Checking access to a private AI service
GroundedBid’s internal AI service needed to accept requests only from the authorised application. The assessment tested a repair to that access boundary and the tools used to package, run and recover the work.
What was tested
The host tests exercised authorised application requests alongside attempts to use the service without the required access. The delivery also included tests of the packaging and recovery process, including refusal paths and interrupted publication.
Recorded results
| Verification | Result |
|---|---|
| Fresh host fixture | 30 of 30 passed; no blocked cases |
| Assessment in the specified runtime image | 7 of 7 accepted |
| Focused tests, root account on the test server | 33 of 33 passed; no skips |
| Focused tests, unprivileged account on the test server | 33 of 33 passed; no skips |
| Delivery structure check | Passed |
| Cleanup | No replay containers remained |
The focused tests were also run locally on Linux. On Windows, 29 passed and four were skipped because the account lacked the required symlink privilege.
What the investigation changed
The delivery process was restructured so that validation happens before publication and test-host acceptance happens before setup. Successful publication retains the previous delivery. Failed attempts leave evidence that can be examined and used during recovery.
The first full host attempt exposed missing executable permissions on extracted shell helpers. That attempt was retained. The permissions were corrected in a new directory and the complete suite was rerun; the expected outcomes were preserved.
Review
Following the build, a separate review checked the completed artifacts and reported a pass.
Scope of the result
These results concern the supplied candidate in a disposable test environment. They are evidence of the tested behaviour, not a production deployment or certification.
Recovery assumes an administrator-controlled parent directory and the originating Unix account. The tests cover process interruption and injected filesystem errors, rather than every possible storage power-loss event. The specified image lacked PHP cURL, so the real PHP client was tested during the host stage.
Evidence reference
The accepted delivery is identified by SHA-256:
470628c3f7892f1be77996eca3134495130d0be7841da8345022a46dce2a5e3d
The successful server execution ran from 23:45:23 to 23:47:02 UTC on 24 September 2026, corresponding to 25 September in Geneva. This page is a summary of the retained delivery and review records.