Evidence

Working software. Recorded results.

Controlled tests show selected allowed actions reaching their targets and selected blocked actions stopping on the tested paths. Here is what those results establish.

What was recorded.

Two connected computers

A June 6 recorded test sent one allowed action to a receiving computer and its protected target. The blocked action appeared zero times at both. Both computers were controlled by the founder; this was not a customer or independent test.

Local approval checks

A focused May 30 rerun recorded 11 passing tests. The valid request reached the tool once. Changed approval records, missing approval and reuse attempts produced zero calls to the tool on that tested path.

Supporting historical record

A later source-based report describes one authorized send and six deliberately hostile requests rejected with HTTP 403 responses, with the protected target unchanged during those attempts. The standalone original closeout was not available in the reviewed material, so this remains supporting evidence.

What the next evaluation must measure.

Compare the same permitted workflow with and without DVS. Measure changed actions incorrectly allowed, valid actions incorrectly stopped, delay added, repeated requests and behavior when systems restart or fail.

Check every relevant route to the target. Observe what the target actually did, separately from the decision to allow the request.

Current scope.

A working private implementation exists. The initial in-house test phase is complete; broader case testing is underway. No customer pilot or revenue is established in the reviewed evidence.

  • Customer validation. No customer deployment or payment is claimed.
  • Another party’s production use. DVS has not been established in another party’s production environment.
  • Independent reproduction. No independent external reproduction is claimed.
  • Certification. No security, compliance, regulatory or government certification is claimed.
  • Production identity and record storage. Managed identity and key services, organization-controlled decision records, and shared tracking of reused approvals remain integration work.
  • Coverage across an application. A deployment must find other routes to the same action, remove or control them separately, or explicitly exclude them before claiming coverage of the whole system.
  • Completion and observed results. A DVS decision to allow an action does not prove that the receiving system completed it or produced the intended effect. Strong guarantees when records can change require checks at the receiving system and separate confirmation of the result.

Bring one workflow.

We can identify the relevant recorded evidence and agree on the questions a software evaluation would need to answer.

Checking evaluation availability…