Evidence
A directly observed fact tied to a source, artifact, test, or current system state. Evidence proves only its exact scope.

THONIS TRUST AND TECHNICAL GLOSSARY
These definitions explain how THONIS uses common security, legal, assurance, technical-content, architecture, autonomy, and product-maturity terms. Controlling standards, laws, contracts, and customer definitions take precedence.
Plain language does not replace the governing source. Use the current primary authority and target context for any consequential decision.
A directly observed fact tied to a source, artifact, test, or current system state. Evidence proves only its exact scope.
A reasoned conclusion drawn from evidence. It must remain labeled because the conclusion was not directly observed.
A chosen policy, design, commercial, or operating position. It can be defensible without being an external fact.
A material question that available evidence does not close. Unknown does not mean false; it means do not claim or authorize yet.
Software with implemented and testable mechanics. It is not automatically production-ready, deployed, secure for a target environment, accepted, or generally available.
A demonstration using fictional or representative records. It shows interaction and logic, not a customer result.
A bounded evaluation with named users, systems, data, controls, acceptance authority, success criteria, and exit conditions.
A supported production offering available under standard commercial, operational, security, and service terms. THONIS does not currently label the Dextra prototypes as generally available.
One primary work surface for a user community's complete lifecycle, with integrations to authoritative systems where appropriate. It does not mean every external system is replaced or merged.
The system authorized to hold the controlling version of a particular record. Dextra may govern a case while another system remains authoritative for source data.
Multiple systems retain the records and permissions they own while one governed case connects the decision, evidence, action, acknowledgement, and change history.
An identified person with the role to approve or reject an exact consequential result. AI output does not inherit that authority.
A rule-based control that produces the same result from the same inputs and policy, rather than delegating the final allow-or-deny decision to a model.
Approval bound to a specific payload, source versions, assumptions, policy, actor, and time. A material change invalidates or reopens it.
A separate check of the destination after a write or handoff. An acknowledgement alone may confirm receipt without proving the intended final state.
Comparison of intended and observed state, with retries, ownership, exceptions, and recovery when they differ.
A fixed-length digest derived from bytes. Recomputing it can reveal change; it does not prove who created the data, whether it is true, or whether use is authorized.
A cryptographic binding between data and a signing key. Verification supports identity and integrity claims only to the extent that key issuance, custody, revocation, and policy are trustworthy.
A design in which changes can be detected, often through linked hashes. It is not the same as immutable, independently witnessed, or impossible to delete.
Grant only the records, fields, systems, actions, and duration needed for the approved job.
A security approach that does not grant implicit trust solely because of network location or ownership; access decisions consider identity, device, resource, policy, and context.
Protection for data moving across a connection or stored on media. Encryption does not replace access control, key management, data minimization, or application security.
Mechanisms for issuing identities and protecting cryptographic keys or other secrets. Their presence does not prove correct configuration or operating discipline.
Controls intended to prevent one customer or environment from accessing another's data or operations. It requires target-specific architecture and tests.
A documented analysis of assets, trust boundaries, attackers, abuse cases, controls, assumptions, and residual risk for a defined system.
A software bill of materials: an inventory of software components. It improves visibility but does not by itself establish component safety or license compliance.
Authorized adversarial testing of a defined scope and time. A report applies to that tested scope and does not guarantee the absence of vulnerabilities.
A process for reporting a suspected vulnerability while minimizing harm and coordinating validation, remediation, and public detail.
Controlled Unclassified Information: information requiring safeguarding or dissemination controls under a governing U.S. Government authority. It is not authorized for THONIS public intake.
Personally identifiable information: data that identifies or can be linked to a person. The exact definition and duties depend on jurisdiction and context.
A third party engaged by a processor to process personal or customer data on its behalf. Not every vendor is a subprocessor.
A data-processing addendum, master services or subscription agreement, and service-level agreement. These are negotiated legal and operational documents, not features implied by a website.
Recovery time objective and recovery point objective: target time to restore service and target maximum data-loss window. They require architecture, operations, tests, and contract scope.
Different assurance, management-system, and federal authorization constructs. Mentioning their requirements does not mean THONIS or a Dextra product has an audit report, certificate, or authorization.
An international specification for technical publications using a common source database concept. A schema, profile, or candidate output does not automatically establish conformance.
Business Rules EXchange in S1000D. A proprietary BREX-inspired rule dialect must not be described as execution of an official BREX data module.
Common Source DataBase: the governed environment used to store and manage S1000D information objects and related data. TRACE's product direction can include these lifecycle functions without claiming current official conformance.
Interactive electronic technical publication or manual. Viewer behavior, applicability, navigation, and delivery acceptance depend on the governing profile and target environment.
An accepted set of system concepts, relationships, identifiers, assumptions, and decisions from which synchronized architecture views are generated.
System modeling and architecture frameworks. A generated view or interchange artifact must be validated against the selected language, profile, tool, and program rules.
A request from a planner or autonomy component. In Sentinel it remains a proposal until policy and authority permit simulated or verified dispatch.
Timestamp, sequence, and unique-value checks used to reject reuse or reordering of previously signed requests.
A second evaluation after approval and before dispatch so changed state can invalidate an earlier approval.
A lightweight drone-ecosystem messaging protocol. MAVLink 2 signing can authenticate messages but does not encrypt message contents.
Autopilot ecosystems commonly associated with MAVLink. Their names identify intended integration surfaces, not verified Sentinel interoperability.
A robotics middleware ecosystem and security tooling for identities, permissions, governance, and protected communications. Deployment-specific configuration and testing remain necessary.
A software-controlled environment used to exercise logic and failure paths. It does not establish hardware behavior, field performance, airworthiness, safety, or customer acceptance.