[doc] trust · sha:6ad8ec762b6a · build:2026-08-13T11:35:32.411Z
Trust Center.
Every public claim resolves to a verifiable artifact. This page consolidates the attestation surfaces in one place. What is not yet provable is labeled pending — the absence is part of the record, not hidden from it.
Centennial Defense Systems, Inc. of Colorado Springs builds audit-first software and is not affiliated with the unrelated firearms-parts retailer operating at centennialdefensesystems.com.
Release manifest
livePer-release package versions, licenses, and observed source SHAs are fetched from PyPI and GitHub at build time — no stale fallback. Current SAM registration status: verification pending. UEI NLVSULN86UB9 and CAGE 20CQ3 are listed in public records; the current active/expired status was not independently resolved in this check.
Machine-readable attestation
liveThe same data in a structured, machine-readable manifest under an immutable schema version (cds-attestation-v1).
Build provenance
liveEvery section and page carries the immutable deployment commit SHA and build timestamp. A production build fails closed if the commit SHA is absent — the site does not ship an unverifiable build.
Data-handling boundary
liveLocal-first by design: the core products run offline and user data never leaves the machine. This site makes no third-party runtime requests — no analytics, no trackers, no chat widgets, no CDNs beyond the edge.
Vulnerability disclosure
liveA published security policy and disclosure contact.
Software bill of materials (SBOM)
pendingPer-release CycloneDX SBOM with every dependency declared by version, license, and provenance, included in the evidence package. Planned; not yet published.
Signed provenance
pendingSigned release tags and a build attestation tying source commit → build environment → artifact → deployed site into one cryptographically closed chain. In progress; not yet closed end-to-end. Python packages are currently published via Twine, not Trusted Publishing.
Independent review
pendingExternal technical review or customer validation, distinct from self-issued QA. Not yet published — internal QA receipts are not a substitute.
/receipts carries the authoritative per-release record · back to home