Enablement® FedRAMP Trust Center

Advent Business Company Inc. logo

Advent Business Company Inc. · UEI C7LGVA7B5JT1 · CAGE 627S4 · 20x Class C (Program path) · impact Moderate

FedRAMP ID: FR2628647239 · Status: Initial Implementation (approved 2026-07-17) · Marketplace listing

This page is the human-readable half of Advent's FedRAMP Certification Data. Everything on it is rendered from the same document served as JSON at the Certification Package Overview, so the two formats cannot disagree (CDS-CSO-CBF). Generated 2026-08-07T05:28:49Z.

If this page is ever unreachable, the public certification data is mirrored off this infrastructure at https://d3arb1q8mam5wu.cloudfront.net — bookmark it now, because during an outage you cannot load this page to find it. Point-in-time copy of the PUBLIC trust-center artifacts (this CPO, the trust page, the SCG, and both availability formats), refreshed every 15 minutes into the AWS commercial partition (account 971328156383, us-east-1) and served from S3 via CloudFront. It shares no partition, account, region, host, database, web server, TLS certificate or DNS zone with production, so it stays reachable during an outage of this offering. It is not authoritative: each artifact is stamped with mirroredAt in https://d3arb1q8mam5wu.cloudfront.net/mirror-manifest.json, and the live endpoints take precedence whenever they answer. No token-gated certification data is mirrored.

Public information (CDS-CSO-PUB)

#Required itemValue
1FedRAMP IDFR2628647239 · package id ADVENTBUSINESS-ENB · FedRAMP Marketplace listing
2Service ModelSaaS, PaaS
3Deployment ModelGovernment Community Cloud
4Business CategoryCybersecurity & Risk Management; Development Tools; Data Management; Artificial Intelligence (AI); System Administration; Mobile Device Management (MDM); Governance, Risk, and Compliance (GRC); Content Management System (CMS); Operations Management; Finance
5UEI NumberC7LGVA7B5JT1 · CAGE 627S4
6Sales Contactsupport@adventbusiness.com
7Security Contactrajesh@adventbusiness.com · FedRAMP Security Inbox: fedramp-security@adventbusiness.com
8Product Websitehttps://enablement.cc
9Product Logohttps://enablement.cc/assets/enablement/logo.png
10Overall Service DescriptionSee Service description below.
11Services and Security CategoriesSee Certified services below (9 services, each with its security category, plus what is out of scope).
12Secure Configuration Guidancehttps://enablement.cc/ml/20x/scg
13Documentation OverviewSee Documentation below (9 document repositories).
14Trust Centerhttps://enablement.cc/ml/20x/trust (this page) · access instructions in Access-controlled data below.
15Next Ongoing Certification Report2026-10-01
16Independent Assessment ServiceNot yet assigned; independent assessment (IV&V) in procurement (FedRAMP assessor id 000000 — the unassigned placeholder, not a real assessor id; internal record id 000000)

Service availability (CDS-CSO-AVR)

Current and 30-day historical availability of core services, including availability incidents: status page (human-readable) · availability report (JSON). Both are public; no token is required.

Read this before relying on those figures. The availability service is hosted on the same infrastructure it measures. It cannot report an outage it is part of — during a full outage the status page is down with everything else. Treat an unreachable status page as an availability signal in its own right, and see the limitations block in the JSON for what the measurement does and does not cover.

That is why an independent observation exists off this infrastructure: external availability observation (JSON) · mirror landing page. A job in the AWS commercial partition fetches these public URLs every 15 minutes; when it cannot reach them, it publishes that fact — with a first-failure time and a running duration — from infrastructure this outage does not touch. The mirrored copy of the availability report is last-known-good and stamped with when it was taken; the external observation is live.

