{"assessor":{"assessorID":"000000","id":"000000","name":"Not yet assigned; independent assessment (IV&V) in procurement"},"certifiedServices":[{"dateAvailable":"2026-07-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"The PaaS platform-build layer: business users author complete BPMN processes and applications visually and get web and mobile interfaces generated automatically, with no coding. Customer-authored content is treated as untrusted and runs under server-authoritative tenant binding. Public description capability 1; Secure Configuration Guide \u00a714.","serviceModel":"PaaS","serviceName":"Enablement No-Code Process Designer"},{"dateAvailable":"2026-07-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"Deterministic server-side execution of published processes \u2014 forms, tasks, approvals, and integrations. No generative model is in the execution path, so a process behaves identically on every run and never invents an answer. Public description capability 1.","serviceModel":"SaaS","serviceName":"Enablement Process Execution Engine"},{"dateAvailable":"2026-07-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"Mobile client for the same processes and forms as the web application, with device binding on authenticated sessions. Referenced in the public description as the automatically generated mobile interface.","serviceModel":"SaaS","serviceName":"Enablement Mobile Access"},{"dateAvailable":"2026-07-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"Role-based and attribute-based access control (RBAC/ABAC), user lifecycle, time-boxed privileged grants, and the full authentication range: passkeys, SAML SSO, authenticator apps, and email OTP. The password is proven by challenge-response and is never transmitted to the server. Public description capabilities 5 and 7; Secure Configuration Guide \u00a72\u2013\u00a77.","serviceModel":"SaaS","serviceName":"Enablement Identity, Authentication and Access Control"},{"dateAvailable":"2026-07-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"Encrypted file storage and sharing, secured email, watermarked read-only viewing, and malware scanning of every upload \u2014 all inside the boundary, with no file content sent to an external scanning service. Secure Configuration Guide \u00a710.2\u2013\u00a710.5.","serviceModel":"SaaS","serviceName":"Enablement Secured Files and Secured Email"},{"dateAvailable":"2026-07-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"Automatic CUI and distribution-statement marking to federal standards (DoW and NARA), plus a share-time authorization check that warns or blocks before a document reaches unauthorized personnel. Public description capabilities 5 and 6; Secure Configuration Guide \u00a710.1.","serviceModel":"SaaS","serviceName":"Enablement Automated Marking and Share-Time Leak Prevention"},{"dateAvailable":"2026-07-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"Tamper-evident audit capture of user and administrative activity with scoped audit-log access for customer administrators, plus execution-pattern anomaly detection and an operator kill switch for a runaway process or account. Secure Configuration Guide \u00a79.","serviceModel":"SaaS","serviceName":"Enablement Audit and Activity Monitoring"},{"dateAvailable":"2026-07-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"Scheduled and recurring execution of published processes, operated inside the boundary with no external scheduler or orchestration service.","serviceModel":"SaaS","serviceName":"Enablement Process Scheduler"},{"dateAvailable":"2026-04-17","inMinimumAssessmentScope":true,"minimumAssessmentScopeReference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1-2.3, \u00a72.6","securityCategory":{"categorizationScope":"System-wide FIPS 199 high-water mark; not separately derived for this service.","certificationClass":"Class C","certificationImpactLevel":"Moderate","fips199SystemCategorization":"High"},"serviceDescription":"Native, always-on continuous monitoring operated entirely within the authorization boundary, covering network vulnerability, container/IaC, cloud-posture, and host configuration/CVE assessment, producing OSCAL + FedRAMP CR26 machine-readable compliance evidence. No data is sent to any external scanning or monitoring service.","serviceModel":"SaaS","serviceName":"Enablement