Effective sample size in continuous sensor capture
Why 40,000 frames from 22 sorties is 22 samples for a per-sortie hazard, how intra-cluster correlation propagates into a sufficiency calculation, and what a defensible ρ looks like for video, simulation and field logs.
SufficiencyCorrelationCoverage
The 10⁻⁹ problem, stated plainly
The arithmetic showing that catastrophic-level residual rates are unreachable by testing for learned components, what that leaves available — architectural mitigation and domain restriction — and how to quantify the shortfall so it can be argued about rather than hidden.
Residual rateCertificationMitigation
Reproducibility classes for machine learning evidence
An R0–R3 taxonomy for how reproducibly a run replays, what causes each class in practice on real accelerator hardware, and why evidence cited at an inadmissible class has to be refused rather than annotated.
DeterminismEvidenceReplay
Why readiness is a vector
What is destroyed when six assurance dimensions are collapsed into a single score, why the criticality level has to travel in the same visual unit as the figures, and how a decomposable dimension differs from a decorative one.
ReadinessPresentationAssessment
Offline verification of an evidence bundle
The export bundle format, the inclusion and consistency proofs it carries, and a walk through verifying a dossier claim end to end on a machine that has never contacted the issuing installation.
VerificationTransparency logProvenance
The sim-to-real defeater
Why simulation-derived evidence carries a mandatory defeater in the assurance case, what evidence discharges it, and why a vendor that generates the data cannot also be the party adjudicating the gap.
SimulationAssurance caseTrust boundary