Service description

Enablement® is the self-contained, no-code compliance platform you fully own. It is deterministic (no AI, no hallucinations, no token costs), portable to any cloud or data center, CMMC-ready with native continuous monitoring, and zero-trust with no third-party data egress. It is error-proof by design, through automated access control, automated marking, and share-time leak prevention. Built by CMMI-appraised, ISO-certified Advent.

Enablement®
Own your compliance. Send nothing out. Need no experts, no AI.
Most compliance platforms make you hire specialists, wire in third-party services, and increasingly hand your data to AI you cannot audit. Enablement flips that. It is a self-contained, deterministic, zero-trust platform where your teams build and run everything visually, and nothing ever leaves your boundary.

1. No-code process building. No developers, no AI, no token bills.
Business users design complete workflows (BPMN) visually and get web and mobile interfaces generated automatically, with no coding, no integration team, and no consultants. Because the engine is deterministic rather than generative, it is free from AI hallucination and carries zero per-token cost. Every process behaves the same way every time, is fully auditable, and never invents an answer. What you design is exactly what runs.

2. Deploy anywhere. True portability.
One platform, any environment. Run Enablement in any commercial cloud, government cloud, or your own data center, or as a fully self-contained appliance. There is no cloud lock-in and no vendor-specific dependency. Move it, mirror it, or air-gap it.

3. Rapid CMMC Level 2 compliance with built-in continuous monitoring.
CMMC Level 2 readiness comes out of the box, backed by native, always-on continuous monitoring, with no separate scanning products to buy, license, or integrate. Assess, monitor, and produce authorization evidence from day one, on a single system.

4. A genuine zero-trust boundary. Your data never touches a third party.
Enablement keeps everything inside your perimeter. Your source code lives in its own repository. No data is sent to any outside service for user authentication, code-quality analysis, container scanning, file scanning, or continuous monitoring. Nothing is shipped off to a SaaS, a scanning vendor, or an AI provider. What happens in your boundary stays in your boundary.

5. RBAC and ABAC, with automated document marking that removes human error.
Fine-grained role-based and attribute-based access control (RBAC and ABAC) governs exactly who can see and do what. Documents are marked automatically to federal standards (DoW and NARA), with no manual labeling, no inconsistent tags, and no mislabeled files. The platform does the marking so people cannot get it wrong.

6. Stop data leaks before they happen, and the liability that follows.
Human error is the number one cause of data spillage. Enablement checks every share and warns before a document reaches unauthorized personnel, catching the mistake at the moment of sharing rather than after a breach. That turns a potential disclosure, and the corporate liability that comes with it, into a blocked action.

7. Every authentication method, and your password never leaves your device.
Support the full range of sign-in: passkeys, single sign-on (SSO), authenticator apps, email, and more. Critically, the password is never sent over the network or to the server. It is proven with a challenge-response so the secret never leaves the user's device. Strong, flexible, phishing-resistant authentication without ever transmitting the credential.

Certified services and security categories (CDS-CSO-SVC)

