{"binderId":"compliance-audit-export/2026-07-29","exportedAt":"2026-07-29T05:12:29.064Z","module":"Compliance Readiness","version":"1.0.0-2026.07.05","doctrine":"Show, cite, comply — every framework control maps to honest posture, evidence artifact, and proof route. NOT_HELD and DESIGN_INTENT are first-class; no silent overclaim.","company":{"legalName":"Integrated Services and Solutions LLC","ein":"87-2795417","uei":"C7YDV3P8EHL7","cage":"9VKK3"},"authoritiesNotHeld":["FedRAMP authorization","CMMC Level 2 C3PAO assessment","IL-4/IL-5 hosting authority","FIPS 140-2/140-3 module validation","CAC/PKI integration","ATO"],"registry":{"version":"1.0.0","updated":"2026-07-22T18:00:00Z","doctrine":"Show, cite, comply — every framework control maps to honest posture, evidence artifact, and proof route. NOT_HELD and DESIGN_INTENT are first-class; no silent overclaim.","legend":{"HELD":"Third-party certificate or government authorization held today.","ALIGNED":"Implementation conforms to published spec; self-assessed mapping on file.","IN_PROGRESS":"Control mapping or evidence collection underway — gap visible.","DESIGN_INTENT":"Architecture targets this control; not yet attested or assessed.","NOT_HELD":"Authority not held; listed so auditors see the gap on the record."},"surfaces":{"hub":"/compliance-hub","vendorSecurity":"/vendor-security","governance":"/governance","standards":"/standards","contracting":"/contracting","atoPath":"/contracting/ato-path","redTeam":"/evaluate/red-team","evaluateReviewer":"/evaluate/reviewer"},"apis":{"registry":"/api/compliance/registry","status":"/api/compliance/status","auditExport":"/api/compliance/audit-export","authorities":"/api/platform/authorities","companyIdentity":"/api/company/identity","standards":"/api/standards","compliancePack":"/api/security/compliance-pack/v1","hitlAudit":"/api/governance/hitl-audit","hitlAttest":"/api/governance/hitl/attest","systemOfRecord":"/api/governance/system-of-record","redTeamReadiness":"/api/governance/red-team-readiness"},"auditScript":"npm run compliance:audit","frameworks":[{"id":"nist-csf-2","label":"NIST Cybersecurity Framework 2.0","source":"https://www.nist.gov/cyberframework","posture":"ALIGNED","honestNote":"Self-assessed control mapping; no third-party CSF certification.","controls":[{"id":"csf-gv-oc-01","family":"Govern","title":"Organizational cybersecurity risk management strategy","posture":"ALIGNED","implementation":"server/governance-engine.ts","evidence":["server/templates/governance.html","data/compliance-framework-registry.json"],"proofRoutes":["/api/governance/policy","/governance"]},{"id":"csf-id-am-01","family":"Identify","title":"Asset inventory and system-of-record posture","posture":"ALIGNED","implementation":"server/governance-hitl-store.ts","evidence":["scripts/ensure-governance-hitl-audit.sql"],"proofRoutes":["/api/governance/system-of-record","/api/governance/hitl-audit"]},{"id":"csf-pr-ds-01","family":"Protect","title":"Data security — tenant isolation per portal","posture":"ALIGNED","implementation":"server/portal-engine.ts","evidence":["server/portals/governance.json","server/portals/compliance.json"],"proofRoutes":["/api/governance/export-manifest?portal=corporate"]},{"id":"csf-de-cm-01","family":"Detect","title":"Continuous monitoring — immunology antigen sensing","posture":"ALIGNED","implementation":"server/security/immunology-engine.ts","evidence":["docs/infra/defense-daas-demo.md"],"proofRoutes":["/api/security/vendor-dashboard","/vendor-security"]},{"id":"csf-rs-ma-01","family":"Respond","title":"Incident response — cyber response engine + COA chain","posture":"ALIGNED","implementation":"server/cyber-response-engine.ts","evidence":["server/cop-alert-intelligence.ts"],"proofRoutes":["/api/cop/alerts-intel","/api/prove/touch?behavior=1"]}]},{"id":"nist-ai-rmf","label":"NIST AI Risk Management Framework 