NULLWORKS // OPERATIONAL ASSURANCEAFTER TRIAGE
Your free triage found a signal

Now we find out whether the signal survives contact with evidence.

The free triage is respondent-supplied. Paid work starts where the questionnaire stops: acquiring evidence, challenging claims, reconstructing authority, falsifying controls, assigning remediation, and retesting the repaired state.

No automatic upsell.

The right answer may be a bounded verification review, an assurance sprint, a full pressure test, a simple workflow correction, or no further NULLWORKS engagement at all.

What changes after free triage

Answer -> Signal -> Evidence -> Falsification -> Finding -> Remediation -> Retest

That chain is the product. The deliverable is not a prettier questionnaire. It is a defensible understanding of what the system can actually support, what it cannot, and what changed after intervention.

AnswerSignalEvidence standardCriticalityFalsificationFindingRemediationRetest
Ways to engage

Start with the smallest defensible scope.

TARGETED

Bounded Verification Review

Scoped after evidence review

For a strong self-reported posture and a narrow question. We acquire the evidence behind the highest-value claims and independently support or falsify them before broadening scope.

WHAT GETS TESTED IN THIS SCOPE
  • Selected high-value control claims and the evidence behind them
  • Named human authority, approval, stop, revoke, and escalation paths
  • Relevant access boundaries and role separation
  • Traceability from source data to consequential output
  • Decision receipts, logs, and reconstruction quality
  • One or more targeted failure or changed-condition checks
  • A concise finding packet with supported, unsupported, and unknown states

Representative scope only. Exact test selection depends on system boundaries, evidence availability, consequence, and the failure surfaces identified during intake. Proprietary test mechanics are not published here.

REQUEST SCOPE ->
CRITICAL REPAIR

Operational Assurance Sprint

$20K-$35K

For material control gaps that need an owned repair plan. We identify failure surfaces, implement or coordinate missing controls, establish evidence, and retest the original failure conditions.

WHAT GETS TESTED IN THIS SCOPE
  • The control gaps identified by triage and initial evidence review
  • Authority and escalation paths around the affected workflow
  • Access, credential, and separation-of-duty weaknesses
  • Evidence capture needed to reconstruct consequential actions
  • Recovery and safe-state behavior for the affected process
  • Changed-condition and regression scenarios around the repair
  • Remediation ownership, acceptance criteria, and registered retests
  • Before-and-after receipt showing what changed and what remains open

Representative scope only. Exact test selection depends on system boundaries, evidence availability, consequence, and the failure surfaces identified during intake. Proprietary test mechanics are not published here.

ENGAGE NULLWORKS ->
CONSEQUENTIAL SYSTEMS

Full Pressure Test

$50K-$125K+

Evidence acquisition, interviews, technical inspection, falsification testing, authority reconstruction, changed-condition scenarios, findings, remediation ownership, and retesting across a larger system.

WHAT GETS TESTED IN THIS SCOPE
  • End-to-end operating loop: agents, tools, data, humans, handoffs, and consequences
  • Authority, approval, override, stop, revoke, and escalation controls
  • Identity, access, credential, privilege, and separation boundaries
  • Data provenance, transformations, exposure, retention, and export assumptions
  • Decision evidence, logs, receipts, contradictions, and reconstruction quality
  • Failure handling, recovery paths, safe-state behavior, and degraded operation
  • Continuity after model, vendor, workflow, role, or organizational change
  • Representative falsification, changed-condition, and adversarial scenarios
  • Remediation priorities, named owners, acceptance criteria, and retesting
  • Executive and technical evidence packages with explicit truth boundaries

Representative scope only. Exact test selection depends on system boundaries, evidence availability, consequence, and the failure surfaces identified during intake. Proprietary test mechanics are not published here.

REQUEST SCOPE ->
What you receive

Receipts that survive the meeting.

Claim-to-control map

What the system says it can do, the control expected to carry the claim, and the evidence state behind it.

Finding packet

Observed behavior, source pins, falsification method, confidence, blockers, unknowns, and explicit truth boundaries.

Remediation ownership

Priority repair order, named owners, acceptance criteria, and registered retests instead of a pile of recommendations.

Retest receipt

Before-and-after evidence showing what changed, what closed, what regressed, and what remains unresolved.

Public case receipt // CIRIS

Testing that led to changes in the next release.

NULLWORKS pinned a public CIRIS test surface, independently reran selected behavior, challenged authority and evidence boundaries, separated confirmed results from blockers and unknowns, and produced a private technical report plus a sanitized public evidence surface.

The useful pattern is baseline -> test -> finding -> correction -> retest -> receipt. Subsequent corrective work was reported at the agent layer. New release claims remain candidate test surfaces until independently reproduced.

Living test surface, not permanent certification.

A release note, message, or collaborator statement is not automatically a NULLWORKS finding.

OPEN SANITIZED PUBLIC PROOF ->
Confidential work

Explain the method without publishing the machinery.

Private source, prompts, exploit detail, internal controls, customer data, proprietary architecture, and trade-secret operating logic stay outside the public case record. Public material can describe the problem class, why it mattered, the evidence class produced, and what changed.

Why this exists

AI can fail while every component looks “working.”

Authority

Who can approve, stop, revoke, escalate, or correct consequential action?

Evidence

What survives after action: source, state, actor, rationale, approval, contradiction, correction?

Completion

Did the real-world work finish, or did software merely emit a terminal action?

Continuity

After model, vendor, role, or workflow change, are controls re-established by proof or inherited by assumption?

The audit is allowed to end the sale.

No new AI. No new software. No permanent OISA. No further NULLWORKS engagement. If evidence points there, that is the answer.