# Security and isolation evidence

> Validate policy boundaries, no-writer guarantees, redaction, and trust-domain separation.

Source: https://accd.github.io/verchestra/docs/qualification/security-and-isolation-evidence/
Content digest: `sha256:3846fa3963bebdf6c1caed24e777953583447e8be84f1a7fc5b732b460011ded`

Security qualification covers path containment, secret handling, capability denial, approval transitions, lease identity, driver isolation, probe no-writer behavior, support-bundle allowlists, and crash recovery.

Negative tests matter: unsafe inputs must fail closed and produce no promoted evidence. Discrimination checks deliberately remove a control or inject a fault to prove the sensor detects the intended violation.

T69–T72 will add an isolated Self-Test identity and signed diagnostics without weakening these production boundaries.
