WitnessOps Verification Report
Bastion 0-day hunt — OFFSECSHIELD / WITNESSOPS
A buyer-facing view of recorded evidence references, assessment status, receipt fingerprints, and explicit proof boundaries.
Engagement
source metadata- ID
bastion-0day-hunt-20260621T083757Z- ROE
- operator-owned infrastructure; honest 0-day vs misconfig labeling
- Notes
- Public kernel stays witnessops-web on goal0. Console is fleet-local only.
- Evidence Store ID
WOPS-ES-4FA06525C53D4B62- Evidence namespace
evd://engagement/bastion-0day-hunt-20260621T083757Z- Evidence Manifest ID
- Not recorded
- Custody Descriptor
- Operator-held evidence; external evidence store
- Custody Proof Token
Not recorded- Updated
- 2026-06-21T23:48:33.952Z
Scope & contract boundary
read-only import contract- Schema
witnessops.operator_data_contract.v1- Writer
- witnessops-console
- Readers
- witnessops-forge, witnessops-saas
- Engagements
engagements/<id>.json- Verify runs
verify-runs/<uuid>.json- Hunt snapshots
hunt-snapshots/<engagement_id>/latest.json
Not enabled in this shell
- SaaS production
- public verify (in shell)
- public mesh-gate (in shell)
- goal0 mirror live
- Neon
- Clerk
- Stripe
- billing
- Vercel deployment
- SaaS login
Verify-run status
verifier recordsNo verify runs recorded for this engagement.
Verify runs are written by console when public verify is invoked. Empty state is honest — not a product failure.
Hunt snapshot
assessment snapshot- Ingested
- 2026-06-22T00:45:24.767Z
- Latest gate
- PASS
- Latest action
- stop
- Closeout
- misconfig complete no zero day
- Loop tail
- Overall gate passed and no active leaks remain; ready for operator closeout.
- Lines cached
- 32
Top findings (closeout)
- critical
consoleState-public-staticremediated - critical
bastion-8008-publicremediated - medium
mcp-no-bearerpass_on_bastion
Receipt hashes
evidence fingerprintsNo receipt fingerprints are available for this evidence handle.
Public verify
placeholder · external authorityProof packs are verified on witnessops.com/api/verify. Mesh gate checks use witnessops.com/api/mesh-gate.
This demo does not POST verify requests. Console records verify-run results when operators run them locally.
Evidence custody
chain-of-custody note- Operator custody keeps raw evidence outside the report. Buyer views use stable evidence handles.
- Metadata records hold engagements, assessment snapshots, and verify-run records. Written only by witnessops-console.
- Receipt hashes are SHA-256 fingerprints read from operator-held evidence at display time. They are not a public attestation without a recorded verify run.
- Scaffold receipt
FORGE_PHASE_5_NEXT_FORGE_SCAFFOLD_INIT_V1closed with body hash264eec3f…3054d5c2.
Demonstrated by Available Evidence
Facts this read-only shell can show from recorded metadata and evidence fingerprints.
- Engagement record present — assessment gate PASS
- Hunt snapshot gate PASS (action: stop)
- Closeout verdict: misconfig complete no zero day
- Operator contract record present
Not Demonstrated by Available Evidence
Limits buyers should understand before treating this as production SaaS.
- No verify-run records are present for this engagement
- Public verify not executed from this shell — authority is witnessops.com
- Third-party cryptographic attestation not shown here
- Raw evidence is not embedded in this report (custody boundary)
- SaaS production — not enabled
- public verify (in shell) — not enabled
- public mesh-gate (in shell) — not enabled
- goal0 mirror live — not enabled
- Neon — not enabled
- Clerk — not enabled
- Stripe — not enabled
- billing — not enabled
- Vercel deployment — not enabled
- SaaS login — not enabled