Skip to main content

Document metadata

Status
Maintained
Approval
Approved
Version
1.0
Classification
PUBLIC
Owner
Lightning IT Documentation Maintainers
Approver
Lightning IT Security and Compliance Maintainers
Audience
customers, security reviewers, compliance reviewers, engineering contributors
Last reviewed
Next review
(Annual)

Evidence Center

The Evidence Center publishes reviewed summaries of bounded observations. Each record identifies its subject, revision, method, result, owner, review state, retention class, relationships, and limitations. A passing record never means that a wider product is secure, compliant, certified, production-ready, or free of defects.

Public boundary

Public records are generated from an allowlisted schema. They exclude raw scanner output, customer or personal data, credentials, private URLs, hostnames, topology, findings, risk acceptance, audit work papers, and incident detail. Protected source material remains in separately authorized systems. The public record may state withheld or unavailable without exposing a private identifier or confirming that protected evidence exists.

Status model

StatusPublic meaning
passedThe named method met the bounded acceptance rule.
failedThe method ran and did not meet the rule.
warningThe method completed with a material limitation.
not-applicableAn accountable owner recorded why the method does not apply.
unavailableExpected public evidence cannot currently be obtained.
withheldPublic release of the source is prohibited.
expiredThe observation is outside its review or validity window.
supersededA linked later record replaces current interpretation.
revokedThe owner invalidated the record or authorization.

Zero-count states remain in the generated manifest so failure and absence cannot disappear from summaries.

Continue