{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:36:13Z",
  "record_id": "VXI-EXT-SPDX-30-02-v1",
  "record_kind": "external_reference",
  "title": "SPDX: Standard and certification boundary",
  "system": "SPDX",
  "evidence_family": "software_supply_chain",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Does publishing an SPDX document certify the software it describes?",
  "near_questions": [
    "Does an SPDX label certify a package?",
    "What does SPDX standards status apply to?",
    "Can a standard format contain incomplete inventory?",
    "Does an SPDX document prove license compliance?",
    "Why record the SPDX version in an evidence receipt?",
    "Can an agent equate document conformance with software safety?",
    "Which evidence supports the contents of an SPDX file?",
    "Does using an international standard verify a supplier?",
    "What remains unproven after generating an SPDX document?",
    "Should a buyer review the inventory producer and scope?",
    "Can SPDX presence replace dependency review?",
    "What is the limit of a standards-based inventory claim?"
  ],
  "supported_claims": [
    {
      "claim": "SPDX is an open specification for exchanging supply-chain information. Its standards status does not certify a submitted document's completeness, license conclusions or the safety of its software.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "software safety certification",
    "complete component inventory",
    "verified license compliance"
  ],
  "public_summary": "SPDX is an open specification for exchanging supply-chain information. Its standards status does not certify a submitted document's completeness, license conclusions or the safety of its software.",
  "related_record_ids": [
    "VXI-EXT-CYCLONEDX-17-01-v1",
    "VXI-EXT-CYCLONEDX-17-02-v1",
    "VXI-EXT-CDX-17-05-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "SPDX Specifications",
    "source_url": "https://spdx.dev/use/specifications/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-SPDX-30-02-v1",
    "candidate_record_sha256": "cf890a266633ef0b0617f9141a50621e9bfce727baa79dcec11d6ca210168422",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "SPDX is an open specification for exchanging supply-chain information. Its standards status does not certify a submitted document's completeness, license conclusions or the safety of its software.",
    "required_buyer_context": "The SPDX document version, producer, declared scope and evidence for the proposed claim.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#spdx-standard-versus-certification",
  "machine_readable_record": "/varexis-index/records/spdx-standard-versus-certification.json"
}
