VAREXIS-INDEX

Public Evidence Catalog

A public-safe discovery layer for bounded evidence and claim-boundary questions. Inspect the source and its limits before relying on a claim.

122 public records are currently exposed: 38 VAREXIS evidence summaries, 44 external documentation references and 40 derived claim-boundary records. Documentation and derived entries are not VAREXIS experiments.

122public records
108agentic routes
1528near-question hooks

Near-question hooks count distinct wording across records, routes and contexts; repeated wording is counted once.

Machine-readable index · Service/payment routing · Daily entry builder · Make a request

Questions, public answers and service routes

Read the public answer and source for free. For paid handling, choose a service, pay, then email your question. The owner fulfils requests asynchronously when available; no fixed turnaround is promised.

Browse 108 agentic routes

Which records show safe refusal, non-promotion, or not-qualified outcomes?

Public records identify refusal and not-qualified states. They do not convert negative evidence into a success claim.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What should a developer or agent pay for?

Agents can inspect public catalog, public records, question routes and pricing metadata before paying.

VAREXIS-INDEX Developer/API

Relevant public records

Can this evidence be used to claim production readiness, savings, or broad deployment?

Public records expose unsupported and not-demonstrated claim classes. Overclaiming should route to refusal or nearest-supported claim.

VAREXIS-INDEX Single Request

Relevant public records

Which BDAS records show positive selective-execution or workload-reduction evidence?

Public records show bounded positive evidence. They do not show unrestricted production readiness or customer savings.

VAREXIS-INDEX Single Request

Relevant public records

Which records should prevent an overclaim?

Public records expose non-promotion and negative states so agents do not convert them into success claims.

VAREXIS-INDEX Single Request

Relevant public records

Can VAREXIS show evidence pipeline discipline before a developer integrates?

Public records show pipeline and contract-binding discipline without claiming a fully automated self-service runtime.

VAREXIS-INDEX Single Request

Relevant public records

When is paid VAREXIS-INDEX access justified?

Public discovery is free. Paid access is justified when a buyer needs structured routing, receipts, exports, repeated requests or onboarding.

VAREXIS-INDEX Developer/API

Relevant public records

What does A2A establish about communication between independent agents?

The A2A specification defines a shared interaction model for independent agent systems. A particular pair of deployments still needs compatibility checks.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can an agent discover another agent's advertised capabilities through A2A?

A2A describes capability discovery and supported interaction modes. Advertised capability is a declaration; delivery quality and access permissions require separate evidence.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does A2A task collaboration require exposing an agent's internal memory or tools?

A2A describes task collaboration and information exchange without requiring peers to expose their internal state, memory or tools. This is a protocol design statement, not proof of a deployment's confidentiality.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can OPA evaluate policy for a proposed agent action?

OPA evaluates policy against structured input. An agent action must be represented by suitable input and policy; this record does not show that a buyer's rules are complete or correct.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does an OPA decision by itself enforce an agent's permissions?

OPA separates policy evaluation from enforcement. The calling application must apply the decision at the relevant action boundary; a returned decision alone does not establish that enforcement occurred.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can OPA run alongside services that need policy decisions?

OPA documents deployment alongside services and management interfaces for policy distribution and telemetry. Documentation of this architecture does not establish latency or availability for a particular installation.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What do OPA's management interfaces cover?

OPA documents interfaces for policy bundles, decision logs, status and discovery configuration. Integrators configure or implement the surrounding management service; the interfaces alone are not a completed control plane.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What does a SPIFFE SVID establish about a workload?

An SVID lets a workload present a verifiable SPIFFE identity. Identity evidence does not by itself grant permission for a requested action or demonstrate the workload's behaviour.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can an SVID from any SPIFFE trust domain be accepted automatically?

SPIFFE roots identity trust in the relevant trust domain and signing authority. Acceptance across domains requires an appropriate trust relationship and verification policy.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What can a workload obtain through the SPIFFE Workload API?

The Workload API defines retrieval of workload identity documents and trust material. Availability and entitlement depend on the implementation and its configured caller identification.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can SPIFFE tooling support short-lived credentials for workload authentication?

SPIFFE deployment guidance describes workload-bound keys and short-lived X.509 credentials for authentication and TLS. Correct rotation and acceptance still depend on the deployment.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does the Workload API's lack of an explicit client secret mean caller checks are unnecessary?

The Workload API specification places caller identification on the endpoint implementation through out-of-band checks. Lack of an application-level secret does not mean callers may be accepted without identification.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What isolation model does gVisor provide for agent-executed code?

gVisor documents an application-kernel sandbox between workloads and the host. This supports a design description, not a security guarantee for a specific agent deployment.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does a sandboxed workload directly use the host kernel's full interface through gVisor?

gVisor's Sentry handles workload system calls in userspace and mediates necessary host interaction. Workload compatibility and the configured access boundary need separate assessment.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can gVisor integrate with container tooling through runsc?

gVisor provides the runsc OCI runtime for container integration. Runtime integration support does not establish that a particular image or workload is compatible.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does gVisor's security model eliminate every host-side risk?

gVisor aims to reduce host system-interface exposure through mediation and restriction. Its documented scope does not remove every attack vector or replace a secure surrounding architecture.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What does SLSA mean by software provenance?

SLSA describes provenance as verifiable information about an artifact's origin and production. Provenance does not by itself establish that the software is harmless or suitable for a customer's use.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can a SLSA claim be assessed without naming its track and requirements?

SLSA v1.2 separates Build and Source tracks, each with its own requirements. A specific assurance claim needs the relevant track, level and supporting evidence.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does using a recommended SLSA attestation format demonstrate SLSA assurance?

SLSA v1.2 recommends Provenance and Verification Summary Attestation formats without requiring those particular formats. Format choice alone does not show that underlying requirements were met.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What does Sigstore's keyless signing model bind together?

Sigstore's documented keyless flow binds a signing key to an authenticated identity using a short-lived certificate. The identity binding does not establish software quality or permission to deploy.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What does a Rekor transparency entry establish?

Sigstore describes Rekor as a public, append-only record of signing information. Log evidence supports auditability; it does not by itself approve the artifact's contents.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Is verifying an artifact signature sufficient for a Sigstore reliance decision?

The documented Sigstore verification flow checks the signature, expected identity, certificate trust and log inclusion evidence. Reliance also needs the buyer's expected artifact and use context.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does possession of a Sigstore bundle mean an artifact has already been verified?

A Sigstore bundle packages signature content and supporting verification material. A verifier still needs to evaluate that material against the expected artifact and trust policy.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What do OpenTelemetry semantic conventions contribute to agent observability?

OpenTelemetry semantic conventions standardise names for operations and telemetry data. Consistent naming does not establish that a deployment captures complete or accurate evidence.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does the N1 wind-SCADA outcome establish selective-execution performance?

The supplied N1 evidence records a fallback selected before outer truth access when candidates did not qualify. The recorded external outcome supports safe refusal, not selective-execution performance.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What does M4B establish when its centrifuge candidate was not qualified?

The supplied M4B evidence records non-qualification frozen before outer scoring and a full-processing fallback. Its accepted outcome is bounded safe refusal; candidate diagnostics do not establish live selective performance.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does the M4B prospective prediction establish a validated workload classifier?

