01 / Principles
Protect the process before testing the product.
- Safety and availability first. No finding is worth risking a physical process, service, person, or environment.
- Lab before field. New scenarios are built and validated away from live operations.
- Authorization before capability. No active testing until product ownership and scope are verified.
- Least action necessary. Use the lowest-impact method that proves or disproves exploitability.
- Named accountability. Every human and workload action must be attributable and revocable.
- Recovery is part of the method. Every scenario begins from a known baseline and ends in a verified safe state.
02 / Authorization
Scope has to be provable.
The planned onboarding flow will require a named vendor or integrator, verified product ownership, an exact asset inventory, and written authorization defining the lab environment, methods, exclusions, disclosure contact, maximum impact, and stop-work authority.
Default boundaries
- Disconnected, vendor-owned, or Tropiro-owned lab environments first.
- Explicit hardware, firmware, hostname, IP, repository, identity, protocol, and API allowlists.
- No ambiguous third-party assets or inherited authorization.
- No live safety systems, destructive testing, ransomware, persistence, denial of service, or unauthorized credential use.
03 / Execution controls
Every run gets a boundary, a safe state, and an exit.
- Representative hardware or simulations separated from live operator environments.
- Restoreable firmware, workstation images, configuration, and test data.
- Ephemeral, isolated model and tool workers with automatic teardown.
- Outbound traffic restricted to the authorized target allowlist and required service dependencies.
- Rate, time, concurrency, and impact limits set before execution.
- Human approval gates and independent stop authority before deeper validation.
- Physical or logical kill controls, rapid credential revocation, and immutable run logs.
- Recovery and exact reproduction before a finding is presented as verified.
04 / Identity and access
No shared users. No permanent keys.
The target operating model uses organization-domain identities, phishing-resistant MFA, managed devices, short-lived workload credentials, least-privilege roles, and complete user attribution. Shared sessions and static production credentials are outside the design.
05 / Data handling
Collect less. Separate more.
Assessment data can be sensitive even when a test is authorized. The planned system separates customer environments, encrypts stored artifacts, limits retention, redacts secrets where practical, and prevents security evidence from being used as generic model-training material without explicit agreement.
Final retention periods, subprocessors, and contractual commitments will be published before any external assessment service becomes generally available.
06 / Standards direction
Use the language critical-system teams already trust.
The methodology is being designed with reference to NIST SP 800-82, ISA/IEC 62443, CISA performance goals, NIST CSF, and MITRE ATT&CK for ICS. These frameworks inform scope, evidence, risk communication, and product-security lifecycles.
Reference to a framework is not a certification or conformance claim. Tropiro will publish detailed mappings only after the underlying test methods and operating controls have been implemented and independently reviewed.
07 / Current status
This is a build standard, not a certification claim.
RangeSpec 0.1.0 now implements the first machine-readable authorization and evidence boundary as a public, verified component. The physical range and external testing capability do not yet exist. This page does not claim an audit, certification, customer, field capability, program approval, or affiliation with a model provider.
Found a security issue in this website or future Tropiro software? Read the responsible disclosure policy.