{
 "artifacts": [
  {
   "authoritativeSourceUrl": "https://enablement.cc/ml/20x/trust",
   "bytes": 39047,
   "contentType": "text/html; charset=utf-8",
   "key": "trust.html",
   "label": "Trust center landing page",
   "lastRefreshOutcome": "refreshed",
   "mirrorUrl": "https://d3arb1q8mam5wu.cloudfront.net/trust.html",
   "mirroredAgeHuman": "0 seconds ago",
   "mirroredAgeSeconds": 0,
   "mirroredAt": "2026-08-07T05:28:49Z",
   "refreshedThisRun": true,
   "sha256": "1a2b6ce986cb90f93a4fc88afd3d9fe11319f242dec366942065a1e3c6df6142",
   "whyThisIsPublic": "Served unauthenticated at /ml/20x/trust; listed in PUBLIC_20X_VIEWS as get_trust. Contains the offering summary only."
  },
  {
   "authoritativeSourceUrl": "https://enablement.cc/ml/20x/package?src_id=1711",
   "bytes": 34467,
   "contentType": "application/json; charset=utf-8",
   "key": "package.json",
   "label": "Certification Package Overview (CPO)",
   "lastRefreshOutcome": "refreshed",
   "mirrorUrl": "https://d3arb1q8mam5wu.cloudfront.net/package.json",
   "mirroredAgeHuman": "0 seconds ago",
   "mirroredAgeSeconds": 0,
   "mirroredAt": "2026-08-07T05:28:49Z",
   "refreshedThisRun": true,
   "sha256": "906c4d8990ec4b93e6e5c9b77577fdbcb2590c2cffecc9f35a346c3f057a775f",
   "whyThisIsPublic": "Served unauthenticated; PUBLIC_20X_VIEWS get_package. CDS-CSO-PUB requires the offering summary to be public."
  },
  {
   "authoritativeSourceUrl": "https://enablement.cc/ml/20x/scg",
   "bytes": 78948,
   "contentType": "text/markdown; charset=utf-8",
   "key": "scg.md",
   "label": "Secure Configuration Guide",
   "lastRefreshOutcome": "refreshed",
   "mirrorUrl": "https://d3arb1q8mam5wu.cloudfront.net/scg.md",
   "mirroredAgeHuman": "0 seconds ago",
   "mirroredAgeSeconds": 0,
   "mirroredAt": "2026-08-07T05:28:49Z",
   "refreshedThisRun": true,
   "sha256": "574cf65aa6d69f57411d8f7b9a82d665e7c5430a63a11f8eef8847ddaa6eb200",
   "whyThisIsPublic": "Served unauthenticated; PUBLIC_20X_VIEWS get_scg. CDS-CSO-PUB item 12 requires the SCG to be publicly available."
  },
  {
   "authoritativeSourceUrl": "https://enablement.cc/ml/20x/availability",
   "bytes": 26053,
   "contentType": "application/json; charset=utf-8",
   "key": "availability.json",
   "label": "Availability report (machine-readable)",
   "lastRefreshOutcome": "refreshed",
   "mirrorUrl": "https://d3arb1q8mam5wu.cloudfront.net/availability.json",
   "mirroredAgeHuman": "0 seconds ago",
   "mirroredAgeSeconds": 0,
   "mirroredAt": "2026-08-07T05:28:49Z",
   "refreshedThisRun": true,
   "sha256": "d632ccad343a048035f852bcb01feab4a2c58f3c99faaca5f38de5f976ed1dce",
   "whyThisIsPublic": "Served unauthenticated; PUBLIC_20X_VIEWS get_availability. Daily rollups and incident windows only \u2014 no per-probe rows, no versions, no error bodies, so CDS-CSO-RIS is not engaged."
  },
  {
   "authoritativeSourceUrl": "https://enablement.cc/ml/20x/status",
   "bytes": 22457,
   "contentType": "text/html; charset=utf-8",
   "key": "status.html",
   "label": "Availability report (human-readable)",
   "lastRefreshOutcome": "refreshed",
   "mirrorUrl": "https://d3arb1q8mam5wu.cloudfront.net/status.html",
   "mirroredAgeHuman": "0 seconds ago",
   "mirroredAgeSeconds": 0,
   "mirroredAt": "2026-08-07T05:28:49Z",
   "refreshedThisRun": true,
   "sha256": "61cdd3a2b90b612921b01e5e33f9c87a0557f1235bdf590732f5e1d5c3f7852a",
   "whyThisIsPublic": "Served unauthenticated; PUBLIC_20X_VIEWS get_status. Same document as availability.json, rendered."
  }
 ],
 "documentType": "Trust Center Mirror Manifest",
 "fedRampId": "FR2628647239",
 "generatedAt": "2026-08-07T05:28:48Z",
 "provider": "Advent Business Company Inc.",
 "publicSurface": {
  "allowList": [
   "trust.html",
   "package.json",
   "scg.md",
   "availability.json",
   "status.html",
   "index.html",
   "mirror-manifest.json",
   "mirror-availability.json",
   "external-probe-history.json"
  ],
  "basis": "Explicit allow-list, not an exclusion list. The refresher fetches only the literal paths in MIRROR_SOURCES, holds no trust-center bearer token so every gated artifact answers 401 to it, writes only on HTTP 200, and the S3 bucket policy grants read on these exact object ARNs with no wildcard \u2014 so an object outside this list is not reachable from the internet at all.",
  "gatedDataIsNotHere": "No token-gated artifact is mirrored: not /20x/docs, /20x/doc/<key>, /20x/evidence/*, and not the SDR, KSI, VDR, AVI, OCR, historical, assessor or query services. Those remain available only through the live trust center under bearer-token control with per-access logging (CDS-TRC-AAI)."
 },
 "refreshIntervalMinutes": 15,
 "service": "Enablement\u00ae",
 "staleness": {
  "howToTellFreshFromStale": "Each artifact carries mirroredAt (UTC) here and as the S3 object metadata header x-amz-meta-mirrored-at. The refresher runs every 15 minutes, so an age much beyond that means either the offering stopped answering (see mirror-availability.json, which distinguishes the two) or the refresher itself stopped. Both are alarmed.",
  "oldestArtifactAgeHuman": "0 seconds ago",
  "oldestArtifactAgeSeconds": 0,
  "refresherAlarm": "The refresher's own liveness is watched by cm_freshness_worker.py signal `trust_mirror`, which reads generatedAt from this document and emails fedramp-security@adventbusiness.com when it ages past its warn/breach budget. A silently frozen mirror is the failure mode this design most has to avoid, so it is not left to be noticed."
 },
 "thisIsNotAuthoritative": "This is a POINT-IN-TIME COPY, not the live trust center. The authoritative endpoints are on the offering itself at https://enablement.cc/ml/20x/... and take precedence over anything here whenever they are reachable. Read mirroredAt on each artifact before relying on it.",
 "whyThisMirrorExists": "CDS-TRC-USH, CDS-CSO-UTC and the independent-hosting arm of CDS-CSO-AVR require certification data to remain shareable when the offering is not. The live trust center runs inside the offering it describes and cannot meet that clause from where it sits; this mirror runs in a different AWS partition, account and region and can."
}