The supplied observation record describes a prediction frozen before scoring and evaluated after the outcome. It preserves prospective evaluation evidence while the model remains unestablished; it grants no execution authority.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does M4's manufacturing outcome demonstrate selective performance?

The supplied M4 result records non-qualification before outer scoring and use of the full-processing fallback. It supports a bounded safe-refusal outcome beyond the earlier protocol-only summary, without establishing selective performance.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does Backblaze D0 characterisation establish a qualified selective operator?

The D0 source records completed development characterisation with no operator freeze. Qualification and locked-outer access remain recorded as unopened. This is preparation evidence, not an acceleration result.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can Backblaze D1 be cited as a successful performance result?

The D1 final state is worker failure. The supplied final record reports qualification and locked outer unopened and no production promotion. No successful performance result can be inferred from this run.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Which BDAS evidence distinguishes selective correctness, safe fallback and run failure?

PUMP-E2C preserves bounded consumed-data selective evidence. N1 and M4B preserve full-processing refusal outcomes. Backblaze D1 reports worker failure. These states cannot be combined into a general performance claim.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What context does a Cedar authorization request need?

Cedar requests identify the principal, action, resource and context. A correctly shaped request does not prove that these values accurately represent the intended operation.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does Cedar's default denial mean every policy error denies the whole request?

Cedar denies when no permit applies, and a satisfied forbid overrides a permit. Policies that error are skipped; error handling must not be described as unconditional denial.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does Cedar policy validation prove that the policy expresses the intended permissions?

Cedar can check policies against an application schema for consistency. Schema changes can invalidate earlier checks; validation alone does not establish the intended permission model.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can a CVSS score alone determine a buyer's operational risk?

CVSS v4.0 separates Base, Threat, Environmental and Supplemental metrics. Supplemental values add context without changing the score; a severity score alone does not establish local risk.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What does a CVSS vector add to a published score?

A CVSS vector records the metric choices behind a score. FIRST's publication guidance calls for both score and vector; this makes the assessment inspectable without proving its inputs correct.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does an omitted CVSS Safety value mean there are no safety impacts?

CVSS v4.0 includes safety-related context. An omitted Supplemental Safety assessment does not establish absence of safety impacts; deployment-specific consequences require separate assessment.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does an empty OSV query prove a package has no vulnerabilities?

OSV provides queries for known vulnerabilities by package version or commit, including batches. No returned match does not prove absence of unknown issues or correct identification of the deployed artifact.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What does OSV aggregation establish about a vulnerability advisory?

OSV aggregates advisories in a shared vulnerability format. The originating advisory and affected-version mapping remain relevant; aggregation does not establish that a particular deployment is affected.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Are OSV import findings accepted vulnerability results?

OSV documents an experimental endpoint for records that fail import-time quality checks. Such findings describe ingestion issues and must not be treated as accepted vulnerability results or a stable interface guarantee.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does scanning a lockfile or SBOM establish complete deployment coverage?

OSV-Scanner documents SBOM, lockfile and directory inputs. The result depends on what the supplied input represents; supported input formats do not establish a complete inventory of the running system.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does publishing an SPDX document certify the software it describes?

SPDX is an open specification for exchanging supply-chain information. Its standards status does not certify a submitted document's completeness, license conclusions or the safety of its software.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does citing RFC 9700 establish that an OAuth deployment is secure?

RFC 9700 documents OAuth 2.0 security best practices and updates earlier guidance. Citation alone does not demonstrate that a deployment implements the relevant requirements.

VAREXIS-INDEX Evidence Receipt

Relevant public records

What can sender-constrained access tokens support in an OAuth security claim?

RFC 9700 recommends sender-constraining access tokens to reduce misuse of stolen tokens. A deployment claim needs evidence that the relevant proof is checked; the mechanism is not a universal compromise guarantee.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does OAuth server metadata prove the deployment is correctly configured?

RFC 9700 recommends publishing authorization server metadata and using it where available. Metadata supports configuration but does not prove that advertised controls are correctly enforced.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Do CycloneDX format and version fields establish that a BOM is complete?

CycloneDX 1.7 defines format and specification-version identifiers. They identify the declared representation; completeness and correctness of the described inventory require separate evidence.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Can CycloneDX represent service and dependency relationships as well as components?

CycloneDX can describe components, services and dependency relationships. Representation support does not establish that a supplied BOM captures every direct or transitive relationship.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Does a valid SBOM and an empty vulnerability lookup prove a release is safe?

An inventory format identifies represented content, and a lookup reports known matches for its inputs. Check inventory completeness, artifact mapping and lookup date before describing coverage; neither result guarantees safety.

VAREXIS-INDEX Evidence Receipt

Relevant public records

Machine-readable question routes

External documentation review

A2A: Agent interoperability

Question: What does A2A establish about communication between independent agents?

The A2A specification defines a shared interaction model for independent agent systems. A particular pair of deployments still needs compatibility checks.

Source: A2A Protocol current specification. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • universal interoperability
  • tested compatibility of a named deployment
  • permission to delegate or spend

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

A2A: Capability discovery

Question: Can an agent discover another agent's advertised capabilities through A2A?

A2A describes capability discovery and supported interaction modes. Advertised capability is a declaration; delivery quality and access permissions require separate evidence.

Source: A2A Protocol current specification. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • capability declarations as independent validation
  • automatic access to every advertised skill
  • guaranteed task quality

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

A2A: Task collaboration boundary

Question: Does A2A task collaboration require exposing an agent's internal memory or tools?

A2A describes task collaboration and information exchange without requiring peers to expose their internal state, memory or tools. This is a protocol design statement, not proof of a deployment's confidentiality.

Source: A2A Protocol current specification. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • automatic confidentiality of a deployment
  • access to another agent's private internals
  • task completion guaranteed by protocol support

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Attribution V2: Claim truth boundary

Question: Does an Attribution V2 check prove the truth of all linked claims?

The public Attribution V2 source supports evidence-binding posture. It explicitly excludes the truth of all claims and does not confer authority by itself.

Derived from BDAS Fused Attribution V2 — Attribution Check Pass. No new experiment or validation is claimed.

Claim boundaries
  • truth of all claims
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Attribution V2: Private source disclosure boundary

Question: Does Attribution V2 permit public exposure of private sources?

The Attribution V2 source supports binding posture while explicitly excluding public exposure of private sources. Attribution is not disclosure permission.

Derived from BDAS Fused Attribution V2 — Attribution Check Pass. No new experiment or validation is claimed.

Claim boundaries
  • public exposure of private sources
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

public scale reduction with boundaries

BDAS 163M-Row Public Reduction — Public-Scale Summary

Question: What does the 163M-row public reduction record evidence?

Public-safe public-scale reduction summary. It gives the index a scale signal while preserving claim boundaries.

Claim boundaries
  • end-to-end commercial saving
  • production readiness
  • independent replication
  • broad workload applicability
  • mechanism disclosure

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

recovered frozen tranche

BDAS 7001071 — Recovered INDEX Corpus Tranche

Question: What does the 7001071 INDEX tranche evidence?

Public-safe index entry for the recovered 7001071 corpus tranche. It signals corpus existence and bounded validation posture without exposing private artefacts.

Claim boundaries
  • new performance claim
  • production readiness
  • generalised selective execution
  • customer savings

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

correctness qualified economics not qualified

BDAS 7026446 — Correctness Qualified, Economics Not Qualified

Question: How can correctness pass while economics fail?

