# Conformance review — Whitehat ASM fixture calibrations **Repository:** gate-house **Status:** fixture harness calibrated; live targets pending **Date:** 2026-09-02 **Executor:** whitehat-security **Executor revision:** `6f1ca0b` **Source:** State Hub message `32926191-4ca1-46ad-8eec-0d499036d66b` **Specification:** `asm-assurance-targets.v1` **Evidence class:** `fixture` **Gate House disposition:** `no_change` **Workplan:** GH-WP-0001-T06 ## Returned calibration Whitehat-security created in-process registrations and evidence for Canon T-01 through T-10: ```text targets/fixture-asm-tNN.json evidence/offline-asm-tNN-calibration.json ``` For every test, the Whitehat-owned known-bad fixture loses the specified oracle and records a `finding`; the corresponding known-good fixture records `pass`. T-08 and T-09 each calibrate two distinct failure shapes. T-06 drives the committed secrets-engine consume client at revision `4b4d556` through an in-process CAS opener; the other fixtures are Whitehat-owned in-process models of their target invariant. Gate House reproduced the focused suite against Whitehat revision `6f1ca0b`: ```text uv run --project /home/worsch/whitehat-security \ pytest -p no:cacheprovider tests/test_asm.py tests/test_plane.py tests/test_cli.py 53 passed in 0.34s ``` This establishes that each published target has a probe capable of detecting a known-bad case. It closes the risk that a probe could report green merely because it cannot observe its own oracle. ## Evidence bound This is harness calibration, not assurance of ten estate systems: - evidence class is `fixture`; - no network, live service, OpenBao instance, credential, packet, or production effect was used; - no live `asm-tNN` registration became applicable; - no component other than the bounded T-06 consume client was exercised; - a fixture `pass` means the probe distinguished its known-good model from its known-bad model, not that the corresponding estate control currently holds. All live T-01 through T-10 targets remain `pending` / `not_run` until an owner names the surface, identities, and window and Whitehat admits a dated engagement. `WHITEHAT-WP-0007-T11` preserves that residual. ## Doctrine disposition `no_change` to `asm-assurance-targets.v1`. The returned fixture set implements Whitehat-owned attack designs while preserving Gate House's invariant and oracle identifiers. No calibration exposed an ambiguous, contradictory, or untestable Gate House target. This disposition accepts the harness/specification fit only; it does not convert fixture outcomes into live conformance. ## Reporting closure Whitehat supplied the complete T-06 envelope, including engagement and authorization references, in message `a1ebf012-bd1e-43d2-843c-ba3ddecb8c82`. Final review: `docs/conformance/2026-09-02-whitehat-t06-fixture-return.md`.