1.0","source":"https://www.nist.gov/itl/ai-risk-management-framework","posture":"ALIGNED","honestNote":"HITL required for critical insights; no NIST AI RMF third-party audit.","controls":[{"id":"ai-rmf-govern-1","family":"Govern","title":"Human-in-the-loop for AI-generated critical insights","posture":"ALIGNED","implementation":"server/governance-engine.ts","evidence":["docs/canonical/06_responsible_ai_governance_wedge.md"],"proofRoutes":["/api/governance/hitl-audit","POST /api/governance/hitl/attest"]},{"id":"ai-rmf-map-1","family":"Map","title":"AI provider orchestration transparency and failover","posture":"ALIGNED","implementation":"server/ai-provider-orchestrator.ts","evidence":["server/templates/governance.html"],"proofRoutes":["/api/ai-orchestrator/health","/api/governance/red-team-readiness"]},{"id":"ai-rmf-measure-1","family":"Measure","title":"Evaluator prove chain — behavioral AI touch verification","posture":"ALIGNED","implementation":"server/prove-touch-routes.ts","evidence":["docs/evidence/evaluator-pre-present-*.md"],"proofRoutes":["/api/prove/touch?behavior=1","/api/evaluate/cohesion-status"]}]},{"id":"fedramp","label":"FedRAMP Authorization","source":"https://www.fedramp.gov/","posture":"NOT_HELD","honestNote":"Platform is not FedRAMP-authorized. ATO path memo documents honest phase plan.","controls":[{"id":"fedramp-ssp","family":"RMF","title":"System Security Plan (SSP) draft artifacts","posture":"IN_PROGRESS","implementation":"data/compliance-framework-registry.json","evidence":["server/templates/contracting-ato-path.html","docs/canonical/20_full_stack_validation_blueprint.md"],"proofRoutes":["/contracting/ato-path","/api/compliance/audit-export"]},{"id":"fedramp-conmon","family":"RMF","title":"Continuous monitoring hooks","posture":"DESIGN_INTENT","implementation":"server/prove-touch-routes.ts","evidence":["scripts/compliance-audit.mjs"],"proofRoutes":["/api/health/live","npm run compliance:audit"]}]},{"id":"cmmc-l2","label":"CMMC 2.0 Level 2","source":"https://dodcio.defense.gov/CMMC/","posture":"DESIGN_INTENT","honestNote":"Practices referenced in internal mapping; no C3PAO assessment held.","controls":[{"id":"cmmc-ac-l2","family":"Access Control","title":"RBAC event bus + site access gate","posture":"ALIGNED","implementation":"server/site-access-gate.ts","evidence":["docs/infra/site-access-setup.md"],"proofRoutes":["/access","/api/health/live"]},{"id":"cmmc-au-l2","family":"Audit","title":"HITL audit dual-write to Postgres","posture":"ALIGNED","implementation":"server/governance-hitl-store.ts","evidence":["scripts/ensure-governance-hitl-audit.sql"],"proofRoutes":["/api/governance/system-of-record","POST /api/governance/hitl/attest"]},{"id":"cmmc-sc-l2","family":"System Communications Protection","title":"PQC hybrid key exchange (FIPS 203/204)","posture":"ALIGNED","implementation":"server/security/pqc-bridge.ts","evidence":["docs/infra/defense-daas-demo.md"],"proofRoutes":["/api/security/pqc/v1","/vendor-security"]}]},{"id":"soc2-type2","label":"SOC 2 Type II","source":"https://www.aicpa.org/soc","posture":"NOT_HELD","honestNote":"No SOC 2 report issued. Full CC1-CC9 + Availability + Confidentiality control set mapped; continuous PQC-signed evidence monitor live; independent CPA examination required before any claim.","controls":[{"id":"soc2-cc1","family":"Control Environment","title":"Governance, integrity, oversight, accountability","posture":"IN_PROGRESS","implementation":"docs/compliance/soc2/01_Information_Security_Management_System_Policy.md","evidence":["docs/compliance/soc2/01_Information_Security_Management_System_Policy.md"],"proofRoutes":["/api/compliance/vanta/tests"]},{"id":"soc2-cc2","family":"Communication","title":"Internal/external security communication","posture":"ALIGNED","implementation":"server/templates/security.html","evidence":["server/templates/trust-center.html"],"proofRoutes":["/security","/trust-center"]},{"id":"soc2-cc3","family":"Risk