Evidence Request Checklist

Informative Appendix (non-normative)

This appendix gives customers, procurement teams, and security reviewers a simple checklist of evidence to request when evaluating an autonomous pentest platform against APTS.

It is intended to be practical and lightweight. It does not create new requirements.

How to Use This Checklist

Use this appendix when you want a short list of concrete artifacts to request from a platform operator.

Recommended workflow:

  1. pick the domains most relevant to your environment
  2. ask for the sample artifacts listed below
  3. review whether the artifacts are complete, current, and internally consistent
  4. use the Vendor Evaluation Guide and Customer Acceptance Testing appendices if you need deeper validation

Minimum Evidence Pack

If you only want a short first-pass review, request these five artifacts first:

Domain-by-Domain Checklist

Scope Enforcement (SE)

Request:

Quick checks:

Safety Controls (SC)

Request:

Quick checks:

Human Oversight (HO)

Request:

Quick checks:

Graduated Autonomy (AL)

Request:

Quick checks:

Auditability & Reproducibility (AR)

Request:

Quick checks:

Manipulation Resistance (MR)

Request:

Quick checks:

Third-Party & Supply Chain Trust (TP)

Request:

Quick checks:

Reporting (RP)

Request:

Quick checks:

Simple Reviewer Questions

For each artifact you receive, ask:

Notes

This checklist is intentionally simple. It is meant to help reviewers ask for the right artifacts quickly before doing a deeper review.