Government · Defence · Critical infrastructure
For the people
who must justify
the decision.
OOVS gives an organisation a published, testable way to demonstrate how an intelligence product was authorised, traced, verified, reviewed, and released — in terms an auditor, an oversight body, or a court of inquiry can follow.
Position
An assurance layer, not another platform.
OOVS does not ingest data, host anything, or ask you to replace a system. It sits above whatever you already operate — in-house, open-source, or commercial — and describes what a defensible process must be able to show.
That distinction matters in procurement. A platform commitment locks you to a vendor. An assurance standard gives you criteria you can apply to any vendor, including the one you already bought, and it remains valid when the tooling changes.
The question OOVS answers is not "which software should we buy?" but "how would we prove this conclusion was sound if we had to?"
Adoption ladder
Each stage supports a specific claim. No stage implies endorsement.
| Stage | Evidence involved | Supportable claim |
|---|---|---|
| Evaluation | Read the standard, run the worked example | “Evaluating OOVS” |
| Assessment | One workflow or product assessed, with recorded scope, period, and evidence | “Assessed against OOVS v0.1.0 for [scope] during [period]” |
| Pilot | Approved trial on synthetic or de-identified material, method published | “Participating in an OOVS pilot” |
| Independent implementation | Reproduced without assistance from the authors, results published | “Implemented the cited version for the stated scope” |
| Procurement profile | Jurisdiction and sector controls, security and accessibility requirements, contract language, assessor method | A scope-specific procurement reference |
No stage permits implying endorsement by OWASP, a government, an agency, a court, or a participating reviewer.
Evaluation checklist
What serious evaluators ask for.
Mission and legal authority
- Defined mission, decision, accountable owner, and authority
- Jurisdiction and mandate-specific legal analysis
- Necessity, proportionality, and impact assessment
- Safeguards for minors, vulnerable people, biometrics, and political activity
- Due process, correction, redress, oversight, and records management
Security and operations
- Access control appropriate to the environment
- Encryption, key management, audit, monitoring, and incident response
- Retention, deletion, backup, and continuity
- Supply-chain and vulnerability evidence
- Deployment patterns for sovereignty, residency, and disconnected operation
Analytic assurance
- Measured provenance completeness and source-origin independence
- Calibrated uncertainty, with false-link and false-positive rates
- Independent challenge, reproducibility, and correction propagation
- Evaluation of any automated component, and enforced human accountability
- Competence, sampling, assessor consistency, and audit evidence
Interoperability and procurement
- Field-level mappings to the exchange formats you already use
- Accessible documentation, including low-bandwidth and offline formats
- Open licensing, version support, migration, and exit terms
- Vendor-neutral acceptance criteria, with no platform requirement
OOVS addresses the analytic assurance column directly and gives you the vocabulary for the others. The controls themselves must be validated in your own environment — a standard cannot certify your infrastructure.
Pilot pattern
A first trial that produces evidence, not enthusiasm.
Use one recurring, low-risk product, and synthetic or approved de-identified material. The aim is a measurement you can defend, not a demonstration.
- 01Baseline
Measure review time, provenance completeness, claim traceability, contradiction detection, corrections issued, and how clearly the product supported the decision.
- 02Intervention
Apply the standard for six to twelve weeks: the pre-work record, provenance and verification records, a stated confidence basis, a review gate, and the structured result format.
- 03Independent check
Have someone who did not build the workflow assess the same sample. Disagreement between assessors is a finding about the standard, not a failure of the assessor.
- 04Report
Publish aggregate method, agreement, exceptions, implementation effort, false links, missed contradictions, and time-to-correction. Never case or operational data.
- 05Stop conditions
Halt if the pilot creates unapproved collection, exposes sensitive data, or produces a rights impact. A pilot that damages people to prove a process has failed already.
Legitimacy
Not designed around any single sponsor.
Government, law-enforcement, and intelligence organisations are welcome adopters and reviewers. They are deliberately not the sole design centre.
Civil society, journalism, academia, affected communities, privacy and human-rights specialists, small teams, and international users must all be able to challenge the standard. Broad legitimacy is a control on the standard's quality, not a marketing posture — a baseline that only large state bodies can implement will not improve practice where most harm actually occurs.
Currently missing, and openly so
No independent assessment has been recorded, no agreement between separate assessors has been measured, and no field deployment has taken place. An evaluator should weigh the standard on its stated criteria and its verifiability — not on adoption claims, because there are none to make.