Assessment","title":"Risk identification, fraud, change","posture":"IN_PROGRESS","implementation":"docs/compliance/soc2/00_SOC2_Readiness_Assessment.md","evidence":["docs/compliance/soc2/05_SOC2_Evidence_Register.md"],"proofRoutes":["/api/compliance/vanta/dashboard"]},{"id":"soc2-cc4","family":"Monitoring Activities","title":"Continuous control monitoring","posture":"ALIGNED","implementation":"server/soc2-continuous-monitor.ts","evidence":["data/soc2-evidence/*.jsonl"],"proofRoutes":["/api/compliance/soc2/monitor/status","/api/compliance/soc2/monitor/verify"]},{"id":"soc2-cc5","family":"Control Activities","title":"Technical + policy control activities","posture":"ALIGNED","implementation":"server/lane-firewall.ts","evidence":["docs/compliance/soc2/04_SOC2_Control_Matrix.md"],"proofRoutes":["/api/lane-firewall/status"]},{"id":"soc2-cc6","family":"Logical & Physical Access","title":"RBAC, MFA, least privilege, boundary","posture":"IN_PROGRESS","implementation":"server/site-access-gate.ts","evidence":["docs/compliance/soc2/01_Information_Security_Management_System_Policy.md"],"proofRoutes":["/api/lane-firewall/status","/api/company/identity"]},{"id":"soc2-cc7","family":"System Operations","title":"Monitoring, vuln mgmt, incident response","posture":"IN_PROGRESS","implementation":"server/agos-writer.ts","evidence":["docs/compliance/soc2/02_Incident_Response_Plan.md"],"proofRoutes":["/api/compliance/soc2/monitor/verify"]},{"id":"soc2-cc8","family":"Change Management","title":"Version-controlled change with gates","posture":"ALIGNED","implementation":"package.json:gate:push","evidence":["deploy stamps","commit history"],"proofRoutes":["/api/compliance/vanta/tests"]},{"id":"soc2-cc9","family":"Risk Mitigation","title":"Vendor risk + business disruption","posture":"IN_PROGRESS","implementation":"docs/compliance/soc2/03_Business_Continuity_DR_Plan.md","evidence":["docs/compliance/soc2/03_Business_Continuity_DR_Plan.md"],"proofRoutes":["/api/compliance/vanta/dashboard"]},{"id":"soc2-a1","family":"Availability","title":"Capacity, backup, disaster recovery","posture":"IN_PROGRESS","implementation":"docs/compliance/soc2/03_Business_Continuity_DR_Plan.md","evidence":["docs/compliance/soc2/03_Business_Continuity_DR_Plan.md"],"proofRoutes":["/api/health/live"]},{"id":"soc2-c1","family":"Confidentiality","title":"Data classification, handling, disposal","posture":"IN_PROGRESS","implementation":"docs/compliance/soc2/01_Information_Security_Management_System_Policy.md","evidence":["docs/compliance/soc2/01_Information_Security_Management_System_Policy.md"],"proofRoutes":["/api/compliance/vanta/tests"]}]},{"id":"cjis","label":"FBI CJIS Security Policy","source":"https://www.fbi.gov/services/cjis/cjis-security-policy","posture":"NOT_HELD","honestNote":"No CJIS-compliant hosting or policy attestation. Listed for law-enforcement pursuit honesty.","controls":[{"id":"cjis-ia","family":"Identification & Authentication","title":"Advanced authentication for CJIS systems","posture":"NOT_HELD","implementation":null,"evidence":["server/company-identity.ts"],"proofRoutes":["/api/platform/authorities"]}]},{"id":"iso-27001","label":"ISO/IEC 27001","source":"https://www.iso.org/standard/54534.html","posture":"NOT_HELD","honestNote":"No ISO 27001 certification. ISMS mapping derived from NIST CSF alignment.","controls":[{"id":"iso-a5","family":"Organizational","title":"Information security policies","posture":"ALIGNED","implementation":"server/templates/governance.html","evidence":["docs/canonical/06_responsible_ai_governance_wedge.md"],"proofRoutes":["/governance","/api/governance/policy"]}]},{"id":"fips-pqc","label":"NIST FIPS 203 / 204 Post-Quantum Cryptography","source":"https://csrc.nist.gov/projects/post-quantum-cryptography","posture":"ALIGNED","honestNote":"ML-KEM / ML-DSA implementation with transparency log; not a FIPS 140-3 