RESTRICTED OPERATIONAL PHASE ACTIVE UEG-001 LIVE: PASS 16/16 FEDERATION: 3 SEV-SNP LANES RUN: 20260510T203403Z
The Evidence Engine

Proof that the Tarmac works.

Cloud Capable proof shows that high-value work can be admitted, refused, measured, and evidenced without asking the reader to trust a black box.

What is a capability proof?

A capability proof is how a claim becomes reviewable. It is a bounded, runnable proof of one capability: what it is allowed to do, what it refuses to do, how it behaves at runtime, and what evidence it produces.

Technical Diligence

Same request. Same governed decision.

This table demonstrates how different user or model inputs can resolve into a single governed operation with the same decision, policy boundary, and proof root.

Agent/Model Input (The Variable) Normalized Operation Policy Decision Decision Fingerprint Proof Root
"Upload this file to approved bucket." GCS.PUT_OBJECT ADMIT 41fc76ce2fd40f22... T1 Silicon (VCEK)
"Put object into gs://approved-bucket." GCS.PUT_OBJECT ADMIT 41fc76ce2fd40f22... T1 Silicon (VCEK)
"Store artifact in corporate archive." GCS.PUT_OBJECT ADMIT 41fc76ce2fd40f22... T1 Silicon (VCEK)
LIVE SILICON DRIFT TEST CONFIDENTIAL_WORKLOAD.VERIFY REFUSE 0c092d12abd70b0e... AMD_SEV_SNP

Case Study: Real-Time Refusal

During a live validation run, the system correctly verified the hardware integrity but refused execution because the manifest no longer matched the expected state. The result: automatic refusal before any data was exposed. This is the definition of a fail-closed Tarmac.

ClaimWhat is promisedThe proof defines exactly what the capability is allowed to mean in plain language.
BoundaryWhat is refusedThe proof shows what the system will not do instead of treating every action as allowed.
RunHow it behavesThe proof connects the claim to runtime behavior, not just a static document.
ProofWhat is provenThe run produces evidence IDs, control mappings, and reviewer-ready proof notes.

Why buyers care

Evidence is not decoration. It lowers review friction, supports procurement, helps CISOs explain risk, and gives leadership a reason to approve the next step.

ProcurementFaster diligenceGive reviewers mapped claims instead of asking them to interpret a black box.
SecurityClearer risk postureShow admission, refusal, containment, and teardown signals.
FinanceDefensible valueConnect governed work to transaction counts, refusals, and GCF compression records.
LegalSafer languageKeep claims bounded so the company can market with discipline.

What logs show vs what proof requires

Cloud provider telemetry is essential. It tells reviewers what happened at the infrastructure layer. Cloud Capable adds governance evidence: why an action was allowed or refused, what boundary applied, and what proof ties the decision to a business outcome.

Buyer question Cloud provider native layer Cloud Capable adds
Did the machine or API run?Audit logs, metrics, uptime, resource activity, and API events.Why the action was allowed or refused, and what it means for the business.
Was an action denied?Cloud policy-denied logs when provider policy blocks access.Capability-level refusal when an action may be technically possible but violates a Cyber-Safety boundary.
Was confidential execution used?Confidential computing and attestation signals for supported environments.Proof records tying attestation to the specific workflow, evidence boundary, and business outcome.
Who called what?IAM principal, resource, method, time, and location context.Admission records mapping identity, data sensitivity, network path, and AI/action scope to a governed outcome.
What value did the run create?CPU, memory, bytes, API calls, and infrastructure consumption.G-TPS throughput and GCF compression records for governed transactions, refused work, evidence events, and value-meter output.

Cloud Capable does not replace cloud-native logging, monitoring, or attestation. It turns those signals plus governed runtime decisions into reviewer-ready capability evidence.

Capability proof architecture

Cloud Capable connects capability, boundary, and evidence into a single system that can be reviewed without guesswork.

Capability

Each capability carries a plain-language outcome: what it enables, what it refuses, what it eliminates, and what it proves.

Architecture

NIRA makes adoption non-invasive. G-TPS / GCF make governed work measurable. Capability proofs make the claims independently reviewable.

Review

Boundaries, proof records, and control mappings let buyers evaluate the claim without guessing, and defend it without reconstructing.

Evidence is the ultimate closer.

When proof exists, decisions move forward.

Transition from buyer curiosity to technical and regulatory confidence.

Evidence-backed claims

The current evidence track supports bounded language: what passed, under what run, which capability it maps to, and what business confidence it creates.

The strongest current proof anchor is : a bounded live Tarmac run including verified capabilities and verified teardown.

Silicon Proof

The proof artifact exposes the attestation fields.

A reviewer should not have to infer whether the run was actually hardware-bound. The proof artifact shows the confidential runtime, workload measurement, policy binding, verifier chain, refusal outcome, and teardown state in one place.

