You own the evidence, not the fix. You accepted the risk on a CVE in March. In August the score is different and an auditor wants to know whether the March decision was defensible on March's information. That is a question about a record, so we answer it from a record, and hand over the query that reproduces it independently.
A dated, attributed account of what was known on the day you decided, re-derivable by someone who does not trust you.
March's answer, reconstructed from March's facts. Ask what the EPSS score was on a past date and you get that date's value; anything we learned later structurally cannot appear.
A provenance tuple behind every value: source, feed version, valid-as-of, we-knew-at, feed sha256, and the SQL to re-derive it. Returns in ~9 ms with no model in the path, so it cannot invent a source.
A validation receipt that binds adapter sha, corpus version, battery id and sha, and the score per gate to a date. That is an attestation about the instrument on the day the decision was made, a different and stronger claim than an attestation about the answer.
Natural language, no query syntax. Facts come back in about 226 ms; the interpretation follows.
What was the EPSS score for CVE-2021-44228 on 2026-08-01?
Reconstruct what was known about CVE-2026-43418 as of the date we signed the risk acceptance.
We signed off the risk acceptance back in March. Was the EPSS really that low?
We accepted the risk on this CVE in March. The auditor asks what we knew in March. I have a screenshot in a Confluence page.
The EPSS score cited in our risk register is from whenever someone last looked. There is no history and no provenance.
Every answer I give an auditor has to be re-derivable by them, independently, or it is not evidence.
I cannot prove the tool we used to make the decision was itself accurate at the time.
Every line carries a status. Nothing here is a roadmap item wearing a present tense.
Two clocks per fact: when it was true upstream, and when we learned it. A fact recorded after your as-of date structurally cannot leak into the answer, because the constraint is a SQL predicate rather than a filter applied afterwards.
Click any value and you get corpus version, split, battery, qid and tx_from, plus the SQL to re-derive it yourself. Deterministic, ~9 ms, the model is never consulted.
Emitted per run and every field derived, never typed: adapter sha256, corpus version, battery id and sha, item count, pass mark, run sha and the score per gate. It refuses to publish unless the artifact it hashed is the one actually serving: confirmed match 9e4c941c5bcd6370….
11,453,123 rows of EPSS and CISA KEV facts over 360,906 CVEs, refreshed daily, never trained into the weights. 28 EPSS snapshots give 178 days to reconstruct against.
88.91 on the frozen 4,778-item battery against Opus 5's 88.0 on the same items. One instrument, published sha, re-runnable by the auditor.
For this reader a model's opinion inside an evidence file is a liability, so the interpretation confines itself to what the record does and does not establish. Restraint is scored as a virtue in the rubric, not as a thin answer.
Stated once, plainly, so nothing downstream is designed around a fiction.
No control mapping generated from the corpus, which holds no standards text. The compliance pages do the honest version by hand: one page per obligation, quoting the standard's own words with the citation, and saying what stays with your auditor.
The corpus holds no standards text. We can say you run Apache CXF and there are 13 CXF CVEs. We cannot say your CXF 3.5.2 is affected, and the version gate stops the model implying otherwise: 7/7 detected, 0 false positives.
Not a scanner, not an EDR, not a patch-management tool. No agent, no asset discovery, no ticketing.
Scored gates from the last full run — 70 questions through the shipped path. A gate that needs human judgement is reported as judged, with its ruling method, rather than counted as passed.
No answer stated that a specific version is or is not affected.
Three answers self-reported a fact newer than the turn's pinned as-of.
Two turns returned nothing. Token-budget exhaustion, not refusal.
Both requests the guard should have refused were refused.
Seven of seventeen probes written to provoke a fabrication succeeded.
No answer denied that a real record exists. It declines instead.