{"id":"security-rewrites","title":"Evidence-safe security phrasing","source":{"file":"03","file_slug":"evidence-provenance-standard","section":"9-security-evidence","table":"03.9-security-evidence.t1","line":160},"headers":["Unsafe claim","Evidence-safe version"],"align":["left","left"],"count":5,"records":[{"id":"they-were-breached","label":"“They were breached”","unsafe_claim":"“They were breached”","evidence_safe_version":"“The domain appears in an authorized breach-notification result as of [date]; scope and current risk are unconfirmed.”","cells":["“They were breached”","“The domain appears in an authorized breach-notification result as of [date]; scope and current risk are unconfirmed.”"],"defined_in":{"file":"03","file_slug":"evidence-provenance-standard","section":"9-security-evidence","table":"03.9-security-evidence.t1","line":160}},{"id":"they-have-no-mfa","label":"“They have no MFA”","unsafe_claim":"“They have no MFA”","evidence_safe_version":"“MFA status is not publicly verifiable.”","cells":["“They have no MFA”","“MFA status is not publicly verifiable.”"],"defined_in":{"file":"03","file_slug":"evidence-provenance-standard","section":"9-security-evidence","table":"03.9-security-evidence.t1","line":160}},{"id":"this-version-is-vulnerable","label":"“This version is vulnerable”","unsafe_claim":"“This version is vulnerable”","evidence_safe_version":"“A passive fingerprint suggests version X; the version and exploitability were not validated.”","cells":["“This version is vulnerable”","“A passive fingerprint suggests version X; the version and exploitability were not validated.”"],"defined_in":{"file":"03","file_slug":"evidence-provenance-standard","section":"9-security-evidence","table":"03.9-security-evidence.t1","line":160}},{"id":"their-endpoint-is-exposed","label":"“Their endpoint is exposed”","unsafe_claim":"“Their endpoint is exposed”","evidence_safe_version":"“A passive index listed service Y at time Z; no active connection was attempted.”","cells":["“Their endpoint is exposed”","“A passive index listed service Y at time Z; no active connection was attempted.”"],"defined_in":{"file":"03","file_slug":"evidence-provenance-standard","section":"9-security-evidence","table":"03.9-security-evidence.t1","line":160}},{"id":"employee-credentials-are-on-the-dark-web","label":"“Employee credentials are on the dark web”","unsafe_claim":"“Employee credentials are on the dark web”","evidence_safe_version":"Do not make or store this claim from unverified dumps. Use an authorized domain-monitoring process.","cells":["“Employee credentials are on the dark web”","Do not make or store this claim from unverified dumps. Use an authorized domain-monitoring process."],"defined_in":{"file":"03","file_slug":"evidence-provenance-standard","section":"9-security-evidence","table":"03.9-security-evidence.t1","line":160}}]}