# Evidence and open findings

Version 2.4 — reviewed September 7, 2026 through 14:48:48 UTC

This is a dated snapshot, not a live status page. Engineering evidence was produced by the product engineering process, not an independent assessor. A deployed version proves availability of that source, not that a customer's source or response control is configured. No customer results are claimed.

| Area | Evidence available | What it does not establish |
| --- | --- | --- |
| Evidence downloads and verification | Briard R02 release `34add7a`, September 5: protected release checks, all three production sites READY, live public verifier checks; KAIDAN R02 `bb100ee` deployed with health/auth-boundary checks and separate fictional portable verification | A public sample is not a customer's signer, a trusted timestamp, factual truth or complete source visibility |
| Public fictional incident journey | P05 PR 172 reviewed head `c9b246c0495f905aa958b9cd89b28ab66ca57c1c` with all protected checks green, then squash-merged at `f2e0b25b2ba79c76c4111d47a4d6ef0d696a3bb0`, tree `aa0596ffe3f855532708823580e8e612f5239fc5`, at 10:28:56 UTC. App `dpl_CVR6C9cBT4x3d3ny3eHy4eWzrZmY`, marketing `dpl_98o1f8LaQfR76QnQEtEqYEWQSnxM` and docs `dpl_6g6HT1jVtuoBkcign6m2TsfCnoTj` were READY and reported that exact source SHA. Post-main verifier run [34111666571](https://github.com/wildzealot/Briard-AI/actions/runs/34111666571) and four-job release run [34111666592](https://github.com/wildzealot/Briard-AI/actions/runs/34111666592) passed; browser/accessibility completed at 10:45:37 UTC. Repeated live desktop and 390-pixel-phone checks of `/kaidan?sample=journey` completed all six steps, all three decision packages and three offline verifications with zero Axe, page, request or product-write failures | This is an account-free fictional sample. Its pinned fictional key and sample signing time do not establish production signer identity, independent time, factual truth, provider action, Briard account mutation, customer configuration or customer outcome |
| Source setup | I02 release records include KAIDAN `6a66cd5` deployment and Briard `36d27d6` live desktop/phone sign-in handoff; hosted tests exercise the installed SDK, real API/database and restart | Five source families' controlled harness results do not prove five customer provider accounts are connected; a sign-in handoff is not completed customer MFA |
| Response actions and alert review | R01 reviewed `09e7988` and entered production in `04d8883`; it is included in current deployed KAIDAN revision `6b71b4d` after successful [CI 34104525952](https://github.com/wildzealot/Kaidan1/actions/runs/34104525952), [Security 34104525969](https://github.com/wildzealot/Kaidan1/actions/runs/34104525969) and [deployment 34106355694](https://github.com/wildzealot/Kaidan1/actions/runs/34106355694). Hosted tests cover the authenticated API, durable PostgreSQL queue, worker authority and actual isolated Elasticsearch effects for credential revocation, tool restriction and retrieval exclusion | Controlled fictional effects are not production provider mutations or customer incidents. The final signed-in production checks for R01 response plans and D04 priority, grouping and quiet-event review remain open |
| Incident-to-policy review | KAIDAN G05 source and its accessibility correction are included in deployed revision `6b71b4d`. Briard G05 source is merged; production records contain migrations `20260907031334` and `20260907051001`, and release `e25bccc` corrected the review route | Source, deployment, exact migration records and a signed-out 401 boundary do not prove the signed-in production workflow. That final live review remains open |
| Local detector and alert outcomes | The first D02/D03 production run against `04d8883` was retained as a policy denial. The region correction in PR 90 is included in deployed revision `6b71b4d` | The correction still needs signed-in production D02-D04 checks for local detection, multi-step/cross-session/delayed events, priority, grouping and quiet-event outcomes |
| Invitation delivery | Release `9339994` and [production deployment 6304018049](https://github.com/wildzealot/Briard-AI/deployments/6304018049) contain migration `20260907051658`. Production health/ready checks passed; four authenticated scheduled drains returned 200 from 07:30:41 through 07:33:41 UTC. A private 07:35:36 UTC snapshot showed no queued, sending, retry, needs-attention or due work and no receipts | An empty queue and accepted drain requests do not prove that an invitation reached a provider. One fictional live invitation and provider-acceptance receipt remain pending signed-in access |
| Engineering load and alert timing | A corrected bounded loopback run for exact source `86152045f6280625265cf6f552c5c019fb4ed8fa` passed the 2x forecast profile on PostgreSQL 16.15. The hosted history below retains five failed capacity runs, one superseded capacity attempt, one post-activation verification failure and two superseded runner-fixture failures. Repaired exact head `06e98f0` passed both isolated PostgreSQL 18.4 capacity cells; object-store hardening merged as verified `786a81d`, and least-privilege deployment-probe correction merged as verified `e0a9b5b` after exact-head and exact-main CI/Security passed. Corrected deployment `34133754984`, direct administration, isolated restore, continuity, controlled recovery, final health and Production Health `34134980871` passed | O01 release is closed within the stated engineering scope. The hosted capacity pass proves aggregate software behavior on the two recorded runners, not one host's 80 events/second or production capacity; a provider response header is not recipient delivery or reading |
| Briard object recovery | August 28 production record: revision `766713f`, 56 objects / 624,358 bytes copied, manifest/hash checks and one non-destructive object restore/readback/cleanup passed | Historical object-level evidence is not a current database, identity, full-boundary or second-person recovery rehearsal |
| KAIDAN test-account recovery | A retained July record shows a successful interactive Entra MFA recovery at `2026-07-21T14:09:16Z` followed 30 milliseconds later by protected `GET /v1/cases` HTTP 200. The Entra success was operator-transcribed, not retained as a raw provider export. The sanitized proof SHA-256 is `4dc9a1eaac6a429167dfa92fbaea3fda3028b3621c6a7a3b86120889ab28bdcb` | The retained evidence does not establish an Owner role. One test-account recovery does not prove independent second-person succession or recovery for every customer identity provider |
| KAIDAN backup and technical recovery | O02 is deployed at revision `6b71b4dede46543a030a26f2024a12150c1e057b`: [CI 34104525952](https://github.com/wildzealot/Kaidan1/actions/runs/34104525952), [Security 34104525969](https://github.com/wildzealot/Kaidan1/actions/runs/34104525969) and [deployment 34106355694](https://github.com/wildzealot/Kaidan1/actions/runs/34106355694) succeeded. The 09:38:44 UTC backup created snapshot `c76e7184574f33c20a044c8c6f8afd450f2a0329f88aec542d8938c518d4bdd3` with schema ID `b6d9b467cd2cc2adf9766cfb770a65a5d94573273cc784d47d4d734419ba7e99`. A network-isolated restore recovered 2,035 files totaling 255.731 MiB in 8 seconds; network isolation, release, object-store, OpenBao and continuity-audit checks passed. The fail-safe confirmation negative test passed: the guarded recovery action did not proceed without the required confirmation. Controlled restart, alert and health recovery ran from 09:39:36 to 09:39:55 UTC in 19 seconds; the final health audit passed | This scoped company-hosted KAIDAN rehearsal is engineering evidence, not independent assurance, a contractual RPO/RTO result, customer-provider recovery, independent second-person succession, or broader Briard database/identity/full-boundary recovery |