validated module.","controls":[{"id":"fips-203-mlkem","family":"Cryptography","title":"ML-KEM hybrid key encapsulation","posture":"ALIGNED","implementation":"server/security/pqc-bridge.ts","evidence":["server/pqc-crypto.ts"],"proofRoutes":["/api/security/pqc/v1","/api/security/pqc/v1/transparency-log"]},{"id":"fips-140-module","family":"Cryptography","title":"FIPS 140-2/140-3 validated cryptographic module","posture":"NOT_HELD","implementation":null,"evidence":["server/company-identity.ts"],"proofRoutes":["/api/platform/authorities"]}]},{"id":"iron-rule-9","label":"IRON RULE 9 — Capability Alignment Matrix","source":"docs/alignment/capability-matrix.md","posture":"IN_PROGRESS","honestNote":"Matrix exists; UNVERIFIED rows visible in dev audit; strict CI mode fails until citations filled.","controls":[{"id":"ir9-matrix","family":"Traceability","title":"RFP + user citation per advertised capability","posture":"IN_PROGRESS","implementation":"docs/alignment/capability-matrix.md","evidence":["scripts/alignment-matrix-audit.mjs"],"proofRoutes":["node scripts/alignment-matrix-audit.mjs","node scripts/alignment-matrix-audit.mjs --json"]},{"id":"ir9-claims","family":"Congruence","title":"Frontend claim → backend endpoint resolver","posture":"ALIGNED","implementation":"scripts/capability-claim-audit.mjs","evidence":["scripts/capability-claim-audit.mjs"],"proofRoutes":["node scripts/capability-claim-audit.mjs"]}]}]},"status":{"module":"Compliance Readiness","version":"1.0.0-2026.07.05","generatedAt":"2026-07-29T05:12:28.935Z","doctrine":"Show, cite, comply — every framework control maps to honest posture, evidence artifact, and proof route. NOT_HELD and DESIGN_INTENT are first-class; no silent overclaim.","readinessScore":60,"summary":{"frameworkCount":9,"controlCount":30,"byPosture":{"ALIGNED":18,"IN_PROGRESS":9,"DESIGN_INTENT":1,"NOT_HELD":2},"notHeldFrameworks":["fedramp","soc2-type2","cjis","iso-27001"]},"live":{"systemOfRecord":{"ok":true,"body":{"module":"Governance Engine","version":"1.0.0-2026.06.28","systemOfRecord":"postgres","demoMirror":"in-memory","postgresEnabled":true,"postgresRowCount":68,"migrationNote":"Demo uses an in-memory mirror for agility; every append dual-writes to governance_hitl_audit (Postgres). Production auditors query Postgres as the authoritative system of record.","dualWrite":true,"auditLogApi":"/api/governance/hitl-audit","postgresTable":"governance_hitl_audit","memoryEntries":0,"operatorScript":"Postgres is the authoritative system of record; API read path is postgres-primary when governance_hitl_audit is populated. In-memory mirror remains for demo agility on cold start."}},"redTeamReadiness":{"ok":true,"body":{"module":"Governance Engine","version":"1.0.0-2026.06.28","pass":true,"questions":[{"id":"system-of-record","question":"Show me the System of Record.","answer":"Demo uses an in-memory mirror for agility; every append dual-writes to governance_hitl_audit (Postgres). Production auditors query Postgres as the authoritative system of record.","proof":{"api":"/api/governance/system-of-record","hitlLog":"/api/governance/hitl-audit","postgresTable":"governance_hitl_audit"},"live":{"dualWrite":true,"memoryEntries":0,"postgresEnabled":true,"postgresRowCount":68}},{"id":"provider-resilience","question":"What happens if the AI provider goes down?","answer":"All LLM calls route through the AI Provider Orchestrator with visible failover (OpenAI → xAI Grok → Gemini → corpus-only RAG). Runtime hot-swap via POST /api/ai-orchestrator/prefer-tier — no redeploy