Sample evidence pack

An evidence pack is twelve exports from a running system, generated by a script and never written by hand. This one is a sample drawn from the reference kit: its seed data, its provider zone, its redaction rules and its controls matrix. None of it describes a real client. An item with no seeded example says so, because an empty table would read as a clean result.

§01

What the pack contains

Twelve items, in the order every pack lists them.

  1. Item 1: Ledger extract

    Rows in the sample

  2. Item 2: Audit log integrity proof

    Rows in the sample

  3. Item 3: Approval log

    Rows in the sample

  4. Item 4: Killswitch test record

    Rows in the sample

  5. Item 5: Ceiling configuration and breaches

    Rows in the sample

  6. Item 6: Model version manifest

    Rows in the sample

  7. Item 7: Provider list and egress proof

    Counted in the sample

  8. Item 8: Schema registry

    Rows in the sample

  9. Item 9: Redaction rules and test results

    Rows in the sample

  10. Item 10: Incident log

    Rows in the sample

  11. Item 11: The controls matrix

    Published as its own page

  12. Item 12: The not-covered register

    Rows in the sample

§02

The twelve items

  1. Item 1: Ledger extract

    Every metered call for the period, model or tool, with its subject, model version, estimated and actual cost, and outcome. Dry runs are listed apart, so a rehearsal never reads as spend.

    Spend

    SAMPLE

    1. Time (UTC)
      2026-09-01 09:14:22 UTC
      Type
      Model call
      Model
      claude-sonnet-5
      Estimated
      £0.0024
      Cost
      £0.0021
      Outcome
      Booked
      Subject
      Classify inbound complaint 4471 against the deployment’s own category list
    2. Time (UTC)
      2026-09-01 09:14:51 UTC
      Type
      Model call
      Model
      claude-sonnet-5
      Estimated
      £0.0024
      Cost
      £0.0000
      Outcome
      Refused
      Subject
      Classify inbound complaint 4472, refused at the spend path while the killswitch was engaged
    3. Time (UTC)
      2026-09-01 09:40:12 UTC
      Type
      Model call
      Model
      claude-sonnet-5
      Estimated
      £0.0180
      Cost
      £0.0000
      Outcome
      Refused at ceiling
      Subject
      Summarise the correspondence history for complaint 4471 before the reply is drafted
    4. Time (UTC)
      2026-09-01 09:52:30 UTC
      Type
      Model call
      Model
      claude-sonnet-5
      Estimated
      £0.0024
      Cost
      £0.0023
      Outcome
      Booked
      Subject
      Classify inbound complaint 4473 against the deployment’s own category list

    Dry runs

    SAMPLE

    1. Time (UTC)
      2026-09-01 09:13:40 UTC
      Type
      Model call
      Model
      claude-sonnet-5
      Estimated
      £0.0024
      Cost
      £0.0000
      Outcome
      Dry run
      Subject
      Rehearsal of the complaint pipeline, end to end, spending nothing
  2. Item 2: Audit log integrity proof

    The audit log's hash chain for the period, each entry with its own hash and the hash of the entry before it, and the result of checking every link.