Continuous Monitoring"}],"certifiedServicesNote":{"dateAvailableBasis":"dateAvailable is the date the service entered the declared FedRAMP 20x certification scope (Initial Implementation approval, 2026-07-17), not a commercial general-availability date. The platform capabilities predate the FedRAMP effort; their original ship dates are not published here because they are not the dates that matter to this certification.","rule":"CDS-CSO-SVC","schemaNote":"securityCategory, inMinimumAssessmentScope, and serviceModel are additional properties. The pinned FedRAMP CPO schema (fedramp-certification-package-overview-schema-2026-06-24.json) defines no field for a service security category; when it does, these move into it.","scopeDetermination":"Every service listed in certifiedServices is inside the FedRAMP Minimum Assessment Scope; servicesNotIncluded names what is outside it. Both lists are public and require no access to underlying FedRAMP Certification Data, which is what this rule requires."},"contactInformation":[{"contactEmail":"rajesh@adventbusiness.com","contactName":"Security Team","contactType":"Security"},{"contactEmail":"support@adventbusiness.com","contactName":"Sales Team","contactType":"Sales"},{"contactEmail":"fedramp-security@adventbusiness.com","contactName":"FedRAMP Security Inbox (AFC-CSO-INB)","contactType":"FedRAMP Security Inbox"}],"crossFormatConsistency":{"documentsPublishedInBothFormats":[{"humanReadable":"https://enablement.cc/ml/20x/trust","machineReadable":"https://enablement.cc/ml/20x/package?src_id=1711","renderer":"render_trust_html(cpo)"},{"humanReadable":"https://enablement.cc/ml/20x/status","machineReadable":"https://enablement.cc/ml/20x/availability","renderer":"render_status_html(doc)"}],"howOmissionIsPrevented":"Single-sourcing stops the page contradicting the JSON; it does not stop the page omitting part of it, which is the failure that actually occurred when availability endpoints were added to the document after the HTML tables were written. fedramp_20x.cpo_html_divergence and availability_html_divergence walk every scalar in the JSON and assert it reached the page, so a new field must be either rendered or added to a named exemption list carrying its reason.","howStalenessIsPrevented":"Structurally, not procedurally. Each human-readable page is RENDERED FROM the machine-readable document at request time and is handed no other source of facts \u2014 no database handle, no second query, no cached copy. A stale HTML rendering is therefore not a state this service can be in.","howToVerifyIndependently":"Fetch both formats and diff them yourself, or run the provider's own check: `python3 app/routes/fedramp_20x.py --selftest` fails on any divergence, and the unit suite re-runs it across an outage, a measurement gap, a partial day, a single-endpoint window and an empty log.","limitationsOfThisCheck":"It runs at build and self-test time, not on every request, so it gates a release rather than a response. It compares values one way (every JSON scalar must appear in the HTML); the reverse needs no check because the page has no other source. Booleans and nulls are matched by field rather than by literal, since a page renders them as words.","rule":"CDS-CSO-CBF"},"enablementArtifacts":{"machineReadable":{"access_log_summary":"https://enablement.cc/ml/20x/access-log-summary","availability":"https://enablement.cc/ml/20x/availability","avi":"https://enablement.cc/ml/20x/avi?src_id=1711","historical":"https://enablement.cc/ml/20x/historical?src_id=1711","ksi":"https://enablement.cc/ml/20x/ksi?src_id=1711","ocr":"https://enablement.cc/ml/20x/ocr?src_id=1711","oscal_ar":"https://enablement.cc/ml/oscal/assessment-results?src_id=1711","oscal_poam":"https://enablement.cc/ml/oscal/poam?src_id=1711","sdr":"https://enablement.cc/ml/20x/sdr?src_id=1711","vdr":"https://enablement.cc/ml/20x/vdr?src_id=1711"},"offCsoMirror":{"authoritative":false,"availability":"https://d3arb1q8mam5wu.cloudfront.net/availability.json","base":"https://d3arb1q8mam5wu.cloudfront.net","mirrorExternalObservation":"https://d3arb1q8mam5wu.cloudfront.net/mirror-availability.json","mirrorExternalObservationHistory":"https://d3arb1q8mam5wu.cloudfront.net/external-probe-history.json","mirrorManifest":"https://d3arb1q8mam5wu.cloudfront.net/mirror-manifest.json","note":"Point-in-time