required.","proof":{"health":"/api/ai-orchestrator/health","preferTier":"/api/ai-orchestrator/prefer-tier","tiers":["openai","xai-grok","perplexity","gemini","corpus-only"],"tierHealth":{"openai":{"tier":"openai","available":true,"lastSuccessAt":null,"lastFailureAt":null,"lastFailureReason":null,"consecutiveFailures":0},"gemini":{"tier":"gemini","available":true,"lastSuccessAt":null,"lastFailureAt":null,"lastFailureReason":null,"consecutiveFailures":0},"xai-grok":{"tier":"xai-grok","available":true,"lastSuccessAt":null,"lastFailureAt":null,"lastFailureReason":null,"consecutiveFailures":0},"perplexity":{"tier":"perplexity","available":true,"lastSuccessAt":null,"lastFailureAt":null,"lastFailureReason":null,"consecutiveFailures":0},"corpus-only":{"tier":"corpus-only","available":true,"lastSuccessAt":null,"lastFailureAt":null,"lastFailureReason":null,"consecutiveFailures":0}},"runtimePreferTier":null}},{"id":"workbench-configuration","question":"How is the Workbench configured?","answer":"Portal manifests declare workbenches[] against workbench-library.json. corporate.json physically excludes military operational tools — isolation is manifest-enforced, not UI-hidden.","proof":{"library":"/api/portals/workbench-library","corporate":"/api/portals/corporate","military":"/api/portals/military","e2e":"npm run test:e2e:ia"},"live":{"corporateWorkbenches":["efficiency","risk","integrity"],"corporateToolIds":["bottleneck-simulation","resource-allocation","kpi-trajectory","scenario-modeling","constraint-sweeps","regulatory-crosswalk","hitl-log","reasoning-trace","manifest-export"],"militaryExcludedFromCorporate":true}}],"surfaces":{"redTeamPage":"/evaluate/red-team","bushSchoolSynthesizer":"/api/evaluate/synthesizer/run"}}},"compliancePack":{"ok":true,"body":{"packId":"atlas-compliance-pack/v1","exportedAt":"2026-07-29T05:12:28.924Z","label":"Governance-as-a-Service Compliance Pack","portalId":"corporate","masterGovernance":{"id":"governance-master","version":"1.0.0-2026.06.28","label":"ATLAS Master Governance & Security Policy","dataSovereignty":"Tenant data is strictly isolated by portal. Your operational data never trains shared models or bleeds across military and corporate tenants.","dataIsolation":"Engine is shared; knowledge and entity graph partitions are siloed per portal. Corporate supply-chain data does not train military incident models, and vice versa.","aiLiabilityModel":"AI is an advisor only. Human-in-the-loop review is required before any critical insight becomes an authorized decision. Operator retains liability for all actions taken.","hitlLabel":"AI-Generated Insight: Human Review Required","portability":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","auditCompliance":"All AI suggestions and human approvals are recorded in the HITL audit log at /api/governance/hitl-audit. Reasoning traces must cite source references before executive action.","pricingModel":"Per-portal / per-workbench licensing — predictable TCO. No per-token or per-query surprise billing for standard operator seats.","dayOneValue":"Pre-built industry blueprints (e.g. logistics) activate in under 24 hours via configuration, not multi-year customization.","connectorFramework":"Enterprise data ingress via documented API gateway and connector catalog — SAP, Oracle, Salesforce adapters are integration targets with staged/live posture labels.","exportFormats":["json","yaml"],"exportApi":"/api/governance/export-manifest","auditLogApi":"/api/governance/hitl-audit","systemOfRecordApi":"/api/governance/system-of-record","redTeamReadinessApi":"/api/governance/red-team-readiness","systemOfRecordNote":"Demo dual-writes HITL to in-memory mirror + Postgres governance_hitl_audit. Production auditors treat Postgres as authoritative.","connectorsApi":"/api/governance/connectors","blueprintsApi":"/api/governance/blueprints","requiredPortalFields":["governance"]},"portalGovernance":{"id":"governance-master","version":"1.0.0-2026.06.28","label":"ATLAS Master Governance & Security Policy","dataSovereignty":"Corporate tenant data never trains military models or shared fine-tuning datasets.","dataIsolation":"Engine is shared; knowledge and entity graph partitions are siloed per portal. Corporate supply-chain data does not train