Local engineering readiness

What works and what still requires an owner

The synthetic closed-pilotA controlled test phase with limited participants, an approved purpose and no automatic authorization for production. contour is reproducible locally; external authorization and production infrastructure remain blocked.

15local checks passed
8external owner gates
11adapters disabled

Synthetic local contour only

local-engineering-pass · production=false · private-data=false

VerifiedLOCAL-01

Evidence SpineThe connected chain from source to conclusion that preserves versions, exact anchors, limitations, transformations and human decisions. and strict persisted contracts

  • schemas
  • tests/test_domain_models.py
  • tests/test_service_workflow.py
VerifiedLOCAL-02

TenantA security boundary isolating one organization's users, cases, keys and policy from every other organization. and case isolation with purpose-bound roles

  • app/context.py
  • app/storage.py
  • tests/test_storage.py
VerifiedLOCAL-03

Hash-chained auditA log where every event is linked to the previous event hash, making later undisclosed alteration detectable. and tamper detection

  • app/storage.py
  • tests/test_storage.py
VerifiedLOCAL-04

No-network capture target and DNS policy

  • app/capture_policy.py
  • science/benchmarks/capture-policy-hostile-v1.json
  • tests/test_capture_policy.py
VerifiedLOCAL-05

Idempotent durable operation lifecycle

  • schemas/operation-job-v1.schema.json
  • app/services/hub.py
  • tests/test_jobs.py
VerifiedLOCAL-06

Tenant-local multilingual reference search

  • app/search.py
  • science/benchmarks/local-search-multilingual-v1.json
  • tests/test_search.py
VerifiedLOCAL-07

Database and immutable-vault recovery rehearsal

  • app/storage.py
  • app/vault.py
  • scripts/verify_pilot.py
  • tests/test_recovery.py
VerifiedLOCAL-08

Encrypted private case portability

  • app/bundles.py
  • tests/test_bundle.py
VerifiedLOCAL-09

Fail-closed typed portfolio adapter registry

  • reference/adapters/portfolio-adapters.v1.json
  • app/adapters.py
  • tests/test_adapters.py
VerifiedLOCAL-10

Reproducible Science benchmarkA test set with expected answers that measures a reference implementation, not real-world quality. and method registry

  • science/methods
  • science/benchmarks
  • app/benchmarks.py
  • scripts/verify_benchmarks.py
VerifiedLOCAL-11

Dependency locks SBOMA machine-readable inventory of software components, versions and provenance included in a specific product build. and clean-tree release gate

  • requirements.lock
  • requirements-dev.lock
  • artifacts/openapi.json
  • artifacts/sbom.spdx.json
  • scripts/verify_release.py
VerifiedLOCAL-12

Static fail-closed container profile without runtime claimAn atomic, verifiable statement linked to evidence, a coverage envelope and separate human assessment dimensions.

  • Dockerfile
  • docker-compose.yml
  • .dockerignore
  • tests/test_deployment_contract.py
VerifiedLOCAL-13

Strict multilingual glossary and accessible first-occurrence definitions

  • reference/glossary/osint-glossary.v1.json
  • app/glossary.py
  • tests/test_glossary.py
VerifiedLOCAL-14

Complete read-only synthetic Investigation Workbench

  • app/workbench.py
  • templates/workbench_case.html
  • tests/test_workbench.py
VerifiedLOCAL-15

Content, persona, responsive and accessibility acceptance contract

  • docs/PERSONA_ACCEPTANCE.md
  • docs/CONTENT_OPERATING_SYSTEM.md
  • reference/content/content-registry.v1.json
  • reference/content/route-persona-ledger.v1.json
  • scripts/verify_ui.py
  • tests/test_content_surface.py

Owner required

external owner gates

Owner requiredEXTERNAL-01

License legal privacy and source terms

Portfolio owner plus Legal and DPO

Required closure evidenceResearch material whose provenance, time, integrity state and link to an exact source version are preserved.

Selected project and data licenses, approved legal register, DPIAA prior assessment of risks that personal-data processing creates for people and the measures used to reduce those risks. and connector-specific source admission.

Owner requiredEXTERNAL-02

Production identity and privileged WebAuthnA public-key authentication standard supporting phishing-resistant hardware security keys and passkeys.

Identity owner plus Security

Required closure evidence

Canonical IdP, phishing-resistant privileged authentication, revocation and recovery drill.

Owner requiredEXTERNAL-03

Production tenant keys secrets and data cells

Security plus Storage owner

Required closure evidence

Independent tenant keys, rotation, adversarial isolation tests and approved secret owner.

Owner requiredEXTERNAL-04

Object storage search and workflow owners

Architecture council plus Operations

Required closure evidence

Repeatable bake-offs, cost and restore evidence, deletion propagation and signed ownership ADRs.

Owner requiredEXTERNAL-05

Capture sandbox egress and document quarantine

Security plus QazPipe and Compute owners

Required closure evidence

Escape, SSRFA vulnerability class where an attacker causes a server to request an internal, local or otherwise forbidden address., DNS rebindingAn attack technique where one domain name changes between validation and connection to another, often internal, IP address., malware corpusA research data collection with provenance, time window, rights and exclusion rules. and packet-level tests in the selected isolated runtime.

Owner requiredEXTERNAL-06

Runtime capacity observability backup and rollback

Operations plus Finance

Required closure evidence

Named runtime, SLO and cost envelope, encrypted backups, restore timing, signed artifact and rollback drill.

Owner requiredEXTERNAL-07

Pilot organizations training and incident tabletop

Product plus Partners plus Security

Required closure evidence

Named pilot organizations, agreements, competency checks, offboarding rehearsal and incident action log.

Owner requiredEXTERNAL-08

Remote domain public surface and release approval

Product owner plus Release owner

Required closure evidence

Authoritative remote, assigned domain and runtime owner, two-person promotion approval and public verification.