whitehat-security/evidence/README.md

17 lines
837 B
Markdown
Raw Normal View History

# Evidence
This directory stores sanitized run artifacts. `offline-calibration.json` and
`offline-e3-calibration.json` are generated from repository-created fixtures
and prove only that the harness distinguishes known-good from known-bad
behavior. They are not target assurance. `WH-ENG-20260822-AUDIT-E2-02-abort.json`
is an abort record (`evidence_class: abort`), not an E2 pass or finding.
`WH-ENG-20260822-AUDIT-E2-03.json` is the first authorized target pass; SHA-256
`2d5a21141b78024a5334881e2b7fd62a69c46931057f77515a6c6f18ec497593`. A pass
means only that the attempted attacks did not work.
Before committing target evidence, verify that it contains no response body,
credential, database URL, real tenant identifier, or real tenant value. A
run-local digest is allowed; it must not be reusable across runs as a data
oracle.