CertiSigma Prudentia Suite
Essential English guide: project, modules, licence, architecture and glossary
This documentation describes the suite as a local and offline product. It is not a normative guide, not an incident response procedure and does not replace DPOs, CISOs, consultants, lawyers, auditors or competent functions. It explains what the suite does, how the modules are organized and which cautions should be maintained when working on cases, evidence, scenarios, prompts and exports.
1. The project
CertiSigma Prudentia Suite is a local suite for preparing and organizing work in privacy, cyber, evidential and organizational cases. It is designed for the moment when an operator must pause before responding, separate what is known from what is only assumed, understand which evidence is missing and decide how to ask for support without unnecessarily exposing the real case.
The operating principle is simple: a delicate situation should not immediately become a communication, a report, a prompt or a decision. It first needs to be put in order. The suite helps do this through four modules: Blindspot, Drill, Prompt Builder and Challenge/Mirror.
The project does not promise certifications, definitive diagnoses or automatic answers. It produces working material: gap maps, exercise scenarios, session records, structured requests, training reports and local exports. These outputs are useful precisely because they do not pretend to close the case: they make it more legible and easier to handle by whoever is responsible for deciding.
1.1 Who it is for
The suite is intended for competent operators: privacy and cybersecurity consultants, DPOs, IT managers, compliance officers, auditors, tabletop exercise facilitators, security contacts, legal functions and organizations that want to train their response posture under pressure.
It can also be used in less structured contexts, but it works best when guided by someone able to distinguish facts, assumptions, obligations, evidence and communication cautions.
1.2 Working principles
- Locality: the suite runs in the browser, without an application server and without uploading cases.
- Minimization: the tools help avoid telling more than necessary, especially when preparing an external request.
- Traceability: exports, seeds, reports and vaults preserve the work when it is useful to do so.
- Anti-inference: a difference, a category or a selection does not automatically become evidence or conclusion.
- Prudential training: the goal is not to reward a brilliant answer, but to train decisions compatible with evidence, proportionality and control of exposure.
1.3 Recommended path
A typical path starts with Blindspot, which brings out what is missing. The findings can become material for Drill, where the gap is exercised in a scenario. When support must be requested from an interlocutor or an external AI system, Prompt Builder helps formulate an orderly, non-identifying request. Finally, Challenge/Mirror trains prudential posture in short, tricky situations.
2. Blindspot module
Blindspot helps see what the organization does not see well enough: missing evidence, uncertain owners, controls that are declared but not demonstrable, unmapped dependencies, unavailable logs, processes entrusted to one person's memory or to a supplier.
The module does not start from the assumption that there is already an incident. It starts from a more useful question: if someone asked us today to prove this, could we do it?
2.1 What it produces
Blindspot produces a structured reading of exposures and blind spots. The result can become an operational register, a list of evidence to retrieve, a clarification plan or a seed for Drill.
A Blindspot finding is not a fault and not a definitive diagnosis. It is a work indication: it shows where the organizational response could become fragile if a request, a check, an audit, a challenge or a critical event arrived.
2.2 When to use it
- before an audit or an evidence request;
- when a process is formally described but the evidence is hard to locate;
- when a supplier, account, log, backup or technical integration is not clearly governed;
- when a gap should be turned into an exercise scenario.
2.3 Operational caution
Blindspot does not certify the state of the organization and does not replace an audit. It helps prepare one better. Its value is to surface questions that are often not asked until it is too late.
3. Drill module
Drill is the exercise module. It turns a doubt, a gap or a simulated case into a guided session, with roles, timing, complications, decisions, evidence and debriefing.
It does not technically simulate an attack. It simulates the organizational ability to respond: who decides, who documents, who communicates, which evidence is preserved, which assumptions remain assumptions and which steps require escalation.
3.1 What it produces
Drill produces exercise materials and records useful for improvement: decisions made, missing elements, roles involved, evidence requested, communications to prepare and points to correct after the session.
When it starts from a Blindspot seed, Drill preserves the link with the original finding: a gap does not remain a note, but becomes a practical response test.
3.2 When to use it
- to exercise a team before a real incident;
- to check whether a procedure is understandable and practicable;
- to turn a blind spot into a simulated event;
- to prepare debriefings and corrective actions without waiting for a crisis.
3.3 Operational caution
An exercise does not by itself prove that the organization is ready in every circumstance. It shows how the team worked in that session and which improvements emerged. The value is in the debriefing, not in the score.
4. Prompt Builder module
Prompt Builder helps build orderly, minimized and non-identifying external requests. It is useful when the user wants to ask an AI system, a supplier, a consultant or another interlocutor for help without transferring the real case, unnecessary data or raw attachments.
The module is not a chat system and does not send anything outside. It prepares text and structured traces that the user may copy, export, encrypt or archive locally.
