Chapter 10 · Syphio Runtime
Rule Registry
Rules define applicability, detection, required Evidence, severity, compatibility and the limits of each verification method.
Chapter outcome
You will be able to trace a Finding back to the exact public rule contract used to evaluate it.
Stable identity and version
Each reviewed public rule has a stable SYP identifier, a human-readable URL and a versioned methodology.
Complete public contract
A Registry entry documents Description, Severity, Why, Detection, Evidence, Examples, Limitations, References and Compatibility.
Finding relationship
The rule ID and version in a Finding identify the detection contract used for that result. Later rule changes must not silently rewrite an existing report.
Registry scope
Only reviewed public rules appear in the Registry. Syphio does not claim a fixed rule count, and an unpublished rule is not presented as available coverage.
References
External references provide relevant platform documentation. They support the detection contract but do not replace the Finding’s own Evidence.