## O01 hosted qualification history

- [Run 34101805472](https://github.com/wildzealot/Kaidan1/actions/runs/34101805472), head `38e4259` / tree `b14ac`, failed its single two-CPU burst cell with 988 generator drops and 17 rejected admissions.
- [Run 34105020712](https://github.com/wildzealot/Kaidan1/actions/runs/34105020712), head `056991d` / tree `c13b`, failed both cells with unconfirmed admissions: cell 0 recorded 7,476/7,500 originals, 352/360 replay acknowledgements and 32 unconfirmed admissions; cell 1 recorded 7,478/7,500, 349/360 and 33.
- [Run 34107510589](https://github.com/wildzealot/Kaidan1/actions/runs/34107510589), head `328f350` / tree `9b87e6`, passed warmup and sustained phases in both cells but failed burst: cell 0 recorded 7,491/7,500 originals, 349/360 replays and 20 rejected or unconfirmed admissions; cell 1 recorded 7,490/7,500, 349/360 and 21. It retained zero generator drops, HTTP 5xx responses or read failures and completed restart, drain and cleanup.
- [Run 34110802725](https://github.com/wildzealot/Kaidan1/actions/runs/34110802725), head `eb1e41cd26727ac9c0ce1cbc1646955e2bbeb912` / tree `385a5989f60b26c46b0a3767d630d6bdfe712a36`, failed both isolated two-CPU PostgreSQL 18.4 cells after each completed its schedule and cleanup. Both exhausted PostgreSQL serialization retries. Cell 0 recorded three exhaustion events, one warmup HTTP 5xx, three of 60 burst replays rejected and one alert commit unconfirmed; report SHA-256 `8f29004e2fcb0bdb96ed820f5eb4b458ea6d0cf6535dce729d6e2abb8eb10ee4`. Cell 1 recorded five exhaustion events, one of 1,200 burst originals and four of 60 burst replays rejected; its durable-alert totals, accepted-event-to-alert p95 and source-skew checks consequently failed; report SHA-256 `1ef0ae49700f5aea04f56eacca8fd0b1267cf9abb59754f25690290a80a629ba`. It used frozen profile SHA-256 `b940f2cc7440bda1c5865c50eda76abe9067ae795b8ce76410e0ca281eef2716`, had no generator drops or read failures, and is retained as a genuine failed qualification.
- [Run 34113906052](https://github.com/wildzealot/Kaidan1/actions/runs/34113906052), head `155f4b663ef72cfc5358dc7faeba7f82f89962ce` / tree `523473ab16715ac90e437ea386ee25a4aa280874`, failed both isolated two-CPU cells after both completed their full schedule and clean disposal. Cell 0 had three observation-serialization exhaustion events: warmup accepted 297/300 with three rejected admissions, sustained accepted 6,000 originals plus 300 replays, burst accepted 1,200 plus 60, and durable totals were 7,497 originals, 360 replays, three unconfirmed admissions and 72 alerts; artifact `10015965868`, archive SHA-256 `db38f2889cfa3cf9dbbbcada19e71d7c99496ac6b02d11e24e47592cd2ca46c5`, report SHA-256 `7512507db6c5963db18bc7c2ca7d3e41d3cc55c903417d2edff2140c61ea806d`. Cell 1 had two exhaustion events: warmup accepted 300/300, sustained accepted 6,000 plus 300, burst accepted 1,199 plus 59 with two rejected admissions, and durable totals were 7,499 originals, 359 replays, two unconfirmed admissions and 71 alerts; artifact `10015975331`, archive SHA-256 `f9bc4d20928d77ed9b51bfc01bc63a8ca5a4f9b2c5af9bf2b0203f23d528f247`, report SHA-256 `4648dfe96db4a7bd8a7ddf4262abc91740f8cf86f7b875de2e213996db404ecc`. Both cells had zero generator drops, server errors, read failures, dispatch failures or worker errors and drained their queues, but the missing durable admissions keep this run failed.
