[doc] trust · sha:29b2de8e4054 · build:2026-06-20T23:34:47.545Z
Trust Center.
Every public claim resolves to a verifiable artifact. This page consolidates the attestation surfaces in one place. What is not yet provable is labeled pending — the absence is part of the record, not hidden from it.
Release manifest
livePer-release package versions, licenses, and registry SHAs are fetched from PyPI and GitHub at build time — no stale fallback. Contractor registration (CAGE / UEI, SAM active) is published as plain fact.
Machine-readable attestation
liveThe same data in a structured, machine-readable manifest under an immutable schema version (cds-attestation-v1).
Build provenance
liveEvery section and page carries the immutable deployment commit SHA and build timestamp. A production build fails closed if the commit SHA is absent — the site does not ship an unverifiable build.
Data-handling boundary
liveLocal-first by design: the core products run offline and user data never leaves the machine. This site makes no third-party runtime requests — no analytics, no trackers, no chat widgets, no CDNs beyond the edge.
Vulnerability disclosure
liveA published security policy and disclosure contact.
Software bill of materials (SBOM)
pendingPer-release CycloneDX SBOM with every dependency declared by version, license, and provenance, included in the evidence package. Planned; not yet published.
Signed provenance
pendingSigned release tags and a build attestation tying source commit → build environment → artifact → deployed site into one cryptographically closed chain. In progress; not yet closed end-to-end. Python packages are currently published via Twine, not Trusted Publishing.
Independent review
pendingExternal technical review or customer validation, distinct from self-issued QA. Not yet published — internal QA receipts are not a substitute.
/receipts carries the authoritative per-release record · back to home