ServiceDescriptionModel Security categoryIn Minimum Assessment Scope Date available
Enablement No-Code Process DesignerThe PaaS platform-build layer: business users author complete BPMN processes and applications visually and get web and mobile interfaces generated automatically, with no coding. Customer-authored content is treated as untrusted and runs under server-authoritative tenant binding. Public description capability 1; Secure Configuration Guide §14.PaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-07-17
Enablement Process Execution EngineDeterministic server-side execution of published processes — forms, tasks, approvals, and integrations. No generative model is in the execution path, so a process behaves identically on every run and never invents an answer. Public description capability 1.SaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-07-17
Enablement Mobile AccessMobile client for the same processes and forms as the web application, with device binding on authenticated sessions. Referenced in the public description as the automatically generated mobile interface.SaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-07-17
Enablement Identity, Authentication and Access ControlRole-based and attribute-based access control (RBAC/ABAC), user lifecycle, time-boxed privileged grants, and the full authentication range: passkeys, SAML SSO, authenticator apps, and email OTP. The password is proven by challenge-response and is never transmitted to the server. Public description capabilities 5 and 7; Secure Configuration Guide §2–§7.SaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-07-17
Enablement Secured Files and Secured EmailEncrypted file storage and sharing, secured email, watermarked read-only viewing, and malware scanning of every upload — all inside the boundary, with no file content sent to an external scanning service. Secure Configuration Guide §10.2–§10.5.SaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-07-17
Enablement Automated Marking and Share-Time Leak PreventionAutomatic CUI and distribution-statement marking to federal standards (DoW and NARA), plus a share-time authorization check that warns or blocks before a document reaches unauthorized personnel. Public description capabilities 5 and 6; Secure Configuration Guide §10.1.SaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-07-17
Enablement Audit and Activity MonitoringTamper-evident audit capture of user and administrative activity with scoped audit-log access for customer administrators, plus execution-pattern anomaly detection and an operator kill switch for a runaway process or account. Secure Configuration Guide §9.SaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-07-17
Enablement Process SchedulerScheduled and recurring execution of published processes, operated inside the boundary with no external scheduler or orchestration service.SaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-07-17
Enablement Continuous MonitoringNative, always-on continuous monitoring operated entirely within the authorization boundary, covering network vulnerability, container/IaC, cloud-posture, and host configuration/CVE assessment, producing OSCAL + FedRAMP CR26 machine-readable compliance evidence. No data is sent to any external scanning or monitoring service.SaaSModerate (Class C)
FIPS 199 system categorization: High
System-wide FIPS 199 high-water mark; not separately derived for this service.
Yes
MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6
2026-04-17

dateAvailable is the date the service entered the declared FedRAMP 20x certification scope (Initial Implementation approval, 2026-07-17), not a commercial general-availability date. The platform capabilities predate the FedRAMP effort; their original ship dates are not published here because they are not the dates that matter to this certification.

Every service listed in certifiedServices is inside the FedRAMP Minimum Assessment Scope; servicesNotIncluded names what is outside it. Both lists are public and require no access to underlying FedRAMP Certification Data, which is what this rule requires.

Rule CDS-CSO-SVC · securityCategory, inMinimumAssessmentScope, and serviceModel are additional properties. The pinned FedRAMP CPO schema (fedramp-certification-package-overview-schema-2026-06-24.json) defines no field for a service security category; when it does, these move into it.

Not included in this certification

ItemWhy it is out of scopeReference
Enablement® deployed outside Advent's GovCloud environmentThis certification covers exactly one deployment: the Advent-operated multi-tenant instance in AWS GovCloud us-gov-east-1. The public description correctly says the software is portable to any cloud, to a customer data center, or to a self-contained appliance — none of those customer-operated deployments is inside this authorization boundary or covered by this certification.MINIMUM_ASSESSMENT_SCOPE.md §2.1
Non-production environments (test.enablement.cc)Physically separate host holding synthetic data only; no federal customer data. Note the CI/CD pipeline that deploys to production runs on that host and IS in scope — the test application environment is not.MINIMUM_ASSESSMENT_SCOPE.md §4 and §9.1 item 2
Customer-controlled componentsCustomer premise equipment, customer browsers and devices, the customer's own SSO identity provider, and customer logging systems are outside the provider boundary. The interfaces to them are in scope; the systems themselves are not.MINIMUM_ASSESSMENT_SCOPE.md §4
Corporate workstations and code-analysis toolingDeveloper workstations and source-code analysis tooling process no federal customer data and sit outside the boundary; the development team has no access to production inside the boundary.MINIMUM_ASSESSMENT_SCOPE.md §4

