, SOCaaS, production, autonomous SOC, disposition, or case-closure claim is made.
Runtime boundary
Each level names a stronger runtime status. The public surface holds at controlled validation; higher rungs are sealed gates that require separate evidence and human approval.
| Level | Status | What it does not prove |
|---|---|---|
| 01 · Controlled validation | SUPPORTED | It does not prove runtime activation or any signal observation. |
| 02 · Runtime path initialized | SOURCE-VISIBLE | Source presence is not runtime; nothing here is claimed as executed in production. |
| 03 · Runtime-supported (private) | PARTIAL | Public runtime proof is blocked; the private marker is not a public claim. |
| 04 · Runtime-observed (private) | PARTIAL | Public NDR, cross-source, and signal-observed proof are not claimed from this surface. |
| 05 · Public runtime proof | BLOCKED | Runtime-active, signal-observed, and public-safe runtime proof are blocked and not claimed until a separate promotion gate clears them. |
| 06 · Production / customer / fleet | BLOCKED | Production-ready, customer-validated, partner-endorsed, fleet-wide, and autonomous SOC claims are blocked and not made anywhere on this surface. |
Evidence bay
The flagship record leads; supporting records follow at lower weight. Each holds its bounded ceiling and a supports / does-not-prove split.
SOCaaS Pilot Receipt · controlled-test validation
Supports
Does not prove
Remaining blocked
Promotion requirements
CloudTrail-style IAM denial fixture proof card
Supports
Does not prove
Remaining blocked
Promotion requirements
Windows Service Creation / Binary Change · bounded summary
Supports
Does not prove
Remaining blocked
Promotion requirements
Suspicious Scheduled Task Creation · bounded summary
Supports
Does not prove
Remaining blocked
Promotion requirements
Suspicious identity session context · no proof record
Supports
Does not prove
Remaining blocked
Promotion requirements
MFA fatigue / repeated MFA failure · no proof record
Supports
Does not prove
Remaining blocked
Promotion requirements
Privileged role / admin group change · no proof record
Supports
Does not prove
Remaining blocked
Promotion requirements
Impossible travel / anomalous session · no proof record
Supports
Does not prove
Remaining blocked
Promotion requirements
Security Onion visibility contract · boundary scaffold
Supports
Does not prove
Remaining blocked
Promotion requirements
Each record holds its bounded ceiling and routes reviewers to source and validation. Website rendering is not proof.
Promotion gates
The ladder is sequential — no rung is skipped. Stronger runtime, signal, and public proof wording cannot ship until its gate clears.
Governed work · Snapshot as of 2026-05-18
Recent governed work on the proof repo. Reviewer-visible cards that do not change the public claim ceiling. Stronger wording requires a separate evidence-backed promotion gate.
Context-only case study describing the governed AI-assisted proof routing model. Not pipeline proof.
Reviewer-package wording for Proof Pack 001 tightened. Wording only.
Routes
Rendering is not proof.
Evidence, validators, and human review authorize claims. The website routes reviewers to proof; it does not author it.