copies, not the live endpoints. Read mirroredAt in mirrorManifest before relying on any of them. Rules served: CDS-TRC-USH, CDS-CSO-UTC, and the independent-hosting arm of CDS-CSO-AVR.","package":"https://d3arb1q8mam5wu.cloudfront.net/package.json","refreshIntervalMinutes":15,"scg":"https://d3arb1q8mam5wu.cloudfront.net/scg.md","status":"https://d3arb1q8mam5wu.cloudfront.net/status.html","trust":"https://d3arb1q8mam5wu.cloudfront.net/trust.html"},"public":{"availability":"https://enablement.cc/ml/20x/availability","package":"https://enablement.cc/ml/20x/package?src_id=1711","scg":"https://enablement.cc/ml/20x/scg","status":"https://enablement.cc/ml/20x/status","trust":"https://enablement.cc/ml/20x/trust"},"rulesVersion":"2026.07.01.01","schemaPin":"2026-06-24","schemaPinSynced":"2026-07-30"},"securityCategorization":{"authority":"MINIMUM_ASSESSMENT_SCOPE.md \u00a73 (information flows and security categories) and \u00a79.1 item 8 (Class C declaration). Available token-gated at https://enablement.cc/ml/20x/doc/mas.","categorizationBasis":"FIPS 199 high-water mark across the 13 NIST SP 800-60 information types the platform handles (Personal Identity & Authentication rated High/High/High is the driver), per SSP \u00a73 Table 3.1 and Appendix K Table K.1. Digital identity level IAL2/AAL2/FAL2, with IAL3/AAL3/FAL3 supported where an agency requires it.","fips199Rev5PackageCategorization":"High","perServiceCategorization":"NOT declared per service. Every service below handles the same federal customer data inside one authorization boundary, on the same in-scope components, so the system-level high-water mark applies uniformly. No service carries a separately derived C/I/A triad, and none is invented here to fill the column.","reconciliation":"Two categorizations are in force at once and both are accurate. The Rev5 authorization package of record categorises the system FIPS 199 High. The FedRAMP 20x certification being pursued is Class C, which corresponds to Moderate impact; that declaration was made by the System Owner on 2026-07-10 and is tracked as an open, deliberate reconciliation item. Class D (the 20x High path) is the intended upgrade when FedRAMP opens it, estimated 2027. A prospective customer should read this as: the system is built and assessed to a High water mark, and the certification currently being sought is Class C / Moderate.","twentyXCertificationClass":"Class C","twentyXImpactLevel":"Moderate"},"serviceIdentification":{"cageCode":"627S4","certificationClass":"Class C","certificationPath":"Program","certificationType":"20x","deploymentModel":"Government Community Cloud","description":"Enablement\u00ae is the self-contained, no-code compliance platform you fully own. It is deterministic (no AI, no hallucinations, no token costs), portable to any cloud or data center, CMMC-ready with native continuous monitoring, and zero-trust with no third-party data egress. It is error-proof by design, through automated access control, automated marking, and share-time leak prevention. Built by CMMI-appraised, ISO-certified Advent.\n\nEnablement\u00ae\nOwn your compliance. Send nothing out. Need no experts, no AI.\nMost compliance platforms make you hire specialists, wire in third-party services, and increasingly hand your data to AI you cannot audit. Enablement flips that. It is a self-contained, deterministic, zero-trust platform where your teams build and run everything visually, and nothing ever leaves your boundary.\n\n1. No-code process building. No developers, no AI, no token bills.\nBusiness users design complete workflows (BPMN) visually and get web and mobile interfaces generated automatically, with no coding, no integration team, and no consultants. Because the engine is deterministic rather than generative, it is free from AI hallucination and carries zero per-token cost. Every process behaves the same way every time, is fully auditable, and never invents an answer. What you design is exactly what runs.\n\n2. Deploy anywhere. True portability.\nOne platform, any environment. Run Enablement in any commercial cloud, government cloud, or your own data center, or as a fully self-contained appliance. There is no cloud lock-in and no vendor-specific dependency. Move it, mirror it, or air-gap it.\n\n3. Rapid CMMC Level 2 compliance with built-in continuous monitoring.