Skip to content

Glossary

Release-evidence verification glossary

Canonical definitions for the terms GoSentrix uses to describe evidence-backed release decisions, security verification, and AI-generated code governance.

Defined term

Release-evidence verification

Release-evidence verification is the process of qualifying evidence from security, engineering, and workflow systems, evaluating that evidence against versioned policy, and preserving the basis for an explicit software release decision.

Why it matters: It gives security, engineering, and governance teams a reviewable basis for proceed, stop, escalate, or require-authorization decisions.

Defensible release decisionProof artifactPolicy-version binding

Defined term

Security verification body

A security verification body is an independent evidence layer that determines whether available security evidence is strong enough to support a consequential action.

Why it matters: It separates the tools that generate claims from the authority to make policy-bound security decisions.

Release-evidence verificationEvidence ladderContinuous security verification

Defined term

Proof artifact

A proof artifact is a preserved record that links a claim, the evidence supporting or refuting it, the policy version applied, and the decision outcome.

Why it matters: It lets a later reviewer reconstruct why a release was allowed, blocked, escalated, or sent for authorization.

Decision recordPolicy-version bindingEvidence-backed release

Defined term

Policy-version binding

Policy-version binding means a decision is evaluated and recorded against the exact policy version active at the time the decision was made.

Why it matters: It prevents later policy changes from rewriting the basis for past release decisions.

Defensible release decisionDecision recordRelease readiness evidence

Defined term

Defensible release decision

A defensible release decision is a software release decision whose evidence, applicable policy, and reasoning can be reviewed and explained after the fact.

Why it matters: Defensibility does not mean perfection. It means the organization can show what it knew, what rule applied, and why the outcome followed.

Evidence-backed releaseProof artifactPolicy-version binding

Defined term

Evidence-backed release

An evidence-backed release is a software release authorized by qualified evidence rather than ticket state, verbal assurance, or unreviewed tool output alone.

Why it matters: It turns release approval into a reproducible decision instead of a trust exercise.

Release readiness evidenceDefensible release decisionProof artifact

Defined term

AI-generated code governance

AI-generated code governance is the discipline of capturing provenance, reviewing AI-produced changes, and verifying claims made by coding agents before those changes are released.

Why it matters: It keeps agentic development fast while preventing probabilistic claims from becoming release authority without independent evidence.

AI-BOMValidated autofixAgent-neutral governance

Defined term

Vulnerability fix proof

Vulnerability fix proof is evidence that the original vulnerable behavior or exposure no longer applies to the release artifact being evaluated.

Why it matters: It distinguishes real remediation from ticket closure, suppression, or a scanner result disappearing in one run.

Verified remediationSuppression vs disprovalProof artifact

Defined term

Release readiness evidence

Release readiness evidence is the set of qualified records used to decide whether a software change satisfies the release policy for its risk context.

Why it matters: It gives reviewers a concrete basis for release approval instead of relying on summarized status alone.

Evidence-backed releasePolicy-version bindingDecision record

Defined term

Continuous security verification

Continuous security verification is repeated qualification of security evidence across the delivery lifecycle so decisions are evaluated as evidence changes.

Why it matters: It prevents stale approvals and old scanner states from carrying authority into a new release context.

Security verification bodyRelease-evidence verificationEvidence ladder

Defined term

Evidence ladder

An evidence ladder is a governed sequence of evidence states, such as detected, observed, corroborated, validated, proven, disproven, or accepted.

Why it matters: It prevents teams from treating a raw signal as proof before the signal has earned authority.

Security verification bodySuppression vs disprovalVerified remediation

Defined term

Decision record

A decision record is the preserved explanation of a release or security decision, including evidence inputs, policy version, outcome, and reasoning.

Why it matters: It makes release history reviewable for audits, incident response, and executive accountability.

Proof artifactDefensible release decisionPolicy-version binding

Defined term

Agent-neutral governance

Agent-neutral governance means security controls evaluate evidence consistently regardless of which AI coding agent, IDE, repository, scanner, or CI system produced the change.

Why it matters: It avoids locking governance to a single AI tool while preserving a common release evidence standard.

AI-generated code governanceAI-BOMContinuous security verification

Defined term

Validated autofix

A validated autofix is an AI- or automation-produced fix that has independent evidence showing the original risk is absent in the new artifact.

Why it matters: It separates a generated patch from a verified remediation outcome.

AI-generated code governanceVulnerability fix proofVerified remediation

Defined term

AI-BOM

An AI-BOM is a bill of materials for AI-assisted software work, recording models, agents, prompts, tool calls, and generated changes that influenced an artifact.

Why it matters: It gives reviewers and auditors provenance for code produced or modified through agentic workflows.

AI-generated code governanceAgent-neutral governanceProof artifact

Defined term

Verified remediation

Verified remediation is confirmation, through qualified evidence, that a claimed fix removed or neutralized the specific risk being evaluated.

Why it matters: It closes the loop on remediation using evidence, not workflow status.

Vulnerability fix proofEvidence ladderProof artifact

Defined term

Suppression vs disproval

Suppression hides or accepts a finding for workflow purposes; disproval provides evidence that the finding is invalid in the evaluated context.

Why it matters: It prevents ignored findings from being misrepresented as proven false.

Evidence ladderVerified remediationVulnerability fix proof

Defined term

Claim-to-evidence gap

The claim-to-evidence gap is the distance between what a tool, ticket, or person says and the evidence required to rely on that claim for a decision.

Why it matters: It explains why more findings and more dashboards do not automatically create defensible release authority.

Release-evidence verificationEvidence ladderDecision record

Start with the category

The glossary is meant to make GoSentrix terms extractable and precise. For the full category explanation, read the release-evidence verification pillar page and the public verification doctrine.

Glossary FAQs

What is release-evidence verification?

Release-evidence verification is the process of qualifying evidence from security, engineering, and workflow systems, evaluating that evidence against versioned policy, and preserving the basis for an explicit software release decision.

What is security verification body?

A security verification body is an independent evidence layer that determines whether available security evidence is strong enough to support a consequential action.

What is proof artifact?

A proof artifact is a preserved record that links a claim, the evidence supporting or refuting it, the policy version applied, and the decision outcome.

What is policy-version binding?

Policy-version binding means a decision is evaluated and recorded against the exact policy version active at the time the decision was made.

What is defensible release decision?

A defensible release decision is a software release decision whose evidence, applicable policy, and reasoning can be reviewed and explained after the fact.

What is evidence-backed release?

An evidence-backed release is a software release authorized by qualified evidence rather than ticket state, verbal assurance, or unreviewed tool output alone.

What is ai-generated code governance?

AI-generated code governance is the discipline of capturing provenance, reviewing AI-produced changes, and verifying claims made by coding agents before those changes are released.

What is vulnerability fix proof?

Vulnerability fix proof is evidence that the original vulnerable behavior or exposure no longer applies to the release artifact being evaluated.