Public-safe record showing separation between correctness qualification and economic non-qualification.

Claim boundaries
  • economic gain
  • end-to-end acceleration
  • commercial saving
  • outer holdout promotion

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

staged candidate batch

BDAS 7026447 — Candidate Batch Summary

Question: What does the 7026447 candidate batch evidence?

Public-safe summary of the 7026447 staged candidate batch. It exposes counts and status boundaries only.

Claim boundaries
  • all candidates canonical
  • all candidates public-safe
  • runtime API availability
  • external validation of every candidate

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

development characterisation no operator freeze

BDAS Backblaze D0: Development characterisation

Question: Does Backblaze D0 characterisation establish a qualified selective operator?

The D0 source records completed development characterisation with no operator freeze. Qualification and locked-outer access remain recorded as unopened. This is preparation evidence, not an acceleration result.

Supplied evidence reviewed 2026-10-07. The experiment was not rerun; protected source material is not published.

Claim boundaries
  • qualified selective operator
  • performance acceleration
  • fresh qualification result
  • locked-outer validation

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

worker failed no promotion

BDAS Backblaze D1: Worker failure

Question: Can Backblaze D1 be cited as a successful performance result?

The D1 final state is worker failure. The supplied final record reports qualification and locked outer unopened and no production promotion. No successful performance result can be inferred from this run.

Supplied evidence reviewed 2026-10-07. The experiment was not rerun; protected source material is not published.

Claim boundaries
  • successful performance campaign
  • operator correctness demonstrated by completion
  • qualification success
  • production promotion

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

locked outer evaluation with boundaries

BDAS C1 Pump — Locked Outer Evaluation

Question: What does C1 Pump locked outer evidence?

Public-safe locked outer pump evaluation summary. Useful for pump-specific due diligence and paid bounded requests.

Claim boundaries
  • broad pump diagnostics
  • production deployment
  • customer saving
  • unrestricted acceleration
  • external generalisation beyond scope

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

promising development not promoted

BDAS C3 Info-Geometry — Promising Development Record

Question: What does C3 info-geometry evidence?

Public-safe development record. It signals promising direction while refusing premature promotion.

Claim boundaries
  • qualification promotion
  • production readiness
  • customer saving
  • external validation
  • deployed capability

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

not promising development record

BDAS C4 Machine-Local Calibration — Not Promising

Question: What does C4 machine-local calibration evidence?

Public-safe negative development record. It helps show that VAREXIS preserves dead-ends and not-promising paths.

Claim boundaries
  • promoted calibration capability
  • performance improvement
  • deployment readiness
  • commercial saving
  • general method success

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

validation probe pass

BDAS Centered Live Probe V1 — Validation Probe Pass

Question: What does Centered Live Probe V1 evidence?

Public-safe probe-pass record. Useful for showing build/check discipline without implying public runtime service.

Claim boundaries
  • public API availability
  • production deployment
  • external customer use
  • commercial saving
  • unrestricted reliability

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

capture complete no promotion

BDAS CK4A — Capture Complete, No Promotion

Question: What does CK4A evidence?

Public-safe record preserving capture and replay evidence without converting it into an unsupported promotion claim.

Claim boundaries
  • new acceleration claim
  • promotion decision
  • new holdout access
  • calibration fit

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

contract binding check pass

BDAS Consumer Binding V1 — Contract Binding Check

Question: What does Consumer Binding V1 evidence?

Public-safe contract-binding record. Useful for developer confidence without overstating runtime availability.

Claim boundaries
  • public runtime deployment
  • performance qualification
  • customer saving
  • external production use
  • deployment approval

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

decoder check pass

BDAS Decoder V4 — Decoder Check Pass

Question: What does Decoder V4 evidence?

Public-safe decoder validation summary. Useful as an interface-confidence record, not a performance claim.

Claim boundaries
  • performance acceleration
  • production deployment
  • mechanism disclosure
  • customer saving
  • general workload qualification

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

attribution check pass

BDAS Fused Attribution V2 — Attribution Check Pass

Question: What does Fused Attribution V2 evidence?

Public-safe attribution check record. It supports the index concept of source/evidence binding without exposing private material.

Claim boundaries
  • truth of all claims
  • deployment readiness
  • independent validation
  • public exposure of private sources
  • certification

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

locked synthetic confirmation

BDAS G5.2 — Locked Synthetic Confirmation

Question: What does G5.2 evidence?

Public-safe locked synthetic confirmation record. It gives the index a controlled exactness signal while preserving boundaries.

Claim boundaries
  • external generalisation
  • customer saving
  • production deployment
  • independent validation
  • real-world performance

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

locked seed validation pass with boundaries

BDAS H1.3 — Locked-Seed Validation

Question: What does H1.3 evidence about BDAS selective execution?

Public-safe positive validation record for H1.3. It supports bounded selective-execution posture while refusing broader deployment and savings claims.

Claim boundaries
  • production deployment
  • customer saving
  • external generalisation
  • unrestricted performance acceleration
  • mechanism disclosure

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

safe not selective

BDAS H2.1 — Hydraulic Pump Safe But Not Selective

Question: What does H2.1 evidence about external pump evaluation?

Public-safe record showing that an external pump result may be safe but not selective. This is valuable because the index preserves refusal boundaries.

Claim boundaries
  • selective execution qualification
  • performance qualification
  • production pump monitoring readiness
  • customer saving
  • broad pump diagnostic capability

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

development pass

BDAS I1 — Development Pass

Question: What does I1 evidence within the BDAS development chain?

Public-safe development-pass record. It helps show evidence progression without overstating maturity.

Claim boundaries
  • external validation
  • production readiness
  • commercial saving
  • independent replication
  • unrestricted deployment claim

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

reserved hashed holdout

BDAS I2 — Holdout Reserved and Hashed

Question: What does I2 evidence about holdout discipline?

Public-safe holdout-control record. It shows reservation and integrity posture without claiming unopened performance.

Claim boundaries
  • holdout performance
  • production readiness
  • customer saving
  • external generalisation
  • post-hoc validation upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

synthetic reduction evidence with boundaries

BDAS IIoT Synthetic 60M Logs — Public-Safe Reduction Summary

Question: What does the IIoT synthetic 60M-log record evidence?

Public-safe scale summary for synthetic IIoT-style workload reduction. It is a discovery record, not a customer ROI claim.

Claim boundaries
  • real customer environment validation
  • production deployment
  • customer saving
  • external independent replication
  • broad sensor-data generalisation

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

canonical freeze bundle

BDAS INDEX Ledger 0042 — Canonical Freeze Bundle

Question: What does ledger entry 0042 evidence?

Public-safe summary of ledger bridge VRX-RL-2026-0042, binding a set of canonical INDEX freezes without exposing private logs or mechanisms.

Claim boundaries
  • production deployment
  • performance qualification
  • commercial saving
  • external generalisation
  • mechanism disclosure

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

qualification development pass with boundaries

BDAS M1 — Qualification Engine With AURIC Monitor

Question: What did the M1 qualification engine establish?

Public-safe M1 record showing qualification-engine posture and AURIC-monitor boundary without exposing implementation mechanics.

