Independent clean-lab software assurance

Evidence should say exactly what was proven.

If it was not proven, it does not pass.

WindAnvil takes an exact source or release, applies explicit policy outside the subject, preserves the receipts, and returns one honest outcome.

PASS FAIL BLOCKED

If the proof is missing, the result is BLOCKED. It never quietly becomes PASS.

immutable objectexplicit policyindependent evidenceportable record

Most assurance failures begin by blurring different claims together.

A green build is not provenance. An SBOM is not proof of which build graph produced it. A skipped check is not a passing check.

WindAnvil keeps identity, policy, execution, observation, and decision separate so the final claim can be narrower and stronger.

Bind the object first. Then prove only what the evidence supports.

01

Admit

Fix the exact source, release, or artifact identity before work begins.

02

Plan

Apply the external minimum policy and any additive local requirements.

03

Execute

Run authorized work without substituting source, architecture, or capability.

04

Observe

Collect results, hashes, provenance, and capability evidence as distinct facts.

05

Decide

Return PASS, FAIL, or BLOCKED. Never a stronger claim than the proof allows.

The Assurance Record is the durable product.

It binds the admitted object to the policy, execution plan, observations, artifact digests, and terminal verdict without inventing a second layer of interpretation.

subject.shaimmutable
policy.digestbound
plan.digestbound
observationscanonical
artifactssha256
verdictPASS | FAIL | BLOCKED

Narrower claims.

Stronger evidence.

No invisible gaps.