SecondMark position
Digital decisions become physical consequences. Timing, sensors, actuators, degraded states, human takeover, and environmental assumptions must enter the assurance boundary.
The examination is bounded to defined claims, a versioned system, and evidence that can be traced to the state under review. Any material exclusion or uncertainty remains visible in the conclusion.
Core questions
What the examination needs to establish.
- 01
What physical authority can software exercise?
- 02
How are unsafe states prevented or contained?
- 03
Does takeover work under real timing constraints?
- 04
Which environmental assumptions are monitored?
Evidence model
Evidence is assembled around the claim—not the folder structure.
Domain-specific operating context
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Authority and consequence mapping
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Human and automated control points
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Failure containment and recovery evidence
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Intended outcome
Evidence on whether autonomous behavior remains bounded and recoverable in the intended operating context.
Professional boundary
What an opinion does—and does not—mean.
It provides
A traceable independent conclusion on defined claims, grounded in the evidence and system state examined.
It does not provide
A guarantee that failure is impossible, a permanent certification, or a conclusion beyond the stated scope and validity conditions.
