{
    "schema": "clariodb-trust-report",
    "version": 3,
    "release": "0.9.71",
    "report_id": "7b09e09d10139654f01b74113f56dcbc",
    "scope": "public",
    "generated_at": "2026-09-02T06:57:10Z",
    "freshness": "current_report",
    "counts": {
        "confirmed": 12,
        "review": 2,
        "critical": 0,
        "unknown": 0,
        "not_applicable": 2,
        "not_covered": 2
    },
    "category_counts": {
        "integrity": {
            "total": 4,
            "confirmed": 3,
            "review": 0,
            "critical": 0,
            "unknown": 0,
            "not_applicable": 0,
            "not_covered": 1
        },
        "identity": {
            "total": 4,
            "confirmed": 3,
            "review": 1,
            "critical": 0,
            "unknown": 0,
            "not_applicable": 0,
            "not_covered": 0
        },
        "transport": {
            "total": 2,
            "confirmed": 2,
            "review": 0,
            "critical": 0,
            "unknown": 0,
            "not_applicable": 0,
            "not_covered": 0
        },
        "continuity": {
            "total": 2,
            "confirmed": 1,
            "review": 1,
            "critical": 0,
            "unknown": 0,
            "not_applicable": 0,
            "not_covered": 0
        },
        "traceability": {
            "total": 1,
            "confirmed": 1,
            "review": 0,
            "critical": 0,
            "unknown": 0,
            "not_applicable": 0,
            "not_covered": 0
        },
        "database": {
            "total": 1,
            "confirmed": 1,
            "review": 0,
            "critical": 0,
            "unknown": 0,
            "not_applicable": 0,
            "not_covered": 0
        },
        "coverage": {
            "total": 4,
            "confirmed": 1,
            "review": 0,
            "critical": 0,
            "unknown": 0,
            "not_applicable": 2,
            "not_covered": 1
        }
    },
    "categories": {
        "integrity": {
            "labelFr": "Intégrité & livraison",
            "labelEn": "Integrity & delivery",
            "summaryFr": "Octets livrés, registre de versions et attestations publiées.",
            "summaryEn": "Delivered bytes, release registry, and published attestations.",
            "counts": {
                "total": 4,
                "confirmed": 3,
                "review": 0,
                "critical": 0,
                "unknown": 0,
                "not_applicable": 0,
                "not_covered": 1
            }
        },
        "identity": {
            "labelFr": "Identité & secrets",
            "labelEn": "Identity & secrets",
            "summaryFr": "Authentification, session, coffre et dérivation cryptographique.",
            "summaryEn": "Authentication, session, vault, and cryptographic derivation.",
            "counts": {
                "total": 4,
                "confirmed": 3,
                "review": 1,
                "critical": 0,
                "unknown": 0,
                "not_applicable": 0,
                "not_covered": 0
            }
        },
        "transport": {
            "labelFr": "Transport & HTTP",
            "labelEn": "Transport & HTTP",
            "summaryFr": "Connexion Directe ou Agent, cookies et politiques de réponse.",
            "summaryEn": "Direct or Agent connection, cookies, and response policies.",
            "counts": {
                "total": 2,
                "confirmed": 2,
                "review": 0,
                "critical": 0,
                "unknown": 0,
                "not_applicable": 0,
                "not_covered": 0
            }
        },
        "continuity": {
            "labelFr": "Sauvegarde & continuité",
            "labelEn": "Backup & continuity",
            "summaryFr": "Clés d’archive, planification, workers et restauration vérifiée.",
            "summaryEn": "Archive keys, scheduling, workers, and verified restoration.",
            "counts": {
                "total": 2,
                "confirmed": 1,
                "review": 1,
                "critical": 0,
                "unknown": 0,
                "not_applicable": 0,
                "not_covered": 0
            }
        },
        "traceability": {
            "labelFr": "Audit & traçabilité",
            "labelEn": "Audit & traceability",
            "summaryFr": "Chaîne d’événements, résultats et preuves attribuables.",
            "summaryEn": "Event chain, outcomes, and attributable evidence.",
            "counts": {
                "total": 1,
                "confirmed": 1,
                "review": 0,
                "critical": 0,
                "unknown": 0,
                "not_applicable": 0,
                "not_covered": 0
            }
        },
        "database": {
