Audit and evidence
Terms used in this lesson
- Guardian
- A Ducat policy-checking signer that can authorize or reject defined protocol transactions.
- DKG
- Distributed key generation: participants create shares of a group key without one party learning the complete secret.
- Validator
- Software or a participant that independently checks state transitions under a system's rules. The exact role depends on the protocol being discussed.
Tests, conformance vectors, attestation receipts, reproducible builds, live rehearsals, and external review support different security claims.
Loading lesson visuals...
Learn the idea
Evidence answers a specific claim, version, environment, and threat. A unit test checks one isolated behavior. An integration test checks components together. A conformance vector gives independent implementations the same input and expected result. A reproducible build links source to matching artifact bytes. An attestation identifies a measured running workload. A rehearsal tests an operational procedure. An external audit reviews a named scope and records findings. None substitutes for all the others.
State the claim first
Define exactly what behavior, environment, version, and threat the evidence is meant to support.
Inspect every idea above to open it.
An audit covers a named scope and revision. Later changes, excluded components, configuration, operations, and deployment remain separate evidence.
The questions unlock after every required learning activity
Inspect every guided idea, open the worked example, rebuild its mechanism, and complete the deterministic lesson tool. Your progress is saved automatically.