    The chain

    SAMPLE

    1. Entry
      1
      Time (UTC)
      2026-09-01 09:31:40 UTC
      Event
      Approval decided
      By
      sample.reviewer
      Applies to
      Approval
      Hash
      f5b79afa3162d97975307271d6f854c5995921969b2651f26bc0df4fcd5d11e2
      Previous entry’s hash
      None: the first entry
    2. Entry
      2
      Time (UTC)
      2026-09-01 09:40:12 UTC
      Event
      Ceiling refusal
      By
      spend-path
      Applies to
      Ledger entry
      Hash
      314dbb139a9eab2f14da24101a36c3a6fc53d32b7d25a2abf1e884f06b83fd31
      Previous entry’s hash
      f5b79afa3162d97975307271d6f854c5995921969b2651f26bc0df4fcd5d11e2
    3. Entry
      3
      Time (UTC)
      2026-09-01 09:53:05 UTC
      Event
      Incident opened
      By
      sample.operator
      Applies to
      Incident
      Hash
      162ae58d858bdfdc1f1487a03f39f3021f20e40a1b1dce1e0cff88b9faeed5c6
      Previous entry’s hash
      314dbb139a9eab2f14da24101a36c3a6fc53d32b7d25a2abf1e884f06b83fd31
    4. Entry
      4
      Time (UTC)
      2026-09-01 09:58:00 UTC
      Event
      Incident updated
      By
      sample.operator
      Applies to
      Incident
      Hash
      717429e20eb5be138cdd288f57d641d08b1ff8d3449331895946131490f31f01
      Previous entry’s hash
      162ae58d858bdfdc1f1487a03f39f3021f20e40a1b1dce1e0cff88b9faeed5c6
    5. Entry
      5
      Time (UTC)
      2026-09-01 10:05:00 UTC
      Event
      Incident updated
      By
      sample.operator
      Applies to
      Incident
      Hash
      3a58bf814626ab3e8ff57b4da8fa291e2f58a5ea7ef229e41ece96cb4104b528
      Previous entry’s hash
      717429e20eb5be138cdd288f57d641d08b1ff8d3449331895946131490f31f01
    6. Entry
      6
      Time (UTC)
      2026-09-01 10:30:00 UTC
      Event
      Incident updated
      By
      sample.operator
      Applies to
      Incident
      Hash
      20107286ce77f87c214b306b70f7daaa4d869247512fd97845c8b6e81c390f1e
      Previous entry’s hash
      3a58bf814626ab3e8ff57b4da8fa291e2f58a5ea7ef229e41ece96cb4104b528

    Verification

    SAMPLE

    1. Result
      Verified
      Faults
      None
      Tenant
      0192f3a1-0000-7000-8000-000000000001
      Entries
      6
      First entry
      1
      Last entry
      6
      Content erased
      0
      What this shows
      Each entry’s hash was recomputed from the fields it commits to and compared with the hash it stores. Each entry after the first was also checked for the hash of the entry before it. That catches an entry deleted from between two others, and a change to a hashed field unless every hash from that entry onward was recomputed too. Three fields are outside the hash: the retention date, the erasure record and the sample mark. The kit publishes no head hash, so a chain rewritten and recomputed from any entry onward, or cut at either end, would pass as well.
  3. Item 3: Approval log

    Every human gate decision: who decided, when, what they saw, and what they decided.

    SAMPLE

    1. Decided
      2026-09-01 09:31:40 UTC
      By
      sample.reviewer
      Decision
      Approved
      What the reviewer saw
      Proposed category: "Billing dispute". Model claude-sonnet-5. The reviewer saw the model output, the complaint text it was given, and the two categories it ranked below this one.
  4. Item 4: Killswitch test record

    Each killswitch drill: the date, the operator, what stopped, the recovery time, and the safe-state behaviour observed.

    SAMPLE

    1. Ran
      2026-09-01 09:14:45 UTC
      By
      sample.operator
      Recovery
      180 s
      What stopped
      Every paid model call, at the spend path, before any provider was contacted
      Safe state
      No call was in flight when the flag was set: the previous one had already completed and booked. The next call was refused at the spend path rather than being dropped, so it stands in the ledger as a refusal instead of going missing from it.
  5. Item 5: Ceiling configuration and breaches

    The spend ceilings in force, and every breach of them.

    Ceilings

    SAMPLE

    1. Ceiling
      Per call
      Limit
      £0.0060
      In force from
      2026-08-03 08:00:00 UTC
      In force until
      Still in force
      Source
      packages/db/src/seed-data.ts
    2. Ceiling
      Organisation, rolling 24 hours
      Limit
      £5.0000
      In force from
      2026-08-03 08:00:00 UTC
      In force until
      Still in force
      Source
      packages/db/src/seed-data.ts
    3. Ceiling
      Whole system, rolling 24 hours
      Limit
      £20.0000
      In force from
      2026-08-03 08:00:00 UTC
      In force until
      Still in force
      Source
      packages/db/src/seed-data.ts

    Breaches

    SAMPLE

    1. Time (UTC)
      2026-09-01 09:40:12 UTC
      Ceiling
      Per call
      Limit
      £0.0060
      Already committed
      £0.0000
      Estimated
      £0.0180
      Cost
      £0.0000
      Outcome
      Refused at ceiling
      Subject
      Summarise the correspondence history for complaint 4471 before the reply is drafted
  6. Item 6: Model version manifest

    Which model version answered which component, and when that changed.