TARMAC-LIVE-20260510T203403Z Representative field view from the bounded live Tarmac run.
TEE runtimeAMD SEV-SNP confidential VM
Attestation statusVERIFIED_BY_SILICON
Verifier chainVCEK scoped lane evidence + NovaZK verifier
Workload measurementsha256: 7f91...c2a8
Policy contractidentity + data + network + AI-action boundary
Admission verdictPASS: governed workflow admitted
Refusal evidenceunsafe export path refused before execution
Teardown proofephemeral state eliminated; zero-egress bytecount confirmed

Current verified claims

Summarized evidence from the range. Full raw evidence binders are available for intentional review.

Claim Evidence ID Result Capability
NIRA/PNP adoption can preserve existing source, schema, and workflow across representative systems.NIRA-PNP-ADOPTION-GAUNTLET-20260510T115157ZPASSNIRA
Runtime conformance passed across the full proof suite.CAPABILITY-PROOF-20260510T115157Z27/27 PASSProof Packaging
The live Tarmac run passed bounded confidential execution with NovaCore, NovaDust, NovaMemX, NovaPay, and verified teardown.TARMAC-LIVE-20260510T203403ZPASSTarmac / NovaVault-X
NovaDust zero-egress evidence exists at scale.NVD-001-G-TPS-SCALE-20260510T021311ZCONFIRMEDNVD
NovaPay/GCF economic value-meter evidence exists.NOVAPAY-G-TPM-STRESS-20260509T023505ZCONFIRMEDNovaPay / GCF
NovaPay/GCF mid-size simulation value-meter evidence exists.NOVAPAY-MIDSIZE-SIM-20260510T045645ZCONFIRMEDNovaPay / GCF
Compliance & Audit

Regulatory control mapping

Cloud Capable supports and evidences the control objectives behind major cloud, privacy, AI, cybersecurity, and operational-resilience regimes.

For compliance, audit, and regulatory review. Executives: skip to the pilot.

This mapping is a readiness and evidence guide, not a legal opinion, formal certification, or regulatory exemption. Certification depends on scope, customer environment, auditor review, and the applicable regulator or assessment body.

Framework Control objective Cloud Capable mapping
GDPR Art. 32Security of processing: confidentiality, integrity, availability, resilience, and testing.NovaDust zero-egress, NovaVault-X attestation, NovaMemX continuity, and Tarmac proof records.
HIPAA Security RuleAdministrative and technical safeguards for electronic protected health information.Identity and authority gates, governed access/refusal, evidence logs, CyberSafe ID, and zero-exfiltration posture.
FedRAMP / NIST 800-53Access, audit, configuration, incident response, system integrity, and cloud authorization evidence.Hardware-scoped evidence, NovaCore decisions, Tarmac proof records, and teardown verification.
NIST CSF 2.0Govern, Identify, Protect, Detect, Respond, and Recover lifecycle.Cyber-Safety spine: identity governance, detection, refusal, recovery, and proof records.
CSA CCMCloud control assurance across identity, logging, data protection, resilience, and supply chain.Cloud Capable packaging, decision artifacts, G-TPS throughput records, GCF compression records, and audit binder outputs.
SOC 2Security, availability, processing integrity, confidentiality, and privacy.Proof records, admission/refusal outcomes, NovaPay classification, NovaMemX continuity, and evidence-chain integrity.
PCI DSS v4.0.1Network security, account data protection, access control, monitoring, and testing.NovaShield authorization, NVD containment, CyberSafe ID, logging, and refusal evidence.
DORAICT risk management, resilience testing, third-party risk, incident handling, and continuity.Tarmac live proof, NIRA adoption, NovaMemX continuity, NovaDust refusal, and verified teardown.
NIS2Technical, operational, and organizational cyber risk management measures.NovaCore admissibility, NovaShield enforcement, identity governance, and evidence-backed refusal.
EU AI ActAI robustness, cybersecurity, logging, human oversight, and lifecycle consistency.Capability proof objects, NovaVision governed perception, NovaCore refusal, G-TPS throughput records, and GCF compression records.
CMMC / NIST 800-171Safeguarding Federal Contract Information and Controlled Unclassified Information.Access control, auditability, proof records, governed refusal, and zero-exfiltration posture.

Deliberate boundaries

Credibility is a product feature. These boundaries keep the claim disciplined until each statement becomes formally true.

We do not claim (yet)

  • Production certified.
  • Third-party certified.
  • Cloud-provider endorsed.
  • Guaranteed compliant.
  • Regulatory exemption.

We say instead

  • Designed to support.
  • Evidence-ready for.
  • Mapped to control objectives.
  • Validated in a bounded run.
  • Full binder available on request.
The Closer

When the conversation turns to proof, this is what you bring.

Transition from buyer curiosity to technical and regulatory confidence. The binder is ready. The proof records are real. The next step is yours.