An AARP appraisal reports a claim set, not a trust score. Each claim name says what the verifier mechanically confirmed, and the paired limitations say what a reader must not infer from that evidence.
This page renders from the public JSON dictionary shipped with the Pipelock SDK. The human page is a view of that source, not a separate hand-maintained table.
Reserved entries are vocabulary locks. They name future transparency, deployment, and authority claims, but the current verifier does not emit those claims until the evidence and hostile fixtures exist.
Profile: aarp/v0.1
Source: aarp-claims-dictionary/v0.1. Reserved entries freeze names only; the current verifier does not emit reserved claims.
Emitted Verified Claims
| Claim | Axis | Status | Proves | Does not prove | Tested by |
|---|---|---|---|---|---|
receipt_signature_valid | integrity | emitted | At least one parallel AARP signature verified under a trusted key over the canonical signed assertion payload. |
| g01-single-ed25519-mediated |
mediator_key_pinned | identity | emitted | A verifying signature's key id is bound by a verifier-side trust entry to the asserted mediator identity, role, and trust domain when scoped. |
| g01-single-ed25519-mediated |
receipt_timestamp_monotonic_chain_present | integrity | emitted | The signed assertion carries a well-formed Rung-1 chain link with a sequence number and prior payload hash. |
| g03-chain-genesis-linked |
signing_workload_svid_chain_validated | identity | emitted | The X.509-SVID leaf chain validated offline against the pinned bundle at action time and the SPIFFE ID was permitted. |
| s01-valid-ecdsa-p256-baseline |
signing_workload_svid_bound | identity | emitted | The SVID leaf key signed the receipt and assertion binding, proving possession by the signing workload identity. |
| s01-valid-ecdsa-p256-baseline |
signing_workload_svid_valid_at_action_time | freshness | emitted | The X.509-SVID was valid at the action time under the pinned historical bundle. |
| s01-valid-ecdsa-p256-baseline |
Reserved Verified Claims
| Claim | Axis | Status | Proves | Does not prove | Tested by |
|---|---|---|---|---|---|
policy_hash_bound | authority | reserved | Reserved for the claim that the decision policy hash is bound into the signed assertion. |
| reserved-policy-hash-bound |
receipt_timestamp_contiguous_chain_verified | authority | reserved | Reserved for stream-level verification that an issuer chain is contiguous for the checked range. |
| reserved-contiguous-chain-verification |
external_witness_checkpoint_signature_valid | transparency | reserved | Reserved for verification that an external witness signed the checkpoint being checked. |
| reserved-external-witness-checkpoint-signature |
receipt_chain_root_matches_witnessed_checkpoint | transparency | reserved | Reserved for verification that the receipt-chain root matches the externally witnessed checkpoint root. |
| reserved-chain-root-witness-match |
witness_checkpoint_covers_chain_seq_range | transparency | reserved | Reserved for verification that a witnessed checkpoint covers the asserted issuer chain sequence range. |
| reserved-witness-checkpoint-range |
witness_checkpoint_observed_at_time | transparency | reserved | Reserved for verification that the external witness observation time for a checkpoint was recorded and validated. |
| reserved-witness-checkpoint-observed-time |
witness_checkpoint_gap_bounded_observed | transparency | reserved | Reserved for observing that the witness-silence interval after the last witnessed checkpoint stayed within the configured bound, assuming process, clock, witness path, and deployment boundary were operating. |
| reserved-witness-checkpoint-gap-bounded |
k8s_namespace_egress_policy_restricts_workload_to_mediator_observed | deployment | reserved | Reserved for attested observation that a Kubernetes namespace egress policy restricts the workload to the mediator path. |
| reserved-k8s-namespace-egress-policy |
k8s_pod_spec_proxy_injection_observed | deployment | reserved | Reserved for attested observation that the workload pod spec contains the expected Pipelock proxy injection. |
| reserved-k8s-pod-spec-proxy-injection |
k8s_workload_identity_bound_to_mediator_policy | deployment | reserved | Reserved for attested observation that the Kubernetes workload identity is bound to the mediator policy under review. |
| reserved-k8s-workload-identity-policy-binding |
k8s_admission_policy_hash_bound | deployment | reserved | Reserved for attested observation that the Kubernetes admission policy hash is bound to the appraisal evidence. |
| reserved-k8s-admission-policy-hash |
linux_process_egress_owner_rule_observed | deployment | reserved | Reserved for attested observation that a Linux process-owner egress rule was present for the mediated workload. |
| reserved-linux-process-egress-owner-rule |
Limitations
| Claim | Axis | Status | Proves | Does not prove | Tested by |
|---|---|---|---|---|---|
absence_of_bypass | limitation | emitted | The appraisal explicitly does not assert that no bypass path existed. |
| g01-single-ed25519-mediated |