Security categorization

Two categorizations are in force and both are accurate.
FedRAMP 20x certification target: Class C (Moderate impact).
Rev5 package FIPS 199 categorization: High.
BasisFIPS 199 high-water mark across the 13 NIST SP 800-60 information types the platform handles (Personal Identity & Authentication rated High/High/High is the driver), per SSP §3 Table 3.1 and Appendix K Table K.1. Digital identity level IAL2/AAL2/FAL2, with IAL3/AAL3/FAL3 supported where an agency requires it.
ReconciliationTwo categorizations are in force at once and both are accurate. The Rev5 authorization package of record categorises the system FIPS 199 High. The FedRAMP 20x certification being pursued is Class C, which corresponds to Moderate impact; that declaration was made by the System Owner on 2026-07-10 and is tracked as an open, deliberate reconciliation item. Class D (the 20x High path) is the intended upgrade when FedRAMP opens it, estimated 2027. A prospective customer should read this as: the system is built and assessed to a High water mark, and the certification currently being sought is Class C / Moderate.
Per-service categorizationNOT declared per service. Every service below handles the same federal customer data inside one authorization boundary, on the same in-scope components, so the system-level high-water mark applies uniformly. No service carries a separately derived C/I/A triad, and none is invented here to fill the column.
AuthorityMINIMUM_ASSESSMENT_SCOPE.md §3 (information flows and security categories) and §9.1 item 8 (Class C declaration). Available token-gated at https://enablement.cc/ml/20x/doc/mas.

Access-controlled certification data (CDS-CSO-RIS)

KSI evidence reports, the Security Decision Record, vulnerability artifacts (VDR/AVI/historical), Ongoing Certification Reports, and the assessment documents are shared with federal agencies, FedRAMP, and assessors over bearer-token API access with per-access logging (CDS-TRC-USH / PAC / AAI).

How to get access: email rajesh@adventbusiness.com identifying your agency or assessment organization and what you need. Advent issues a bearer token out-of-band. Then send Authorization: Bearer <token> to any endpoint below. Requests without a token return HTTP 401 with these same instructions in the response body; they do not fail silently.

Machine-readable certification data

EndpointRepository typeContents Access
https://enablement.cc/ml/20x/vdr?src_id=1711Machine-Readable Authorization DataVulnerability Detail Report (VER-RPT-VDT)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/avi?src_id=1711Machine-Readable Authorization DataAccepted Vulnerability Info (VER-RPT-AVI)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/historical?src_id=1711Machine-Readable Authorization DataHistorical VER activity for automated retrieval (VER-TFR-MRH)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/ocr?src_id=1711Machine-Readable Authorization DataOngoing Certification Report (CCM-OCR-AVL)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/sdr?src_id=1711Machine-Readable Authorization DataSecurity Decision Record (SDR-CSO-FRR)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/ksi?src_id=1711Machine-Readable Authorization DataKSI evidence report (FRC-CSX-VVK / FRC-CSX-MOT)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/oscal/poam?src_id=1711Machine-Readable Authorization DataRev5 OSCAL Plan of Action & MilestonesToken
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/oscal/assessment-results?src_id=1711Machine-Readable Authorization DataRev5 OSCAL Assessment ResultsToken
Request tenant-scoped API access from rajesh@adventbusiness.com.

Documentation supplied by the provider

EndpointRepository typeDocument Access
https://enablement.cc/ml/20x/doc/iec-runbookAssessment DocumentationIncident Evaluation & Communication runbook (IEC-CSO-*)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/doc/ksi-self-assessmentAssessment DocumentationKSI Self-Assessment — 46 Class C KSIs with implementation, evidence pointers, and self-verdicts (IVV Verify-step input)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/doc/masAssessment DocumentationMinimum Assessment Scope (MAS-CSO-*)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/doc/poamAssessment DocumentationPlan of Action & Milestones — open 20x itemsToken
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/doc/ruleset-statusAssessment DocumentationClass C ruleset status tracker (all 15 rulesets)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/doc/scn-processAssessment DocumentationSignificant Change Notification process (SCN-CSO-*)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/doc/validation-designAssessment DocumentationKSI Validation Design & Measurement System — end-to-end trace of every automated validation method (scope, source, code/thresholds, failure semantics, preservation) per the 20x assessor guidanceToken
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/docsAssessment Documentation, Evidence RepositoryAssessment document index + supporting evidence records (SSP appendices, signed records, boundary diagrams)Token
Request tenant-scoped API access from rajesh@adventbusiness.com.
https://enablement.cc/ml/20x/access-log-summaryAssessment DocumentationTrust-center access-log summary + retention statement (CDS-TRC-ACL) — monthly access counts by endpoint and outcome, so an assessor can verify access logging without a database accountToken
Request tenant-scoped API access from rajesh@adventbusiness.com.

