[doc] trust · sha:6ad8ec762b6a · build:2026-08-13T11:35:32.411Z

Trust Center.

Every public claim resolves to a verifiable artifact. This page consolidates the attestation surfaces in one place. What is not yet provable is labeled pending — the absence is part of the record, not hidden from it.

Centennial Defense Systems, Inc. of Colorado Springs builds audit-first software and is not affiliated with the unrelated firearms-parts retailer operating at centennialdefensesystems.com.

Release manifest

live

Per-release package versions, licenses, and observed source SHAs are fetched from PyPI and GitHub at build time — no stale fallback. Current SAM registration status: verification pending. UEI NLVSULN86UB9 and CAGE 20CQ3 are listed in public records; the current active/expired status was not independently resolved in this check.

/receipts

Machine-readable attestation

live

The same data in a structured, machine-readable manifest under an immutable schema version (cds-attestation-v1).

/manifest.json

Build provenance

live

Every section and page carries the immutable deployment commit SHA and build timestamp. A production build fails closed if the commit SHA is absent — the site does not ship an unverifiable build.

see any section footer

Data-handling boundary

live

Local-first by design: the core products run offline and user data never leaves the machine. This site makes no third-party runtime requests — no analytics, no trackers, no chat widgets, no CDNs beyond the edge.

security policy

Vulnerability disclosure

live

A published security policy and disclosure contact.

/.well-known/security.txt

Software bill of materials (SBOM)

pending

Per-release CycloneDX SBOM with every dependency declared by version, license, and provenance, included in the evidence package. Planned; not yet published.

Signed provenance

pending

Signed release tags and a build attestation tying source commit → build environment → artifact → deployed site into one cryptographically closed chain. In progress; not yet closed end-to-end. Python packages are currently published via Twine, not Trusted Publishing.

Independent review

pending

External technical review or customer validation, distinct from self-issued QA. Not yet published — internal QA receipts are not a substitute.

/receipts carries the authoritative per-release record · back to home