Inside the evidence package
Outputs vary by product, selected checks, completion state, verification mode, regulatory inputs, and whether a human reviewer explicitly signs off. A stopped or artifact-inconsistent run may remain incomplete and unsealed.
The five-drawer structure
Top level: the primary readable report and any applicable corrected/redlined output.
System files: canonical machine record and scope/consistency records.
Transparency: detailed evidence, confirmed-failure ledger, and result-bound sign-off history when present.
Integration: applicable
evidence.json, SARIF, cards, and OpenTelemetry/OpenInference exports.Integrity: signed manifest, signer certificate, verifier, and conditional RFC 3161 timestamp.
Product output matrix
| Output | Scout | SitRep | Watchtower |
|---|---|---|---|
| Primary readable report | Completed run | Completed run | Completed cycle |
| Executive summary | When generated | When generated | When generated |
| System/data card | System and data records | Data card | System card |
| Gap/remediation diagnostic | Applicable confirmed failures | Applicable checks/findings | Applicable confirmed failures |
| Regulatory record | Annex IV §2(g)-shaped testing record; provider fields may be incomplete | Applicable data-governance record | Applicable monitoring record/crosswalk |
| Machine exports | Evidence, SARIF, spans when applicable | Evidence, findings, SARIF, spans when applicable | Evidence, model card, SARIF, spans when applicable |
| Signature | Successfully completed, seal-eligible package only | ||
| RFC 3161 timestamp | Only when enabled and reachable; deliberately absent in air-gapped operation | ||
| Human sign-off | Explicit reviewer action; never automatic | ||
Read the methodology or inspect historical sample run records. Historical records retain their original version and structure rather than being rewritten.