{
  "id": "EVI-CRM228-C-0257",
  "claimId": "EVI-CLSA-C-0257",
  "reportId": "REP-EVULGARE-CYBER-DEFENSE-001",
  "reportPath": "docs/long-term-memory/reports/autonomous-cyber-defense-architecture.md",
  "sourceRecordPath": "docs/long-term-memory/archives/source-reports/autonomous-cyber-defense-architecture-source.md",
  "claimClass": "PRESENT_CAPABILITY_CLAIM",
  "priorAuditState": "UNSUPPORTED_FOR_PUBLIC_REUSE",
  "priorCorrectionExecutionId": "EVI-CCX-0166",
  "reviewedExactlyOnce": true,
  "queuedOrDeferred": true,
  "disposition": "REJECTED",
  "exactBeforeText": "- Useful defensive concepts include short-lived workload identity, hardware and software attestation, supply-chain provenance, evidence correlation, append-only integrity, bounded containment, key epochs, reconciliation, attested recovery, and explicit abstention. - Defensive responses should be reversible, least-privilege, non-destructive, evidence-preserving, and incapable of becoming counterattack or arbitrary punishment. - A procedural click is not a merits review; restoration and authority changes require bounded roles, evidence, conflict disclosure, and independent review appropriate to the actual deployment. - Synthetic fault injection can test parser and state-machine behavior without touching production systems, customer networks, physical devices, or public infrastructure.",
  "exactAfterText": "- Useful defensive concepts include short-lived workload identity, hardware and software attestation, supply-chain provenance, evidence correlation, append-only integrity, bounded containment, key epochs, reconciliation, attested recovery, and explicit abstention. - Defensive responses should be reversible, least-privilege, non-destructive, evidence-preserving, and incapable of becoming counterattack or arbitrary punishment. - A procedural click is not a merits review; restoration and authority changes require bounded roles, evidence, conflict disclosure, and independent review appropriate to the actual deployment. - Synthetic fault injection can test parser and state-machine behavior without touching production systems, customer networks, physical devices, or public infrastructure.",
  "beforeSha256": "8341bae3d4869cd029b5aa3f4620cd9e6b2f45bb6b370a95c13aabf18eca6406",
  "afterSha256": "8341bae3d4869cd029b5aa3f4620cd9e6b2f45bb6b370a95c13aabf18eca6406",
  "sourceBinding": {
    "retrievalDate": "2026-08-08",
    "sourceTitle": "RFC 9711 — Entity Attestation Token",
    "publisher": "Internet Engineering Task Force / RFC Editor",
    "sourceUrl": "https://www.rfc-editor.org/rfc/rfc9711.html",
    "verificationMethod": "REUSED_BATCH_PRIMARY_SOURCE_RESULT",
    "authoritativeSourceAvailability": "AVAILABLE",
    "externalSourceKey": "IETF_EAT",
    "reusedLocalEvidenceOnly": true
  },
  "sourceRecordSha256": "a788ea241ae033cd141cf57798c3dcf416a0704ef8307abffa555eb8d2074299",
  "reason": "Prior controlled execution state REJECTED remains controlling because no stronger authorized source or deterministic fact resolves it in this zero-network round.",
  "affectedPublicClaims": [
    "/reference/report-memory/claim-level-sources/autonomous-cyber-defense-architecture/claims/present-capability-claim/"
  ],
  "propagationResult": "NO_MUTATION",
  "ownerArchitectureRuleApplied": false,
  "strongerPrimarySourceApplied": false,
  "deterministicRepositoryFactApplied": false,
  "submittedSourceMutated": false,
  "activeSynthesisMutated": false,
  "networkCalls": 0,
  "canonicalRoute": "/reference/report-memory/claim-remediation/v2-28/claims/evi-clsa-c-0257/",
  "machineReadableUrl": "/api/report-claim-remediation/claims/evi-clsa-c-0257.json",
  "truthBoundary": "Claim-level remediation decision only. Unresolved currentness remains deferred or unavailable; no source or synthesis text is silently rewritten.",
  "recordSha256": "f861f29caeaf26069680a41113cf9f6180e8853a213a3779e787deb5f948fe4d"
}