- Superseded attempt exact head `c7b53f37307a2f4b01042a8ac3d422487c63a9fe` / tree `8f3be1e8e7519bd62683d57960289845c61105ba` passed [Security 34116719253](https://github.com/wildzealot/Kaidan1/actions/runs/34116719253), but [CI 34116719250](https://github.com/wildzealot/Kaidan1/actions/runs/34116719250) and capacity [34116723124](https://github.com/wildzealot/Kaidan1/actions/runs/34116723124) were automatically canceled as superseded when its repaired replacement was pushed. Review had found that rollback inherited an unbounded background context, so a stalled or broken rollback could indefinitely retain the dedicated pooled connection and session advisory lock. Capacity cell 0 artifact `10016877994`, archive SHA-256 `07e9ec9bb1f26d4c0c6cac44db24b613b20d129e9a9a3ed67f18f5e63a3c201c`, and cell 1 artifact `10016877665`, archive SHA-256 `531f28c0fcd457e54d9ac41e53719e5decc7c247189d767d42e6dd0877391652`, each contain only the test-start line. No qualification report was produced, so this canceled attempt neither supersedes a retained failure nor qualifies O01.
- Repaired replacement [run 34118429419](https://github.com/wildzealot/Kaidan1/actions/runs/34118429419), exact head `06e98f063bc605985d82b80feccc921df0250e68` / tree `d7a6f060458e70441387b6a30ef2564809461653` / frozen profile SHA-256 `b940f2cc7440bda1c5865c50eda76abe9067ae795b8ce76410e0ca281eef2716`, passed both isolated two-CPU PostgreSQL 18.4 cells with complete schedules and disposable-volume cleanup. Each cell committed 7,500 originals, 360 replays, 72 alerts and five urgent handoffs with zero generator drops, unconfirmed or rejected admissions, HTTP 5xx responses, read or dispatch failures, receipt-commit unknowns, backlog, duplicate accepted effects or worker errors; both restarted to worker generation 2. Cell 0 measured alert p95 0.5 seconds and urgent provider-response-header p95 30 seconds; artifact `10017706234`, archive SHA-256 `b83d091df7b180ff0aec6af944d0784de8234faf734b5772484a142289ee8eaa`, report SHA-256 `340d6c094e7a3f857bca61ab01504d1042a4ffa32fbff25ab1a6c1379d87a5e1`, manifest SHA-256 `50970bbcffa2c717b2205f3d5dbf3874ab9bfaa0ad0e1fa0738d4fddf88911db`. Cell 1 measured alert p95 0.5 seconds and urgent p95 0.1 seconds; artifact `10017714244`, archive SHA-256 `bb0b27a52f7b1e10b3e5e99f432fbfa8d1a91c2e84496339745d4e7626bbb08a`, report SHA-256 `eb7d9214e5a34f192765dd16d7d956bab6dbe0744d44f5584593c0cf348a2765`, manifest SHA-256 `5d23a56697553437a310c06f242f7a5d5306f434d35701d4bf3f5b4353bbd6bb`. Aggregate totals were 15,000 originals, 720 replays, 144 alerts and 10 urgent handoffs. Exact-head [CI 34118427589](https://github.com/wildzealot/Kaidan1/actions/runs/34118427589) and [Security 34118427617](https://github.com/wildzealot/Kaidan1/actions/runs/34118427617) passed. PR [93](https://github.com/wildzealot/Kaidan1/pull/93) then squash-merged reviewed head `06e98f0` as signed and verified main commit `142418191a3722d268ea0b0caf5e55c5206bd01a`, unchanged tree `d7a6f060458e70441387b6a30ef2564809461653`, parent `6b71b4dede46543a030a26f2024a12150c1e057b`, at 12:07:48 UTC. Post-main [CI 34120188869](https://github.com/wildzealot/Kaidan1/actions/runs/34120188869) passed all five jobs, with console accessibility completing at 12:27:54 UTC. [Security 34120188991](https://github.com/wildzealot/Kaidan1/actions/runs/34120188991) attempt 1 failed only its container build/scan after `proxy.golang.org` returned HTTP/2 `INTERNAL_ERROR` responses while fetching locked `github.com/minio/minio-go/v7@v7.0.91` and `aead.dev/mtls@v0.2.1` modules; every other applicable source and security job passed. Unchanged-SHA attempt 2 reran only container build/scan and failed at 12:27:22 UTC: the relay image built, but the pinned MinIO image again stopped when `proxy.golang.org` returned HTTP/2 `INTERNAL_ERROR` for locked `github.com/minio/mux@v1.9.2`. Both failed container attempts are retained as recurring external infrastructure fetch failures; they do not show a source defect. KAIDAN