Critical Systems Lab / operating direction 0.2

Safety defines the test.

Tropiro is being designed for authorized, lab-based validation of industrial products. Before external testing begins, the range, recovery path, operator context, and stopping conditions must be as deliberate as the adversarial work.

01 / Principles

Protect the process before testing the product.

  • Safety and availability first. No finding is worth risking a physical process, service, person, or environment.
  • Lab before field. New scenarios are built and validated away from live operations.
  • Authorization before capability. No active testing until product ownership and scope are verified.
  • Least action necessary. Use the lowest-impact method that proves or disproves exploitability.
  • Named accountability. Every human and workload action must be attributable and revocable.
  • Recovery is part of the method. Every scenario begins from a known baseline and ends in a verified safe state.

02 / Authorization

Scope has to be provable.

The planned onboarding flow will require a named vendor or integrator, verified product ownership, an exact asset inventory, and written authorization defining the lab environment, methods, exclusions, disclosure contact, maximum impact, and stop-work authority.

Default boundaries

  • Disconnected, vendor-owned, or Tropiro-owned lab environments first.
  • Explicit hardware, firmware, hostname, IP, repository, identity, protocol, and API allowlists.
  • No ambiguous third-party assets or inherited authorization.
  • No live safety systems, destructive testing, ransomware, persistence, denial of service, or unauthorized credential use.

03 / Execution controls

Every run gets a boundary, a safe state, and an exit.

  • Representative hardware or simulations separated from live operator environments.
  • Restoreable firmware, workstation images, configuration, and test data.
  • Ephemeral, isolated model and tool workers with automatic teardown.
  • Outbound traffic restricted to the authorized target allowlist and required service dependencies.
  • Rate, time, concurrency, and impact limits set before execution.
  • Human approval gates and independent stop authority before deeper validation.
  • Physical or logical kill controls, rapid credential revocation, and immutable run logs.
  • Recovery and exact reproduction before a finding is presented as verified.

04 / Identity and access

No shared users. No permanent keys.

The target operating model uses organization-domain identities, phishing-resistant MFA, managed devices, short-lived workload credentials, least-privilege roles, and complete user attribution. Shared sessions and static production credentials are outside the design.

05 / Data handling

Collect less. Separate more.

Assessment data can be sensitive even when a test is authorized. The planned system separates customer environments, encrypts stored artifacts, limits retention, redacts secrets where practical, and prevents security evidence from being used as generic model-training material without explicit agreement.

Final retention periods, subprocessors, and contractual commitments will be published before any external assessment service becomes generally available.

06 / Standards direction

Use the language critical-system teams already trust.

The methodology is being designed with reference to NIST SP 800-82, ISA/IEC 62443, CISA performance goals, NIST CSF, and MITRE ATT&CK for ICS. These frameworks inform scope, evidence, risk communication, and product-security lifecycles.

Reference to a framework is not a certification or conformance claim. Tropiro will publish detailed mappings only after the underlying test methods and operating controls have been implemented and independently reviewed.

07 / Current status

This is a build standard, not a certification claim.

RangeSpec 0.1.0 now implements the first machine-readable authorization and evidence boundary as a public, verified component. The physical range and external testing capability do not yet exist. This page does not claim an audit, certification, customer, field capability, program approval, or affiliation with a model provider.

Found a security issue in this website or future Tropiro software? Read the responsible disclosure policy.