Content-addressed reports — Repository, policy, tracked content, toolchain, and findings are digest-bound so stale evidence is rejected.
Candidates, not defects — Static signals stay provisional until a reviewer adjudicates them against the relevant production surface.
Native audit boundaries — Declared adapters use validated argv, bounded runtime, credential-free environments, read-only snapshots, and no shell.
Review separation — Pack and reviewer signatures use distinct versioned Ed25519 message domains; legacy raw-digest signatures are refused.
Deterministic interchange — Candidate and review state project into SARIF 2.1.0 without losing exact anchors or evidence status.
Controlled remediation — Plans preserve dependencies, accepted risks, conflicts, and missing evidence without granting execution authority.
Per-rule maturity probation — Every detection rule stays an anchored review candidate in explicit probation until an adopter policy is met by source-bound completed reviews.
Offline verificationrigor verify checks signed evidence, key lifecycle, expiry, unavailable records, and model-alias collapse entirely offline.
CRA readiness

Optional policy schema 1.4 activates CR001–CR006 CRA readiness rules. Imported-only CRA component inventories validate bounded CycloneDX 1.5/1.6, and an offline CRA Article 14 preparation lane stores strict content-addressed records.