production remained on `6b71b4dede46543a030a26f2024a12150c1e057b` and was untouched. PR [95](https://github.com/wildzealot/Kaidan1/pull/95) first candidate exact head `364fd359e41f7dc255b16ffc5e5fbbb6c5f14344` / tree `baeaa1bf216334ff053384cc59dd3278666190eb` / parent `142418191a3722d268ea0b0caf5e55c5206bd01a` hardens the pinned object-store build with a fixed four-attempt, 240-second-per-attempt HTTP/1 full-module-graph prefetch, then `GOPROXY=off` compilation and `go mod verify`. Pinned MinIO and security-overlay versions plus builder/runtime image digests remain unchanged. The exact-head [Security 34122497940](https://github.com/wildzealot/Kaidan1/actions/runs/34122497940) container job failed at 12:40:18 UTC after its HTTP/1 prefetch and `go mod download all` completed: `GOPROXY=off` compilation found locked `github.com/pborman/getopt@v0.0.0-20170112200414-7148bc3a4c30` absent from the cache. This is an incomplete offline-prefetch hardening defect; the candidate has not qualified or deployed. [Security 34122497940](https://github.com/wildzealot/Kaidan1/actions/runs/34122497940) finished failed at 12:40:58 UTC with all seven other jobs passing. [CI 34122497949](https://github.com/wildzealot/Kaidan1/actions/runs/34122497949) passed its format/build and SDK jobs, then its integration, accessibility and race jobs were automatically canceled as superseded when the corrected replacement was pushed; the run finished canceled at 12:43:01 UTC. The corrected final PR 95 candidate, exact head `b48801011a3b3580a2bf67b9f3503a5212ad2444` / tree `53321ac7451232bccf3d7c578fa5210a7dbc8c23` / parent `142418191a3722d268ea0b0caf5e55c5206bd01a`, retained the bounded HTTP/1 graph and overlay prefetch and added exact Linux, non-CGO, `kqueue` build-dependency resolution under the same fixed bounds. Its generation, compilation and `go mod verify` then ran with `GOPROXY=off`; pinned MinIO and security-overlay versions plus builder/runtime image digests remained unchanged. Exact-head CI `34123352820` passed all five jobs, with console accessibility completing at 13:01:36 UTC; Security `34123352826` passed all eight jobs, including the object-store build and all three candidate-image scans. PR 95 squash-merged as signed and verified main commit `786a81d2f4da27a41cec72323524cad12ea622c3`, unchanged tree `53321ac7451232bccf3d7c578fa5210a7dbc8c23`, parent `142418191a3722d268ea0b0caf5e55c5206bd01a`, at 13:02:17 UTC. Post-main CI `34125139565` passed all five jobs, with console accessibility completing at 13:17:03 UTC; Security `34125139467` passed all seven applicable jobs, with container build and scan completing at 13:12:54 UTC. Automatic production deployment `34126531698` selected exact revision `786a81d2f4da27a41cec72323524cad12ea622c3`, matched Security, built revision-bound images, assembled and verified the checksum-bound bundle, passed rollback preflight, loaded the images, applied the unchanged 64-migration schema, and passed nginx, health and maintenance checks; it reported that exact revision ready at 13:27:01 UTC. The workflow then failed at 13:27:03 UTC because the restricted deploy account could not run an arbitrary `sudo test -x` post-activation helper probe, and the invalid-token proof was skipped. An administrative read-only check confirmed the live revision and exact release symlink, 64 migrations with schema ID `b6d9b467cd2cc2adf9766cfb770a65a5d94573273cc784d47d4d734419ba7e99`, all three helpers directly executable, the service active, and the health audit passing at disk 9% and inodes 3%. Run `34126531698` is retained as a post-activation verification and least-privilege workflow failure, not as a failed activation or runtime health result.