Other published endpoints

EndpointRepository typeContents Access
https://enablement.cc/ml/20x/availabilityAvailability ReportingAvailability report (CDS-CSO-AVR): current state and 30-day historical availability of core services with availability incidents, machine-readable. Public, no token required.Public
No request needed.
https://enablement.cc/ml/20x/statusAvailability ReportingAvailability status page (CDS-CSO-AVR), human-readable rendering of the same data. Public, no token required.Public
No request needed.
https://enablement.cc/ml/20x/trustTrust CenterEnablement FedRAMP Trust Center: public offering summary and SCG; token-gated programmatic access to certification artifacts with per-access logging (CDS-TRC-USH/PAC/AAI).
Point-in-time copy of the PUBLIC trust-center artifacts (this CPO, the trust page, the SCG, and both availability formats), refreshed every 15 minutes into the AWS commercial partition (account 971328156383, us-east-1) and served from S3 via CloudFront. It shares no partition, account, region, host, database, web server, TLS certificate or DNS zone with production, so it stays reachable during an outage of this offering. It is not authoritative: each artifact is stamped with mirroredAt in https://d3arb1q8mam5wu.cloudfront.net/mirror-manifest.json, and the live endpoints take precedence whenever they answer. No token-gated certification data is mirrored. https://d3arb1q8mam5wu.cloudfront.net
Public
Public page. Tokens for access-controlled artifacts: rajesh@adventbusiness.com
https://enablement.cc/ml/20x/scgSecure Configuration GuidanceEnablement® Secure Configuration Guide — recommended secure configuration, use instructions, and secure defaults for customer administrators.Public
No request needed.
https://enablement.cc/ml/20x/statusAvailability ReportingPublic availability status service (CDS-CSO-AVR): current state, 30-day history, and availability incidents. Machine-readable JSON at https://enablement.cc/ml/20x/availability. This endpoint is hosted on the infrastructure it measures and therefore cannot report an outage it is part of; the off-CSO mirror below can, and does.
The independent-hosting arm of CDS-CSO-AVR. The mirror's refresher is itself an external probe running in the AWS commercial partition: every 15 minutes it records whether this offering answered, and when it did not, it publishes that — with a first-failure time and a running duration — from infrastructure the outage does not touch. The mirrored copy of the availability report is last-known-good and stamped; the external observation is live. https://d3arb1q8mam5wu.cloudfront.net/index.html
Public
No request needed.

Off-CSO mirror of the public artifacts

authoritativeFalse
availabilityhttps://d3arb1q8mam5wu.cloudfront.net/availability.json
basehttps://d3arb1q8mam5wu.cloudfront.net
mirrorExternalObservationhttps://d3arb1q8mam5wu.cloudfront.net/mirror-availability.json
mirrorExternalObservationHistoryhttps://d3arb1q8mam5wu.cloudfront.net/external-probe-history.json
mirrorManifesthttps://d3arb1q8mam5wu.cloudfront.net/mirror-manifest.json
notePoint-in-time copies, not the live endpoints. Read mirroredAt in mirrorManifest before relying on any of them. Rules served: CDS-TRC-USH, CDS-CSO-UTC, and the independent-hosting arm of CDS-CSO-AVR.
packagehttps://d3arb1q8mam5wu.cloudfront.net/package.json
refreshIntervalMinutes15
scghttps://d3arb1q8mam5wu.cloudfront.net/scg.md
statushttps://d3arb1q8mam5wu.cloudfront.net/status.html
trusthttps://d3arb1q8mam5wu.cloudfront.net/trust.html

