Goal: kit usable as a control in a no-egress / air-gapped enclave for regulated environments.
Shipped (this session)
→ The no-egress enclave story is now end-to-end: link triage at internal mirrors, scan against signed local DBs, verify artifact provenance offline, and keep a tamper-evident + SIEM-exportable audit trail. Nothing reaches the public internet.
Deferred (decision-gated, not built — deliberately)
🤖 Generated with Claude Code
https://claude.ai/code/session_015ERHw6bVUz39sAuoQZ1iyg
Goal: kit usable as a control in a no-egress / air-gapped enclave for regulated environments.
Shipped (this session)
KIT_AIRGAP=1(PR feat(scan): offline air-gap mode (KIT_AIRGAP=1) #83)[air_gap]config in.kit.toml(PR feat(airgap): declarative [air_gap] config in .kit.toml #85)kit audit verify(PR feat(audit): tamper-evident hash-chained audit log + kit audit verify #86)kit audit export --format cef|syslog|json(PR feat(audit): SIEM export (CEF / syslog / json) #90)KIT_MEMORY_REDACT=1(PR feat(memory): opt-in redaction-at-capture (KIT_MEMORY_REDACT) #91)kit verify-provenance(cosign--offline+ shipped-in trusted_root, fail-closed) (PR feat(airgap): offline provenance verification (kit verify-provenance) #93)→ The no-egress enclave story is now end-to-end: link triage at internal mirrors, scan against signed local DBs, verify artifact provenance offline, and keep a tamper-evident + SIEM-exportable audit trail. Nothing reaches the public internet.
Deferred (decision-gated, not built — deliberately)
🤖 Generated with Claude Code
https://claude.ai/code/session_015ERHw6bVUz39sAuoQZ1iyg