{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:09:49Z",
  "record_id": "VXI-EXT-SLSA-12-TRACK-01-v1",
  "record_kind": "external_reference",
  "title": "SLSA: Build and Source tracks",
  "system": "SLSA",
  "evidence_family": "software_supply_chain",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Can a SLSA claim be assessed without naming its track and requirements?",
  "near_questions": [
    "What is the difference between SLSA Build and Source tracks?",
    "Can a build claim prove source-process controls?",
    "What must a buyer specify when claiming a SLSA level?",
    "Does a provenance file establish every SLSA requirement?",
    "How should a receipt identify the applicable SLSA track?",
    "Can source revision controls validate the build environment?",
    "Which record separates source and build assurance?",
    "What evidence supports a track-specific level claim?",
    "Does using SLSA terminology demonstrate compliance?",
    "Can an agent compare levels across different tracks as identical?",
    "What is missing from an unspecified SLSA assurance claim?",
    "How should a paid review scope a SLSA statement?"
  ],
  "supported_claims": [
    {
      "claim": "SLSA v1.2 separates Build and Source tracks, each with its own requirements. A specific assurance claim needs the relevant track, level and supporting evidence.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "a SLSA level inferred from a product name",
    "equivalence of Build and Source assurance",
    "certification by this index"
  ],
  "public_summary": "SLSA v1.2 separates Build and Source tracks, each with its own requirements. A specific assurance claim needs the relevant track, level and supporting evidence.",
  "related_record_ids": [
    "VXI-EXT-SLSA-12-PROV-01-v1",
    "VXI-EXT-SLSA-12-03-v1",
    "VXI-EXT-SIGSTORE-01-v1",
    "VXI-EXT-SIGSTORE-02-v1",
    "VXI-EXT-SIGSTORE-03-v1",
    "VXI-EXT-SIGSTORE-BUNDLE-01-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "SLSA 1.2 Tracks",
    "source_url": "https://slsa.dev/spec/v1.2/tracks",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-SLSA-12-TRACK-01-v1",
    "candidate_record_sha256": "8535b048db7a27c406cd9cceab31ead6561646c6f2224a8c224953d8246c3f47",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "SLSA v1.2 separates Build and Source tracks, each with its own requirements. A specific assurance claim needs the relevant track, level and supporting evidence.",
    "required_buyer_context": "Specification version, track, asserted level, requirements and evidence for the exact artifact or process.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#slsa-build-source-tracks",
  "machine_readable_record": "/varexis-index/records/slsa-build-source-tracks.json"
}