4.1 What it produces
Prompt Builder produces prompts and working traces organized by objective, context, constraints, known facts, missing elements, requested output and communication cautions. It includes quick paths and more structured paths.
The important point is not only the wording of the prompt. The important point is the discipline that comes before the prompt: remove identifiers, declare uncertainties, avoid inventing facts, ask for limits, and keep control of what is shared.
4.2 When to use it
- when an external AI system may help, but the real case must not be disclosed;
- when a request to a supplier or consultant must be precise and proportionate;
- when the current state must be compared with a previous saved case;
- when a user tends to paste too much information into external tools.
4.3 Operational caution
Prompt Builder reduces the risk of over-disclosure, but does not guarantee that the copied text is safe in every context. The user remains responsible for reviewing the generated text before using it outside the local environment.
The comparison between states is documentary, not evidential in itself: a difference between two compilations shows that the written state has changed, not automatically that an action was actually performed.
5. Challenge/Mirror module
Challenge is the prudential training module. It presents short scenarios and asks the operator to choose what to do. The point is not to guess the pleasant answer, but to hold a decision under pressure without qualifying too early, disclosing too much, skipping evidence or accepting unsafe channels.
Challenge uses controlled decks, reproducible seeds, answer weights, required actions, incompatible choices and local reports. The scoring is deliberately strict: one risky shortcut can bring the result down even if other selected answers are good. This reflects how sensitive operational decisions often work.
5.1 What it produces
Challenge produces a local training history: scenarios completed, competences acquired, attempts, prudential floor, omissions, blocks covered and, when the path is complete, badges. These outputs are training artefacts, not professional certifications or individual suitability assessments.
The module also manages guided review. When the path shows a persistent difficulty, the guided step explains the logic of the scenario and shows reference answers, but it does not count for acquiring the competence.
5.2 Mirror
Mirror is the Challenge capstone focused on human factors of security. It does not measure personality, resilience, empathy or reliability. It shows situations in which a competent person may be pushed toward a worse decision: urgency, gratitude, fear, pressure, manipulation, isolation, desire to help or to appear trustworthy.
Mirror is therefore not an HR assessment and not a psychological profile. It is a situational exercise: it asks what is acting on the operator while the operator decides.
5.3 When to use it
- after Blindspot, Drill or Prompt Builder, to train recurring weak points;
- during awareness sessions where short, high-density decisions are useful;
- to check whether prudential principles remain active under pressure;
- to exercise off-site, supplier, AI, disclosure, evidence and escalation situations.
5.4 Operational caution
Challenge and Mirror must not be used to rank people, discipline operators or infer personal traits. A low result indicates a scenario or competence to train, not a personal diagnosis. Reports should be interpreted as training records.
6. CC BY 4.0 licence and attribution
The public project is released under the Creative Commons Attribution 4.0 International licence, unless a specific file states otherwise. This means it may be copied, adapted and redistributed, including with modifications, provided that attribution is preserved.
6.1 What must be kept
Anyone reusing the project must keep a correct attribution to Ten Sigma Sagl / CertiSigma, indicate whether changes were made and preserve the licence reference. Attribution must not imply endorsement by Ten Sigma Sagl or CertiSigma of modified, derived or redistributed versions.
A derived version may have its own public name, interface and organizational context. It must not present itself as an official CertiSigma release unless it is one.
6.2 ESR — Evidence-Safe Response
ESR — Evidence-Safe Response. The suite uses the technical prefix ESR to indicate the framework for prudential response based on evidence. The public name of the release is CertiSigma Prudentia Suite, but technical keys, files and some runtime objects use ESR as a neutral identifier. This separation is intentional: anyone reusing the project under the CC BY 4.0 licence must correctly attribute Ten Sigma Sagl / CertiSigma, but is not required to use CertiSigma as the operating name, trademark or technical prefix of their own derivative work.
6.3 Release holder
The attribution reference is Ten Sigma Sagl / CertiSigma. The user must always check the licence file included in the package and any additional notices distributed with the specific release.
7. Local architecture, files and JSON
This section describes the local CC BY package structure: a clean static release without internal revision files and without operator-training manuals not intended for public redistribution.