Claim boundaries
  • unrestricted external generalisation
  • production deployment
  • all workloads qualified
  • automatic commercial readiness

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

safe refusal

BDAS M3 — External Locked Safe Refusal

Question: What does M3 evidence?

Public-safe safe-refusal record. It demonstrates that VAREXIS preserves non-promotion and refusal outcomes as part of the evidence index.

Claim boundaries
  • qualification promotion
  • selective execution approval
  • external performance success
  • customer deployment suitability

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

protocol and dataset receipt

BDAS M4 — Manufacturing External Protocol

Question: What does M4 manufacturing evidence?

Public-safe external protocol record. It signals proper protocol and receipt discipline without claiming result success.

Claim boundaries
  • performance qualification
  • deployment readiness
  • commercial saving
  • post-hoc scoring claim
  • broad manufacturing generalisation

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

fresh external safe refusal

BDAS M4: Manufacturing safe refusal

Question: Does M4's manufacturing outcome demonstrate selective performance?

The supplied M4 result records non-qualification before outer scoring and use of the full-processing fallback. It supports a bounded safe-refusal outcome beyond the earlier protocol-only summary, without establishing selective performance.

Supplied evidence reviewed 2026-10-07. The experiment was not rerun; protected source material is not published.

Claim boundaries
  • external selective validation
  • heavy-kernel speedup
  • customer savings
  • production readiness

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

fresh external safe refusal

BDAS M4B: Centrifuge safe refusal

Question: What does M4B establish when its centrifuge candidate was not qualified?

The supplied M4B evidence records non-qualification frozen before outer scoring and a full-processing fallback. Its accepted outcome is bounded safe refusal; candidate diagnostics do not establish live selective performance.

Supplied evidence reviewed 2026-10-07. The experiment was not rerun; protected source material is not published.

Claim boundaries
  • selective-execution promotion
  • economic speedup
  • heavy-kernel performance
  • production readiness

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

model evaluation unestablished

BDAS M4B: Prospective observation limits

Question: Does the M4B prospective prediction establish a validated workload classifier?

The supplied observation record describes a prediction frozen before scoring and evaluated after the outcome. It preserves prospective evaluation evidence while the model remains unestablished; it grants no execution authority.

Supplied evidence reviewed 2026-10-07. The experiment was not rerun; protected source material is not published.

Claim boundaries
  • validated workload-suitability classifier
  • promotion authority
  • permission to skip execution
  • broad predictive accuracy

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

fresh external safe refusal

BDAS N1: Wind SCADA safe refusal

Question: Does the N1 wind-SCADA outcome establish selective-execution performance?

The supplied N1 evidence records a fallback selected before outer truth access when candidates did not qualify. The recorded external outcome supports safe refusal, not selective-execution performance.

Supplied evidence reviewed 2026-10-07. The experiment was not rerun; protected source material is not published.

Claim boundaries
  • selective-execution promotion
  • acceleration or customer savings
  • production readiness
  • broad external generalisation

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

safe but not performance qualified

BDAS NASA IMS E4.1 — Safe But Not Performance Qualified

Question: What did NASA IMS E4.1 demonstrate?

Public-safe record for NASA IMS E4.1. It is valuable because it preserves exact/safe external evidence while refusing an unsupported performance claim.

Claim boundaries
  • performance qualification
  • deployment readiness
  • general acceleration claim
  • commercial cost saving

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

development check no reduction promotion

BDAS OT3 — Frequency-Localized Development Record

Question: What does OT3 evidence?

Public-safe development record showing that no-reduction or non-promoted results remain useful in the index.

Claim boundaries
  • workload reduction
  • performance qualification
  • production deployment
  • commercial saving
  • broad diagnostic capability

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

persistence check pass

BDAS Persistent Output V3 — Output Persistence Check

Question: What does Persistent Output V3 evidence?

Public-safe persistence record. It supports evidence-route discipline without publishing raw outputs.

Claim boundaries
  • claim truth
  • production readiness
  • public runtime availability
  • raw output disclosure
  • deployment approval

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

challenged negative

BDAS PUMP-E1 — Challenged Negative Evidence

Question: Why is PUMP-E1 not a promoted selective-execution claim?

PUMP-E1 is indexed as a negative/challenged record. It demonstrates that VAREXIS-INDEX preserves failed or non-promoted evidence rather than deleting it.

Claim boundaries
  • safe promotion
  • zero false skips
  • deployment suitability
  • broad pump diagnostic capability

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

supported with boundaries

BDAS PUMP-E2C — Consumed Engineering Selective Execution Evidence

Question: What exactly is evidenced by PUMP-E2C?

Existing public full record for PUMP-E2C consumed engineering selective-execution evidence.

Claim boundaries
  • fresh holdout validation
  • production readiness
  • customer savings
  • external generalisation
  • full score reconstruction
  • unrestricted performance acceleration
  • broad pump-audio diagnostic capability
  • hardware-mismatched consumer contract

VAREXIS-INDEX informs evidence reliance; it does not grant authority to deploy or act.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Human record · Request an answer or receipt

correctness strong economics not qualified

BDAS QV1 PCB1 Vision — Correctness Strong, Economics Not Qualified

Question: What did QV1 PCB1 vision demonstrate?

Public-safe record showing that correctness evidence was not inflated into an economics claim.

Claim boundaries
  • net end-to-end economic gain
  • production readiness
  • broad vision workload acceleration
  • unbounded deployment claim

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

reference compatibility only

BDAS S1 Spectral Alarm — Reference Compatibility Record

Question: What does the S1 spectral alarm reference evidence?

Public-safe spectral reference record. Useful for routing spectral questions while refusing deployment claims.

Claim boundaries
  • production alarm system
  • commercial deployment
  • broad sensor acceleration
  • safety certification
  • customer saving

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

exact replay diagnostic

BDAS S1 Spectral Replay — Exact Replay Evidence

Question: What does S1 spectral replay evidence?

Public-safe replay record preserving exact/diagnostic evidence while refusing production or broad deployment claims.

Claim boundaries
  • production alarm system
  • external deployment
  • general sensor acceleration
  • commercial saving

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

controlled reduction with boundaries

BDAS Stage B — Controlled Reduction Evidence

Question: What does Stage B evidence about BDAS reduction?

Public-safe controlled-reduction record for BDAS. It is useful as a positive but bounded commercial-interest signal.

Claim boundaries
  • general acceleration
  • production saving
  • external customer validation
  • independent replication
  • unrestricted workload applicability

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

safe not selective

BDAS Stage F/G — Safe But Not Selective

Question: What does Stage F/G evidence?

Public-safe negative/boundary record. It demonstrates that VAREXIS preserves non-promoted outcomes.

Claim boundaries
  • selective execution qualification
  • performance qualification
  • deployment readiness
  • customer saving
  • broad workload claim

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Paid VAREXIS-INDEX access may provide fuller evidence-route metadata, receipt handling, exports, saved/retrieved routes, request handling, or launch-phase Developer/API onboarding. Public records intentionally omit raw logs, thresholds, private implementation details, reconstruction-level methods and sensitive evidence payloads.

Machine-readable record · Request an answer or receipt

Derived claim boundary

C1 Pump: Diagnostic scope boundary

Question: Does C1 Pump locked outer evaluation establish broad pump diagnostics?

The C1 Pump source supports pump-specific evidence routing. It explicitly excludes broad pump diagnostics.

