PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Evidence · Prove · Reuse

Evidence

Security work is only useful when the evidence survives the engagement.

Preserve what was mapped, tested, chained, changed, and retested, then turn the same reviewed evidence into engineering records, control proof, leadership summaries, framework mappings, and buyer-ready artifacts.

Evidence is the durable record behind M.A.D.E. Findings do not disappear into a final PDF. Architecture context, reproduction evidence, Attack Path Analysis outputs, remediation decisions, retest results, control status, caveats, and review state stay connected so the same security truth can support engineering work, release decisions, audits, and enterprise review.

Evidence Pack dossierA secured evidence dossier organized for buyers, compliance, audit, product, and executives.BuyersComplianceAuditProductExecutivesFindingsControlsCaveatsRetest NotesApproved ClaimsEvidence Packpack:v1.4sha256:7ab9…

What Evidence makes durable

Engineering evidence

analyst-reviewed findingsreproduction recordsattack pathsremediation work itemsacceptance criteriaretest stateregression conditions

Control evidence

architecture decisionsauthorization and ownership recordsguardrail / eval resultstelemetry requirementsrelease-gate decisionscontrol implementation status

Buyer and governance evidence

reviewed questionnaire answersevidence packstrust-center languageframework mappingsscoped attestationspublic-safe summariesapproved caveats

Machine-readable evidence

structured evidence bundlesJSON / SARIF where supportedAttack FlowATT&CK Navigator layersrisk-register / qualitative loss-exposure annotations where supportedintegration / export payloads

Evidence must survive the move from engineering to decision-making.

Runtime observations, configuration state, findings, retest results, reports, and executive decisions should remain connected rather than becoming disconnected summaries.

EVD-04

Evidence-to-Decision Stack

Executive conclusions remain trustworthy only when they stay traceable to technical evidence and replayable proof.

Layered artifact stack from observed evidence and structured findings through remediation and retest records to technical and executive reporting.

PROVENANCE CONTROLSSource referencesVersion andgenerated timeReview and approvalstateObserved and reproduced evidenceRuntime tracesConfiguration and policy snapshotsReproduction recordStructured findings and pathsFinding objectPath and relationship objectClaim and validation stateRemediation and retestControl and owner recordRetest resultRegression fixtureDecision-ready reportingTechnical reportExecutive summaryDecision recordCONSUMERSEngineeringSecurityLeadership

The evidence stack preserves provenance as technical facts move into remediation, customer assurance, procurement, executive reporting, and publication.

Capabilities

One evidence system. Many useful outputs.

Evidence Pack Builder

Turn reviewed scope, architecture context, findings, remediation state, retest results, and approved notes into decision-ready evidence packs for launches, security review, procurement, leadership, and customer assurance.

One Graph, Many Formats

Render the same reviewed evidence into the formats each audience and system needs. Structured findings, engineering exports, framework mappings, Attack Path Analysis artifacts, reports, attestations, and partner-safe outputs should derive from the same underlying evidence rather than being rewritten as separate truths.

Validation Gate

Evidence can be machine-checked without becoming automatically publishable. Deterministic validation catches unsupported identifiers, enrichment, relationships, secrets, and schema problems; human review remains required for customer-facing findings, attestations, and public-safe claims.

Finding-to-Fix Trail

Preserve what was found, what changed, what was retested, what passed, what failed, and what remains accepted risk. Findings stay linked to remediation and retest instead of becoming disconnected report text.

Claim-Readiness Review

Keep internal technical evidence separate from what the organization can safely claim externally. Draft findings, scoped tests, unresolved remediation, and limited evidence should never silently become public assurance language.

Questionnaire Answer Bank

Translate reviewed evidence into reusable enterprise-security answers instead of rebuilding responses deal by deal.

Public-Safe Summaries

Create redacted, scoped summaries that preserve date, coverage, caveats, findings status, and review limits without exposing restricted technical detail.