PR 96 first candidate exact head `94123876d021cb22523cd0b2f811d167ff378178` / tree `5880b714b764f10aa6ed678fcfeca5573d5a22a3` / parent `786a81d2f4da27a41cec72323524cad12ea622c3` replaced the arbitrary sudo probe with direct non-root executable checks and added a regression that rejects the sudo form. Security `34127623989` passed. CI `34127624025` attempt 1 failed only job `101759925556`: 31 prior database/provider/object-store gates passed before the first local-resilience scenario hit a runner-local TCP reset connecting to mapped PostgreSQL; log SHA-256 `3de4cb7a52db694dcfa18936c10eb97a13f61ed50d7764b7197a599406b11c5f`. Its one unchanged-head retry, attempt 2 job `101764438338`, failed at a distinct runner-fixture point after the real Elasticsearch 9.4.4 identity probe passed but the first security-role PUT returned status 0 under the 3-second setup timeout; local resilience never ran, and the log SHA-256 is `846d81667b027b8cfdd7571ce1df6132b328aa6a74e18df53297b470362f4040`. These two superseded attempts are retained as runner-fixture readiness failures, not production, capacity or customer results.

Final PR 96 head `47dbbe896ec356ebad7553d7042c8a4feaff5ff6` / tree `2b7c1d2377046f4a4e7e0efd613bc3d2b89e9412` / parent `786a81d2f4da27a41cec72323524cad12ea622c3` retained the least-privilege probe and added final-PID-1 PostgreSQL readiness plus bounded Elasticsearch setup/operational probe timing. Exact-head CI `34130124723` passed all five jobs and Security `34130124750` passed all eight. PR 96 squash-merged as signed and verified main commit `e0a9b5b3031b79ab77bd5d540370f3eea5d20b4c`, unchanged tree `2b7c1d2377046f4a4e7e0efd613bc3d2b89e9412`, parent `786a81d2f4da27a41cec72323524cad12ea622c3`, at 14:15:19 UTC. Exact-main CI `34131955343` passed all five jobs, with console accessibility completing at 14:35:07 UTC; Security `34131955590` passed all seven applicable jobs. Corrected automatic production deployment `34133754984`, job `101779780952`, passed at exact revision `e0a9b5b3031b79ab77bd5d540370f3eea5d20b4c` from 14:35:13 through 14:43:21 UTC; authoritative raw GitHub run-log byte SHA-256 `65c9dfc16f942673a7c7002c1da3ce2747a01cbcfc4b8a61d9b024aa92bb51a7`; local CRLF-normalized PowerShell text-export SHA-256 `272419c42ebee32c57734713b12a4306a18a563a458c07145855d8d0a333bcaf`. All steps were green, including matching-Security validation, revision-bound image build, checksum-bound bundle assembly, transfer/activation, direct non-root recovery-helper assertions and invalid-token ingress throttling/version suppression. A direct administrative no-regression check passed and retained log SHA-256 `abcdc5c254353a18c579adbf0e5e0c3ee1b731add45d11e605e7bdc9167f6144`; the exact revision and release symlink remained current.

