For reviewers

Ask the supplier for a buyer one-pager (supplier evidence summary) and, if needed, the review pack (JSON + markdown). Then decide whether to dig deeper.

Not conformity assessment. Not CE marking. Not a notified-body opinion.

Open sample review page

Artifact trust table

ArtifactWhat you can trustWhat you must not assume
Gate JSON / action reportStructural evidence on the tree shownLegal conformity or CE readiness
SARIF (Static Analysis Results Interchange Format)Same findings in CI/IDE formA security audit complete
Buyer-questions / lay-of-landHonest checklist and mapA CVE or GRC program
Buyer one-pager / review packShareable evidence snapshotA certificate of conformity
Sources (allowlisted links)Informational citation trail on the back of the one-pagerLegal authority or gate pass/fail input
SBOM / OpenVEX draftsBest-effort inventory / draft notesComplete vulnerability status
Attest capsuleSigned only if ssh-agent signedUnsigned equals verified

Procurement language must stay claim-safe: never equate gate pass with CE marking or notified-body approval. Optional Sources on a one-pager are informational only—they do not prove conformity. Deeper brief: for authorities. Voice: voice and terms.

For suppliers who used research when drafting: research brief sample (informational writer aid — not a peer to the buyer one-pager; never a gate input).