Documentation
Platform governance
The operating rules behind Raksha’s testing and evidence records.
Authorised live testing
Guided and autonomous tests only run inside signed engagements. Ownership is rechecked before each run, and every request is constrained by scope, safe methods, blocked paths, rate, concurrency, total budget, time window and a kill switch.
Evidence grading
A confirmed result records actor, entry point, missing control, trust boundary, affected resource and observed result. Unproven observations remain hardening guidance or are discarded.
Coverage
Coverage identifies what ran, what was skipped, what was blocked and what was outside scope. A failed or unavailable check is never represented as a pass.
Retention and legal holds
Evidence is retained for the workspace plan period. At expiry, Raksha creates an integrity manifest before raw evidence is removed. Owner-applied legal holds suspend expiry.
Compliance mapping
Framework packs map technical evidence to controls using four honest states: gap found, covered by testing, not tested and organisational evidence required. They are not certifications.
Auditor packs
Each generated pack is a frozen snapshot with a version, generation time, evidence window and integrity hash. Markdown, JSON and CSV representations carry the same source snapshot.