Independent operational assurance

CIRIS public proof

Sanitized evidence that NULLWORKS completed a read-only, exact-version-pinned operational assurance review of CIRISAgent and preserved reproducible test receipts.

Truth boundary: this page is not the confidential report, a certification, a compliance approval, a penetration test, or an endorsement by CIRISAI. It publishes only non-confidential evidence classes, test counts, source pins, balanced conclusions, and artifact hashes.

What was proved

42 / 42

Targeted tests passed

Selected CIRIS-owned tests were independently rerun in an isolated runner.

10 / 10

Source checks passed

Deterministic claim-to-control checks passed against the pinned source.

3 / 3

Authority calls executed

A direct imported-code probe tested role behavior across resource labels.

PINNED

Exact source custody

The reviewed Agent and Persist revisions were frozen before execution.

Preliminary disposition

Assessment

Credible architecture / conditional assurance

CIRIS contains substantive constitutional-AI machinery, including a multi-stage reasoning pipeline, human deferral, persistent lineage, completed-trace signing, and append-only correction primitives.

Primary seam

Role is not the same as jurisdiction

The review found meaningful domain-aware service routing, while the inspected core human authorization surface remained broader than resource-specific jurisdiction.

Public receipts

These receipts show how the engagement was grounded without exposing the confidential builder report, raw evidence packet, private correspondence, or NULLWORKS internal orchestration method.

R-001 — Source custody

CIRISAgent: 7f2369bed22c626404a1dcf8e09bfeb81a573d82

CIRISPersist: e8cdb535b60a549948f2b0ceb43deb6921009260

Meaning: findings apply to these exact revisions unless later retesting says otherwise.

R-002 — Independent test reproduction

Method: isolated GitHub-hosted runner, Python 3.12 environment, dependency inventory, JUnit output, logs, and SHA-256 manifest.

Result: 42 selected CIRIS project tests passed; 0 failed.

R-003 — Authority-boundary probe

Observed: AUTHORITY + medical resource was authorized; the same AUTHORITY + financial resource was also authorized; OBSERVER + medical resource was denied.

Interpretation: the role gate functioned, while the supplied resource did not mechanically narrow the inspected core result.

R-004 — Environment blocker preserved honestly

A selected CIRISPersist Rust test reached native compilation but required the runner's TPM2-TSS development library. It was recorded as an environment dependency blocker, not mislabeled as a CIRIS failure or silently discarded.

Sanitized findings

Human authority placement

Bind domain, resource, scope, assignment, delegation, and time validity into the human decision object.

Timeout semantics

Separate pure scheduling from human-approval-required deferral so time cannot impersonate authorization.

Decision-signature custody

Verify and preserve the exact Wise Authority decision signature before consequential state mutation.

Incomplete-path receipts

Preserve an explicit aborted or incomplete trace receipt before partial execution records are swept.

Artifact integrity

ArtifactPurposeSHA-256
Final PDF reportConfidential human-readable report087cb3335749384472e9dd0b6679ac0fa6e4d1eb4303065192c168c470e69d8d
Editable DOCX reportBuilder-editable report source5b7621729a6382a05731fdf9bb659c1a6cb0dadf9fbbc9de4e0ddba96a9103f4
Evidence packet ZIPLogs, JUnit, manifests, and probe outputs873d9c5dd80683e4796d733937bd42b7bf85a61393c66a09d67d0f1db100c68e

A matching hash proves byte-for-byte artifact identity. It does not independently prove the report's conclusions.

What remains private

  • The full confidential report and editable report source.
  • Raw test logs, JUnit files, dependency inventories, and execution artifacts.
  • Private correspondence and builder-specific discussion.
  • NULLWORKS internal orchestration, scoring, and assurance methodology.