FedRAMP Trust Center — off-CSO mirror

Advent Business Company Inc. · Enablement® · FedRAMP ID FR2628647239

Mirrored public certification data

ArtifactCopiedAuthoritative SHA-256 (first 16)
Trust center landing page
trust.html
0 seconds ago
2026-08-07T05:28:49Z
live source1a2b6ce986cb90f9
Certification Package Overview (CPO)
package.json
0 seconds ago
2026-08-07T05:28:49Z
live source906c4d8990ec4b93
Secure Configuration Guide
scg.md
0 seconds ago
2026-08-07T05:28:49Z
live source574cf65aa6d69f57
Availability report (machine-readable)
availability.json
0 seconds ago
2026-08-07T05:28:49Z
live sourced632ccad343a0480
Availability report (human-readable)
status.html
0 seconds ago
2026-08-07T05:28:49Z
live source61cdd3a2b90b6129

SHA-256 is over the exact bytes the offering served. The mirrored files are byte-identical copies — nothing is rewritten, annotated or reformatted — so you can fetch the live URL and compare hashes to confirm this copy is faithful. One consequence, stated rather than hidden: because trust.html and status.html are unmodified, the links and the logo inside them still point at enablement.cc and will not resolve while the offering is down. Use this page, not those, as the entry point during an outage — it loads nothing from anywhere.

Is the offering up? — observed from outside it

Every public trust-center URL answered HTTP 200 to an unauthenticated GET from outside the offering.

100.0% of 23 external observations found every public URL answering since 2026-08-07T00:28:16Z. Machine-readable: mirror-availability.json · external-probe-history.json. The offering’s own, finer-grained availability report is mirrored above as availability.json; it measures a 5-minute probe series but is served from the host it measures, so it cannot report its own outage. This observation can, and that difference is the point.

What is deliberately NOT here

Only artifacts that are already public without authentication are mirrored. Token-gated certification data — the evidence index, the individual package documents, and the SDR, KSI, VDR, AVI, OCR, historical, assessor and query services — is not mirrored and never will be. A static bucket has no token gate, so anything placed here would be world-readable. Those artifacts stay on the live trust center under bearer-token control with per-access logging. Agencies and assessors request a token at rajesh@adventbusiness.com.

The copy list is an explicit allow-list of 9 object keys, and the bucket policy grants read on exactly those object ARNs with no wildcard — so an object outside the list is not reachable from the internet even if one were somehow uploaded. The list is published in mirror-manifest.json under publicSurface.allowList.