Reviewed Aug 2026
DE
DA-07 · LESSON 09

Audit and evidence

KEY DEFINITIONS

Terms used in this lesson

Guardian
A Ducat policy-checking signer that can authorize or reject defined protocol transactions.
DKG
Distributed key generation: participants create shares of a group key without one party learning the complete secret.
Validator
Software or a participant that independently checks state transitions under a system's rules. The exact role depends on the protocol being discussed.

Tests, conformance vectors, attestation receipts, reproducible builds, live rehearsals, and external review support different security claims.

35 min Difficulty 5/5 Not started

Loading lesson visuals...

01

Learn the idea

Evidence answers a specific claim, version, environment, and threat. A unit test checks one isolated behavior. An integration test checks components together. A conformance vector gives independent implementations the same input and expected result. A reproducible build links source to matching artifact bytes. An attestation identifies a measured running workload. A rehearsal tests an operational procedure. An external audit reviews a named scope and records findings. None substitutes for all the others.

GUIDED EXPLANATION1/4 ideas inspected
1

State the claim first

Define exactly what behavior, environment, version, and threat the evidence is meant to support.

Inspect each idea before the worked example.
The worked example follows the explanation

Inspect every idea above to open it.

Important distinctionAn audit badge proves every current deployment is secure.

An audit covers a named scope and revision. Later changes, excluded components, configuration, operations, and deployment remain separate evidence.

02
FINISH LEARNING FIRST

The questions unlock after every required learning activity

Inspect every guided idea, open the worked example, rebuild its mechanism, and complete the deterministic lesson tool. Your progress is saved automatically.