Derived from BDAS C1 Pump — Locked Outer Evaluation. No new experiment or validation is claimed.

Claim boundaries
  • broad pump diagnostics
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

C3: Promising research versus promotion

Question: Does promising C3 development establish qualification promotion?

C3 is preserved as promising development evidence, not a promoted capability. Its source excludes qualification promotion.

Derived from BDAS C3 Info-Geometry — Promising Development Record. No new experiment or validation is claimed.

Claim boundaries
  • qualification promotion
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

C4: Performance improvement boundary

Question: Does the C4 development record establish performance improvement?

The public C4 source records a not-promising development outcome. It excludes performance improvement.

Derived from BDAS C4 Machine-Local Calibration — Not Promising. No new experiment or validation is claimed.

Claim boundaries
  • performance improvement
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Candidate batch 7026447: Canonical status boundary

Question: Can every staged candidate in batch 7026447 be counted as canonical?

The public batch summary describes staged candidates and explicitly excludes the claim that all candidates are canonical. A staged count is not a count of qualified public records.

Derived from BDAS 7026447 — Candidate Batch Summary. No new experiment or validation is claimed.

Claim boundaries
  • all candidates canonical
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Candidate batch 7026447: Publication boundary

Question: Does the 7026447 staging summary make every candidate public-safe?

The candidate-batch source explicitly excludes the claim that every candidate is public-safe. Staging does not authorise disclosure.

Derived from BDAS 7026447 — Candidate Batch Summary. No new experiment or validation is claimed.

Claim boundaries
  • all candidates public-safe
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

External documentation review

Cedar: Authorization policy scope

Question: Does using Cedar establish that an agent's actions are authorised?

Cedar provides a language and engine for authorization decisions. Correct policy, request data and application enforcement still need deployment evidence.

Source: Cedar Policy Language Reference. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • complete business policy
  • correct deployment enforcement
  • permission to spend

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

Cedar: Denial and evaluation errors

Question: Does Cedar's default denial mean every policy error denies the whole request?

Cedar denies when no permit applies, and a satisfied forbid overrides a permit. Policies that error are skipped; error handling must not be described as unconditional denial.

Source: How Cedar authorization works. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • every evaluation error forces denial
  • all guardrails evaluated successfully
  • complete enforcement from a default rule

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

Cedar: Request context

Question: What context does a Cedar authorization request need?

Cedar requests identify the principal, action, resource and context. A correctly shaped request does not prove that these values accurately represent the intended operation.

Source: How Cedar authorization works. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • authentic request data
  • complete entity context
  • permission inferred from request shape

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

Cedar: Schema validation limits

Question: Does Cedar policy validation prove that the policy expresses the intended permissions?

Cedar can check policies against an application schema for consistency. Schema changes can invalidate earlier checks; validation alone does not establish the intended permission model.

Source: Cedar policy validation. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • business-policy correctness
  • unchanged validity after schema edits
  • deployment enforcement

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

Derived claim boundary

CK4A: Capture versus promotion

Question: Does completed CK4A capture establish a promotion decision?

The CK4A public source records capture completion with no promotion. Capture preservation does not establish a promotion decision.

Derived from BDAS CK4A — Capture Complete, No Promotion. No new experiment or validation is claimed.

Claim boundaries
  • promotion decision
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

CK4A: Holdout access boundary

Question: Does CK4A capture completion establish new holdout access?

The CK4A public source preserves capture and replay evidence. It explicitly excludes new holdout access.

Derived from BDAS CK4A — Capture Complete, No Promotion. No new experiment or validation is claimed.

Claim boundaries
  • new holdout access
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Consumer Binding V1: Runtime deployment boundary

Question: Does Consumer Binding V1 establish public runtime deployment?

The Consumer Binding V1 source supports interface discipline and consumer matching. It excludes public runtime deployment.

Derived from BDAS Consumer Binding V1 — Contract Binding Check. No new experiment or validation is claimed.

Claim boundaries
  • public runtime deployment
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Corpus 7001071: Recovery versus performance

Question: Does recovering corpus 7001071 establish a new performance result?

The public source records recovery of a frozen corpus tranche. It excludes a new performance claim.

Derived from BDAS 7001071 — Recovered INDEX Corpus Tranche. No new experiment or validation is claimed.

Claim boundaries
  • new performance claim
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

External documentation review

CVSS: Safety context

Question: Does an omitted CVSS Safety value mean there are no safety impacts?

CVSS v4.0 includes safety-related context. An omitted Supplemental Safety assessment does not establish absence of safety impacts; deployment-specific consequences require separate assessment.

Source: CVSS v4.0 Specification. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • absence of human safety impact
  • industrial safety certification
  • safe deployment from a missing metric

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

CVSS: Score traceability

Question: What does a CVSS vector add to a published score?

A CVSS vector records the metric choices behind a score. FIRST's publication guidance calls for both score and vector; this makes the assessment inspectable without proving its inputs correct.

Source: CVSS v4.0 Specification. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • correct metric selection
  • independent scoring validation
  • complete risk evidence

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

CVSS: Severity and context

Question: Can a CVSS score alone determine a buyer's operational risk?

CVSS v4.0 separates Base, Threat, Environmental and Supplemental metrics. Supplemental values add context without changing the score; a severity score alone does not establish local risk.

Source: CVSS v4.0 Specification. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • complete business risk assessment
  • automatic remediation priority
  • deployment safety

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

CycloneDX: Document revision traceability

Question: What do CycloneDX serial numbers and BOM versions establish?

CycloneDX 1.7 recommends unique serial numbers and increasing a BOM's version when it is modified. These identify document revisions; they do not prove the truth of a revised inventory.

Source: CycloneDX 1.7 official JSON schema. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • verified inventory changes
  • authenticity from identifiers alone
  • unchanged software from a document version

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

CycloneDX: Inventory relationship scope

Question: Can CycloneDX represent service and dependency relationships as well as components?

CycloneDX can describe components, services and dependency relationships. Representation support does not establish that a supplied BOM captures every direct or transitive relationship.

Source: CycloneDX Specification Overview. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • complete dependency graph
  • verified service boundary
  • automatic discovery of every component

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

CycloneDX: Schema identification

Question: Do CycloneDX format and version fields establish that a BOM is complete?

CycloneDX 1.7 defines format and specification-version identifiers. They identify the declared representation; completeness and correctness of the described inventory require separate evidence.

Source: CycloneDX 1.7 official JSON schema. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • complete dependency inventory
  • accurate component data
  • safe software from schema fields

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Decoder V4: Acceleration boundary

Question: Does a Decoder V4 check establish performance acceleration?

The Decoder V4 source supports interface and consumer discipline. It explicitly excludes performance acceleration.

Derived from BDAS Decoder V4 — Decoder Check Pass. No new experiment or validation is claimed.

Claim boundaries
  • performance acceleration
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

G5.2: Real-world performance boundary

Question: Does G5.2 synthetic confirmation establish real-world performance?

G5.2 supports a locked synthetic confirmation and regression posture. Its public source excludes real-world performance.

Derived from BDAS G5.2 — Locked Synthetic Confirmation. No new experiment or validation is claimed.

