Examples
Seven corridor bundles, lifecycle/signing packs, and a verifier release
The public `examples` repo now has a small `minimal` blocked bundle, a `failed` corridor that demonstrates present-but-non-compliant evidence, a `stale` corridor that demonstrates freshness-blocked evidence, a richer `medium` blocked corridor with raw synthetic source exports spanning repo policy, CI policy, IAM, cloud, password policy, managed WAF state, centralized monitoring, storage encryption, infrastructure identity state, and environment-segmentation state, signed governance attestations for access-review closure, monitoring review, configuration exceptions, patch exceptions, incident procedures, and vendor terms, plus Lean-backed access-review-export, password-policy, managed-WAF, centralized-monitoring, managed-boundary, admin-ingress, plaintext-transport, encryption-at-rest, unique-infrastructure-identity, repository-integrity, CI-policy, and segmentation claims, an `issued` ExampleCo corridor that demonstrates the narrow certificate path with typed access-review exports, scoped password-policy, managed-WAF, centralized-monitoring, storage-encryption, infrastructure-identity, and environment-segmentation exports, plus signed closure, monitoring-review, and incident-runbook attestations, a `cyber-baseline` corridor that demonstrates a clean Cyber Essentials-style hygiene baseline with Lean-backed default-deny boundary, secure-baseline, update-hygiene, and malware-protection proofs, and an `ai-governance` corridor that now demonstrates documentary AI governance plus machine-checkable disclosure and provenance, alongside signed evaluation and data-quality governance attestations. The `exampleco-showcase` meta-pack aggregates the strongest company-level story across four corridors, while the lifecycle pack shows drift, delta rechecks, and composed component certificates, the signing pack carries a synthetic public key plus signed-artifact manifests, and the `verifier-release/` lane now carries a stitched public verifier bundle that can rerun the synthetic corridors outside the private monorepo. Together they show persisted classification artifacts, boundary-aware proof-runner metadata, an explicit LegalLean typed-boundary summary, runtime-consumed LegalLean verdicts across all current public corridors, typed punch-lists, scoped certificates, replay bundles, transparency logs, inclusion proofs, OSCAL-shaped projections, witness receipts, lifecycle artifacts, public signature verification, a release-manifest contract, a machine-readable verifier contract, and a buyer-facing showcase model without leaking private data. Behind that public surface, the current release is now rebuilt, validated, and smoke-checked through one scripted private operator path before publication.
Conformance
The validator now checks all seven corridors
The public `conformance` repo validates typed payload schemas, persisted classification artifacts, mixed-control decompositions, proof-bundle mappings, proof-runner boundary inventory, the LegalLean typed-boundary metadata summary, runtime-consumed claim metadata for all seven current public corridors, witness digests, transparency logs, inclusion proofs, corridor control references, control-boundary mapping maturity metadata, the exact-anchor review pilot, and OSCAL projection consistency across the seven synthetic corridor bundles. It also now ships a public showcase builder that regenerates the `exampleco-showcase` summary from the checked-in corridor artifacts. The lifecycle pack is public and executable, but it is still a descriptive example rather than part of the conformance matrix.