Objective
Audit preflight evidence and decide internal-cohort entry.
Notes: Independent t293 comparison recorded NO-GO: eight of nine boundaries fail or lack evidence; notably 5/20 cold samples, warm p50 5.204s >3s, incomplete auth matrix, and missing recovery/rollback/deletion proofs.
Approach
Reuses existing report research/findings/private-pilot-audit-t296.md — tables/metrics preserved verbatim via source_report pointer. Body below summarizes grounded evidence from that report and adjacent artifacts.
Files / code / data changed
- No commit SHA confidently associated with
t296in sampled log [reconstructed — uncertain]. - Source report:
research/findings/private-pilot-audit-t296.md - Task-history entry:
research/findings/task-history.json#t296
Results
Key table from source report (preserved):
| t293 boundary | Evidence audited | Independent result | Required remediation |
|---|---|---|---|
| Health | t295 reports an observed evaluator health check, but no 60 consecutive checks, two static/local checks, or primary and backup alert-delivery proof. | Fail — missing. | Capture the full continuity sequence and prove delivery to both operators. |
| Evaluation reliability | Five controlled cold and 30 warm authenticated samples had zero failures. t293 requires 30 scripted authenticated runs including five cold runs, so the reported run count and mix satisfy the reliability sample requirement. | Pass. | Preserve the redacted sample and revision evidence used for the result. |
| Latency | Five cold samples produced p95 48.559 seconds; 30 warm samples produced p50 5.204 seconds and p95 5.617 seconds. t293 requires at least 20 cold samples and warm p50 at most 3 seconds. | Fail — insufficient cold sample count and warm p50 above the gate. | Collect at least 20 valid cold samples and select or tune a host that meets all three preregistered limits. A free-host preference cannot waive t293, which expressly permits only stricter host targets. |
| Authentication | Missing/malformed tokens, exact-origin CORS, and two disposable owners' CRUD/cross-owner isolation passed. The record does not explicitly evidence expired, wrong-issuer, or wrong-audience tokens. | Fail — incomplete matrix. | Repeat and retain redacted results for valid, expired, malformed, wrong-issuer, wrong-audience, and cross-account cases. |
| Storage/isolation | Anonymous/two-owner behavior passed, but no evidence shows the latest encrypted backup was less than 24 hours old. | Fail — backup-age evidence missing. | Create the required off-site encrypted export, record its age, and repeat the anonymous/two-user RLS probe. |
| Recovery | No portable export, fresh-destination restore, RPO, RTO, hash/count comparison, restored RLS probe, or restored public-API CRUD proof exists. | Fail — missing. | Complete every t293 restore acceptance assertion with RPO at most 24 hours and RTO at most 4 hours. |
| Spend | The evaluator is on a free resource, but budget alert delivery and cap/kill behavior were not rehearsed. | Fail — missing. | Record idle/request cost, approved budget, alerts, and exercised kill behavior; ensure no uncapped paid resource exists. |
| Account-data deletion | Deferred to t298; no live deletion, old-token rejection, or seven-day backup-expiry evidence exists. | Fail — pending. | Complete t298 with a disposable subject and retain only the permitted ticket and timestamps. |
Conclusions and metrics are in research/findings/private-pilot-audit-t296.md; see detail page for preserved tables/metrics.
Conclusions
[reconstructed — uncertain] Outcome inferred from status done and task note.
Problems / follow-ups
- See source report or PR discussion for follow-ups. No unsupported follow-ups fabricated.
Links
- Task-history:
research/findings/task-history.jsonidt296 - Findings:
research/findings/private-pilot-audit-t296.md