DORA TLPT Evidence

The TLPT evidence surface prepares deterministic white-team planning, baseline, and evidence-pack artifacts for DORA TLPT support. Stella does not run offensive tests, select targets by itself, or submit TLPT artifacts to a regulator. Operators and their appointed TLPT roles own scope approval, execution, findings treatment, and reporting.

This is a surface of the DORA Operational Resilience Pack.

Claim boundary: operator-support.

Source Docs

Runtime Boundary

The local CLI flow covers deterministic handoff artifacts:

Live Graph asset registry query mode is not part of this local CLI slice. EvidenceLocker TLPT audit action emission remains service-owned follow-up work.

Evidence Pack

The target Assurance export profile id is dora.tlpt-evidence-pack. The current compatibility route is stella tlpt pack plus stella verify tlpt-pack.

Expected evidence includes:

Boundaries

The TLPT surface must not:

Any live-service implementation must preserve the same offline verification properties as the CLI handoff.