Loading workspace…
signed outSign in
Every requirement in bioskepsis-insights-user-requirements-v1.1.md, with the verdict the document’s own rules force. No requirement now carries the verdict BLOCKED. Each row carries both halves of its account, what is buildable and what is still held, and names the decisions that released it. A requirement answered the other way is DROPPED, and that is the one verdict nobody can go and change.
Showing the 2 requirements that OQ-29 released. A requirement that the document alone would have held is here because a decision with a date let it through.
| ID | Verdict | Basis | What that means |
|---|---|---|---|
SEC-01 | BUILD | research | All of it that a build can carry. OQ-29 sets the path: SOC 2 Type I now, and a Type II report completed before the first pharma contract. What that asks of this codebase is evidence kept from the start, so the Type II observation period can begin without rework: access logs, change records and the security policies themselves. Still held. Nothing. The audit dates and the report itself are EFEVRE's to schedule, and no claim of certification may appear in the product or its materials before a report exists. |
SEC-02 | BUILD | research | All of it that a build can carry, on the same answer as SEC-01: the evidence an information security management system needs is produced from the start rather than assembled in front of an audit (OQ-29). Still held. Nothing. The certification timeline and the scope statement are EFEVRE's decisions, taken against the first pharma contract rather than against a date. Released by OQ-29. |