Evidence Policy
Version 1.0.0 · last reviewed 2026-09-19. Structure fixed by legal review; wording subject to final review before launch.
What is evidence
For every run: a hash-chained event ledger, the script ids, versions and implementation hashes that ran, the release and artifact hashes, PASS/FAIL outcomes, execution metadata, AI-call records (model, parameters, request and response hashes; never content). The attestation is signed by Auditor with an Ed25519 key at the recorded time; the execution ledger is hash-chained and its evidence is stored under write-once retention. No third-party timestamping or external anchoring is used, by design.
What is not evidence
Your source code (never retained), and findings content, which is encrypted at rest with your organisation's key and is only readable by your organisation.
Retention
6 years from each run, independently of account closure, on the basis of Spanish Commercial Code art. 30 (6-year record-keeping) and GDPR art. 17(3)(b) and (e); the evidence contains no personal data.
Verification
Anyone can verify an attestation with the published keys; the organisation can download the signed evidence package and verify it offline with the published script.
Disputes
A dispute opened on a result places the related evidence under legal hold until the case is closed.