            "labelFr": "Base & modèle",
            "labelEn": "Database & model",
            "summaryFr": "Métadonnées, identité des lignes, relations et stockage.",
            "summaryEn": "Metadata, row identity, relationships, and storage.",
            "counts": {
                "total": 1,
                "confirmed": 1,
                "review": 0,
                "critical": 0,
                "unknown": 0,
                "not_applicable": 0,
                "not_covered": 0
            }
        },
        "coverage": {
            "labelFr": "Limites & couverture",
            "labelEn": "Boundaries & coverage",
            "summaryFr": "Capacités absentes, certifications non revendiquées et frontières publiées.",
            "summaryEn": "Missing capabilities, unclaimed certifications, and published boundaries.",
            "counts": {
                "total": 4,
                "confirmed": 1,
                "review": 0,
                "critical": 0,
                "unknown": 0,
                "not_applicable": 2,
                "not_covered": 1
            }
        }
    },
    "checks": [
        {
            "id": "AUD-PUB-DEPLOY-001",
            "state": "confirmed",
            "severity": "attention",
            "category": "integrity",
            "proofType": "checksum",
            "titleFr": "Intégrité de la version publiée",
            "titleEn": "Published version integrity",
            "summaryFr": "Les deux jeux de condensats sont conformes.",
            "summaryEn": "Both checksum sets are valid.",
            "evidence": {
                "manifest": {
                    "ok": 648,
                    "total": 648
                },
                "delivery": {
                    "ok": 649,
                    "total": 649
                },
                "observed_at": "2026-09-02T06:57:10Z",
                "age_seconds": 0,
                "cache_state": "miss"
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "checksum",
            "source": "checksum_verification"
        },
        {
            "id": "AUD-PUB-AGENT-001",
            "state": "confirmed",
            "severity": "info",
            "category": "transport",
            "proofType": "runtime_observation",
            "titleFr": "Agent épinglé et réponses signées",
            "titleEn": "Pinned Agent and signed responses",
            "summaryFr": "Le protocole livré prend en charge l’identité épinglée, l’anti-rejeu et les attestations signées.",
            "summaryEn": "The shipped protocol supports pinned identity, anti-replay and signed attestations.",
            "evidence": [],
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "runtime_observation",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-RETRY-001",
            "state": "confirmed",
            "severity": "info",
            "category": "coverage",
            "proofType": "runtime_observation",
            "titleFr": "Aucun retry aveugle après mutation ambiguë",
            "titleEn": "No blind retry after ambiguous mutation",
            "summaryFr": "Les chemins de mutation classent les issues ambiguës et interdisent le rejeu automatique.",
            "summaryEn": "Mutation paths classify ambiguous outcomes and prevent automatic replay.",
            "evidence": [],
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "runtime_observation",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-ATTEST-001",
            "state": "confirmed",
            "severity": "info",
            "category": "integrity",
            "proofType": "signature",
            "titleFr": "Signature de l’attestation publique",
            "titleEn": "Public attestation signature",
            "summaryFr": "Les rapports publics sont signés avec Ed25519.",
            "summaryEn": "Public reports are signed with Ed25519.",
            "evidence": {
                "state": "configured",
                "public_key_base64": "kCXiiVuXa26IB0ANa31767FV2X1yfV6CwjoTjUDmFfo="
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "signature",
            "source": "signing_configuration"
        },
        {
            "id": "AUD-PUB-CERT-001",
            "state": "not_covered",
            "severity": "info",
            "category": "integrity",
            "proofType": "declared_boundary",
            "titleFr": "Certifications externes",
            "titleEn": "External certifications",
            "summaryFr": "Aucune certification CSA STAR, ISO/IEC 27001, SOC 2/SOC 3 ou OWASP n’est revendiquée à ce jour.",
            "summaryEn": "No CSA STAR, ISO/IEC 27001, SOC 2/SOC 3 or OWASP certification is currently claimed.",
            "evidence": [],
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Cette capacité n’est pas couverte par la version active.",
            "boundaryEn": "This capability is not covered by the active release.",
