The work product is a map with the evidence attached to it
The work product is a mapped digital supply chain: the providers an application actually contacts, resolved to operators, companies, owners, and governing jurisdictions, with the observed chain set against the declared one and every divergence listed in both directions. Concentration and substitutability are assessed for the nodes that matter, and the evidence sits attached to each finding rather than behind it.
It is timestamped and reproducible. Every finding names the capture it came from, so the same session can be re-examined and a later capture can be compared against it to show what moved. Where a provider could not be attributed past a certain layer, that is stated plainly and the unresolved node is named, so the follow-on question has an address.
This yields indicators, not proof. A provider in an adverse jurisdiction is an exposure to weigh, not a verdict to act on, and it is presented that way, with provenance and confidence attached, so it can be argued with rather than simply believed.
Scope is stated alongside the findings. What was observed is what ran, on the paths exercised in that session. A provider reached only from a backend leaves no trace in a client session and is pursued through disclosure or a direct question instead. Routine cross-border operation is separated from exposure that actually warrants a decision, because almost every application touches several jurisdictions and treating that as a finding produces noise. An application whose observed chain matches its declared one, with no unattributed operator, is a real result and is reported as one.