Public commitments · Closed

Public commitments registry

All six enterprise documentation commitments from the BeProof PRD are published on this website for pilot and procurement review. BeProof remains pilot-ready — not full Enterprise GA.

Commitments documented6/6

Closure status

6 of 6 PRD public commitments documented with public pages — retention, support matrix, SSO/RBAC, isolation/encryption, vulnerability disclosure, versioning.

Claim-to-evidence ledger

Product claims are scoped to a support level, a public proof artifact, and an explicit limitation. Contract fixtures are labelled separately from live integrations.

ClaimStatusBoundaryEvidence
Causal action reconstructionAvailable / source-dependentLocal action adapters can emit causal links when the source provides stable identifiers. Provider or project matches remain correlated, and missing links create CoverageGap records.Redacted causal-chain fixture
External enforcement evidenceContract + synthetic fixtureA blocked outcome requires an explicit EnforcementEvent with enforcedBy and provenance. Production control-product adapters remain planned; BeProof does not perform enforcement.External block event fixture
Supported runtimesmacOS available · remote plannedThe verified endpoint collection surface is macOS. Cloud, CI, server, Windows, and Linux expansion remains on the roadmap unless a specific adapter is marked otherwise.Public coverage matrix
Incident bundle verificationShippedEndpoint-generated incident bundles can be checked offline for artifact hash, manifest hash, and Ed25519 signature. Public contract fixtures use placeholder signatures and are structural examples only.Export signing contract
1

Retention schedule

Documented

Personal, managed endpoint, and control plane retention — default 90 days upstream in pilot.

2

macOS support matrix

Documented

macOS 14–15, Apple Silicon, permissions, PPPC, and MDM deployment runbooks.

3

SSO / RBAC model

Documented

Firebase admin auth (pilot), four org roles, device JWT enrollment. SAML/OIDC — post-GA.

4

Tenant isolation & encryption

Documented

Per-tenant scope, RBAC, TLS. Journal payloads are encrypted; inventory tables are metadata-only but not encrypted in the current release. Ed25519 export signing; GCP cloud encryption.

5

Vulnerability disclosure

Documented

Private report channel, 3-day ack target, latest-release support policy, safe harbor.

6

Unified versioning contract

Documented

Three independent axes: app release, Policy Pack semver, data contract version — all in export manifest.

Pilot → GA documentation pack

Public commitments closure completes the pilot → GA documentation pack:

Post-pilot gaps (documented honestly)

These are not hidden — they are outside the six PRD public commitments and remain roadmap or contractual items:

  • BeProof SOC 2 / ISO 27001 certification
  • SAML/OIDC enterprise admin SSO
  • SIEM production streaming (M4)
  • EU data residency (on requirement)
  • Enterprise SLA and commercial pricing