Claim boundaries
  • real-world performance
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

External documentation review

gVisor: Limits of host protection

Question: Does gVisor's security model eliminate every host-side risk?

gVisor aims to reduce host system-interface exposure through mediation and restriction. Its documented scope does not remove every attack vector or replace a secure surrounding architecture.

Source: gVisor Security Model. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • elimination of all host risks
  • protection against every side channel
  • security certification

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

gVisor: OCI runtime integration

Question: Can gVisor integrate with container tooling through runsc?

gVisor provides the runsc OCI runtime for container integration. Runtime integration support does not establish that a particular image or workload is compatible.

Source: What is gVisor?. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • all container images are compatible
  • a working installation in a named environment
  • unchanged workload performance

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

gVisor: Sentry interface boundary

Question: Does a sandboxed workload directly use the host kernel's full interface through gVisor?

gVisor's Sentry handles workload system calls in userspace and mediates necessary host interaction. Workload compatibility and the configured access boundary need separate assessment.

Source: Introduction to gVisor security. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • complete Linux compatibility
  • absence of all host interaction
  • a measured performance advantage

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

gVisor: Workload isolation

Question: What isolation model does gVisor provide for agent-executed code?

gVisor documents an application-kernel sandbox between workloads and the host. This supports a design description, not a security guarantee for a specific agent deployment.

Source: Introduction to gVisor security. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • immunity to escape or compromise
  • security assurance for a customer deployment
  • permission to run arbitrary code

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

Derived claim boundary

H1.3: Generalisation boundary

Question: Does H1.3 locked-seed validation establish external generalisation?

H1.3 is a positive locked-seed validation summary with explicit boundaries. Its public source excludes external generalisation.

Derived from BDAS H1.3 — Locked-Seed Validation. No new experiment or validation is claimed.

Claim boundaries
  • external generalisation
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

H1.3: Mechanism disclosure boundary

Question: Does H1.3 validation justify disclosing protected mechanisms?

H1.3 supports bounded locked-seed validation. Its public source excludes mechanism disclosure, including through paid request handling.

Derived from BDAS H1.3 — Locked-Seed Validation. No new experiment or validation is claimed.

Claim boundaries
  • mechanism disclosure
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

H2.1: Pump diagnostics boundary

Question: Does H2.1 establish broad pump diagnostic capability?

H2.1 is publicly recorded as safe but not selective. Its source excludes broad pump diagnostic capability.

Derived from BDAS H2.1 — Hydraulic Pump Safe But Not Selective. No new experiment or validation is claimed.

Claim boundaries
  • broad pump diagnostic capability
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

I1: Independent replication boundary

Question: Does the I1 development pass establish independent replication?

The I1 public source records development progression. It lists independent replication as not demonstrated.

Derived from BDAS I1 — Development Pass. No new experiment or validation is claimed.

Claim boundaries
  • independent replication
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

I2: Holdout reservation versus performance

Question: Does I2 holdout reservation demonstrate holdout performance?

The I2 public source establishes holdout-control posture. It explicitly excludes holdout performance; reservation by itself is not a scored result.

Derived from BDAS I2 — Holdout Reserved and Hashed. No new experiment or validation is claimed.

Claim boundaries
  • holdout performance
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Ledger 0042: Deployment boundary

Question: Does Ledger 0042 establish production deployment?

Ledger 0042 publicly groups canonical corpus freezes. Its existence and grouping claims do not establish production deployment.

Derived from BDAS INDEX Ledger 0042 — Canonical Freeze Bundle. No new experiment or validation is claimed.

Claim boundaries
  • production deployment
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Live Probe V1: Public API availability boundary

Question: Does a Centered Live Probe V1 pass prove public API availability?

The probe source supports pipeline and check integrity. It excludes public API availability; the public discovery surface and launch-phase onboarding do not change that evidence boundary.

Derived from BDAS Centered Live Probe V1 — Validation Probe Pass. No new experiment or validation is claimed.

Claim boundaries
  • public API availability
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

M1: Workload qualification scope

Question: Does the M1 qualification-engine record establish that all workloads qualify?

The M1 source supports bounded development evidence for a qualification engine and monitor. It explicitly excludes the claim that all workloads qualify.

Derived from BDAS M1 — Qualification Engine With AURIC Monitor. No new experiment or validation is claimed.

Claim boundaries
  • all workloads qualified
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

M3: Qualification promotion boundary

Question: Does the M3 safe-refusal record qualify the workload for promotion?

The M3 public source preserves a locked external safe refusal. It explicitly excludes qualification promotion.

Derived from BDAS M3 — External Locked Safe Refusal. No new experiment or validation is claimed.

Claim boundaries
  • qualification promotion
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

M4: Protocol versus performance

Question: Does the M4 protocol and dataset receipt establish performance qualification?

The M4 public source records protocol and dataset-receipt discipline. It explicitly excludes performance qualification.

Derived from BDAS M4 — Manufacturing External Protocol. No new experiment or validation is claimed.

Claim boundaries
  • performance qualification
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

NASA IMS E4.1: Performance boundary

Question: Does the safe NASA IMS E4.1 result establish performance qualification?

The public NASA IMS E4.1 source records a safe but not performance-qualified result. The safe status does not support a performance qualification claim.

Derived from BDAS NASA IMS E4.1 — Safe But Not Performance Qualified. No new experiment or validation is claimed.

Claim boundaries
  • performance qualification
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

External documentation review

OAuth: Public-client PKCE requirement

Question: What does RFC 9700 require for public clients using authorization codes?

RFC 9700 requires PKCE for public clients using the authorization code grant. A claim of PKCE support still needs evidence that the deployed flow enforces it.

Source: RFC 9700: Authorization Code Grant. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • correct PKCE enforcement
  • complete OAuth security
  • tested protection from a library feature list

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OAuth: Security guidance scope

Question: Does citing RFC 9700 establish that an OAuth deployment is secure?

RFC 9700 documents OAuth 2.0 security best practices and updates earlier guidance. Citation alone does not demonstrate that a deployment implements the relevant requirements.

Source: RFC 9700: OAuth 2.0 Security Best Current Practice. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • deployment conformance
  • complete security assurance
  • authorization for an agent action

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OAuth: Sender-constrained token scope

Question: What can sender-constrained access tokens support in an OAuth security claim?

RFC 9700 recommends sender-constraining access tokens to reduce misuse of stolen tokens. A deployment claim needs evidence that the relevant proof is checked; the mechanism is not a universal compromise guarantee.

Source: RFC 9700: Access Tokens. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • all token theft prevented
  • proof verification in an untested deployment
  • protection after all relevant key material is compromised

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OAuth: Server metadata scope

Question: Does OAuth server metadata prove the deployment is correctly configured?

RFC 9700 recommends publishing authorization server metadata and using it where available. Metadata supports configuration but does not prove that advertised controls are correctly enforced.

Source: RFC 9700: Other Recommendations. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • correct enforcement of advertised features
  • trusted configuration without issuer checks
  • complete deployment validation

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OPA: Decision versus enforcement

Question: Does an OPA decision by itself enforce an agent's permissions?

OPA separates policy evaluation from enforcement. The calling application must apply the decision at the relevant action boundary; a returned decision alone does not establish that enforcement occurred.

Source: Open Policy Agent. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • automatic enforcement by a decision response
  • absence of bypass paths
  • complete deployment protection

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OPA: Decisions over structured input

Question: Can OPA evaluate policy for a proposed agent action?

