A governed evidence layer that separates forensic states and preserves their respective authority boundaries.
Evidence must remain evidence.
Forensic Evidence Governance is the forensic boundary architecture of the immo.quick Serverless Edition. It separates network observation from human attribution, package generation from disclosure authority, retention expiry from indefinite storage, and correlation from a right to reconstruct the original identifier.
What it is
A governed evidence layer that separates forensic states and preserves their respective authority boundaries.
It is not automatic attacker identification, independent disclosure authority or unlimited retention permission.
This page explains public architecture, assurance objectives and semantic boundaries. It does not publish internal control logic, secrets, key management, exploit mechanics, operational forensic schemas or implementation sequences.
Why this boundary matters
ATTRIBUTION
A network identity is not a human identity.
DISCLOSURE
A generated evidence package is not permission to disclose it.
RETENTION
Expiry requires a separate legal basis or an end to readable retention.
CORRELATION
Correlation supports pattern recognition, not silent reconstruction of identity.
WITNESS, NOT JUDGE
The system structures evidence; attribution remains with legitimate external authorities.
Public model
Forensic Evidence Governance is the forensic boundary architecture of the immo.quick Serverless Edition. It separates network observation from human attribution, package generation from disclosure authority, retention expiry from indefinite storage, and correlation from a right to reconstruct the original identifier.
It is not automatic attacker identification, independent disclosure authority or unlimited retention permission.
Frequently asked questions
Does immo.quick identify attackers?
No. Network observation and public enrichment do not establish human attribution.
Can a generated package be disclosed automatically?
No. Package generation and disclosure authority remain separate.
What happens when retention expires?
The architecture requires readable retention to end or a separately valid legal hold.
Why is a correlation token not identity proof?
Correlation connects technical patterns but does not create a person or a right to reconstruct the original identifier.