\nCMMC Level 2 readiness comes out of the box, backed by native, always-on continuous monitoring, with no separate scanning products to buy, license, or integrate. Assess, monitor, and produce authorization evidence from day one, on a single system.\n\n4. A genuine zero-trust boundary. Your data never touches a third party.\nEnablement keeps everything inside your perimeter. Your source code lives in its own repository. No data is sent to any outside service for user authentication, code-quality analysis, container scanning, file scanning, or continuous monitoring. Nothing is shipped off to a SaaS, a scanning vendor, or an AI provider. What happens in your boundary stays in your boundary.\n\n5. RBAC and ABAC, with automated document marking that removes human error.\nFine-grained role-based and attribute-based access control (RBAC and ABAC) governs exactly who can see and do what. Documents are marked automatically to federal standards (DoW and NARA), with no manual labeling, no inconsistent tags, and no mislabeled files. The platform does the marking so people cannot get it wrong.\n\n6. Stop data leaks before they happen, and the liability that follows.\nHuman error is the number one cause of data spillage. Enablement checks every share and warns before a document reaches unauthorized personnel, catching the mistake at the moment of sharing rather than after a breach. That turns a potential disclosure, and the corporate liability that comes with it, into a blocked action.\n\n7. Every authentication method, and your password never leaves your device.\nSupport the full range of sign-in: passkeys, single sign-on (SSO), authenticator apps, email, and more. Critically, the password is never sent over the network or to the server. It is proven with a challenge-response so the secret never leaves the user's device. Strong, flexible, phishing-resistant authentication without ever transmitting the credential.","fedRampId":"FR2628647239","fedRampPackageId":"ADVENTBUSINESS-ENB","impactLevel":"Moderate","implementationPhase":"Initial Implementation","logo":"https://enablement.cc/assets/enablement/logo.png","marketplaceUrl":"https://fedramp.gov/marketplace/products/FR2628647239","providerName":"Advent Business Company Inc.","serviceAcronym":"ENB","serviceDescription":"Enablement\u00ae is the self-contained, no-code compliance platform you fully own. It is deterministic (no AI, no hallucinations, no token costs), portable to any cloud or data center, CMMC-ready with native continuous monitoring, and zero-trust with no third-party data egress. It is error-proof by design, through automated access control, automated marking, and share-time leak prevention. Built by CMMI-appraised, ISO-certified Advent.\n\nEnablement\u00ae\nOwn your compliance. Send nothing out. Need no experts, no AI.\nMost compliance platforms make you hire specialists, wire in third-party services, and increasingly hand your data to AI you cannot audit. Enablement flips that. It is a self-contained, deterministic, zero-trust platform where your teams build and run everything visually, and nothing ever leaves your boundary.\n\n1. No-code process building. No developers, no AI, no token bills.\nBusiness users design complete workflows (BPMN) visually and get web and mobile interfaces generated automatically, with no coding, no integration team, and no consultants. Because the engine is deterministic rather than generative, it is free from AI hallucination and carries zero per-token cost. Every process behaves the same way every time, is fully auditable, and never invents an answer. What you design is exactly what runs.\n\n2. Deploy anywhere. True portability.\nOne platform, any environment. Run Enablement in any commercial cloud, government cloud, or your own data center, or as a fully self-contained appliance. There is no cloud lock-in and no vendor-specific dependency. Move it, mirror it, or air-gap it.\n\n3. Rapid CMMC Level 2 compliance with built-in continuous monitoring.\nCMMC Level 2 readiness comes out of the box, backed by native, always-on continuous monitoring, with no separate scanning products to buy, license, or integrate. Assess, monitor, and produce authorization evidence from day one, on a single system.\n\n4. A genuine zero-trust boundary. Your data never touches a third party.