Document metadata
- Status
- Maintained
- Approval
- Approved
- Version
- 1.0
- Classification
- PUBLIC
- Owner
- Lightning IT Documentation Maintainers
- Approver
- Lightning IT Security and Compliance Maintainers
- Audience
- customers, compliance reviewers
- Last reviewed
- Next review
- (Semiannual)
Assurance frameworks and formats
Policy. OpenSSF, SLSA, SPDX, CycloneDX, Sigstore, provenance, and signing terms describe methods or formats unless a bounded evidence record proves a stronger statement.
Current implementation — docs.l-it.io. CycloneDX SBOM generation and GitHub artifact provenance are release gates. This is not a certification or a portfolio-wide maturity claim.
Unverified gap. Current public external verification and framework-level claims are not available. Owner: Assurance Owner. Review trigger: a scope-specific, authorized public assessment with validity dates.