Predicate: Discovery Coverage – v1

Reserved · CCF Instrument

Type URI: `https://ccframework.org/predicates/coverage/v1`

Status: reserved. The specification publishes here in CCF v1.1, Q1 2027.

This URI identifies the in-toto predicate type for cryptographic discovery coverage: a signed statement attesting how a discovery run was performed, against which reference sets, with which tools, over which attempted scope, and with which failures, so that coverage can be demonstrated to a regulator, insurer or customer without disclosing the inventory itself. It is layer two of the disclosure model described in our published analysis, built as part of the Cryptographic Concentration Framework.

Three design decisions are settled and on the record, and they stay fixed on this page until the specification publishes:

Decision 1. Coverage is asserted against a named reference set, identified by cryptographic digest, never against the estate. An estate is unknowable and any claim to have covered it is unfalsifiable. A claim to have covered this CMDB export, these cloud accounts, this repository manifest, each pinned by hash, is checkable by anyone holding the same reference.

Decision 2. The gap register is mandatory, not optional. What was attempted and failed is the field that makes the claim honest, and it is the first thing a voluntary disclosure regime drops. An attestation that omits the holes converts a partial scan into an apparently clean one.

Decision 3. Scanner provenance is attested separately from findings. Two artifacts, two audiences. The coverage attestation carries no findings. The inventory stays under its own controls.

Stated non-goal. The predicate does not establish that the reference set is right. If a CMDB is missing a quarter of the estate, a perfect attestation against it is a perfect attestation of three quarters of the estate. What it buys is that the denominator becomes a named, versioned, checkable object instead of an unstated assumption.

As of August 15, 2026 the in-toto predicate directory contains no type for scanning or discovery coverage. Any correction to this page is a dated entry on the errata page.