What is a Capability Proof?
A capability proof is how an operational claim becomes mathematically reviewable. Rather than relying on self-asserted documentation or retrospective log files that can be modified, the Cloud Capable Tarmac generates a signed, hardware-backed receipt of every decision. It shows exactly what was proposed, why it was admitted or refused, and the cryptographic proof of the execution context.
| Prompt / Intent (The Variable) | Normalized Operation | Policy Decision | Decision Fingerprint | Proof Root |
|---|---|---|---|---|
| "Upload this CSV report to the audit bucket." | GCS.PUT_OBJECT | ADMIT | 41fc76ce2fd40f22... |
AMD SEV-SNP (VCEK) |
| "Store object in gs://audit-bucket." | GCS.PUT_OBJECT | ADMIT | 41fc76ce2fd40f22... |
AMD SEV-SNP (VCEK) |
| "Send patient records to external contractor." | GCS.PUT_OBJECT | REFUSE | 9e84b2c110da55ef... |
State Invariant Gate (NC-2) |
| "Call billing tool for premium customer." | STRIPE.CHARGE | ADMIT | bb7642da09c3111f... |
Governed Motion (NC-1) |
| "Execute administrative decryption run." | KMS.DECRYPT | REFUSE | f384a29cf0122e11... |
Attestation Failure |
Zero-Trust Compliance Delivery
Through this structured, pre-commit mapping, compliance auditing changes from a retrospective tax into a native, continuous byproduct of software execution. The receipts generated by the Tarmac can be accumulated into your central index or fed directly into GRC dashboard integrations—providing real-time compliance assurances to regulators, board members, and third-party auditors.