Human Review Gate

AI-assisted or machine-generated artifacts remain drafts until a named human reviewer approves external use. Human accountability is part of the evidence model, not a disclaimer added afterward.

Every claim needs an explicit state.

Observed, reproduced, grounded, inferred, rejected, and analyst-reviewed are different evidence states and must not be collapsed into one generic label such as validated.

EVD-03

Claim State Boundary

Observed, reproduced, grounded, inferred, rejected, and analyst-reviewed claims must remain visibly distinct.

Diagram showing observations and reproductions, grounded claims, review boundary, explicit inference, rejected claims, and analyst-reviewed publication state.

SUPPORTED CLAIMSupported claimGroundedQualified consequenceProvenance retainedPublication state approved1Observed

A behavior, artifact, configuration, or trace was directly captured.

2Reproduced

The behavior was repeated under controlled conditions.

3Challenge evidence and alternatives

Review tests source sufficiency and plausible alternative explanations.

4Approve publication state

An analyst confirms the claim language, caveats, and release boundary.

5Inferred

Plausible extension that remains explicitly provisional.

6Rejected

Unsupported, contradicted, or not reproducible.

7Unresolved

Evidence is insufficient for a defensible conclusion.

Explicit claim state prevents machine output, plausible inference, and analyst-approved conclusions from being presented as equivalent evidence. Machine validation is not human approval.

Workbench capabilities and services that produce or consume Evidence

Keep the same truth across every audience.

Output

Evidence Pack / Evidence system

Turn reviewed scope, architecture context, findings, remediation state, retest results, and approved notes into decision-ready evidence packs.

Output

Attack Path Analysis Evidence Trail

Preserve grounded evidence, labeled extensions, validator verdicts, ATT&CK mapping, remediation chokepoints, and analyst-review state.

Service

AI Security Sales Enablement

Buyer-ready answers, evidence packs, safe claims, and review support built from reviewed evidence.

Service

AI Security Program Baseline / Scorecard

Baseline program-level ownership and control gaps so Evidence can point back to durable program records.

Workbench capability

AI Control Crosswalk

Map reviewed findings and controls to supported framework language without treating framework mapping as a substitute for technical evidence.

Workbench capability

Runtime Trace

Capture and replay prompts, retrieval context, model calls, tool calls, approvals, outputs, and policy decisions so evidence can be verified and preserved.

Workbench capability

Code Scanner

Carry AI-native code findings into supported developer, security, evidence, and remediation workflows, including structured outputs such as SARIF where implemented.

Workbench capability

RAG Security Testing

Carry retrieval-authorization, corpus-boundary, and XPIA evidence into review and hardening workflows.

Workbench capability

Trust Scanner

Review public trust, policy, and evidence-surface artifacts for coherence and scope gaps before buyer review.

Output

AI Security Attestation

Practitioner-authored attestation document after a scoped technical review, covering scope, methodology, findings, controls status, and a signed practitioner statement.

Connect evidence to the frameworks buyers and auditors already use.

Where applicable, reviewed findings and controls can be mapped without treating framework mapping as a substitute for technical evidence.

OWASP LLM Top 10
NIST AI RMF
MITRE ATLAS
ISO/IEC 42001
EU AI Act
SOC 2
ISO 27001

Who benefits

Engineers

Reproduction, architecture context, remediation guidance, acceptance criteria, and retest evidence.

Security teams

Analyst-reviewed findings, attack paths, risk disposition, control status, and coverage records.

Engineering managers / product leaders

Prioritized backlog, release conditions, ownership, and remediation state.

Leaders / auditors

Scoped risk summaries, control evidence, review state, and traceable decisions.

Customer trust / procurement

Reviewed evidence packs, framework mappings, questionnaire answers, and public-safe assurance language.

Scope limitation

Evidence is not a certification and does not mean a product is vulnerability-free. Every artifact is scoped, dated, and limited to the work actually performed.