Third-party information resources

ResourceProviderUse
Self-hosted open-source security toolingOperated by Advent within the authorization boundaryNetwork vulnerability, container/IaC, cloud-posture, and host configuration/CVE assessment, all executed inside the boundary; no data leaves the boundary and no external scanning or monitoring service is relied upon.

Consistency between formats (CDS-CSO-CBF)

Machine-readableHuman-readable Rendered by
https://enablement.cc/ml/20x/package?src_id=1711https://enablement.cc/ml/20x/trustrender_trust_html(cpo)
https://enablement.cc/ml/20x/availabilityhttps://enablement.cc/ml/20x/statusrender_status_html(doc)
How staleness is preventedStructurally, not procedurally. Each human-readable page is RENDERED FROM the machine-readable document at request time and is handed no other source of facts — no database handle, no second query, no cached copy. A stale HTML rendering is therefore not a state this service can be in.
How omission is preventedSingle-sourcing stops the page contradicting the JSON; it does not stop the page omitting part of it, which is the failure that actually occurred when availability endpoints were added to the document after the HTML tables were written. fedramp_20x.cpo_html_divergence and availability_html_divergence walk every scalar in the JSON and assert it reached the page, so a new field must be either rendered or added to a named exemption list carrying its reason.
Verify it yourselfFetch both formats and diff them yourself, or run the provider's own check: `python3 app/routes/fedramp_20x.py --selftest` fails on any divergence, and the unit suite re-runs it across an outage, a measurement gap, a partial day, a single-endpoint window and an empty log.
What this check does not doIt runs at build and self-test time, not on every request, so it gates a release rather than a response. It compares values one way (every JSON scalar must appear in the HTML); the reverse needs no check because the page has no other source. Booleans and nulls are matched by field rather than by literal, since a page renders them as words.

Trust-center access logging and retention (CDS-TRC-ACL)

What is loggedEvery access to every /20x/* endpoint, public and token-gated alike, is recorded with endpoint, outcome, client IP, and timestamp.
Retention policyAdvent retains trust-center access summaries for at least 24 months from the date of access, which exceeds the 6-month CDS-TRC-ACL floor. Records are never purged earlier for convenience, capacity, or at a consumer's request.
Enforcement statusStated policy, not yet machine-enforced at write time. No purge job, TTL, scheduled event, or partition-drop targets BPM_RUN.TRUST_CENTER_ACCESS_LOG, so records currently accumulate indefinitely — retention is achieved by the absence of deletion rather than by an enforced retention job. The table was created on 2026-07-11, so a full 6-month retention period has not yet elapsed and cannot yet be demonstrated by observation. What IS enforced is DETECTION: every /20x/access-log-summary response recomputes a retentionIntegrity verdict that compares the oldest surviving record against the code-pinned table-creation watermark and against the six-month floor, and reports BREACH if a record that must still exist has gone. See retentionIntegrity and the retentionDemonstrated flag in /20x/access-log-summary for the live answer rather than trusting this sentence.
Access summaryhttps://enablement.cc/ml/20x/access-log-summary (token-gated)

Contact

SecuritySecurity Team · rajesh@adventbusiness.com
SalesSales Team · support@adventbusiness.com
FedRAMP Security InboxFedRAMP Security Inbox (AFC-CSO-INB) · fedramp-security@adventbusiness.com
Websitehttps://enablement.cc

Schema pin 2026-06-24 (synced 2026-07-30) · rules 2026.07.01.01 · page generated 2026-08-07T05:28:49Z.