# CHQ-ED-2026-019

- **Artifact ID:** CHQ-ED-2026-019
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-019
- **Machine-record SHA-256:** `32e5fe718e42b6a2563d535342f4117de18179681d201309819e596cfda9b8a4`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-019",
  "associated_position": "CHQ-P-2026-011 v1.0",
  "relationship": "reinforcement",
  "issuance_date": "2026-05-04",
  "evidence_freeze_time": "2026-05-04T00:00:00Z",
  "total_exhibits": 1,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "Core Position",
      "claim_text": "The presence of a security tool in a customer environment does not constitute evidence that the tool’s detection capabilities are functioning as designed when the tool’s internal detection logic has been exposed to adversaries who can engineer evasion paths against it without triggering the tool’s signatures.",
      "evidence_exhibits": [
        "CHQ-EX-2026-020"
      ],
      "relevant_sections": "I. Factual Record, II. Failure Pattern",
      "verification_type": "REINFORCING",
      "evidence_class": "REINFORCING",
      "source_text": "SN-2026-04-29-01 (Checkmarx) and SN-2026-05-03-01 (Trellix): Source code of security scanning and endpoint detection products published or accessed by adversaries. Customer environments running these products continued to display operational dashboards consistent with normal function. The asymmetry: the customer sees tool presence; the adversary knows the detection logic."
    },
    {
      "claim_id": "C-02",
      "position_section": "Evidence Pattern",
      "claim_text": "The two source code exposure events occurred within seven days through different actors, different access vectors, and different vendor products, demonstrating that ‘security tool deployed and operational’ is structurally independent of ‘security tool’s detection capabilities are not under adversarial knowledge advantage.’",
      "evidence_exhibits": [
        "CHQ-EX-2026-020"
      ],
      "relevant_sections": "II. Failure Pattern",
      "verification_type": "PATTERN",
      "evidence_class": "PATTERN",
      "source_text": "Pattern across SN-2026-04-29-01 and SN-2026-05-03-01. The dashboards customers use to verify tool function operate at the layer of tool execution. The exposed asymmetry operates at the layer of tool detection logic. These are different layers with different observable states."
    }
  ],
  "signals": [
    {
      "signal_id": "SN-2026-04-29-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "REINFORCING",
      "evidence_exhibits": [
        "CHQ-EX-2026-020"
      ]
    },
    {
      "signal_id": "SN-2026-05-03-01",
      "signal_type": "VENDOR_DISCLOSURE",
      "classification": "REINFORCING",
      "evidence_exhibits": [
        "CHQ-EX-2026-020"
      ]
    }
  ],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-020",
      "title": "Security Vendor Source Code Exposure Class: Checkmarx and Trellix",
      "temporal_tag": "OPERATIONAL (APRIL 26 – MAY 2, 2026)"
    }
  ],
  "notice": [
    "This docket records additional claim-to-source mappings for CHQ-P-2026-011 v1.0 covering reinforcement evidence from April–May 2026.",
    "The position CHQ-P-2026-011 was issued March 2026 with thirteen prior signals supporting structural confirmation. This docket records the addition of two reinforcing signals from the April–May 2026 window. Both signals reinforce the position from the supply-side: when the source code defining a security product’s detection capability is exposed to adversaries, the tool’s operational presence cannot serve as evidence of functioning control.",
    "The signals are classified REINFORCING rather than PRIMARY because they extend an already-CONFIRMED structural condition through a previously underweighted dimension (supply-side detection logic exposure) rather than introducing a new failure mechanism.",
    "Position SIG count update: 13 → 15."
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-011 v1.0 as a reinforcement docket (not a successor).",
    "Both signals (SN-2026-04-29-01 Checkmarx, SN-2026-05-03-01 Trellix) carry CONFIRMED access status — vendor-confirmed in both cases. Exploitation of the exposed source code is not confirmed, consistent with the position’s claim that absence of confirmed exploitation is not evidence of non-exploitation.",
    "CCD record — two layers decomposed (tool presence as customer-facing signal, detection logic as adversarial research target), both CONFIRMED. CCD_INTEGRITY: STRONG. ALIGNMENT_PRESSURE: HIGH.",
    "Primary signals compiled from CHQ Classification Log. All signals passed TSEM evaluation. Source independence assessed per CCD enforcement protocol.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-019 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-011 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