OPA evaluates policy against structured input. An agent action must be represented by suitable input and policy; this record does not show that a buyer's rules are complete or correct.

Source: Open Policy Agent. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • a buyer's policy correctness
  • automatic discovery of all relevant context
  • deployment approval

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OPA: Distributed policy deployment

Question: Can OPA run alongside services that need policy decisions?

OPA documents deployment alongside services and management interfaces for policy distribution and telemetry. Documentation of this architecture does not establish latency or availability for a particular installation.

Source: OPA Management APIs and Architecture. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • measured customer latency
  • high availability of a named deployment
  • automatic consistency of every policy instance

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OPA: Management interfaces

Question: What do OPA's management interfaces cover?

OPA documents interfaces for policy bundles, decision logs, status and discovery configuration. Integrators configure or implement the surrounding management service; the interfaces alone are not a completed control plane.

Source: OPA Management APIs and Architecture. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • a deployed management service
  • complete audit retention
  • secure handling of every decision log

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OpenSSF Scorecard: Project practice evidence

Question: Does an OpenSSF Scorecard result guarantee that a dependency is safe?

OpenSSF Scorecard uses automated checks to assess project security practices. A result is evidence about those checks, not a guarantee that an artifact is safe or suitable for a buyer.

Source: OpenSSF Scorecard. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • absence of vulnerabilities
  • safe dependency certification
  • all security properties tested

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OpenTelemetry: Naming conventions

Question: What do OpenTelemetry semantic conventions contribute to agent observability?

OpenTelemetry semantic conventions standardise names for operations and telemetry data. Consistent naming does not establish that a deployment captures complete or accurate evidence.

Source: OpenTelemetry Semantic Conventions. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • complete observability from naming alone
  • correctness of captured telemetry
  • proof that an agent action was authorised

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OSV-Scanner: Input coverage

Question: Does scanning a lockfile or SBOM establish complete deployment coverage?

OSV-Scanner documents SBOM, lockfile and directory inputs. The result depends on what the supplied input represents; supported input formats do not establish a complete inventory of the running system.

Source: OSV.dev. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • complete running-system inventory
  • zero vulnerabilities
  • all code paths assessed

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OSV: Advisory provenance

Question: What does OSV aggregation establish about a vulnerability advisory?

OSV aggregates advisories in a shared vulnerability format. The originating advisory and affected-version mapping remain relevant; aggregation does not establish that a particular deployment is affected.

Source: OSV data sources and advisory format. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • verified exploitation in a customer system
  • complete database coverage
  • independent confirmation of every advisory

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OSV: Import quality findings

Question: Are OSV import findings accepted vulnerability results?

OSV documents an experimental endpoint for records that fail import-time quality checks. Such findings describe ingestion issues and must not be treated as accepted vulnerability results or a stable interface guarantee.

Source: OSV API 1.0. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • accepted advisory status
  • stable experimental API contract
  • vulnerability proven by an import failure

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

OSV: Known vulnerability queries

Question: Does an empty OSV query prove a package has no vulnerabilities?

OSV provides queries for known vulnerabilities by package version or commit, including batches. No returned match does not prove absence of unknown issues or correct identification of the deployed artifact.

Source: OSV API 1.0. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • absence of all vulnerabilities
  • complete deployed dependency identification
  • runtime exploitability

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

Derived claim boundary

OT3: Workload reduction boundary

Question: Does the OT3 development record establish workload reduction?

The OT3 public source records development learning without reduction promotion. Workload reduction is explicitly not demonstrated.

Derived from BDAS OT3 — Frequency-Localized Development Record. No new experiment or validation is claimed.

Claim boundaries
  • workload reduction
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Output V3: Persistence versus truth

Question: Does preserving an Output V3 result establish claim truth?

Output V3 supports an output-persistence check and auditability posture. Its public source excludes claim truth.

Derived from BDAS Persistent Output V3 — Output Persistence Check. No new experiment or validation is claimed.

Claim boundaries
  • claim truth
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Public row-scale reduction: Applicability boundary

Question: Does the public row-scale reduction record establish broad workload applicability?

The public row-scale source supports bounded scale interest. Its source excludes broad workload applicability.

Derived from BDAS 163M-Row Public Reduction — Public-Scale Summary. No new experiment or validation is claimed.

Claim boundaries
  • broad workload applicability
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

PUMP-E1: Promotion boundary

Question: Can challenged PUMP-E1 evidence be promoted as a safe result?

PUMP-E1 remains a challenged negative record in the public index. Its source lists safe promotion as not demonstrated.

Derived from BDAS PUMP-E1 — Challenged Negative Evidence. No new experiment or validation is claimed.

Claim boundaries
  • safe promotion
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

PUMP-E2C: Customer savings boundary

Question: Can a buyer infer customer savings from PUMP-E2C?

The public PUMP-E2C record supports a narrow selective-execution claim on consumed evidence. It lists customer savings as not demonstrated.

Derived from BDAS PUMP-E2C — Consumed Engineering Selective Execution Evidence. No new experiment or validation is claimed.

Claim boundaries
  • customer savings
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

PUMP-E2C: Fresh holdout boundary

Question: Can PUMP-E2C be cited as a fresh holdout result?

PUMP-E2C is published as historically consumed engineering evidence. Its public source explicitly excludes fresh holdout validation.

Derived from BDAS PUMP-E2C — Consumed Engineering Selective Execution Evidence. No new experiment or validation is claimed.

Claim boundaries
  • fresh holdout validation
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

PUMP-E2C: Hardware contract boundary

Question: Can PUMP-E2C support a hardware-mismatched consumer contract?

The PUMP-E2C public source excludes a hardware-mismatched consumer contract. Its narrow supported claim must retain the stated evidence scope.

Derived from BDAS PUMP-E2C — Consumed Engineering Selective Execution Evidence. No new experiment or validation is claimed.

Claim boundaries
  • hardware-mismatched consumer contract
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

PUMP-E2C: Score reconstruction boundary

Question: Does the PUMP-E2C public record support full score reconstruction?

The PUMP-E2C public source excludes full score reconstruction. Public and paid handling preserve the protected implementation boundary.

Derived from BDAS PUMP-E2C — Consumed Engineering Selective Execution Evidence. No new experiment or validation is claimed.

Claim boundaries
  • full score reconstruction
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

QV1 PCB1: Net economics boundary

Question: Can QV1 PCB1 correctness evidence support net end-to-end economic gain?

The public QV1 PCB1 source retains strong correctness evidence alongside economic non-qualification. It does not establish net end-to-end economic gain.

Derived from BDAS QV1 PCB1 Vision — Correctness Strong, Economics Not Qualified. No new experiment or validation is claimed.

Claim boundaries
  • net end-to-end economic gain
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Record 7026446: Economic gain boundary

Question: Does correctness qualification in record 7026446 establish economic gain?

Record 7026446 separates correctness qualification from economic non-qualification. Its public source does not demonstrate economic gain.

Derived from BDAS 7026446 — Correctness Qualified, Economics Not Qualified. No new experiment or validation is claimed.

Claim boundaries
  • economic gain
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Record 7026446: Outer holdout boundary

Question: Does correctness qualification in 7026446 establish outer holdout promotion?

The public 7026446 source separates correctness from economics and excludes outer holdout promotion.

