The evidence checklist
- Authorized hostname and scope: identify the property and the exact hostname or public surface the customer authorized.
- Rule and version: name the deterministic check and the version or release that produced the observation.
- Timestamps and observed values: record when the baseline and retest ran, including the values that matter to the rule.
- Remediation owner and action: say who changed what, where, and when; do not imply that a provider action was automated if it was not.
- Same-rule retest: use the same rule and scope after remediation so the comparison is meaningful.
- Immutable/content-hash context: preserve the evidence identity or content hash so a later copy can be compared with the original.
- Residual limits: name the properties, paths, subdomains, protocols, or time windows that were not covered.
A client-ready explanation
“We checked the authorized hostname with the same HTTPS rule before and after the provider change. The baseline recorded the old response at the first timestamp; the retest recorded the new response at the second timestamp. This supports that observed change on this surface. It does not certify the whole website or cover systems outside the stated scope.”
That structure is more useful than a green badge because it answers the client’s practical questions: what was checked, what changed, who acted, and what remains outside the evidence.
What RemedyProof adds
RemedyProof connects deterministic observations to remediation guidance, same-rule verification, and a client-ready evidence ledger. Results remain bounded and point-in-time. The free Public Snapshot is a one-time read-only baseline retained for seven days and does not start recurring monitoring.