Skip to content
Preflight Audit

Preflight Audit Laboratories

Preflight Validation Suite

A controlled family of Preflight-developed validation clients, test harnesses, evidence systems and laboratory software. Each module is labelled by its real implementation state. Software readiness never creates external accreditation, certification or validation by itself.

PF-001

Implemented engine

Preflight ACVP Client

Demo-capable client with production fail-closed; production ACVTS remains externally gated.

PF-002

Implemented engine

Preflight ACVTS Demo Runner

Creates Demo sessions, downloads vector sets, executes through controlled IUT adapters and submits results.

PF-003

Implemented engine

Preflight IUT Adapter SDK

Controlled adapter boundary between validation vectors and implementations under test.

PF-004

Implemented engine

Vector / KAT / Monte Carlo Engine

Deterministic vector execution with evidence records and bounded workloads.

PF-005

Implemented readiness

Entropy / DRBG Validation Harness

Health tests and evidence workflow; official entropy validation remains programme-controlled.

PF-006

Implemented readiness

FIPS 140-3 Module Test Harness

Module/evidence readiness controls; no CMVP validation is implied.

PF-007

Implemented engine

PQC Interoperability Harness

KEM/signature interoperability and tamper rejection with sensitive-value redaction.

PF-008

Implemented engine

Side-Channel Trace Pipeline

Welch t-test/TVLA-style analysis with raw-trace digesting rather than raw trace evidence storage.

Physical lab / hardware dependent

PF-009

Implemented engine

Fault Injection Orchestrator

Authorized, interlocked campaign orchestration with hard limits and safe shutdown.

Physical lab / hardware dependent

PF-010

Implemented engine

Preflight Engagement Manifest Service

Exact-SHA immutable scope, ownership classification and tamper verification.

PF-011

Implemented engine

Preflight Evidence Vault

Immutable evidence records, bundles and chain-of-custody controls.

PF-012

Implemented engine

Controlled Method / Competence Engine

Personnel competence, method activation, authorization and reviewer-separation controls.

PF-013

Implemented engine

Preflight Report Forge & Release Gate

Deterministic reports, digest verification, technical/quality review and approved-signatory release.

PF-014

Implemented readiness

Accreditation Readiness Pack Generator

Creates tamper-evident readiness evidence; never creates external accreditation.

PF-015

Readiness profile

Full-Stack Application Security Harness

Controlled AppSec evidence profile for auth, sessions, inputs, secrets, dependencies, logging and rate controls.

PF-016

Readiness profile

Smart Contract / Protocol Property Harness

Controlled Web3 evidence profile for invariants, privilege, oracle/economic risk and emergency controls.

PF-017

Readiness profile

Mobile / Wallet Security Harness

Controlled wallet profile for key generation/storage, signing boundaries, preview, recovery and address integrity.

PF-018

Readiness profile

Firmware / TEE / Attestation Harness

Secure-boot/update/debug/attestation profile; device testing depends on lab hardware.

Physical lab / hardware dependent

PF-019

Readiness profile

IoT Security Test Harness

Connected-device lifecycle/onboarding/transport/update/API profile; formal certification remains scheme-specific.

Physical lab / hardware dependent

PF-020

Readiness profile

FIDO Readiness Harness

Passkey/WebAuthn/FIDO security evidence profile; official certification requires the applicable recognized path.

PF-021

Readiness profile

Payment Security Readiness Harness

Key, CVM, tokenization, transaction, redaction, segmentation and incident-control profile.

PF-022

Readiness profile

AI / Agent Adversarial Evaluation Harness

Tool authorization, prompt injection, data exfiltration, sandboxing, approvals and auditability profile.

PF-023

Readiness profile

Supply-Chain / Build Provenance Harness

SBOM, provenance, signature, isolation, artifact digest, approval and vulnerability-response profile.

PF-024

Readiness profile

Cloud / Infrastructure Security Harness

IAM, least privilege, boundaries, secrets, encryption, logging, recovery and drift profile.

PF-025

Implemented readiness

PIV / Identity Validation Harness

Executable PIV/identity evidence harness is implemented; official NPIVP/PIV validation remains programme/scope controlled.

PF-026

Implemented readiness

Common Criteria / SESIP Evaluation Framework

Executable evidence framework is implemented; official evaluation requires the applicable recognized scheme/laboratory status.

PF-027

Implemented engine

Preflight Standards Watcher

Digest-based standard snapshot/change detection and QMS evidence generation are implemented; authoritative-source ingestion is configured per source.

PF-028

Implemented engine

Preflight Proficiency Runner

Numeric and qualitative proficiency exercises and evidence are implemented; external/interlaboratory participation depends on real providers.

Controlled software is laboratory equipment.

Every tool that can affect a reported result is versioned, regression-tested, change-controlled and linked to exact engagement evidence. Production programme access remains disabled until the required external authorisation, laboratory scope and personnel competence exist.