\nEnablement keeps everything inside your perimeter. Your source code lives in its own repository. No data is sent to any outside service for user authentication, code-quality analysis, container scanning, file scanning, or continuous monitoring. Nothing is shipped off to a SaaS, a scanning vendor, or an AI provider. What happens in your boundary stays in your boundary.\n\n5. RBAC and ABAC, with automated document marking that removes human error.\nFine-grained role-based and attribute-based access control (RBAC and ABAC) governs exactly who can see and do what. Documents are marked automatically to federal standards (DoW and NARA), with no manual labeling, no inconsistent tags, and no mislabeled files. The platform does the marking so people cannot get it wrong.\n\n6. Stop data leaks before they happen, and the liability that follows.\nHuman error is the number one cause of data spillage. Enablement checks every share and warns before a document reaches unauthorized personnel, catching the mistake at the moment of sharing rather than after a breach. That turns a potential disclosure, and the corporate liability that comes with it, into a blocked action.\n\n7. Every authentication method, and your password never leaves your device.\nSupport the full range of sign-in: passkeys, single sign-on (SSO), authenticator apps, email, and more. Critically, the password is never sent over the network or to the server. It is proven with a challenge-response so the secret never leaves the user's device. Strong, flexible, phishing-resistant authentication without ever transmitting the credential.","serviceModel":"SaaS, PaaS","serviceName":"Enablement\u00ae","uei":"C7LGVA7B5JT1","website":"https://enablement.cc"},"serviceProperties":{"additionalRepositories":[{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Vulnerability Detail Report (VER-RPT-VDT)","repositoryType":["Machine-Readable Authorization Data"],"url":"https://enablement.cc/ml/20x/vdr?src_id=1711"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Accepted Vulnerability Info (VER-RPT-AVI)","repositoryType":["Machine-Readable Authorization Data"],"url":"https://enablement.cc/ml/20x/avi?src_id=1711"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Historical VER activity for automated retrieval (VER-TFR-MRH)","repositoryType":["Machine-Readable Authorization Data"],"url":"https://enablement.cc/ml/20x/historical?src_id=1711"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Ongoing Certification Report (CCM-OCR-AVL)","repositoryType":["Machine-Readable Authorization Data"],"url":"https://enablement.cc/ml/20x/ocr?src_id=1711"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Security Decision Record (SDR-CSO-FRR)","repositoryType":["Machine-Readable Authorization Data"],"url":"https://enablement.cc/ml/20x/sdr?src_id=1711"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"KSI evidence report (FRC-CSX-VVK / FRC-CSX-MOT)","repositoryType":["Machine-Readable Authorization Data"],"url":"https://enablement.cc/ml/20x/ksi?src_id=1711"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Rev5 OSCAL Plan of Action & Milestones","repositoryType":["Machine-Readable Authorization Data"],"url":"https://enablement.cc/ml/oscal/poam?src_id=1711"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Rev5 OSCAL Assessment Results","repositoryType":["Machine-Readable Authorization Data"],"url":"https://enablement.cc/ml/oscal/assessment-results?src_id=1711"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Incident Evaluation & Communication runbook (IEC-CSO-*)","repositoryType":["Assessment Documentation"],"url":"https://enablement.cc/ml/20x/doc/iec-runbook"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"KSI Self-Assessment \u2014 46 Class C KSIs with implementation, evidence pointers, and self-verdicts (IVV Verify-step input)","repositoryType":["Assessment Documentation"],"url":"https://enablement.cc/ml/20x/doc/ksi-self-assessment"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Minimum Assessment Scope (MAS-CSO-*)","repositoryType":["Assessment Documentation"],"url":"https://enablement.cc/ml/20x/doc/mas"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Plan of Action & Milestones \u2014 open 20x items","repositoryType":["Assessment