Acceptance baseline

“Done” should be inspectable.

This page explains the technical evidence used at handoff. Commercial commitments belong in the accepted service agreement; this is not a certification, insurance opinion, or promise of perfect security.

Four honest states

Every control has a state, owner, and next action.

Verified

The implemented state was read back and linked to evidence.

Ready for founder review

Open

A decision or remediable item remains with a named owner.

Owner and next action recorded

Blocked

An external dependency or condition prevents completion.

Dependency and escalation recorded

Not applicable

The control does not apply, and the reason is recorded.

Rationale retained in evidence
Synthetic specimenReference evidence format — not a customer result or certification
ControlStateEvidenceOwner
Named human accountsVerifiedRead-back identity inventoryFounder
Sample file recoveryVerifiedBounded restore receiptRecovery owner
Legacy sender ownershipOpenFounder decision requiredFounder
Private network accessNot applicableNo defined private resourceN/A

Each row says what was checked, what supports the state, and who owns the next decision.

Working technical baseline

Evidence expected before handoff.

  • Named identities; no shared routine administrator account.
  • MFA for every included human identity.
  • Least-privilege roles and a tested break-glass path.
  • Recovery material transferred directly to customer-controlled custody.
  • Current inventories for users, devices, administrators, domains, vendors, senders, data owners, and recovery owners.
  • Supported encryption, security, and update settings for included devices.
  • Email-authentication records read back after safe staging.
  • An owner, fallback, error path, and disable step for every included automation.
  • A customer-owned backup configured and one agreed item restored.
  • One supported AI provider account owned and billed directly by the customer.
  • One project-scoped API key placed in client-controlled custody, with a non-sensitive test and documented revocation step.
  • Usable account-loss, outage, onboarding, offboarding, and incident guidance.
  • Residual risks recorded rather than silently converted into passes.