Audit Products
Purchasable reviews for claims, workflows, evidence paths and conformance.
SnapOS does not sell generic AI governance advice. It audits whether a claim, workflow or decision path is still allowed to support a concrete decision.
| Document type | Product Sheet Collection |
|---|---|
| Status | ACTIVE PUBLIC SPECIFICATION |
| Version | v16.3 |
| Last revised | 2026-09-19 |
| Maintainer | SnapOS Foundation / Marko Chalupa |
| Canonical URI | https://snapos.org/en/audit-products.html |
| Cite as | SnapOS.org, Audit Products, v16.3, accessed YYYY-MM-DD. |
Product Sheets — same schema for every product
Every SnapOS audit product is described the same way: what is audited, what decision question it answers, who uses it, what it needs to start, what it delivers, what it does not include. The private audit method behind each product stays protected.
Claim Coverage Audit
| Audit object | One provider/tool/workflow and 3–5 specific claims made about it. |
|---|---|
| Decision question | Can this claim still support the decision that relies on it? |
| Who uses it | Enterprise, Compliance, Procurement |
| Minimum inputs | The claim(s) as stated, the evidence cited for them, and the decision or context they are meant to support. |
| Issued artifacts | Audit memo, claim coverage table, optional evidence gap register and reopen trigger list. |
| Possible labels | SUPPORTED, SUPPORTED WITH CONDITIONS, UNSUPPORTED TRANSFER, INSUFFICIENT EVIDENCE |
| Reliance boundary | Covers only the claims and evidence scoped at intake; does not extend to claims not submitted for review. |
| Explicit exclusions | No certification, no legal opinion, no disclosure of the private audit engine, scoring or benchmark logic. |
| CTA | Request Audit Scoping → |
Workflow Assurance Review
| Audit object | A workflow's decision architecture — model/API, RAG, tools, human review, decision rights, data boundary, monitoring, escalation. |
|---|---|
| Decision question | What exactly is the workflow relying on, and where would that reliance break? |
| Who uses it | Enterprise, Compliance, Auditor |
| Minimum inputs | Workflow documentation or a walkthrough, named decision points and named reviewers. |
| Issued artifacts | Workflow assurance memo, reliance map, reopen trigger list. |
| Possible labels | SUPPORTED, REVIEW REQUIRED, DO NOT RELY |
| Reliance boundary | Describes the workflow as scoped and provided; does not audit code, models or infrastructure directly. |
| Explicit exclusions | No penetration testing, no model evaluation, no certification. |
| CTA | Request Audit Scoping → |
Decision Evidence Path Review
| Audit object | The evidence chain behind a specific past or pending decision. |
|---|---|
| Decision question | Can this decision be reconstructed and reviewed later, by someone who was not in the room? |
| Who uses it | Enterprise, regulator-facing teams, Auditor |
| Minimum inputs | The decision record, the evidence and approvals cited, and their dates/versions. |
| Issued artifacts | Decision evidence path memo, gap register, reliance statement. |
| Possible labels | SUPPORTED, REVIEW REQUIRED, OUT OF SCOPE, INSUFFICIENT EVIDENCE |
| Reliance boundary | Assesses reviewability of the path as documented; does not rule on whether the decision itself was correct. |
| Explicit exclusions | No legal determination, no fault-finding, no engine disclosure. |
| CTA | Request Audit Scoping → |
Authority Asymmetry Audit
| Audit object | Access and rights distribution around a system or workflow — who can see, challenge, validate, override, decide. |
|---|---|
| Decision question | Who actually holds authority here, and does it match who is assumed to hold it? |
| Who uses it | Enterprise, Regulator, vendor-oversight teams |
| Minimum inputs | Role/rights documentation, named systems and named decision points. |
| Issued artifacts | Authority map, asymmetry findings memo. |
| Possible labels | SUPPORTED, REVIEW REQUIRED, DO NOT RELY |
| Reliance boundary | Maps stated and observed authority as scoped; does not assess individual competence or intent. |
| Explicit exclusions | No motive claims, no personnel judgment, no certification. |
| CTA | Request Audit Scoping → |
Conformance Readiness Review
| Audit object | A report template, output format or audit product a third party intends to publish or use. |
|---|---|
| Decision question | Can this output become SnapOS-compatible or SnapOS-conformant? |
| Who uses it | Auditor, Vendor, tool builder |
| Minimum inputs | A sample output or template, and the witnesses/labels it currently carries, if any. |
| Issued artifacts | Readiness memo mapping the output against the minimal schema, witness set, labels and reliance boundaries. |
| Possible labels | SNAPOS-INSPIRED, SNAPOS-COMPATIBLE, GAP IDENTIFIED |
| Reliance boundary | States readiness against the published interface only; does not itself confer compatible or conformant status. |
| Explicit exclusions | No certification, no engine disclosure. |
| CTA | Submit Output for Conformance Review → |
SnapOS-compatible Output Review
| Audit object | A specific, already-produced third-party output claiming or resembling SnapOS compatibility. |
|---|---|
| Decision question | Does this artefact actually meet the minimal output and witness rules it claims or implies? |
| Who uses it | Auditor, Regulator, enterprise receiving the output |
| Minimum inputs | The output itself, in the form it was published or delivered. |
| Issued artifacts | Output review memo with a compatibility finding. |
| Possible labels | SNAPOS-COMPATIBLE, SNAPOS-INSPIRED, NON-CONFORMANT OUTPUT |
| Reliance boundary | A finding about this one artefact; does not certify the issuing party or the process that produced it. |
| Explicit exclusions | No certification, no legal equivalence claim, no engine disclosure. |
| CTA | Submit Output for Conformance Review → |
Labels
Typical result labels include SUPPORTED, SUPPORTED WITH CONDITIONS, UNSUPPORTED TRANSFER, REVIEW REQUIRED, DO NOT RELY, OUT OF SCOPE, INSUFFICIENT EVIDENCE and NON-CONFORMANT OUTPUT.