Document metadata
- Status
- Maintained
- Approval
- Approved
- Version
- 1.0
- Classification
- PUBLIC
- Owner
- Lightning IT Documentation Maintainers
- Approver
- Lightning IT Product Owners
- Audience
- product and system owners, security and compliance owners, platform and delivery teams, customers and technical reviewers
- Last reviewed
- Next review
- (Annual)
Platform Governance & Evidence overview
Platform Governance & Evidence is the Lightning IT governance, compliance, and evidence platform. Its conceptual verb is Verify. It connects scope, controls, technical implementation, documentation, tests, and evidence into a delivery and operating chain whose stated results can be reviewed over time.
It is one of the five sellable products. ModuLix is the shared technical engineering and automation foundation, not a sixth product.
Intended outcomes
Platform Governance & Evidence provides a common model in which:
- requirements become verifiable controls;
- claims are supported by identified evidence rather than self-declaration;
- deviations and residual risks remain traceable;
- a defined control can be checked repeatedly; and
- scope, implementation, documentation, tests, findings, and evidence retain explicit relationships.
The platform can apply the same governance and control model to different assessment targets. The target and scope change; the meaning of a control or evidence relationship does not silently broaden.
Target audiences
The public model is intended for:
- product and system owners;
- security, compliance, and information security management owners;
- platform, operations, project, and delivery teams;
- customers, auditors, and technical decision makers; and
- managed-service teams working within an explicitly agreed scope.
Responsibility boundary
The product structures governance and review. It does not replace the accountable owner who defines scope, decides applicability, accepts a deliverable, or handles a risk through an authorized process. Evidence supports a bounded claim; it does not make every broader claim true.
Platform Governance & Evidence does not promise blanket certification, compliance, conformity, audit success, or absolute security. Acceptance applies only to the agreed scope, artifacts, controls, checks, and evidence.
Public documentation scope
This approved public documentation explains:
- assessment targets, scope, and responsibility;
- controls, documentation, evidence, findings, review, and improvement;
- bounded deliverables and acceptance; and
- public/private and assurance boundaries.
It does not publish customer records, original protected evidence, internal infrastructure, private source locations, commercial terms, service levels, or technology commitments.
Historical terminology
LCP, ESOF, and PGF are historical or source terms. They are not additional products and do not define separate public product promises.
Provenance and lifecycle
This content was independently re-authored in English from the canonical
product authority, LIT-PRD-100-Platform-Governance-Evidence version 14. That
authority approves the https://docs.l-it.io/platform-governance-evidence/
route family and the initial
https://docs.l-it.io/platform-governance-evidence/overview/ route.
Exact-digest, role-authorized approval is recorded for this revision. Git is
the change-history source. Review is required annually and whenever the product
authority, taxonomy, claim boundary, or public route changes.