Argus2026.01
Audit Evidence Bundle

A system you can
defend in court.

A tamper-evident record of remediation: what was reported fixed, what Argus independently validated, and the hash-chained evidence behind every material transition.

Scope period
Q2 2026
Appliance
argus-acme-01
Ledger root
a3f1…9c2e
Classification
Confidential

Non-exploitative validation statement

Argus is a read-only, non-invasive, non-exploiting platform. No finding in this bundle was produced by exploitation; every verdict derives from versioned, reproducible logic over collected evidence. Reported-fixed and validated-fixed are kept distinct. No generative AI participates in the decision path.

Closure

Fix Pack closure summary


Validated closed
64
Reported, awaiting recheck
5
Validation failed
3
Accepted risk
2
Ledger

Validated closures — evidence trail


Fix PackFindingReportedValidatedOutcomeEntry hash
FP-2026-0042Public Swagger endpoint exposed05-2805-29Validatedc0e9…7d20
FP-2026-0019Anonymous LDAP on dc-0205-2605-27Validated9b21…44af
FP-2026-0205Public S3 bucket read ACL05-2405-25Failed7d4c…0e18
FP-2026-0033EOL Windows Server 2012 R2Acceptedf1a8…22b9

Each entry's hash binds the previous entry. Verify the chain offline with the exported proof JSON; any modification breaks the chain.

Alignment

Control alignment


ControlReferenceHow Argus supports it
LoggingISO 27001:2022 A.8.15Every state-changing action recorded with actor, timestamp, outcome
Configuration mgmtA.8.9Templates & knowledge version-locked in the signed release
Threat intelligenceA.5.7NVD · CISA KEV · EPSS from signed feeds, operator-approved updates
Access controlA.5.15CSRF-protected, authenticated operator actions only