7.1 General structure of the integrated local package
index.html
LICENSE
README-LOCAL.txt
common/
README.md
assets/
css/
ESR-SUITE.css
ESR-BLINDSPOT.css
ESR-DRILL.css
ESR-PROMPT-BUILDER.css
ESR-CHALLENGE.css
js/
esr-common.js
esr-contract.js
ESR-CHALLENGE.js
data/
ESR-CANONICAL-CONTRACT.js
ESR-CHALLENGE-CONTRACT.js
img/
logo-certisigma.svg
logo-certisigma.png
esr-suite-logo.png
italy-switzerland/
index.html
LICENSE
ESR-BLINDSPOT.html
ESR-DRILL.html
ESR-PROMPT-BUILDER.html
ESR-CHALLENGE.html
assets/
documentazione.html
documentazione.md
data/
js/
scenarios/
blindspot/
drill/
challenge/
dev/
validate.html
ESR-CHALLENGE-validate.html
europe-switzerland/
index.html
ESR-BLINDSPOT.html
ESR-DRILL.html
ESR-PROMPT-BUILDER.html
assets/
documentation.html
documentation.md
scenarios/
dev/
index.html is the root selector. italy-switzerland/index.html is the Italian menu and, in the version with Challenge, presents four modules. europe-switzerland/ is the English branch and now includes the localized Challenge/Mirror module. The ESR-*.html pages are the application modules. The common/ folder contains shared assets and functions. The assets/data/ and scenarios/ folders contain models, contracts and scenarios.
User documentation therefore describes the integrated local package, not a revision or working archive.
7.3 Models and scenarios
Models describe taxonomies, labels, thresholds, UI texts, mappings, storage keys and local configurations. Scenarios describe cases, questions, answers, weights, competences, blocks and validation conditions.
Many data files are .js files exposing global objects, for example window.ESR_CHALLENGE_MODEL or window.ESR_CHALLENGE_SCENARIOS. This is intentional: it allows local operation even in browsers that restrict fetch() or dynamic imports when the suite is opened from the file system.
When a pure .json file also exists, as in the Challenge pack, it should be read as a data source or maintenance format that is easier to validate, compare and reuse. The page may load a JavaScript wrapper, while the JSON keeps the pure data structure.
7.4 Machine keys and localization
Languages change visible text, not machine keys. IDs such as scenario_id, answer_id, competence_id, block_id, badge_id or human_factor_id must remain stable across language versions, because they support reports, seeds, validators and interoperability.
Titles, questions, answers, descriptions, feedback, UI labels and report texts are translated. Technical identifiers are not translated as if they were copy. This distinction makes it possible to compare exports and sessions across different packages without losing the meaning of the data.
7.5 Export, vault and localStorage
Exports may contain sensitive information even when they do not contain names. For this reason the suite provides text or structured exports and, where available, encrypted export/import and a local encrypted vault.
The local vault uses the browser as a persistence location. It is useful for resuming work on the same workstation, but it is not a collaborative space and does not replace a document retention policy. On shared browsers or untrusted devices it should be used with caution or avoided.
7.6 Validation
The dev/ folder contains control tools for those who modify models and scenarios. Validators help detect inconsistent IDs, wrong weights, unreachable scenarios, missing mappings and other structural breaks. They are not operational modules for the end user.
8. Glossary
Anti-inference
The discipline that prevents a selection, a difference or a category from becoming an unsupported conclusion.
Badge
A training indicator assigned by Challenge when a threshold or path condition is reached. It is not a professional certification.
Blindspot
The module that surfaces blind spots, missing evidence and ownership fragilities.
Challenge
The prudential training module based on short scenarios, multiple choices, competences, blocks and competence acquisition.
Trained competence
The operational area that a Challenge scenario is intended to exercise, for example evidence preservation, minimization, escalation or supplier management.
Compare states
A Prompt Builder function that compares the current compilation with a previous version. It shows documentary differences; it does not automatically prove actions performed.
Local dossier
A file or state produced by the suite. It may contain sensitive information and must be preserved with consistent safeguards.
Drill
The exercise module that turns a case or seed into a guided session with decisions, evidence and debriefing.
Encrypted export
A file exported in protected form through a passphrase. The suite does not store the passphrase and cannot recover it.
ESR
Acronym for Evidence-Safe Response. It is the neutral technical prefix used to indicate the framework for prudential response based on evidence. It does not replace the public name CertiSigma Prudentia Suite or the attribution obligation to Ten Sigma Sagl / CertiSigma under the CC BY 4.0 licence.
JSON
A structured data format used to represent scenarios, seeds, reports or configurations. In the suite, some JSON data is distributed inside JavaScript files to ensure local loading without a server.
Competence acquired
A training outcome reached in a scenario or competence of the Challenge module. It indicates successful training, not personal suitability.
Mirror
The Challenge capstone on human factors of security. It is not psychological profiling and does not measure personal traits.
Owner
The person or function responsible for evidence, a process, a decision or a follow-up.
Passphrase
A phrase used to encrypt and decrypt exports or vaults. It must be kept by the user.
Prompt Builder
The module that helps build orderly, minimized and non-identifying external requests.
Blind spot
An area where a control, evidence, responsibility or reconstruction is not as clear or available as it should be.
Evidential readiness
The ability to demonstrate what the organization declares, with available evidence, clear owners and documentable decisions.
Seed
A data object that transfers information from one module to another, for example from Blindspot to Drill, without automatically turning a finding into a conclusion.
Local encrypted vault
An encrypted browser save, useful for resuming work on the same workstation.
