Evidence matrix

Public proof coverage by surface.

A buyer-readable map of what is proved, where the evidence lives, what CI gate runs it, and what still needs credentials or enterprise rollout work.

Updated

2026-06-10

Surfaces

31

Passed

26

Gated

5

SurfaceStatusLast runEvidenceProofCI gateNext owner action
Golden customer journeyProduction ProfileScheduled2026-06-10 release gate; daily scheduleSignup, login, policy publish, SDK key rotation, runtime proof, scanner upload, DB sandbox, proof export/share, public readback, CLI verify, readiness, and Admin readback.Open proofWorkflowKeep production secrets configured and review the daily artifact.
Production UI smokeWebsiteScheduled2026-06-10 release gate; daily schedulePublic pages, Profile page, Admin page, Worker health, public verifier, static trust registry, and Worker trust registry.Open proofWorkflowKeep Profile/Admin smoke credentials configured.
Public proof verifierProof trust chainPassed2026-06-10Browser and CLI verifier recompute payload digest, ECDSA signature when present, hash chain, stop point, and completeness lanes.Open proofWorkflowVerify new proof schemas before publishing them.
Proof trust registryProof trust chainPassed2026-06-10Accepted schema versions, timestamp policy, key-rotation policy, public key source, and sample packet locations.Open proofWorkflowPublish actual ECDSA public key through the Worker registry when production signing is configured.
Customer API lifecycleAPIPassed2026-06-10Customer API catalog, readiness route, key rotation, old-key rejection, non-secret key metadata, rate-limit advertisement, and Admin readback.Open proofWorkflowKeep the buyer-flow smoke strict for Admin readback in production.
Real DB sandbox hardeningDatabaseScheduled2026-06-10 strict CI gate requires a real Postgres URL secretNative Postgres sandbox hardening, source-isolation checks, cleanup leakage checks, Droplet backup/restore ops, and production buyer-flow DB create/transaction/proof/destroy.Open proofWorkflowKeep a production-like Postgres target secret configured for strict hardening runs.
Enterprise RBAC and auditEnterpriseDocumented2026-06-10Backend admin roles, bootstrap org/workspace/user bindings, append-only audit events, admin login throttling, customer workspace readback, and export story.Open proofWorkflowAdd SSO, SCIM, and SIEM export implementation before claiming full enterprise identity.
Customer onboarding diagnosticsCLIPassed2026-06-10imladri doctor checks local services, DB target wiring, customer API catalog, rate limits, readiness, SDK metadata, public verifier, and trust registry.Open proofWorkflowRun `imladri doctor --customer` before buyer handoff.
LangChainSDK adapterPassed2026-06-104/4 lanes passed; real-package smoke covers langchain, langchain-core/@langchain/core, LangGraph, and langsmith with zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
OpenAI Agents SDKSDK adapterPassed2026-06-104/4 lanes passed across openai-agents and @openai/agents; real-package smoke covers Agent.tools execution with zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
Vercel AI SDKSDK adapterPassed2026-06-102/2 lanes passed; real-package smoke covers ai and zod with 3 allowed body calls, action-alias mapping, forwarded toolCallId metadata, and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
LlamaIndexSDK adapterPassed2026-06-104/4 lanes passed; real-package smoke covers llama-index-core and llamaindex FunctionTool.call with zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
LangGraphSDK adapterPassed2026-06-106/6 LangGraph lanes passed; shared batch proof covers metadata.name, actionAliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
HaystackSDK adapterPassed2026-06-104/4 Haystack lanes passed; real-package smoke covers haystack-ai component.run plus Pipeline.run with 2 allowed body calls and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
AutoGenSDK adapterPassed2026-06-104/4 AutoGen lanes passed.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
Generic HTTPSDK adapterPassed2026-06-103/3 generic lanes passed across Python and TypeScript wrappers.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
MCPMCPPassed2026-06-104 MCP lanes passed; hosted remote HTTP MCP is an optional additional proof lane when configured.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
CrewAISDK adapterPassed2026-06-104/4 CrewAI lanes passed; real-package smoke covers crewai with 3 allowed body calls and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
PydanticAISDK adapterPassed2026-06-102/2 PydanticAI lanes passed; real-package smoke covers pydantic-ai with 2 allowed body calls and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
Semantic KernelSDK adapterPassed2026-06-104/4 Semantic Kernel lanes passed; real-package smoke covers semantic-kernel with 2 allowed body calls and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
MastraSDK adapterPassed2026-06-104/4 Mastra lanes passed; shared batch proof covers metadata.name, actionAliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
DSPySDK adapterPassed2026-06-102/2 DSPy lanes passed; shared batch proof covers metadata.name, action_aliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
DifyHosted workflowPassed2026-06-104/4 Dify lanes passed; shared batch proof covers metadata.name, actionAliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep hosted probe URL/token credentials configured for live hosted proof.
FlowiseHosted workflowPassed2026-06-104/4 Flowise lanes passed; shared batch proof covers metadata.name, actionAliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep hosted probe URL/token credentials configured for live hosted proof.
n8nSDK adapterPassed2026-06-104/4 n8n lanes passed; shared batch proof covers metadata.name, actionAliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
Zapier AI ActionsHosted workflowPassed2026-06-104/4 Zapier AI lanes passed; shared batch proof covers metadata.name, actionAliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep hosted probe URL/token credentials configured for live hosted proof.
BotpressHosted workflowPassed2026-06-104/4 Botpress lanes passed; shared batch proof covers metadata.name, actionAliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep hosted probe URL/token credentials configured for live hosted proof.
RasaSDK adapterPassed2026-06-102/2 Rasa lanes passed; shared batch proof covers metadata.name, action_aliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
smolagentsSDK adapterPassed2026-06-102/2 smolagents lanes passed; shared batch proof covers metadata.name, action_aliases, strict preflight, and zero blocked-path body calls.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
Hosted CI ProofHosted CIPassed2026-06-102/2 hosted CI vendor lanes passed: GitLab and Vercel.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.
LiteLLMSDK adapterCredential gated2026-06-10Use generic wrapper coverage until a dedicated LiteLLM adapter lane exists.Open proofWorkflowKeep wrapper certification passing and upload target proof to Profile when used by a customer.