# AEGIS — Security Assurance Roadmap - **Document ID:** ARCH-57 - **Phase:** E.4 — Readiness & Long-View - **Status:** Draft for review (post four-reviewer discipline) - **Version:** 0.1 - **Date:** 2026-07-10 - **Owner:** Chief Security Architect --- ## 1. Purpose Set the path from the v0-GA assurance posture (ARCH-27 §3) to Level-5 targets across every critical subsystem. Ties together verification instruments, formal-methods pilots (ARCH-40), and Debt Register retirements (ARCH-29). ## 2. Roadmap by Subsystem ### 2.1 Security Kernel - **v0-GA (L3).** Property tests (Golden Invariants) + Watchdog quorum + RIV + Independent audit. - **v0.2 (L3→L4).** Expanded property tests + expanded chaos scenarios. - **v1 (L4).** TLA+ model of Capability Directory + Kernel Decision Loop. - **v1.5–v2 (L4→L5).** External formal-methods review + threshold cryptography pilot + Confidential Computing pilot. - **v3 (L5).** All above + long-term sustained metrics. ### 2.2 Cryptographic Identity - **v0-GA (L3).** SPIFFE-shape SVIDs + short-lived leaves + rotation ceremonies. - **v1 (L4).** Hybrid PQC signatures piloted on long-lived audit archival. - **v2 (L4→L5).** PQC primary across all signature sites. ### 2.3 Audit Chain - **v0-GA (L4).** Layer-A hash chain + Watchdog Audit-in-audit + verifier CLI. - **v0.2 (L4).** Transparency log (Sigstore Rekor + self-hosted witness) integrated. - **v1 (L4→L5).** Formal analysis of monotonicity invariants. ### 2.4 AI Safety Layer - **v0-GA (L3).** Deterministic validators + Golden Invariants + red-team engagements. - **v0.2 (L4).** Multi-model consensus refined + canary corpus grown + purple-team runs. - **v1 (L4).** Continuous adversarial testing + Adaptive Trust integrated. - **v2 (L4→L5).** Formal reasoning about specific invariants (redaction correctness, no-conclusion-from-AI). ### 2.5 Evidence Engine - **v0-GA (L3).** Signed provenance + dual-store ledger + reproduction canaries. - **v1 (L4).** Formal reasoning about transformation-ledger consistency. - **v2 (L4→L5).** Attested evidence exports; TEE-based attestations. ### 2.6 Recovery Engine - **v0-GA (L3).** Recovery Integrity Attestation + drilled runbooks. - **v0.2 (L3→L4).** Ransomware simulation + air-gap drills quarterly. - **v1.5 (L4).** Formal specification of RIA invariants. ### 2.7 Plugin Isolation - **v0-GA (L3, interface-only).** Wasm sandbox pattern defined; runtime v0.2. - **v0.2 (L4).** Full runtime + isolation testing. - **v1 (L4).** Publisher tier maturity + Adaptive Trust integrated. ### 2.8 Supply Chain - **v0-GA (L3).** SLSA-3+, two-CI reproducibility, transparency log for release hashes. - **v0.2 (L4).** Model provenance canary evals baseline. - **v1 (L4).** Threshold cryptography for signing sub-roots piloted. ### 2.9 Other Engines - Detection, Case, Connector, Normalization, Storage, Telemetry, Policy, Risk, Response — v0-GA L2/L3; v1 L3; v2 L4 where criticality warrants. ## 3. Milestones - **v0-GA (year 1).** Achieve L3 baseline + eliminate v0-GA Debt Register entries per targets in ARCH-29 §4. - **v0.2 (year 1 + 3 months).** Plugin runtime; expanded canary + red-team. - **v1 (year 2).** Dashboard/Config Review/Asset Inventory/Risk Scoring/Threat-Intel; L4 targets for most; PQC + SAML + BYOK. - **v1.5 (year 3).** Response Engine narrow; Endpoint agent limited GA; TLA+ delivered on Kernel. - **v2 (year 4).** MSSP hosted; PQC primary; Confidential Computing pilots. - **v3 (year 5+).** L5 for all critical subsystems; FedRAMP Moderate; broad Confidential AI. ## 4. Blockers and Dependencies - **Formal-methods team ramp.** Blocks TLA+ delivery on Kernel; on Q-06-3 pilot. - **PQC library maturity.** Blocks hybrid signature adoption timing. - **TEE hardware availability.** Blocks Confidential Computing pilots. - **Team scale.** Blocks MSSP hosted GA + expanded assurance work. ## 5. Assumption (hypothesis) - **H-1.** *L5 achievable for critical subsystems within 5 years given sustained investment.* - Evidence: industry parallels; internal team velocity. - Validation: milestone-by-milestone retrospective. - Confidence: Medium. - Expiration: annually. - Review Date: 12 months. ## 6. Trust Score Contribution Roadmap progress feeds `Verification` dimension over time. ## 7. Independent Architecture Review - **F-1.** *Roadmap is a plan; plans slip.* Milestone-by-milestone re-planning. - **F-2.** *Assurance targets may be aspirational.* Explicit in table + Debt Register. ## 8. Adversarial Architect Review - **A-1.** *Attacker exploits gap between claimed and actual assurance.* Debt Register + Trust Score + auditor visibility. - **A-2.** *Roadmap edited to hide slip.* Ceremony-controlled (ARCH-22 catalog class). ## 9. Operational Reliability Review - **O-1.** Governance council reviews quarterly. - **O-2.** Adjustments recorded via ADR. ## 10. Self-Critique - **S-1.** *Dates could ossify.* Explicit re-planning cycle. - **S-2.** *"L5" is aspirational.* Documented; incremental progression celebrated. ## 11. First-Target Analysis and Redesign **Target:** the "declared" assurance level. If we claim L4 without evidence, everything downstream is false confidence. Response: assurance level is evidence-gated per ARCH-43; drift monitor; auditor annual audit. ## 12. Future Risks / Known Limitations / Out-of-Scope / Retirement - **Future Risks.** Technology or attacker landscape shifts may require re-scoping. - **Known Limitations.** Roadmap is directional; specific quarters flex. - **Out-of-Scope.** Assurance for retired subsystems. - **Retirement Conditions.** Continually renewed. ## 13. Decisions ### D-57-1. Per-subsystem assurance roadmap with milestone-anchored targets - **Reason.** Mandate #36 + explicit long-view. ## 14. Change Log - **0.1 (2026-07-10)** — Initial draft.