Runtime Cryptographic Evidence to Bounded Assurance Verdicts: Deterministic Conformance and Policy Appraisal for SHA-256 and AES-256-GCM
Robert CampbellCryptographic inventories and runtime detection identify cryptographic use but do not establish implementation conformance or policy satisfaction. We present a deterministic composition linking admitted runtime evidence, provenance closure, exact implementation identity, Contract-registered NIST test-vector conformance, and content-addressed policy appraisal to ACCEPT, REJECT, or REVIEW verdicts. Controlled SHA-256 and AES-256-GCM workloads produced 12 runtime executions and six provenance-distinct occurrences. The frozen subjects produced expected outputs for all 130 SHA-256 inventory entries and 375 AES-256-GCM ENCRYPT cases, yielding two conformance results. A policy precommitted before authentic appraisal produced six positive-path ACCEPT verdicts; controls demonstrated REJECT and REVIEW. Conformance replay was byte-identical in 10/10 executions per subject, and the complete six-occurrence appraisal reconstructed identically in 10/10 replays. All 12 conformance and 25 appraisal, REVIEW, and anti-fabrication controls passed. No raw AES key or registered direct encoding was detected within the scanned retained-artifact boundary. Public access supports validation of released non-secret evidence and eligible tests, not full regeneration of the original experiment: the workload key, private history, and runnable registered OCI images are unavailable in that release. The contribution is a bounded assurance composition; finite test success and policy ACCEPT do not establish exhaustive correctness, certification, or production authorization.