← Home

Inside the evidence package

Outputs vary by product, selected checks, completion state, verification mode, regulatory inputs, and whether a human reviewer explicitly signs off. A stopped or artifact-inconsistent run may remain incomplete and unsealed.

The five-drawer structure

Top level: the primary readable report and any applicable corrected/redlined output.
System files: canonical machine record and scope/consistency records.
Transparency: detailed evidence, confirmed-failure ledger, and result-bound sign-off history when present.
Integration: applicable evidence.json, SARIF, cards, and OpenTelemetry/OpenInference exports.
Integrity: signed manifest, signer certificate, verifier, and conditional RFC 3161 timestamp.

Product output matrix

OutputScoutSitRepWatchtower
Primary readable reportCompleted runCompleted runCompleted cycle
Executive summaryWhen generatedWhen generatedWhen generated
System/data cardSystem and data recordsData cardSystem card
Gap/remediation diagnosticApplicable confirmed failuresApplicable checks/findingsApplicable confirmed failures
Regulatory recordAnnex IV §2(g)-shaped testing record; provider fields may be incompleteApplicable data-governance recordApplicable monitoring record/crosswalk
Machine exportsEvidence, SARIF, spans when applicableEvidence, findings, SARIF, spans when applicableEvidence, model card, SARIF, spans when applicable
SignatureSuccessfully completed, seal-eligible package only
RFC 3161 timestampOnly when enabled and reachable; deliberately absent in air-gapped operation
Human sign-offExplicit reviewer action; never automatic

Read the methodology or inspect historical sample run records. Historical records retain their original version and structure rather than being rewritten.