Skip to content

Evidence

Evidence is the information required to inspect and support a system claim.

Useful evidence is explicit rather than implied.

  • source identifiers
  • canonical or normalized state
  • hashes
  • signatures
  • timestamps
  • manifests
  • replay inputs
  • verification results
  • provenance relationships

Evidence should be:

  • attributable
  • inspectable
  • integrity-protected
  • scoped to the relevant decision or artifact
  • sufficient for the intended verification claim

More evidence is not automatically better.

The goal is enough evidence to support independent inspection without unnecessarily widening the trusted boundary.