Preflight Audit Laboratories
Preflight Validation Suite
A controlled family of Preflight-developed validation clients, test harnesses, evidence systems and laboratory software. Each module is labelled by its real implementation state. Software readiness never creates external accreditation, certification or validation by itself.
PF-001
Implemented enginePreflight ACVP Client
Demo-capable client with production fail-closed; production ACVTS remains externally gated.
PF-002
Implemented enginePreflight ACVTS Demo Runner
Creates Demo sessions, downloads vector sets, executes through controlled IUT adapters and submits results.
PF-003
Implemented enginePreflight IUT Adapter SDK
Controlled adapter boundary between validation vectors and implementations under test.
PF-004
Implemented engineVector / KAT / Monte Carlo Engine
Deterministic vector execution with evidence records and bounded workloads.
PF-005
Implemented readinessEntropy / DRBG Validation Harness
Health tests and evidence workflow; official entropy validation remains programme-controlled.
PF-006
Implemented readinessFIPS 140-3 Module Test Harness
Module/evidence readiness controls; no CMVP validation is implied.
PF-007
Implemented enginePQC Interoperability Harness
KEM/signature interoperability and tamper rejection with sensitive-value redaction.
PF-008
Implemented engineSide-Channel Trace Pipeline
Welch t-test/TVLA-style analysis with raw-trace digesting rather than raw trace evidence storage.
Physical lab / hardware dependent
PF-009
Implemented engineFault Injection Orchestrator
Authorized, interlocked campaign orchestration with hard limits and safe shutdown.
Physical lab / hardware dependent
PF-010
Implemented enginePreflight Engagement Manifest Service
Exact-SHA immutable scope, ownership classification and tamper verification.
PF-011
Implemented enginePreflight Evidence Vault
Immutable evidence records, bundles and chain-of-custody controls.
PF-012
Implemented engineControlled Method / Competence Engine
Personnel competence, method activation, authorization and reviewer-separation controls.
PF-013
Implemented enginePreflight Report Forge & Release Gate
Deterministic reports, digest verification, technical/quality review and approved-signatory release.
PF-014
Implemented readinessAccreditation Readiness Pack Generator
Creates tamper-evident readiness evidence; never creates external accreditation.
PF-015
Readiness profileFull-Stack Application Security Harness
Controlled AppSec evidence profile for auth, sessions, inputs, secrets, dependencies, logging and rate controls.
PF-016
Readiness profileSmart Contract / Protocol Property Harness
Controlled Web3 evidence profile for invariants, privilege, oracle/economic risk and emergency controls.
PF-017
Readiness profileMobile / Wallet Security Harness
Controlled wallet profile for key generation/storage, signing boundaries, preview, recovery and address integrity.
PF-018
Readiness profileFirmware / TEE / Attestation Harness
Secure-boot/update/debug/attestation profile; device testing depends on lab hardware.
Physical lab / hardware dependent
PF-019
Readiness profileIoT Security Test Harness
Connected-device lifecycle/onboarding/transport/update/API profile; formal certification remains scheme-specific.
Physical lab / hardware dependent
PF-020
Readiness profileFIDO Readiness Harness
Passkey/WebAuthn/FIDO security evidence profile; official certification requires the applicable recognized path.
PF-021
Readiness profilePayment Security Readiness Harness
Key, CVM, tokenization, transaction, redaction, segmentation and incident-control profile.
PF-022
Readiness profileAI / Agent Adversarial Evaluation Harness
Tool authorization, prompt injection, data exfiltration, sandboxing, approvals and auditability profile.
PF-023
Readiness profileSupply-Chain / Build Provenance Harness
SBOM, provenance, signature, isolation, artifact digest, approval and vulnerability-response profile.
PF-024
Readiness profileCloud / Infrastructure Security Harness
IAM, least privilege, boundaries, secrets, encryption, logging, recovery and drift profile.
PF-025
Implemented readinessPIV / Identity Validation Harness
Executable PIV/identity evidence harness is implemented; official NPIVP/PIV validation remains programme/scope controlled.
PF-026
Implemented readinessCommon Criteria / SESIP Evaluation Framework
Executable evidence framework is implemented; official evaluation requires the applicable recognized scheme/laboratory status.
PF-027
Implemented enginePreflight Standards Watcher
Digest-based standard snapshot/change detection and QMS evidence generation are implemented; authoritative-source ingestion is configured per source.
PF-028
Implemented enginePreflight Proficiency Runner
Numeric and qualitative proficiency exercises and evidence are implemented; external/interlaboratory participation depends on real providers.
Controlled software is laboratory equipment.
Every tool that can affect a reported result is versioned, regression-tested, change-controlled and linked to exact engagement evidence. Production programme access remains disabled until the required external authorisation, laboratory scope and personnel competence exist.
