# OneVir release and deployment evaluation checklist

Reference: https://onequill.dev/resources/onevir-control-evidence
Source reviewed: 2026-10-07. Source package: 0.2.43 (working tree).

This worksheet does not certify the product or establish that a control passed. The article's referenced tests were not run for publication. Request evidence for your installed release.

## Deployment record

- OneVir version / build:
- Installed artifact digest:
- Deployment mode and execution locations:
- Enabled providers, endpoints and inference engines:
- Model revisions:
- Effective configuration / policy revision:
- Review date and accountable decision owner:

## Evidence provenance

- [ ] Record the release identifier and supplied artifact digest.
- [ ] Match the evidence to the installed version and effective configuration.
- [ ] Distinguish source review, documentation, executed tests and deployment demonstrations.
- [ ] Record test dates, workloads, results and limitations; do not treat a test's existence as a pass.

## Security: credential interpretation

Reviewed finding: The named test asserts rejection of conflicting credentials and handling of supported bearer and WebSocket formats.
Evidence status: Test source reviewed; referenced test not run.

- [ ] Request: Installed version, endpoint and permission matrix, and authentication test results.
- [ ] Verify: Endpoint coverage, key scopes, administrative permissions and transport security.
- [ ] Identify the operator and any upstream provider responsible for the deployment checks.

Evidence reference / attachment:
Version and configuration covered:
Test or demonstration date and result:
Evidence supplier:
Accountable owner:
Limitations and open questions:
Decision, action and due date:

## Privacy: retention and saved history

Reviewed finding: Initialisation rejects an invalid saved retention policy; named history paths describe retention and image restrictions.
Evidence status: Implementation and API documentation reviewed.

- [ ] Request: Configured retention policies, data-flow record, and retention and deletion demonstrations.
- [ ] Verify: Effective retention settings and data flows through providers, caches, files, exports and backups.
- [ ] Identify the operator and any upstream provider responsible for the deployment checks.

Evidence reference / attachment:
Version and configuration covered:
Test or demonstration date and result:
Evidence supplier:
Accountable owner:
Limitations and open questions:
Decision, action and due date:

## Budgets: concurrent spend reservation

Reviewed finding: The named test asserts two admissions from eight competing attempts against a two-attempt allowance.
Evidence status: Test source reviewed; referenced test not run.

- [ ] Request: Configured-route accounting evidence, concurrent reservation results and final settlement examples.
- [ ] Verify: Configured prices, settlement, incomplete streams and counters across enabled routes and nodes.
- [ ] Identify the operator and any upstream provider responsible for the deployment checks.

Evidence reference / attachment:
Version and configuration covered:
Test or demonstration date and result:
Evidence supplier:
Accountable owner:
Limitations and open questions:
Decision, action and due date:

## Reliability: provider health and fallback

Reviewed finding: Named source paths describe provider health states, cooldown and trial behaviour, and health-aware fallback selection.
Evidence status: Implementation and source documentation reviewed.

- [ ] Request: Failure and recovery demonstrations for the providers and streaming workloads in use.
- [ ] Verify: Recovery times, partial streams, provider failure behaviour and restart durability.
- [ ] Identify the operator and any upstream provider responsible for the deployment checks.

Evidence reference / attachment:
Version and configuration covered:
Test or demonstration date and result:
Evidence supplier:
Accountable owner:
Limitations and open questions:
Decision, action and due date:

## Supply chain: a named dependency pin

Reviewed finding: The source manifest pins llama-cpp-sys-2 to =0.1.157; this identifies one declared dependency.
Evidence status: Dependency declaration reviewed.

- [ ] Request: Release artifact digest, dependency inventory, build provenance and exact model revisions.
- [ ] Verify: Delivered artifact digest, complete dependency inventory, model revisions and vulnerability assessment.
- [ ] Identify the operator and any upstream provider responsible for the deployment checks.

Evidence reference / attachment:
Version and configuration covered:
Test or demonstration date and result:
Evidence supplier:
Accountable owner:
Limitations and open questions:
Decision, action and due date:

## Inference: engine and upstream boundaries

Reviewed finding: Named sources distinguish GGUF execution on llama.cpp from exported accelerator assets.
Evidence status: Implementation and engine boundary reviewed.

- [ ] Request: Engine and model inventory plus endpoint, patch, execution-location and isolation evidence for each upstream.
- [ ] Verify: Separate inference services, patch levels, endpoint exposure, execution location and memory isolation.
- [ ] Identify the operator and any upstream provider responsible for the deployment checks.

Evidence reference / attachment:
Version and configuration covered:
Test or demonstration date and result:
Evidence supplier:
Accountable owner:
Limitations and open questions:
Decision, action and due date:

## Decision record

- [ ] List unresolved controls and assign an owner and follow-up date.
- [ ] Record any accepted limitations and the conditions for revisiting the decision.
- [ ] Recheck evidence after changes to the release, configuration, providers or models.

Decision and rationale:
Approved by / date:
Next review trigger:

Request release-specific evidence: sales@onequill.dev