    SAMPLE

    1. Component
      complaint-classifier
      Model
      claude-sonnet-5
      In force from
      2026-08-03 08:00:00 UTC
      Why it changed
      First pinned version for this component at deployment
  7. Item 7: Provider list and egress proof

    The model providers the system may call, and where the proof lives: the policy test showing that no unmetered call exists outside the provider zone.

    The kit's provider zone names 14 hosts and 21 packages that no code outside it may call or import. The pack lists each one by name.

  8. Item 8: Schema registry

    The output schemas in force, with their version history and the rejections for the period.

    SAMPLE

    1. Component
      complaint-classifier
      Version
      1
      In force from
      2026-08-03 08:00:00 UTC
      In force until
      Still in force
      Rejected responses
      1
      Schema
      {"$schema":"https://json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"category":{"minLength":1,"type":"string"}},"required":["category"],"type":"object"}
  9. Item 9: Redaction rules and test results

    The redaction rules in force, and a test of them run each time the pack is generated.

    Redaction rules

    SAMPLE

    1. Field
      decision
      Rule
      Kept as written
    2. Field
      attestation
      Rule
      Kept as written
    3. Field
      scope
      Rule
      Kept as written
    4. Field
      limitMicros
      Rule
      Kept as written
    5. Field
      committedMicros
      Rule
      Kept as written
    6. Field
      transition
      Rule
      Kept as written
    7. Field
      reportingPath
      Rule
      Kept as written
    8. Field
      every field not named above
      Rule
      Dropped

    Redaction tests

    SAMPLE

    1. Result
      Passed
      Withheld
      an email address, a phone number, a postcode, an account number, a name, a bearer token, an internal secret, a driver query, a narrative
      What this shows
      A specimen log line carrying personal data, credentials and free text was redacted by the rules above. Each item listed was missing from the output, and each kept field came out unchanged. That covers this specimen, not every input.
    2. Result
      Passed
      Kept
      decision, attestation, scope, limitMicros, committedMicros, transition, reportingPath
  10. Item 10: Incident log

    Open incidents, and the incident log for the period.

    SAMPLE

    1. Detected
      2026-09-01 09:52:30 UTC
      Opened
      2026-09-01 09:53:05 UTC
      Reported
      2026-09-01 09:58:00 UTC
      Closed
      2026-09-01 10:30:00 UTC
      Severity
      Low
      Status
      Closed
      Reporting path
      The client’s incident process
      Summary
      The complaint classifier’s output for complaint 4473 failed its schema and was rejected
      Why this path
      The rejected output was reported to the client’s incident process
  11. Item 11: The controls matrix

    The controls matrix as it stands.

    The matrix is published as a page of its own: The controls matrix

  12. Item 12: The not-covered register

    What the offer does not do, and who does it instead.

    SAMPLE

    1. Area
      Fundamental rights impact assessment
      Obligations
      Art. 27
      Who covers it
      Client's legal / DPO
    2. Area
      Conformity assessment and CE marking
      Obligations
      Art. 43, Art. 47, Art. 48
      Who covers it
      Provider; notified body
    3. Area
      Training data governance
      Obligations
      Art. 10
      Who covers it
      Model provider
    4. Area
      Bias and fairness testing of the underlying model
      Obligations
      Art. 10, Art. 15
      Who covers it
      Model provider; client's model-risk function
    5. Area
      Registration in the EU database
      Obligations
      Art. 49
      Who covers it
      Client's compliance function
    6. Area
      Watermarking of generated content
      Obligations
      Art. 50
      Who covers it
      Model provider
    7. Area
      Legal opinion on high-risk classification
      Obligations
      Art. 6 + Annex III
      Who covers it
      Client's legal
    8. Area
      DPIA authorship
      Obligations
      GDPR Art. 35
      Who covers it
      Client's DPO
    9. Area
      Threat-led penetration testing
      Obligations
      DORA Art. 26, DORA Art. 27
      Who covers it
      Client's security function; TLPT provider
    10. Area
      ISO/IEC 42001 certification
      Obligations
      ISO/IEC 42001:2023
      Who covers it
      Accredited certification body
    11. Area
      Independent model validation
      Obligations
      PRA SS1/23 Principle 4
      Who covers it
      Client's model validation function
    12. Area
      Employer consultation on workplace AI
      Obligations
      Art. 26(7)
      Who covers it
      Client's HR

§03

Book a scoping call

Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.