Rung. The smoke receipt is what that procedure produces, but no audio has reached the pipeline in any delivery run yet, so no receipt on record carries a segment count from a real capture — what’s proven, and where.
Framework mapping
Mapping, not legal advice; your compliance function owns the interpretation.- Change management (ISO 27001 A.8.32, SOX ITGC, PCI DSS) — the evidence bundle plus the two approval records, machine-collected per release.
- Software integrity (NIST SP 800-53 SI-7, SSDF) — digest pinning and signature verification at admission, by your own policy engine.
- ICT third-party risk (DORA, EBA outsourcing, NIS2) — a contracted provider with incident support, exit clarity, and the telemetry rung your side sets. Everything you run is open source and your evidence verifies offline, so exit leaves you with working software and records.
- Air-gapped networks — releases, evidence and signatures move as OCI content through your own mirror (what is proven).