| Authorized testing | ZeroDev describes authorized, bounded defensive testing as a service capability. | Written authority, named owner, scope, exclusions, rules of engagement, safety contact, permitted methods, and source date. | Authority owner + service owner | A public service description is not permission, a live finding, or a security guarantee. |
| Military, government, or defense fit | The site describes relevant decision contexts and defensive capabilities, not a client, appointment, contract, clearance, or endorsement. | Exact current owner-approved contract, appointment, public reference, or other substantiation permitted for publication. | Company owner + legal/commercial reviewer | Audience fit must not be presented as government affiliation, defense approval, or a security clearance. |
| Framework alignment | Reference families are used to frame applicability, control, evidence, and readiness questions. | Current primary reference, applicable jurisdiction or contract, mapped scope, evidence state, and any required assessor or authority. | Control owner + applicable assessor or authority | Framework discussion is not certification, accreditation, compliance, or publisher endorsement. |
| Supplier assurance | ZeroDev can organize supplier evidence, gaps, access, continuity, incident, concentration, and exit questions. | Supplier source, provenance, coverage, permitted verification, exceptions, accountable buyer, and recorded decision. | Procurement or third-party-risk owner | A questionnaire or review is not supplier approval or independent assurance. |
| Compliance readiness | Readiness support can map requirements to controls, evidence, gaps, owners, and treatment. | Applicable requirement or contract, control evidence, implementation state, exceptions, limitations, and independent review where required. | Control owner + required assessor or authority | Readiness support is not certification, accreditation, clearance, legal advice, or regulator approval. |
| Recovery capability | Plans, dependencies, exercises, and restore evidence can be reviewed to identify resilience gaps. | Observed restore or exercise result, RTO/RPO context, dependency evidence, owner decision, and next validation date. | Continuity or service owner | A documented plan or tabletop alone is not proof that recovery will succeed. |
| Client outcomes and case studies | No client, contract, outcome, testimonial, or case-study claim is made without exact publication authority and substantiation. | Named permission, source record, scope, date, and evidence that can be reviewed without exposing sensitive information. | Company owner + client/publication approver | Do not invent, infer, or generalize client results from a template, preview, or capability description. |
| Public deployment and external domains | The `.com` source candidate, `.eu` gateway, and `.store` surface are separate lifecycle records with separate owner decisions. | Provider receipt, deployed revision, DNS/TLS evidence, public acceptance, and domain-specific ownership/source/catalogue evidence. | Provider/domain owner + release approver | A local build, HTTP response, or `.com` page does not prove public release, `.eu` ownership, `.store` catalogue, payment, or checkout status. |