            "proof_kind": "declared_boundary",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-SESSION-001",
            "state": "confirmed",
            "severity": "info",
            "category": "identity",
            "proofType": "configuration",
            "titleFr": "Secrets temporaires isolés de la session PHP",
            "titleEn": "Temporary secrets isolated from the PHP session",
            "summaryFr": "Le navigateur ne reçoit qu’un identifiant de session opaque et la session PHP ne conserve qu’un handle opaque. Les clés dérivées et identifiants actifs sont chiffrés séparément dans le runtime privé, bornés dans le temps et supprimés à la déconnexion.",
            "summaryEn": "The browser receives only an opaque session identifier and the PHP session retains only an opaque handle. Derived keys and active credentials are encrypted separately in private runtime storage, time-bounded, and removed on logout.",
            "evidence": {
                "browser_cookie_contains": "opaque_session_id_only",
                "php_session_contains": "opaque_secret_state_handle_only",
                "encrypted_runtime_contains": [
                    "derived_vault_key",
                    "active_connection_credentials"
                ],
                "encryption": "libsodium_secretbox"
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "configuration",
            "source": "application_runtime"
        },
        {
            "id": "AUD-PUB-RESTORE-001",
            "state": "review",
            "severity": "attention",
            "category": "continuity",
            "proofType": "runtime_observation",
            "titleFr": "Restauration",
            "titleEn": "Restoration",
            "summaryFr": "ClarioDB fournit une restauration additive asynchrone avec vérification terminale. En Direct, les archives protégées récentes peuvent reprendre depuis un checkpoint atomique ; les issues Agent ambiguës ne sont jamais rejouées. Le remplacement destructif et les tests périodiques automatiques restent non couverts.",
            "summaryEn": "ClarioDB provides asynchronous additive restoration with terminal verification. For Direct connections, recent protected archives can resume from an atomic checkpoint; ambiguous Agent outcomes are never replayed. Destructive replacement and automatic periodic restore tests remain uncovered.",
            "evidence": {
                "coverage": "additive_async_checkpointed"
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Le signal existe, mais ne prouve pas à lui seul le résultat opérationnel.",
            "boundaryEn": "The signal exists but does not alone prove the operational outcome.",
            "proof_kind": "runtime_observation",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-AUTH-001",
            "state": "confirmed",
            "severity": "info",
            "category": "identity",
            "proofType": "configuration",
            "titleFr": "Défense de l’authentification",
            "titleEn": "Authentication defence",
            "summaryFr": "La limitation des tentatives et la consommation unique des pas TOTP sont actives.",
            "summaryEn": "Attempt throttling and single-use TOTP counters are active.",
            "evidence": {
                "available": true,
                "ok": true,
                "attempt_guard": true,
                "shared_status": true,
                "totp_single_use": true,
                "auth_max_attempts": 5,
                "auth_window_seconds": 900,
                "totp_max_attempts": 5,
                "totp_window_seconds": 600,
                "evidence_mode": "loaded_runtime"
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "configuration",
            "source": "application_runtime"
        },
        {
            "id": "AUD-PUB-HTTP-001",
            "state": "confirmed",
            "severity": "info",
            "category": "transport",
            "proofType": "configuration",
            "titleFr": "Périmètre HTTP",
            "titleEn": "HTTP perimeter",
            "summaryFr": "La CSP et les protections d’encadrement attendues sont présentes.",
            "summaryEn": "The expected CSP and framing protections are present.",
            "evidence": {
                "available": true,
                "ok": true,
                "site": "site",
                "csp_present": true,
                "missing_directives": [],
                "frame_ancestors": true,
                "script_unsafe_eval": false,
                "script_inline_attributes_blocked": true,
                "cookie": {
                    "secure": true,
                    "httponly": true,
                    "samesite": "Lax"
                },
                "hsts_max_age": 31536000,
                "headers_implementation": true
