Full assessment
A broad, multi-source review and remediation record. It covers the complete finding register and gives no release verdict.
s1-review build assessment ./engagement
Security assessment as code
Dokimos validates a signed engagement scope, human-adjudicated findings, hashed evidence and release criteria agreed before testing. Then it builds the assessment report or the pre-production gate decision from that one validated record.
δόκιμος · dokimos, “tested and found genuine”
How it works
An engagement file records the targets, modules, evidence policy and, for a gate, the criteria agreed with the product owner before testing starts. Unknown fields are rejected.
Tool output comes in as candidates. A named adjudicator confirms, rejects or re-rates each one; tool severity is never accepted automatically.
Requests, tool results and run manifests are stored with SHA-256 hashes, so a reviewer can confirm nothing changed after collection.
Validation profiles (draft, final, gate) decide what may ship. The build writes the report and a manifest that records exactly what it was built from.
A broad, multi-source review and remediation record. It covers the complete finding register and gives no release verdict.
s1-review build assessment ./engagement
A time-boxed decision against criteria agreed before testing. Only declared rules and manual criteria are evaluated.
s1-review build gate ./engagement
Outputs
Quiet typography, colour only where it carries meaning, and one signature element per document. Each page states its intended audience.
Screens come from the bundled worked example. Every system, name and value in it is fictional.
Gate verdicts
Every configured criterion passed for the recorded target, scope and window.
No blocking failure remains, but a non-blocking criterion did not pass. Each condition needs an owner and a due date.
A blocking criterion failed or was not assessed. The release waits until it is closed and re-verified.
The input was incomplete or invalid, so no decision is issued. The gate fails closed.
A GO does not mean the product is secure, free of vulnerabilities or approved outside that decision. Dokimos makes claims consistent and traceable; it does not create assurance that the scope and evidence do not support.
What it is not
Dokimos is developed by CyberTwierdza. Get in touch to see it on your own engagement.
Contact CyberTwierdza