{
  "ok": true,
  "product": "naxytra",
  "category": "security-reliability-drill-evidence-template",
  "template_version": "naxytra-security-reliability-drill-evidence-v1",
  "posture": "private_operator_evidence_manifest_without_secret_material",
  "intended_location": "private_operator_log_or_ticket_system",
  "public_safe": true,
  "evidence_manifest": {
    "manifest_version": "naxytra-security-reliability-drill-evidence-v1",
    "generated_at_iso": "2026-04-21T00:00:00.000Z",
    "operator_ref": "operator.private.ref",
    "release_line": "2.13.0",
    "evidence_redaction_state": "secret_values_omitted",
    "entries": [
      {
        "drill_id": "token_rotation",
        "status": "pending",
        "performed_at_iso": null,
        "evidence_ref": "private://token_rotation/ticket-or-log-ref",
        "result_summary": "old token rejected, new token accepted, protected ledger and observability routes still work",
        "secret_material_included": false,
        "public_safe": false
      },
      {
        "drill_id": "backup_restore",
        "status": "pending",
        "performed_at_iso": null,
        "evidence_ref": "private://backup_restore/ticket-or-log-ref",
        "result_summary": "restored ledgers match expected counts and no production endpoint is pointed at the restore target",
        "secret_material_included": false,
        "public_safe": false
      },
      {
        "drill_id": "dependency_audit",
        "status": "pending",
        "performed_at_iso": null,
        "evidence_ref": "private://dependency_audit/ticket-or-log-ref",
        "result_summary": "no unresolved production vulnerability is accepted without an explicit risk note",
        "secret_material_included": false,
        "public_safe": true
      },
      {
        "drill_id": "npm_provenance",
        "status": "pending",
        "performed_at_iso": null,
        "evidence_ref": "private://npm_provenance/ticket-or-log-ref",
        "result_summary": "published package contents match intended files and release tag",
        "secret_material_included": false,
        "public_safe": true
      },
      {
        "drill_id": "webhook_signing",
        "status": "pending",
        "performed_at_iso": null,
        "evidence_ref": "private://webhook_signing/ticket-or-log-ref",
        "result_summary": "valid fixture grants once; invalid fixture is rejected; idempotent replay does not double-grant",
        "secret_material_included": false,
        "public_safe": false
      },
      {
        "drill_id": "incident_rehearsal",
        "status": "pending",
        "performed_at_iso": null,
        "evidence_ref": "private://incident_rehearsal/ticket-or-log-ref",
        "result_summary": "operator can identify surface, isolate blast radius, choose mitigation, and write closure note",
        "secret_material_included": false,
        "public_safe": false
      }
    ]
  },
  "validation_rules": [
    "all_required_drill_ids_must_be_present",
    "entries_must_use_pass_fail_or_pending_status",
    "secret_material_included_must_be_false",
    "evidence_ref_must_not_contain_raw_secret_or_token_values",
    "private_drills_must_reference_private_operator_evidence_not_public_payloads"
  ],
  "linked_surfaces": {
    "security_reliability_drills_ref": "/v1/security-reliability-drills",
    "security_reliability_drills_summary_ref": "/v1/security-reliability-drills/summary",
    "evidence_template_ref": "/v1/security-reliability-drills/evidence-template"
  }
}