Ask the supplier for a buyer one-pager (supplier evidence summary) and, if needed, the review pack (JSON + markdown). Then decide whether to dig deeper.
Not conformity assessment. Not CE marking. Not a notified-body opinion.
| Artifact | What you can trust | What you must not assume |
|---|---|---|
| Gate JSON / action report | Structural evidence on the tree shown | Legal conformity or CE readiness |
| SARIF (Static Analysis Results Interchange Format) | Same findings in CI/IDE form | A security audit complete |
| Buyer-questions / lay-of-land | Honest checklist and map | A CVE or GRC program |
| Buyer one-pager / review pack | Shareable evidence snapshot | A certificate of conformity |
| Sources (allowlisted links) | Informational citation trail on the back of the one-pager | Legal authority or gate pass/fail input |
| SBOM / OpenVEX drafts | Best-effort inventory / draft notes | Complete vulnerability status |
| Attest capsule | Signed only if ssh-agent signed | Unsigned equals verified |
Procurement language must stay claim-safe: never equate gate pass with CE marking or notified-body approval. Optional Sources on a one-pager are informational only—they do not prove conformity. Deeper brief: for authorities. Voice: voice and terms.
For suppliers who used research when drafting: research brief sample (informational writer aid — not a peer to the buyer one-pager; never a gate input).