Trust model
The LLM is not the security authority.
ARL separates orchestration from security authority so explanations cannot silently become findings, evidence or deployment decisions.
Evidence chain
What can support readiness
Declared controlsCustomer statements remain declared until supported.
Observed controlsReviewable behaviour or system records.
FindingsAuthoritative ARL security findings.
Attack evidenceResults from bounded authorised tests.
Runtime evidenceRecorded control behaviour where applicable.
Human approvalExplicit accountable approvals when required.
RemediationImplementation evidence for the changed system.
RetestExact verification against the affected control.
Deployment decisionThe final accountable decision remains human.
Production-readiness requirement
Readiness must come from authoritative controls and evidence, not static website copy or a billing state. See System status for the public service-status route.
Unknown evidence remains unknown. A report is not an accredited certification, guarantee, insurance product or legal opinion.