The public SOC lab uses four synthetic scenarios and deterministic triage with a human approval gate.
Limit: The lab does not connect to a model, SIEM, EDR, identity provider, ticketing system or network control.
- Tests
- 2
- CI jobs
- 1
Trace implementation claims to named tests and CI jobs, then inspect six non-confidential examples covering investigation, governance, validation, agent assurance, pilot measurement and improvement planning.
CI rejects a verified claim when its named test or workflow job disappears. Partial and planned claims remain visible so architecture intent is not presented as demonstrated production evidence.
Limit: The lab does not connect to a model, SIEM, EDR, identity provider, ticketing system or network control.
Limit: A role or workflow definition does not grant runtime authority, credentials or production access.
Limit: Hash chaining detects mutation; HMAC authenticity requires a non-default signing secret and protected key handling.
Limit: Contract tests use synthetic fixtures and do not certify a customer connector or production deployment.
Limit: Authorization does not validate a third-party provider's independent retention, security or contractual terms.
Limit: Repository tests verify the application boundary. Production proof still requires external workload-identity issuance, network and DNS enforcement, sensor coverage, connector controls and kill-switch integration in the customer environment.
Limit: Approval establishes governance state; it does not prove that a source statement remains factually correct after review.
Limit: Synthetic fixture success does not establish production detection quality against a customer's telemetry distribution.
Limit: Conformance verifies the declared adapter contract, not the availability or security posture of an external service.
Limit: The bundled persistence profile is suitable for a single self-hosted control plane; clustered deployments require a customer-qualified transactional backend and recovery design.
Limit: Evaluation quality depends on representative, reviewed datasets; synthetic acceptance suites do not establish production effectiveness.
Limit: The public view contains synthetic operating data; real approvals and policy state remain inside the authenticated customer deployment.
Limit: Pilot definitions establish bounded workflow contracts; customer value must still be measured against an agreed baseline and acceptance criteria.
Limit: Repository conformance does not establish customer identity, connector, recovery, tenancy or production operating evidence.
Limit: Deployment owners must still configure trustworthy identities, authoritative context sources and customer-specific risk ceilings.
Limit: Production objectives, alerting ownership and recovery criteria require customer acceptance and live operational testing.
Limit: A reviewed procedure improves consistency but does not prove that every third-party command, platform API or framework reference remains current in a customer environment.
Limit: Lifecycle status describes Yefosec's stated operating boundary and is not an independent certification or vendor endorsement.
Limit: The registry validates environment declarations and evidence references; deployment owners must independently prove the referenced network and resource controls were enforced.
Open synthetic assurance recordLimit: The portfolio is a reference composition and evaluation floor, not evidence that every persona, vendor adapter or banking scenario has been deployed or accepted in a customer environment.
Limit: A new provider or model remains a material change and must pass customer-specific quality, safety, privacy, residency, outage and rollback evaluation before promotion.
Limit: Connector entries are contracts rather than live integrations; the lab is self-reported and browser-local, standards mappings are indicative, and neither catalog validation nor a score proves a customer control is effective.
Limit: Readiness still depends on customer-specific threat modelling, identity, tenancy, connector qualification, runbooks, recovery testing and operational acceptance.
Download pilot evidence templateOpen synthetic pilot outcomeLimit: No named customer outcome, benchmark or production case study is published; the site provides synthetic examples and tested implementation evidence only.
Download pilot evidence templateOpen synthetic pilot outcomeA synthetic impossible-travel alert carried from triage rationale through evidence review and a human containment decision.
Example status: Closed - benign exercise activity confirmed
A synthetic vendor exception showing the evidence, options, accountable owner, expiry and review conditions behind a risk decision.
Example status: Approved with conditions - review due 30 September 2026
A benign synthetic validation that separates observed evidence, missing signals and the owned detection work that follows.
Example status: Validated with one telemetry improvement open
A synthetic roadmap that turns an assessment baseline into sequenced work with owners, evidence and review points.
Example status: Draft for accountable-owner review
A synthetic control-versus-candidate comparison showing deterministic checks, resource accounting, safety vetoes and a human release decision.
Example status: Eligible for human review - not approved for production
A synthetic champion-versus-candidate record for one supervised alert-triage workflow, including quality, time, override and safety gates.
Example status: Synthetic decision: revise before any representative pilot
A scoped review can turn your workflows, controls and obligations into an owned decision record and roadmap.