Documentation

Platform governance

The operating rules behind Raksha’s testing and evidence records.

Authorised live testing

Guided and autonomous tests only run inside signed engagements. Ownership is rechecked before each run, and every request is constrained by scope, safe methods, blocked paths, rate, concurrency, total budget, time window and a kill switch.

Evidence grading

A confirmed result records actor, entry point, missing control, trust boundary, affected resource and observed result. Unproven observations remain hardening guidance or are discarded.

Coverage

Coverage identifies what ran, what was skipped, what was blocked and what was outside scope. A failed or unavailable check is never represented as a pass.

Retention and legal holds

Evidence is retained for the workspace plan period. At expiry, Raksha creates an integrity manifest before raw evidence is removed. Owner-applied legal holds suspend expiry.

Compliance mapping

Framework packs map technical evidence to controls using four honest states: gap found, covered by testing, not tested and organisational evidence required. They are not certifications.

Auditor packs

Each generated pack is a frozen snapshot with a version, generation time, evidence window and integrity hash. Markdown, JSON and CSV representations carry the same source snapshot.