[doc] trust · sha:29b2de8e4054 · build:2026-06-20T23:34:47.545Z

Trust Center.

Every public claim resolves to a verifiable artifact. This page consolidates the attestation surfaces in one place. What is not yet provable is labeled pending — the absence is part of the record, not hidden from it.

Release manifest

live

Per-release package versions, licenses, and registry SHAs are fetched from PyPI and GitHub at build time — no stale fallback. Contractor registration (CAGE / UEI, SAM active) is published as plain fact.

/receipts

Machine-readable attestation

live

The same data in a structured, machine-readable manifest under an immutable schema version (cds-attestation-v1).

/manifest.json

Build provenance

live

Every section and page carries the immutable deployment commit SHA and build timestamp. A production build fails closed if the commit SHA is absent — the site does not ship an unverifiable build.

see any section footer

Data-handling boundary

live

Local-first by design: the core products run offline and user data never leaves the machine. This site makes no third-party runtime requests — no analytics, no trackers, no chat widgets, no CDNs beyond the edge.

security policy

Vulnerability disclosure

live

A published security policy and disclosure contact.

/.well-known/security.txt

Software bill of materials (SBOM)

pending

Per-release CycloneDX SBOM with every dependency declared by version, license, and provenance, included in the evidence package. Planned; not yet published.

Signed provenance

pending

Signed release tags and a build attestation tying source commit → build environment → artifact → deployed site into one cryptographically closed chain. In progress; not yet closed end-to-end. Python packages are currently published via Twine, not Trusted Publishing.

Independent review

pending

External technical review or customer validation, distinct from self-issued QA. Not yet published — internal QA receipts are not a substitute.

/receipts carries the authoritative per-release record · back to home