Air-gapped
Zero network connections. Every check runs offline. Trust anchors are bundled inside the evidence bag. Nothing leaves the container.
Deterministic
Same evidence bag equals same verdict. Always. Run it twice, run it on a different machine. The output is identical.
Fail-closed
If anything is wrong, uncertain, or missing, the verdict defaults to fail. No result is issued without full verification. No ambiguity is accepted.