Documentation"],"url":"https://enablement.cc/ml/20x/doc/poam"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Class C ruleset status tracker (all 15 rulesets)","repositoryType":["Assessment Documentation"],"url":"https://enablement.cc/ml/20x/doc/ruleset-status"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Significant Change Notification process (SCN-CSO-*)","repositoryType":["Assessment Documentation"],"url":"https://enablement.cc/ml/20x/doc/scn-process"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"KSI Validation Design & Measurement System \u2014 end-to-end trace of every automated validation method (scope, source, code/thresholds, failure semantics, preservation) per the 20x assessor guidance","repositoryType":["Assessment Documentation"],"url":"https://enablement.cc/ml/20x/doc/validation-design"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Assessment document index + supporting evidence records (SSP appendices, signed records, boundary diagrams)","repositoryType":["Assessment Documentation","Evidence Repository"],"url":"https://enablement.cc/ml/20x/docs"},{"accessRequestInstructions":"Request tenant-scoped API access from rajesh@adventbusiness.com.","authenticationRequired":true,"repositoryDescription":"Trust-center access-log summary + retention statement (CDS-TRC-ACL) \u2014 monthly access counts by endpoint and outcome, so an assessor can verify access logging without a database account","repositoryType":["Assessment Documentation"],"url":"https://enablement.cc/ml/20x/access-log-summary"},{"authenticationRequired":false,"repositoryDescription":"Availability report (CDS-CSO-AVR): current state and 30-day historical availability of core services with availability incidents, machine-readable. Public, no token required.","repositoryType":["Availability Reporting"],"url":"https://enablement.cc/ml/20x/availability"},{"authenticationRequired":false,"repositoryDescription":"Availability status page (CDS-CSO-AVR), human-readable rendering of the same data. Public, no token required.","repositoryType":["Availability Reporting"],"url":"https://enablement.cc/ml/20x/status"}],"availabilityReporting":{"authenticationRequired":false,"offCsoExternalObservationUrl":"https://d3arb1q8mam5wu.cloudfront.net/mirror-availability.json","offCsoMirrorDescription":"The independent-hosting arm of CDS-CSO-AVR. The mirror's refresher is itself an external probe running in the AWS commercial partition: every 15 minutes it records whether this offering answered, and when it did not, it publishes that \u2014 with a first-failure time and a running duration \u2014 from infrastructure the outage does not touch. The mirrored copy of the availability report is last-known-good and stamped; the external observation is live.","offCsoMirrorUrl":"https://d3arb1q8mam5wu.cloudfront.net/index.html","repositoryDescription":"Public availability status service (CDS-CSO-AVR): current state, 30-day history, and availability incidents. Machine-readable JSON at https://enablement.cc/ml/20x/availability. This endpoint is hosted on the infrastructure it measures and therefore cannot report an outage it is part of; the off-CSO mirror below can, and does.","repositoryType":["Availability Reporting"],"url":"https://enablement.cc/ml/20x/status"},"businessCategory":["Cybersecurity & Risk Management","Development Tools","Data Management","Artificial Intelligence (AI)","System Administration","Mobile Device Management (MDM)","Governance, Risk, and Compliance (GRC)","Content Management System (CMS)","Operations Management","Finance"],"deploymentModel":"Government Community Cloud","digitalIdentityLevel":"IAL2/AAL2","nextOngoingCertificationReportDate":"2026-10-01","secureConfigurationGuidance":{"authenticationRequired":false,"repositoryDescription":"Enablement\u00ae Secure Configuration Guide \u2014 recommended secure configuration, use instructions, and secure defaults for customer administrators.","repositoryType":["Secure Configuration Guidance"],"url":"https://enablement.cc/ml/20x/scg"},"secureConfigurationGuide":"https://enablement.cc/ml/20x/scg","serviceType":["SaaS","PaaS"],"trustCenter":{"accessRequestInstructions":"Public page. Tokens for access-controlled artifacts: rajesh@adventbusiness.com","authenticationRequired":false,"offCsoMirrorDescription":"Point-in-time copy of the PUBLIC trust-center artifacts (this CPO, the trust