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "configuration",
            "source": "application_runtime"
        },
        {
            "id": "AUD-PUB-VAULT-001",
            "state": "confirmed",
            "severity": "info",
            "category": "identity",
            "proofType": "configuration",
            "titleFr": "Coffre et secrets temporaires",
            "titleEn": "Vault and temporary secrets",
            "summaryFr": "Le coffre courant utilise Argon2id v1m et les secrets temporaires vivent dans un runtime secretbox privé.",
            "summaryEn": "The current vault uses Argon2id v1m and temporary secrets live in private secretbox runtime storage.",
            "evidence": {
                "kdf_profile": {
                    "version": "v1m",
                    "opslimit": 3,
                    "memlimit": 268435456
                },
                "runtime_encryption": "libsodium_secretbox"
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "configuration",
            "source": "application_runtime"
        },
        {
            "id": "AUD-PUB-BACKUP-001",
            "state": "confirmed",
            "severity": "info",
            "category": "continuity",
            "proofType": "runtime_observation",
            "titleFr": "Clé d’archive indépendante",
            "titleEn": "Independent archive key",
            "summaryFr": "Chaque nouvelle sauvegarde manuelle chiffrée reçoit une clé aléatoire CDB1 distincte de la passphrase du coffre.",
            "summaryEn": "Each new encrypted manual backup receives a random CDB1 key independent from the vault passphrase.",
            "evidence": {
                "available": true,
                "ok": true,
                "format": "clariodb-archive-credential/1",
                "random_per_backup": true,
                "vault_passphrase_reused": false,
                "email_contains_key": false,
                "evidence_mode": "loaded_runtime"
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "runtime_observation",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-RESET-001",
            "state": "review",
            "severity": "attention",
            "category": "identity",
            "proofType": "configuration",
            "titleFr": "Jetons de réinitialisation",
            "titleEn": "Reset tokens",
            "summaryFr": "Les jetons sont aléatoires, expirent et sont consommés, mais restent actuellement stockés comme secrets porteurs dans la base système jusqu’à consommation ou nettoyage.",
            "summaryEn": "Tokens are random, expire, and are consumed, but are currently stored as bearer secrets in the system database until use or cleanup.",
            "evidence": {
                "stored_as_digest": false,
                "tracked_debt": true
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Le signal existe, mais ne prouve pas à lui seul le résultat opérationnel.",
            "boundaryEn": "The signal exists but does not alone prove the operational outcome.",
            "proof_kind": "configuration",
            "source": "application_runtime"
        },
        {
            "id": "AUD-PUB-KEY-CONTINUITY-001",
            "state": "confirmed",
            "severity": "info",
            "category": "database",
            "proofType": "runtime_observation",
            "titleFr": "Continuité de la clé publique",
            "titleEn": "Public-key continuity",
            "summaryFr": "La clé Ed25519 courante correspond à la racine épinglée ou à une rotation croisée valide.",
            "summaryEn": "The current Ed25519 key matches the pinned root or a valid cross-signed rotation.",
            "evidence": {
                "state": "genesis",
                "ok": true,
                "configured_key_id": "ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
                "pinned_key_id": "ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
                "genesis_key_id": "ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
                "rotation_sequence": 0,
                "issues": [],
                "first_seen_at": "2026-09-02T06:57:10Z",
                "current_since": "2026-09-02T06:57:10Z",
                "state_sha256": "sha256:abc963827f0adaf559120184adf96c81c36217bb1a2223a52795062668d928dd",
                "state_signature_format": "clariodb-trust-key-continuity-state-signature/1",
                "root_pin_sha256": "sha256:3ad76c6529476a155aa1e9416b77696035d00c11c44a386156287dd0c8005011"
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "runtime_observation",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-TRANSPARENCY-001",
            "state": "not_applicable",
            "severity": "attention",
            "category": "coverage",
            "proofType": "declared_boundary",
