Institutional evidence ledger

Evidence and change history

Which public Institutional claims are supported, targeted, stale, unavailable, or not established?

This ledger separates repository-verifiable facts, public statements, declared principles, operational targets, actual-host observations, external validation, and unknowns. Each record names its source, scope, limitations, observation environment, and append-oriented change history.

Direct answer

The ledger shows why a claim is supportable—or why it is not

This is a public claim index and change-history surface, not a compliance register. Every record keeps its claim class, support status, source identity, observation environment, verification method, scope, limitations, defeaters, and change lineage separate.

A repository source does not prove a deployed host. A target does not prove completion. An unavailable check is not favorable evidence. A hash proves byte identity within its stated scope, not factual truth.

Repository-verifiable
SOURCE SCOPECode, templates, configuration, tests, or packaged evidence support the bounded statement.
Operational target
NOT COMPLETIONA declared objective remains a target until implementation and environment-specific acceptance are established.
Actual-host observation
SEPARATE EVIDENCEOnly the public environment and time named in the record are described.
Unknown
NOT ESTABLISHEDNo reviewed source supports turning the matter into a fact; unknown does not mean absent.

Bounded filters

Inspect records without collapsing their evidence states

The server applies these filters, so the result remains usable without JavaScript. Client-side enhancement only reduces reloads.

Clear

4 records shown.

Current public record set

Claim records

Each record has a stable public URL. Open it to inspect source identity, digest scope, limitations, defeaters, and append-oriented change history.

EVI-INST-0011

Browser forms use a CSRF boundary in source

SUPPORTED WITHIN SCOPE

The packaged contact form and application stack include CSRF protection when the Flask application is running with required configuration.

Class
REPOSITORY VERIFIABLE
Page
Security
Source
REPOSITORY SOURCE
Observed
2026-08-13T00:47:38Z
ScopePackaged application source
Open full record and change history
EVI-INST-0012

Restrictive response-header logic exists in source

SUPPORTED WITHIN SCOPE

The packaged application defines security-header behavior, but reverse proxies and host configuration can alter the final public response.

Class
REPOSITORY VERIFIABLE
Page
Security
Source
REPOSITORY SOURCE
Observed
2026-08-13T00:47:38Z
ScopeApplication-generated responses in the packaged source
Open full record and change history
EVI-INST-0013

Security certification and penetration-test results are not established

NOT ESTABLISHED

The public repository does not establish SOC 2, ISO 27001, FedRAMP, penetration-test, bug-bounty, or equivalent security-program status.

Class
UNKNOWN NOT ESTABLISHED
Page
Security
Source
NO CURRENT SOURCE
Observed
2026-08-13T00:47:38Z
ScopePublic packaged material reviewed for RC57
Open full record and change history
EVI-INST-0019

Actual-host response headers remain unavailable

UNAVAILABLE

The build environment could not collect final public response headers or content-security-policy values from the actual host.

Class
ACTUAL HOST OBSERVATION
Page
Security
Source
ACTUAL HOST OBSERVATION RECORD
Observed
2026-08-13T00:47:38Z
ScopeActual-host header evidence for Institutional routes
Open full record and change history

Machine-readable record

The same bounded fields are available as first-party JSON

The endpoint exposes the public claim records, independent class and status vocabularies, change events, filter state, and a deterministic ledger digest. It does not expose private operator notes, protected report paths, credentials, or protected Eviulon strategy.

MISSION-FIRST · EVIDENCE-LOCKED · MACHINE-SPEED

DETECT → VERIFY → DENY → CONTAIN → RECOVER → PROVE

Command integrity. Decision superiority. Compartment security. Attested reconstitution.