← Results index

Audit preflight evidence and decide internal-cohort entry

2026-07-29T16:02:11Z Research done Independent t293 comparison recorded NO-GO: eight of nine boundaries fail or lack evidence; notably 5/20 cold samples, warm p50 5
t296

Source report: research/findings/private-pilot-audit-t296.md

Objective

Audit preflight evidence and decide internal-cohort entry.

Notes: Independent t293 comparison recorded NO-GO: eight of nine boundaries fail or lack evidence; notably 5/20 cold samples, warm p50 5.204s >3s, incomplete auth matrix, and missing recovery/rollback/deletion proofs.

Approach

Reuses existing report research/findings/private-pilot-audit-t296.md — tables/metrics preserved verbatim via source_report pointer. Body below summarizes grounded evidence from that report and adjacent artifacts.

Files / code / data changed

Results

Key table from source report (preserved):

t293 boundaryEvidence auditedIndependent resultRequired remediation
Healtht295 reports an observed evaluator health check, but no 60 consecutive checks, two static/local checks, or primary and backup alert-delivery proof.Fail — missing.Capture the full continuity sequence and prove delivery to both operators.
Evaluation reliabilityFive controlled cold and 30 warm authenticated samples had zero failures. t293 requires 30 scripted authenticated runs including five cold runs, so the reported run count and mix satisfy the reliability sample requirement.Pass.Preserve the redacted sample and revision evidence used for the result.
LatencyFive cold samples produced p95 48.559 seconds; 30 warm samples produced p50 5.204 seconds and p95 5.617 seconds. t293 requires at least 20 cold samples and warm p50 at most 3 seconds.Fail — insufficient cold sample count and warm p50 above the gate.Collect at least 20 valid cold samples and select or tune a host that meets all three preregistered limits. A free-host preference cannot waive t293, which expressly permits only stricter host targets.
AuthenticationMissing/malformed tokens, exact-origin CORS, and two disposable owners' CRUD/cross-owner isolation passed. The record does not explicitly evidence expired, wrong-issuer, or wrong-audience tokens.Fail — incomplete matrix.Repeat and retain redacted results for valid, expired, malformed, wrong-issuer, wrong-audience, and cross-account cases.
Storage/isolationAnonymous/two-owner behavior passed, but no evidence shows the latest encrypted backup was less than 24 hours old.Fail — backup-age evidence missing.Create the required off-site encrypted export, record its age, and repeat the anonymous/two-user RLS probe.
RecoveryNo portable export, fresh-destination restore, RPO, RTO, hash/count comparison, restored RLS probe, or restored public-API CRUD proof exists.Fail — missing.Complete every t293 restore acceptance assertion with RPO at most 24 hours and RTO at most 4 hours.
SpendThe evaluator is on a free resource, but budget alert delivery and cap/kill behavior were not rehearsed.Fail — missing.Record idle/request cost, approved budget, alerts, and exercised kill behavior; ensure no uncapped paid resource exists.
Account-data deletionDeferred to t298; no live deletion, old-token rejection, or seven-day backup-expiry evidence exists.Fail — pending.Complete t298 with a disposable subject and retain only the permitted ticket and timestamps.

Conclusions and metrics are in research/findings/private-pilot-audit-t296.md; see detail page for preserved tables/metrics.

Conclusions

[reconstructed — uncertain] Outcome inferred from status done and task note.

Problems / follow-ups

Links

Source artifact: research/results/t296.md