            "titleFr": "Journal public de transparence",
            "titleEn": "Public transparency ledger",
            "summaryFr": "Ce rapport initialise ou prolonge la chaîne publique.",
            "summaryEn": "This report initialises or extends the public chain.",
            "evidence": {
                "entries": 0,
                "head_hash": "sha256:0000000000000000000000000000000000000000000000000000000000000000",
                "age_seconds": null,
                "stale": true,
                "issues": [],
                "intended_snapshot": {
                    "sequence": 1,
                    "previous_record_hash": "sha256:0000000000000000000000000000000000000000000000000000000000000000",
                    "interval_seconds": 900,
                    "stale_after_seconds": 3600
                }
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Ce contrôle ne s’applique pas au contexte courant.",
            "boundaryEn": "This control does not apply to the current context.",
            "proof_kind": "declared_boundary",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-LEDGER-CHECKPOINT-001",
            "state": "not_applicable",
            "severity": "info",
            "category": "coverage",
            "proofType": "declared_boundary",
            "titleFr": "Point de contrôle signé du journal",
            "titleEn": "Signed ledger checkpoint",
            "summaryFr": "Le premier point de contrôle sera publié avec le premier reçu.",
            "summaryEn": "The first checkpoint will be published with the first receipt.",
            "evidence": {
                "state": "not_applicable",
                "issues": []
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Ce contrôle ne s’applique pas au contexte courant.",
            "boundaryEn": "This control does not apply to the current context.",
            "proof_kind": "declared_boundary",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-AUDIT-ANCHOR-001",
            "state": "confirmed",
            "severity": "info",
            "category": "traceability",
            "proofType": "runtime_observation",
            "titleFr": "Ancrage du journal produit",
            "titleEn": "Product-journal anchoring",
            "summaryFr": "La tête du journal produit est valide et sera reprise dans le prochain reçu public.",
            "summaryEn": "The product-journal head is valid and will be included in the next public receipt.",
            "evidence": {
                "exists": true,
                "valid": true,
                "entries": 17,
                "head_hash": "sha256:eab7545e5d7e6a253462aec9183c0b23df203f8ec6bab85959c268bce08b52f4",
                "issues": []
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "runtime_observation",
            "source": "published_boundary"
        },
        {
            "id": "AUD-PUB-RELEASE-RECEIPT-001",
            "state": "confirmed",
            "severity": "info",
            "category": "integrity",
            "proofType": "registry",
            "titleFr": "Reçu de construction livré",
            "titleEn": "Shipped build receipt",
            "summaryFr": "Un reçu de construction structuré est couvert par le manifeste courant.",
            "summaryEn": "A structured build receipt is covered by the current manifest.",
            "evidence": {
                "state": "present",
                "covered_by_manifest": true,
                "sha256": "sha256:d47593d0eec5b3ca8b94058cd266264fced87600534c9ecc3c95501119c4c860",
                "boundary": "Self-issued release evidence; it is not an external CI witness."
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Mesuré ou dérivé localement pour ce rapport.",
            "boundaryEn": "Measured or derived locally for this report.",
            "proof_kind": "registry",
            "source": "release_registry"
        },
        {
            "id": "AUD-PUB-DNS-PIN-001",
            "state": "not_covered",
            "severity": "info",
            "category": "coverage",
            "proofType": "declared_boundary",
            "titleFr": "Épinglage DNS de la clé",
            "titleEn": "DNS key pinning",
            "summaryFr": "Aucun épinglage DNS indépendant n’est configuré.",
            "summaryEn": "No independent DNS pin is configured.",
            "evidence": {
                "state": "not_configured",
                "ok": false,
                "required": false,
                "name": null,
                "expected_value": "v=clariodb-trust1; key-id=ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
                "observed_values": [],
                "observed_at": null,
                "age_seconds": null,
                "source": "configuration",
                "dnssec_validated": false,
                "boundary": "No DNS observation is configured."