Derived from BDAS 7026446 — Correctness Qualified, Economics Not Qualified. No new experiment or validation is claimed.

Claim boundaries
  • outer holdout promotion
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

S1 reference: Certification boundary

Question: Does S1 reference compatibility establish safety certification?

The S1 spectral alarm reference supports bounded compatibility signalling. Its public source explicitly excludes safety certification.

Derived from BDAS S1 Spectral Alarm — Reference Compatibility Record. No new experiment or validation is claimed.

Claim boundaries
  • safety certification
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

S1 spectral replay: Production alarm boundary

Question: Does S1 exact replay establish a production alarm system?

The S1 replay public source supports bounded exact-replay and diagnostic evidence. It excludes a production alarm system claim.

Derived from BDAS S1 Spectral Replay — Exact Replay Evidence. No new experiment or validation is claimed.

Claim boundaries
  • production alarm system
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

External documentation review

Sigstore: Bundled verification material

Question: Does possession of a Sigstore bundle mean an artifact has already been verified?

A Sigstore bundle packages signature content and supporting verification material. A verifier still needs to evaluate that material against the expected artifact and trust policy.

Source: Sigstore Bundle Format. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • verification from bundle possession
  • acceptance of an arbitrary signer
  • artifact safety from packaging

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

Sigstore: Identity-based signing

Question: What does Sigstore's keyless signing model bind together?

Sigstore's documented keyless flow binds a signing key to an authenticated identity using a short-lived certificate. The identity binding does not establish software quality or permission to deploy.

Source: Sigstore documentation. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • software quality from signer identity
  • deployment permission
  • all signing modes use identical trust assumptions

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

Sigstore: Signing transparency

Question: What does a Rekor transparency entry establish?

Sigstore describes Rekor as a public, append-only record of signing information. Log evidence supports auditability; it does not by itself approve the artifact's contents.

Source: Sigstore documentation. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • artifact safety from log presence
  • endorsement by the log operator
  • correctness of a signed claim

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

Sigstore: Verification expectations

Question: Is verifying an artifact signature sufficient for a Sigstore reliance decision?

The documented Sigstore verification flow checks the signature, expected identity, certificate trust and log inclusion evidence. Reliance also needs the buyer's expected artifact and use context.

Source: Sigstore documentation. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • all trust checks satisfied by signature mathematics alone
  • verification of an actual customer artifact
  • permission to execute after verification

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SLSA: Artifact provenance

Question: What does SLSA mean by software provenance?

SLSA describes provenance as verifiable information about an artifact's origin and production. Provenance does not by itself establish that the software is harmless or suitable for a customer's use.

Source: SLSA Provenance. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • malware freedom
  • fitness for a buyer's intended use
  • truth of arbitrary claims inside an artifact

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SLSA: Attestation format scope

Question: Does using a recommended SLSA attestation format demonstrate SLSA assurance?

SLSA v1.2 recommends Provenance and Verification Summary Attestation formats without requiring those particular formats. Format choice alone does not show that underlying requirements were met.

Source: SLSA specification v1.2. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • format compliance as full assurance
  • mandatory use of a particular recommended format
  • verification inferred from JSON shape

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SLSA: Build and Source tracks

Question: Can a SLSA claim be assessed without naming its track and requirements?

SLSA v1.2 separates Build and Source tracks, each with its own requirements. A specific assurance claim needs the relevant track, level and supporting evidence.

Source: SLSA 1.2 Tracks. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • a SLSA level inferred from a product name
  • equivalence of Build and Source assurance
  • certification by this index

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SPDX: Standard and certification boundary

Question: Does publishing an SPDX document certify the software it describes?

SPDX is an open specification for exchanging supply-chain information. Its standards status does not certify a submitted document's completeness, license conclusions or the safety of its software.

Source: SPDX Specifications. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • software safety certification
  • complete component inventory
  • verified license compliance

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SPIFFE: Identity material retrieval

Question: What can a workload obtain through the SPIFFE Workload API?

The Workload API defines retrieval of workload identity documents and trust material. Availability and entitlement depend on the implementation and its configured caller identification.

Source: SPIFFE Workload API. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • access to identities belonging to other workloads
  • an available endpoint in a buyer's deployment
  • automatic entitlement

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SPIFFE: Short-lived workload credentials

Question: Can SPIFFE tooling support short-lived credentials for workload authentication?

SPIFFE deployment guidance describes workload-bound keys and short-lived X.509 credentials for authentication and TLS. Correct rotation and acceptance still depend on the deployment.

Source: Working with SVIDs. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • working credential rotation in a named system
  • uninterrupted availability during renewal
  • authorisation from certificate possession

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SPIFFE: Trust-domain scope

Question: Can an SVID from any SPIFFE trust domain be accepted automatically?

SPIFFE roots identity trust in the relevant trust domain and signing authority. Acceptance across domains requires an appropriate trust relationship and verification policy.

Source: SPIFFE Identity and SVID. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • automatic cross-domain trust
  • universal acceptance of an SVID
  • validity based only on an identity string

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SPIFFE: Workload API caller checks

Question: Does the Workload API's lack of an explicit client secret mean caller checks are unnecessary?

The Workload API specification places caller identification on the endpoint implementation through out-of-band checks. Lack of an application-level secret does not mean callers may be accepted without identification.

Source: SPIFFE Workload API. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • anonymous access as the intended trust model
  • caller identification verified in a named deployment
  • security from endpoint reachability alone

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

External documentation review

SPIFFE: Workload identity

Question: What does a SPIFFE SVID establish about a workload?

An SVID lets a workload present a verifiable SPIFFE identity. Identity evidence does not by itself grant permission for a requested action or demonstrate the workload's behaviour.

Source: SPIFFE Identity and SVID. Documentation checked 2026-10-07; no deployment validation is claimed.

Claim boundaries
  • permission to execute an action
  • trustworthiness of workload behaviour
  • identity as proof of claim truth

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Stage B: General acceleration boundary

Question: Does Stage B controlled reduction establish general acceleration?

The Stage B source supports bounded controlled-reduction evidence. It explicitly excludes general acceleration.

Derived from BDAS Stage B — Controlled Reduction Evidence. No new experiment or validation is claimed.

Claim boundaries
  • general acceleration
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Stage F/G: Selectivity boundary

Question: Does Stage F/G safety establish selective-execution qualification?

The Stage F/G source preserves a safe but non-selective outcome. Selective-execution qualification is explicitly not demonstrated.

Derived from BDAS Stage F/G — Safe But Not Selective. No new experiment or validation is claimed.

Claim boundaries
  • selective execution qualification
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt

Derived claim boundary

Synthetic IIoT: Customer validation boundary

Question: Does the synthetic IIoT record establish real customer environment validation?

The public IIoT source describes synthetic workload reduction and scale. It excludes real customer environment validation.

Derived from BDAS IIoT Synthetic 60M Logs — Public-Safe Reduction Summary. No new experiment or validation is claimed.

Claim boundaries
  • real customer environment validation
  • new experimental result
  • independent validation
  • evidence maturity upgrade

VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.

Public source and boundary inspection is free. Pay first, then email your question for asynchronous manual fulfilment when the owner is available. No fixed turnaround is promised. Protected evidence is not disclosed.

Machine-readable record · Request an answer or receipt