whitehat-security/evidence/README.md

13 lines
516 B
Markdown
Raw Normal View History

# Evidence
This directory stores sanitized run artifacts. `offline-calibration.json` and
`offline-e3-calibration.json` are generated from repository-created fixtures
and prove only that the harness distinguishes known-good from known-bad
behavior. They are not target assurance.
Before committing target evidence, verify that it contains no response body,
credential, database URL, real tenant identifier, or real tenant value. A
run-local digest is allowed; it must not be reusable across runs as a data
oracle.