# ASR / VRM evidence kit (Phase 0 scaffold)

**Status:** draft evidence mapping / vendor questionnaire stubs  
**Not certification:** this kit is for **mapping and evidence collection** only.

## Explicit non-claims (footer)

CyberHalluciNet **does not claim** SOC 2, ISO/IEC 27001, HIPAA, PCI DSS,
FedRAMP, or any other certification on the basis of these stubs. Documents here
are **templates and mapping aids** for customer ASR/VRM processes. Formal
attestation requires qualified audit/legal review outside this repository.

See also [applicability.md](../../compliance/applicability.md).

## Contents

| File | Purpose |
|------|---------|
| [dfd.md](dfd.md) | Data-flow diagram notes (UDS broker, one-way telemetry, zero-egress sensor) |
| [caiq-sig-lite-stub.md](caiq-sig-lite-stub.md) | CAIQ / SIG Lite answer stubs |
| [dpa-draft-stub.md](dpa-draft-stub.md) | DPA draft outline (not legal advice) |
| [soc2-iso-mapping-template.md](soc2-iso-mapping-template.md) | Control mapping template (evidence pointers only) |
| [threat-model-summary.md](threat-model-summary.md) | Pointers to ADR 0008 + security threat model |

## How to use

1. Copy relevant stubs into a customer-facing packet.
2. Replace placeholders with dated evidence (CI logs, configs, screenshots).
3. Keep the non-claim footer on every exported packet.