Backup snapshot `b5aec0f3112034bccf02456577218d25fde999e51be7763ca3e09c7fc5540d8e` completed at 14:45:47 UTC. The isolated restore passed from 14:45:48 through 14:45:55 UTC in 7 seconds for exact release `e0a9b5b3031b79ab77bd5d540370f3eea5d20b4c`, 64 migrations, schema ID `b6d9b467cd2cc2adf9766cfb770a65a5d94573273cc784d47d4d734419ba7e99` and unsealed OpenBao. The continuity check passed. Controlled recovery passed from 14:45:56 through 14:46:14 UTC in 18 seconds, including an accepted alert, and the final health check passed at disk 9% and inodes 3%. The combined recovery log SHA-256 is `e97b383483d6ae6b4bbc5cc23bb0f1dac8ede84fd869372b8e4150ccc4ff6425`; marker log SHA-256 `d1f3c6bb36533a67e7dd06f97582f7e2c47601e1b1248ca6e8cda79ccbd29cc1`. [Production Health `34134980871`](https://github.com/wildzealot/Kaidan1/actions/runs/34134980871) was dispatched at 14:48:38 UTC; job `101783702570` ran from 14:48:41 through 14:48:48 UTC and passed at exact release `e0a9b5b3031b79ab77bd5d540370f3eea5d20b4c`. The API, console, object-store, notary and KAIDAN-console HTTPS probes passed; provisioning without platform authority failed closed with 401; and all four certificate windows passed. Production Health log SHA-256 is `bbc6d817b6dc8cff4cf78ffa0ca144e64f16bac6987c10da256ab040a8af0c03`. Post-workflow administration again confirmed the exact revision, release symlink, 64-migration schema ID, images, helpers, service and health. The O01 repair adds bounded unsafe-session cleanup. It commits alert status, case association, and the `ActionPromoted` receipt atomically; incident-case creation occurs separately before that transaction and is outside this atomicity claim. O01 release is closed within the stated engineering scope. No production or customer endpoint was contacted by the capacity run.

## Findings and retests retained

R02 corrected unverified browser download handling: missing, malformed, interrupted or mismatched checks now fail before download. Controlled backend/export tests, corruption/revocation negatives and dated public production verifier checks passed. This result does not turn a caller-supplied digest into independently trusted evidence.

I02 corrected a live sign-in handoff that opened the fictional queue without a usable sign-in route. The corrected desktop/phone handoff retained the requested KAIDAN destination after reload; no private data or authentication completion was inferred.

The failed G05 contrast run and first D02/D03 policy denial remain in the record. Later source and deployments corrected the named defects, but the protected signed-in G05 and D02-D04/R01 production checks are still required. The detailed [findings and retests](./findings-and-retests.md) page keeps the failed result, correction and remaining proof separate.

Invitation durability is live through the database, application and scheduled-drain boundary. Provider acceptance remains pending because the fictional live invitation requires fresh signed-in access. The successful O01 local result and every hosted attempt remain separated above; O01 capacity and release are qualified within the recorded engineering scope. KAIDAN O02 technical production recovery is complete within the exact scope above.

O03 corrects dated public statements that omitted the fixed launch window, omitted backup providers and described no Briard object restore proof despite the dated August evidence. It also separates source, database, deployment, health, signed-in workflow and provider acceptance. The accompanying claim checks validate catalog arithmetic, term boundaries and evidence wording; they are not legal or independent review.

## Open assurances and commitments

No SOC 2 report, ISO certificate, TX-RAMP certification decision, independently validated penetration-test report or customer trial result is offered. Broader Briard database/identity/full-boundary restoration, measured contractual service objectives, independent second-person succession, executable customer DPA/residency terms and independent escrow are not inferred from the KAIDAN engineering result. Customer and independent work is kept in a separate future plan; it is not counted as completed engineering or a new prerequisite for documenting the product honestly.

Ask for the dated evidence relevant to your proposed scope. Some operational artifacts require authorized sharing; this page deliberately excludes customer data, credentials, host addresses and raw logs.
