whitehat-security/SCOPE.md
tegwick 3295b715c5 Record the audit-core E2-03 target pass and close T03/T07
Land the sanitized WH-ENG-20260822-AUDIT-E2-03 report, mark the
engagement completed and terminal, and close the applicable E2 harness
and risk-nexus delivery tasks. flex-auth stays pending; tenant-engine
stays not_applicable.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
2026-08-23 00:42:31 +02:00

4.6 KiB

Scope

One-liner

whitehat-security is NetKingdom's authorization-bound offensive-security tooling for producing adversarial evidence about security claims.

Core idea

The repository turns stated security properties into dated, reproducible attack attempts. It remains separate from the systems it tests, reports findings without grading their severity, and never treats a passing probe as proof that a boundary always holds.

In scope

  • Attacker models for tenant isolation, credential confinement, noisy-neighbour behavior and erasure verification.
  • Differential probes that compare behavior across controlled tenant contexts.
  • Known-bad and known-good fixtures that demonstrate every probe can fail.
  • Rules of engagement, target authorization, engagement records, abort controls and evidence minimization.
  • Probe cadence and the resulting assurance/exposure window.
  • Delivery of findings and passing-run evidence to risk-nexus.

Out of scope

  • Fixing defects in target repositories.
  • Assigning severity, disclosure policy or remediation deadlines.
  • Replacing mechanical checks owned by a target repository's CI.
  • Defining the estate's security model or publishing permanent policy.
  • Probing any target without the authorization and engagement records required by the rules of engagement.
  • Blocking build-mode delivery without a separately recorded decision.

Safety invariants

  • The rules of engagement are accepted, but their acceptance authorizes no live target. Without a complete approved engagement record, only documentation and non-networked fixture design may proceed.
  • No live target is authorized by this scope document.
  • Every live run names its authorization, target, owner, window, technique, credential lane, rate ceiling, abort contact and finding destination.
  • A probe stops at the recorded boundary and never follows an adjacent system.
  • Evidence records response shape and counts, never real tenant row values or credentials.
  • Findings leave this repository; repairs do not enter it.

Relevant when

  • A service claims a Tenancy Posture evidence level that requires adversarial rather than mechanical evidence.
  • A boundary must be tested using a leaked runtime credential or hostile tenant context.
  • The estate needs to know when a probe last ran, what attacker it modeled, and whether it was proven against a known-bad fixture.

Not relevant when

  • A repository needs unit, schema or provisioning tests for its own code.
  • A finding needs triage, severity or disclosure handling; use risk-nexus.
  • Permanent policy needs publication; use policy-nexus.
  • The desired activity falls outside an approved engagement boundary.

Current state

  • Repository status: active.
  • Active plan: WHITEHAT-WP-0001. Meantime polish: WHITEHAT-WP-0002 through WHITEHAT-WP-0005 (Railiance WP-0025 custody adapter and fail-closed admission).
  • T01 is complete: the rules of engagement were accepted on 2026-08-21.
  • T02 is complete: the per-axis attacker model is recorded in docs/attacker-model.md.
  • T03 is complete for currently applicable E2 targets: audit-core has dated pass WH-ENG-20260822-AUDIT-E2-03; tenant-engine remains not_applicable. flex-auth is still pending. -01 and -02 are terminal without E2 evidence.
  • T04 is complete for every applicable E2 probe: generic and audit-core shaped fixtures fail known-bad and pass known-good in-process.
  • T05 is in progress: 24-hour cadence, offline evaluator and in-process calibration exist; platform-pg is not_applicable for the requested runtime identity.
  • T06 is in progress: the characterization evaluator is calibrated in-process; shared-substrate is pending a live window and ceiling.
  • T07 is complete: the -03 sanitized pass was delivered to risk-nexus as 40e3f825-fc70-4091-96d2-9ab01d42184a.
  • T08 is the governed test plane contract. Cluster provisioning is outside this repository.
  • -03 is terminal. A later live run needs a new engagement ID, plane admission, and approvals. flex-auth and P1/P2 remain unrun.

Relationships

  • Owner and security canon: net-kingdom.
  • Finding intake, severity and disclosure: risk-nexus.
  • Permanent publication: policy-nexus.
  • Initial proposed target owners: tenant-engine, audit-core and flex-auth.

Getting oriented

  1. Read INTENT.md for the durable purpose and ownership model.
  2. Read the rules of engagement before any probe design or execution.
  3. Read WHITEHAT-WP-0001 for active tasks and sequencing.