épreuveepreuve.io
$ book discovery
THREAT-INFORMED AUDIT READINESS · SOC 2

Everycontrolclaimsitworks.

Put it à l'épreuve.

We start from your risks, work out the protection that must exist, and attack every control that claims to provide it with your own records. Then we try to break our own conclusions before you rely on them.

$ man épreuve
┌─ replay · alder-works · R-DATA → S-D1 → T-D1 · critical
[*] loading replay
authored from the fixed procedure trace · fictional target · no live model
0
steps, from your register to the retest
the same loop for every scenario and every retest
0/77
assertions not yet run, printed first
Not shown: 50 not run · never hidden
0
failures that block our own release
whatever your controls did · 0 opinions issued
THE LOOP

Nine steps. From your register to the retest.

The same deterministic loop for every scenario, every control family and every retest. Code executes, an agent and a reviewer attack the answer, a person releases.

  1. 00
    risk01 recon
    in your register as it is, plus what we may add: breaches at comparable companies, breaches involving your vendors, the data you hold, your incident records
    outthe top risks, high or critical, each with its signals and their provenance
    [!] a missing or under-rated risk comes back to you as an evidence-backed challenge; you own the register
  2. 01
    scenario01 recon
    in one risk
    outa handful of concrete paths, attack and failure alike, each with the protection it requires
  3. 02
    claim01 recon
    in the required protection
    outthe controls that claim to provide it, listed in your framework or not, with their assumptions marked as positions
    [!] each control is judged by its capability, coverage and reliability against the path, never averaged into a score
  4. 03
    populate02 hunt
    in positions, sources, period
    outexpected against obtained population, exclusions, source health
    [!] a sample supports only its own inference; one application does not establish all applications
  5. 04
    procedure02 hunt
    in one position
    outa versioned procedure: payload, assertion, oracle, limits, and the exact authority to run it
  6. 05
    run02 hunt
    in procedure, population, period
    outone result per position: held, broke, open or not run, with its confidence
    [!] same inputs, same bytes; any change is a new revision, never an edit
  7. 06
    challenge03 challenge
    in results and the reasoning behind them
    outrelease, or a hold that blocks release until evidence or a named reviewer resolves it
    [!] an adversarial agent objects, a named reviewer decides; four failures block our release whatever your controls did
    [-] an unsupported favourable conclusion[-] an unsupported adverse conclusion[-] a missed known material failure[-] missing evidence treated as a pass
  8. 07
    debrief04 debrief
    in released and held results across the scope
    outone assessment, several views: team, risk owners, board, engineering, auditor
    [!] not run is printed first; held is a result, not an absence
  9. 08
    retest04 debrief
    in your fix, a new period
    outa new run linked to its parent; the original finding stays
    [!] re-enter the loop where the fact changed
STEPS 02 TO 05, ON ONE CLAIM

One claim. Four positions. Attacked one at a time.

The claim came from a scenario, the scenario from a risk in the register. Each assumption inside the claim is a position; each position gets its own payload from your records, its own status and its own confidence. Keep scrolling to run them.

the claimordinary users reach files via SSO+MFA§can only§[+] held · firm§through central SSO§[-] broke · certain§with MFA§[+] held · firm§separately approved§[?] open · tentativepayloads: idp/auth-events · idp/config-snapshot · exception-approvals✎ afandi · “emergency route, or a second door?” · hold
épreuve hunt(idp/local_login) > run T-D1 · sniper · 0/4
1§can only§[+] held · firm
payload
idp/auth-events · 06-01→06-30
assert
local_login_events == 0 41 sso+mfa · 0 local
2§through central SSO§[-] broke · certain
payload
idp/config-snapshot@06-14 · 7c1e…
assert
local_login == false true
3§with MFA§[+] held · firm
payload
idp/config-snapshot@06-14
assert
mfa_required == all mfa on all 41
4§separately approved§[?] open · tentative
payload
exception-approvals
assert
approvals delivered not delivered
[✎] afandi hold “emergency route, or a second door?” · role ∉ exceptions
exit 1 · broke · certain
skip ↓
WHY YOUR TOOLS DON'T DO THIS

A green tick is a claim.

Platforms start from a control list.

We start from your risks and write down what protection must exist. Then we look for it.

risk R-03protection requiredtarget T-D1

Evidence is collected, not attacked.

Every assumption in a claim gets a payload from your own records and a fixed, inspectable procedure.

[+] held[-] broke[?] open[ ] not run

Nobody prints confidence.

Certain, firm or tentative on every result. Uncertainty is a finding, not a footnote.

broke×certain·held×firm·open×tentative

Nobody attacks their own answer.

An adversarial agent objects, a named reviewer decides, and a hold blocks release. Review never turns broke into held, and held is a result we are glad to print.

[*] result[?] challenger✎ afandihold · release
WHO RUNS IT

Not the auditor. The hunt before the audit.

Your team commissions it and acts on it. Your auditor reads our trace, reperforms what they want, and signs their own report.

0:team*
head of security GRC
$ épreuve --for team
whohead of security GRC · mature SOC 2 · a prior audit to compare
reconyour register, your vendors, peer breaches → the claims worth hunting
huntfull agreed scope · fixed fee · your records as payloads
challengea named reviewer attacks our answer · unknowns printed
debriefbroke/held/open per control · remediation order · board page · trace
thenyou fix · one retest · original finding kept · no retainer
yoursplatform · register · control operation · risk decisions
nota tool · monitoring · an attestation · a pentest
$ épreuve --for team | less →
1:auditor*
the examiner of record
$ épreuve --for auditor
whothe examiner of record · your client’s auditor
youdecide what to reuse · reperform what you want · sign your own report
wehand over scope, method versions, populations, workpapers, result, exit record
route Ayour client commissions the hunt · you inspect the package · your call
route Byou engage us for the substantive testing under your engagement
notauditor software · a report you can sign · a promised fee cut
$ épreuve --for auditor | less →
THE CONSOLE

Open a target. See the whole hunt.

Deep assurance. Boring audits.

Fixed fee · full SOC 2 scope · one retest · you remediate · your auditor signs

free · 45 minutes · with Ayoub, not a sales team