page, the SCG, and both availability formats), refreshed every 15 minutes into the AWS commercial partition (account 971328156383, us-east-1) and served from S3 via CloudFront. It shares no partition, account, region, host, database, web server, TLS certificate or DNS zone with production, so it stays reachable during an outage of this offering. It is not authoritative: each artifact is stamped with mirroredAt in https://d3arb1q8mam5wu.cloudfront.net/mirror-manifest.json, and the live endpoints take precedence whenever they answer. No token-gated certification data is mirrored.","offCsoMirrorUrl":"https://d3arb1q8mam5wu.cloudfront.net","repositoryDescription":"Enablement FedRAMP Trust Center: public offering summary and SCG; token-gated programmatic access to certification artifacts with per-access logging (CDS-TRC-USH/PAC/AAI).","repositoryType":["Trust Center"],"url":"https://enablement.cc/ml/20x/trust"}},"servicesNotIncluded":[{"item":"Enablement\u00ae deployed outside Advent's GovCloud environment","reason":"This certification covers exactly one deployment: the Advent-operated multi-tenant instance in AWS GovCloud us-gov-east-1. The public description correctly says the software is portable to any cloud, to a customer data center, or to a self-contained appliance \u2014 none of those customer-operated deployments is inside this authorization boundary or covered by this certification.","reference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a72.1"},{"item":"Non-production environments (test.enablement.cc)","reason":"Physically separate host holding synthetic data only; no federal customer data. Note the CI/CD pipeline that deploys to production runs on that host and IS in scope \u2014 the test application environment is not.","reference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a74 and \u00a79.1 item 2"},{"item":"Customer-controlled components","reason":"Customer premise equipment, customer browsers and devices, the customer's own SSO identity provider, and customer logging systems are outside the provider boundary. The interfaces to them are in scope; the systems themselves are not.","reference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a74"},{"item":"Corporate workstations and code-analysis tooling","reason":"Developer workstations and source-code analysis tooling process no federal customer data and sit outside the boundary; the development team has no access to production inside the boundary.","reference":"MINIMUM_ASSESSMENT_SCOPE.md \u00a74"}],"thirdPartyInformationResources":{"nonCertified":[{"name":"Self-hosted open-source security tooling","provider":"Operated by Advent within the authorization boundary","useCase":"Network vulnerability, container/IaC, cloud-posture, and host configuration/CVE assessment, all executed inside the boundary; no data leaves the boundary and no external scanning or monitoring service is relied upon."}]},"trustCenterAccessLogging":{"logged":"Every access to every /20x/* endpoint, public and token-gated alike, is recorded with endpoint, outcome, client IP, and timestamp.","retentionEnforcement":"Stated policy, not yet machine-enforced at write time. No purge job, TTL, scheduled event, or partition-drop targets BPM_RUN.TRUST_CENTER_ACCESS_LOG, so records currently accumulate indefinitely \u2014 retention is achieved by the absence of deletion rather than by an enforced retention job. The table was created on 2026-07-11, so a full 6-month retention period has not yet elapsed and cannot yet be demonstrated by observation. What IS enforced is DETECTION: every /20x/access-log-summary response recomputes a retentionIntegrity verdict that compares the oldest surviving record against the code-pinned table-creation watermark and against the six-month floor, and reports BREACH if a record that must still exist has gone. See retentionIntegrity and the retentionDemonstrated flag in /20x/access-log-summary for the live answer rather than trusting this sentence.","retentionMonths":24,"retentionPolicy":"Advent retains trust-center access summaries for at least 24 months from the date of access, which exceeds the 6-month CDS-TRC-ACL floor. Records are never purged earlier for convenience, capacity, or at a consumer's request.","rule":"CDS-TRC-ACL","summaryUri":"https://enablement.cc/ml/20x/access-log-summary"}}