action_safety | limitation | emitted | The appraisal explicitly does not assert that the action was safe. |
| g01-single-ed25519-mediated |
all_tools_discovered | limitation | emitted | The appraisal explicitly does not assert that every tool or action surface was discovered. |
| g01-single-ed25519-mediated |
complete_mediation | limitation | emitted | The appraisal explicitly does not assert complete mediation. |
| g01-single-ed25519-mediated |
delegated_actions_mediated | limitation | emitted | The appraisal explicitly does not assert that delegated actions were mediated. |
| g01-single-ed25519-mediated |
efficacy | limitation | emitted | The appraisal explicitly does not assert that the policy or control was effective. |
| g01-single-ed25519-mediated |
hosted_saas_actions_mediated | limitation | emitted | The appraisal explicitly does not assert that hosted SaaS side actions were mediated. |
| g01-single-ed25519-mediated |
intent_correctness | limitation | emitted | The appraisal explicitly does not assert that the action matched user intent. |
| g01-single-ed25519-mediated |
key_non_compromise | limitation | emitted | The appraisal explicitly does not assert that any signing key was never compromised. |
| g01-single-ed25519-mediated |
local_side_effects_mediated | limitation | emitted | The appraisal explicitly does not assert that local side effects were mediated. |
| g01-single-ed25519-mediated |
policy_correctness | limitation | emitted | The appraisal explicitly does not assert that the policy was correct. |
| g01-single-ed25519-mediated |
semantic_equivalence_after_modify | limitation | emitted | The appraisal explicitly does not assert semantic equivalence after any modifying step. |
| g01-single-ed25519-mediated |
does_not_assert_network_non_bypass_from_identity | limitation | emitted | The appraisal explicitly states that a verified workload identity does not prove network non-bypass. |
| s01-valid-ecdsa-p256-baseline |
does_not_assert_deployment_enforcement_from_identity | limitation | emitted | The appraisal explicitly states that a verified workload identity does not prove deployment enforcement. |
| s01-valid-ecdsa-p256-baseline |
does_not_assert_all_receipts_submitted_to_witness | limitation | reserved | Reserved limitation stating that witness evidence does not assert all receipts were submitted to the witness. |
| reserved-transparency-negatives |
does_not_assert_pre_witness_omission_absence | limitation | reserved | Reserved limitation stating that witness evidence does not assert absence of omissions before the witnessed checkpoint. |
| reserved-transparency-negatives |
does_not_assert_no_split_view_without_gossip | limitation | reserved | Reserved limitation stating that witness evidence without gossip does not assert absence of split view. |
| reserved-transparency-negatives |
does_not_assert_action_stream_completeness | limitation | reserved | Reserved limitation stating that witness evidence does not assert action-stream completeness. |
| reserved-transparency-negatives |
does_not_assert_cluster_admin_cannot_bypass | limitation | reserved | Reserved limitation stating that deployment evidence does not assert a cluster administrator cannot bypass controls. |
| reserved-deployment-negatives |
does_not_assert_node_root_cannot_bypass | limitation | reserved | Reserved limitation stating that deployment evidence does not assert node root cannot bypass controls. |
| reserved-deployment-negatives |
does_not_assert_cni_enforcement_correctness | limitation | reserved | Reserved limitation stating that deployment evidence does not assert CNI enforcement correctness. |
| reserved-deployment-negatives |
does_not_assert_saas_side_actions_mediated | limitation | reserved | Reserved limitation stating that deployment evidence does not assert hosted SaaS side actions were mediated. |
| reserved-deployment-negatives |
does_not_assert_runtime_state_unchanged_after_snapshot | limitation | reserved | Reserved limitation stating that deployment evidence does not assert runtime state stayed unchanged after snapshot or restore. |
| reserved-deployment-negatives |
does_not_assert_all_namespaces_or_workloads_covered | limitation | reserved | Reserved limitation stating that deployment evidence does not assert all namespaces or workloads are covered. |
| reserved-deployment-negatives |
Overclaim Risks
| Claim | Axis | Status | Proves | Does not prove | Tested by |
|---|---|---|---|---|---|
signature_valid_is_not_transparency_inclusion | risk | emitted | The appraisal warns that a valid signature is being reported without a transparency-axis proof. |
| g01-single-ed25519-mediated |
svid_identity_is_not_deployment_non_bypass | risk | emitted | The appraisal warns that a bound SVID identity is being reported without a deployment-axis non-bypass proof. |
| s01-valid-ecdsa-p256-baseline |
chain_link_present_is_not_verified_contiguous_chain | risk | emitted | The appraisal warns that a single signed chain link is being reported without stream-level contiguous-chain verification. |
| g03-chain-genesis-linked |