            },
            "observed_at": "2026-09-02T06:57:10Z",
            "freshness": "current_report",
            "boundaryFr": "Cette capacité n’est pas couverte par la version active.",
            "boundaryEn": "This capability is not covered by the active release.",
            "proof_kind": "declared_boundary",
            "source": "published_boundary"
        }
    ],
    "meta": {
        "version": "0.9.71",
        "certification_guide": ".docs/CERTIFICATIONS-SECURITE-ET-TRANSPARENCE-0.9.44.html",
        "public_routes": {
            "attestation": "/trust-attestation.json",
            "public_key": "/trust-key.json",
            "security_policy": "/security-policy",
            "security_txt": "/.well-known/security.txt"
        },
        "published_boundaries": [
            "no_external_certification_claimed",
            "host_administrator_outside_tamper_resistance_model",
            "automatic_periodic_restore_test_not_covered"
        ],
        "evidence_model": {
            "no_marketing_score": true,
            "business_values_collected": false,
            "secret_values_collected": false,
            "states": [
                "confirmed",
                "review",
                "critical",
                "unknown",
                "not_applicable",
                "not_covered"
            ]
        },
        "source_metrics": {
            "manifest_entries": 648,
            "php_files": 299,
            "javascript_files": 55,
            "css_files": 52,
            "test_files": 110,
            "documentation_files": 168
        },
        "audit_remediation_counts": {
            "confirmed": 11,
            "review": 3,
            "critical": 0,
            "unknown": 0
        },
        "key_continuity": {
            "state": "genesis",
            "ok": true,
            "configured_key_id": "ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
            "pinned_key_id": "ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
            "genesis_key_id": "ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
            "rotation_sequence": 0,
            "issues": [],
            "first_seen_at": "2026-09-02T06:57:10Z",
            "current_since": "2026-09-02T06:57:10Z",
            "state_sha256": "sha256:abc963827f0adaf559120184adf96c81c36217bb1a2223a52795062668d928dd",
            "state_signature_format": "clariodb-trust-key-continuity-state-signature/1",
            "root_pin_sha256": "sha256:3ad76c6529476a155aa1e9416b77696035d00c11c44a386156287dd0c8005011"
        },
        "dns_pin": {
            "state": "not_configured",
            "ok": false,
            "required": false,
            "name": null,
            "expected_value": "v=clariodb-trust1; key-id=ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
            "observed_values": [],
            "observed_at": null,
            "age_seconds": null,
            "source": "configuration",
            "dnssec_validated": false,
            "boundary": "No DNS observation is configured."
        },
        "transparency": {
            "state": "empty",
            "entries": 0,
            "head_hash": "sha256:0000000000000000000000000000000000000000000000000000000000000000",
            "age_seconds": null,
            "stale": true,
            "checkpoint": {
                "state": "not_applicable",
                "ok": false,
                "issues": []
            },
            "snapshot_payloads": {
                "available_snapshots": 0,
                "oldest_sequence": null,
                "newest_sequence": null,
                "policy": {
                    "recent_snapshots": 192,
                    "daily_days": 90,
                    "monthly_months": 24
                },
                "issues": []
            }
        },
        "monitoring_routes": {
            "status": "https://clariodb.net/trust-status.json",
            "ledger": "https://clariodb.net/trust-ledger.json",
            "snapshot": "https://clariodb.net/trust-snapshot.json",
            "key_history": "https://clariodb.net/trust-key-history.json",
            "root_pin": "https://clariodb.net/trust-root.json"
        },
        "snapshot_context": {
            "sequence": 1,
            "previous_record_hash": "sha256:0000000000000000000000000000000000000000000000000000000000000000",
            "interval_seconds": 900,
            "stale_after_seconds": 3600
        }
    },
    "content_sha256": "sha256:5ead38fd6d8c0d8768859cedb0fb38484bcf40916fcea5b9847a7bc879b3337e",
    "sha256": "sha256:0a666a41e310559ea4a73d0559a0095c944233d056afec92f2759876d9a1bebb",
    "attestation": {
        "state": "signed",
        "algorithm": "Ed25519",
        "signature_format": "clariodb-trust-report-signature/2",
        "signed_field": "signature_input",
        "signature_input": {
            "schema": "clariodb-trust-report-signature-input",
            "version": 2,
            "report_schema": "clariodb-trust-report",
            "report_version": 3,
            "release": "0.9.71",
            "scope": "public",
            "report_id": "7b09e09d10139654f01b74113f56dcbc",
            "generated_at": "2026-09-02T06:57:10Z",
            "sha256": "sha256:0a666a41e310559ea4a73d0559a0095c944233d056afec92f2759876d9a1bebb",
            "content_sha256": "sha256:5ead38fd6d8c0d8768859cedb0fb38484bcf40916fcea5b9847a7bc879b3337e"
        },
        "key_id": "ed25519-sha256:a21c7ee5084c9b9d89bd02e366bfede82d87fb2d26408cf5926a7f88f6aad692",
        "public_key_url": "https://clariodb.net/trust-key.json",
        "signature_base64": "gJkKZQkR2/j01yuKVuZyQ//kSKUcTilm4L+8CFGfQrDdjp8py/eXyLP0UgL69VpwLB2VuJ1dt6EEcDVR8idLBw==",
        "public_key_base64": "kCXiiVuXa26IB0ANa31767FV2X1yfV6CwjoTjUDmFfo="
    }
}