military incident models, and vice versa.","aiLiabilityModel":"AI-generated risk insights require executive human approval before operational action.","hitlLabel":"AI-Generated Insight: Human Review Required","portability":"Export full corporate house — graph, dialect, manifest — as JSON/YAML from /api/governance/export-manifest.","auditCompliance":"All AI suggestions and human approvals are recorded in the HITL audit log at /api/governance/hitl-audit. Reasoning traces must cite source references before executive action.","pricingModel":"Per-portal / per-workbench licensing — predictable TCO. No per-token or per-query surprise billing for standard operator seats.","dayOneValue":"Pre-built industry blueprints (e.g. logistics) activate in under 24 hours via configuration, not multi-year customization.","connectorFramework":"Enterprise data ingress via documented API gateway and connector catalog — SAP, Oracle, Salesforce adapters are integration targets with staged/live posture labels.","exportFormats":["json","yaml"],"exportApi":"/api/governance/export-manifest","auditLogApi":"/api/governance/hitl-audit","systemOfRecordApi":"/api/governance/system-of-record","redTeamReadinessApi":"/api/governance/red-team-readiness","systemOfRecordNote":"Demo dual-writes HITL to in-memory mirror + Postgres governance_hitl_audit. Production auditors treat Postgres as authoritative.","connectorsApi":"/api/governance/connectors","blueprintsApi":"/api/governance/blueprints","requiredPortalFields":["governance"]},"workbenches":[{"id":"efficiency","label":"Efficiency / Growth","tagline":"Bottlenecks, resource allocation, and KPI trajectory.","best_for":["Retail","Supply Chain","Manufacturing"],"tools":[{"id":"bottleneck-simulation","label":"Bottleneck Simulation","route":"/executive#risks","description":"Simulate supply-chain bottlenecks and bottom-line impact.","workbenchId":"efficiency"},{"id":"resource-allocation","label":"Resource Allocation","route":"/workspace","description":"Allocate resources across operational lanes.","workbenchId":"efficiency"},{"id":"kpi-trajectory","label":"KPI Trajectory","route":"/executive#kpis","description":"Executive KPI trend and trajectory window.","workbenchId":"efficiency"}],"enabled":true},{"id":"risk","label":"Risk / Compliance","tagline":"What-if scenarios, constraint checks, and regulatory cross-walk.","best_for":["Corporate","Legal","Finance"],"tools":[{"id":"scenario-modeling","label":"Scenario Modeling","route":"/evaluate","description":"What-if evaluation and executive scenario lanes.","workbenchId":"risk"},{"id":"constraint-sweeps","label":"Constraint Sweeps","route":"/evaluate/surface-scan","description":"Surface integrity and constraint audit for demo paths.","workbenchId":"risk"},{"id":"regulatory-crosswalk","label":"Regulatory Cross-Walk","route":"/capabilities","description":"Capability and compliance posture cross-reference.","workbenchId":"risk"}],"enabled":true},{"id":"integrity","label":"Integrity / Audit","tagline":"Human-in-the-loop log, reasoning trace, and portable house export.","best_for":["Compliance","Procurement","C-Suite"],"tools":[{"id":"hitl-log","label":"HITL Log Access","route":"/executive#audit","description":"Human review queue and decision audit trail.","workbenchId":"integrity"},{"id":"reasoning-trace","label":"Reasoning Trace","route":"/evaluate/reviewer","description":"Evaluator prove chain and AI reasoning trace.","workbenchId":"integrity"},{"id":"manifest-export","label":"Manifest Export","route":"/api/governance/export-manifest?portal=corporate&format=json","description":"Export portal house as JSON or YAML.","workbenchId":"integrity"}],"enabled":true}],"hitlAuditSample":[{"id":"hitl-1784137769362-1n8xhy","at":"2026-07-15T17:49:29.362Z","portalId":"corporate","contextType":"corporate","insightType":"export","label":"House export (json)","hitlStatus":"approved","references":["export-manifest"],"reasoningTrace":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","actor":"operator","modulePath":"/executive"},{"id":"hitl-1784137723361-2ms2m3","at":"2026-07-15T17:48:43.361Z","portalId":"corporate","contextType":"corporate","insightType":"export","label":"House export (json)","hitlStatus":"approved","references":["export-manifest"],"reasoningTrace":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","actor":"operator","modulePath":"/executive"},{"id":"hitl-1783957025432-xj78bx","at":"2026-07-13T15:37:05.432Z","portalId":"corporate","contextType":"corporate","insightType":"export","label":"House export (json)","hitlStatus":"approved","references":["export-manifest"],"reasoningTrace":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","actor":"operator","modulePath":"/executive"},{"id":"hitl-1783956993018-14ntw5","at":"2026-07-13T15:36:33.018Z","portalId":"corporate","contextType":"corporate","insightType":"export","label":"House export (json)","hitlStatus":"approved","references":["export-manifest"],"reasoningTrace":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","actor":"operator","modulePath":"/executive"},{"id":"hitl-1783956815107-wesz5u","at":"2026-07-13T15:33:35.107Z","portalId":"corporate","contextType":"corporate","insightType":"export","label":"House export (json)","hitlStatus":"approved","references":["export-manifest"],"reasoningTrace":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","actor":"operator","modulePath":"/executive"},{"id":"hitl-1783956800528-8gv4sn","at":"2026-07-13T15:33:20.528Z","portalId":"corporate","contextType":"corporate","insightType":"export","label":"House export (json)","hitlStatus":"approved","references":["export-manifest"],"reasoningTrace":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","actor":"operator","modulePath":"/executive"},{"id":"hitl-1783956744281-msqjnq","at":"2026-07-13T15:32:24.281Z","portalId":"corporate","contextType":"corporate","insightType":"export","label":"House export (json)","hitlStatus":"approved","references":["export-manifest"],"reasoningTrace":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","actor":"operator","modulePath":"/executive"},{"id":"hitl-1783956734718-ks5zcc","at":"2026-07-13T15:32:14.718Z","portalId":"corporate","contextType":"corporate","insightType":"export","label":"House export (json)","hitlStatus":"approved","references":["export-manifest"],"reasoningTrace":"Full house export available at any time — portal manifest, governance policy, dialect map, and tenant-scoped graph export as JSON or YAML. You own the data; ATLAS owns the engine runtime.","actor":"operator","modulePath":"/executive"}],"apis":{"hitlAudit":"/api/governance/hitl-audit","systemOfRecord":"/api/governance/system-of-record","exportManifest":"/api/governance/export-manifest?portal=corporate&format=json","pqcBridge":"/api/security/pqc/v1","compliancePack":"/api/security/compliance-pack/v1?portal=corporate"},"cisoChecklist":["Data sovereignty and tenant isolation policy attached","HITL audit trail with Postgres system of record","NIST FIPS 203/204 PQC transparency log","Portable house export (JSON/YAML)"]}},"redTeamPass":true,"postgresEnabled":true},"auditReady":{"registry":true,"hub":"/compliance-hub","export":"/api/compliance/audit-export","script":"npm run compliance:audit","evidenceDir":"docs/evidence/compliance-audit-*.json"},"surfaces":{"hub":"/compliance-hub","vendorSecurity":"/vendor-security","governance":"/governance","standards":"/standards","contracting":"/contracting","atoPath":"/contracting/ato-path","redTeam":"/evaluate/red-team","evaluateReviewer":"/evaluate/reviewer"},"apis":{"registry":"/api/compliance/registry","status":"/api/compliance/status","auditExport":"/api/compliance/audit-export","authorities":"/api/platform/authorities","companyIdentity":"/api/company/identity","standards":"/api/standards","compliancePack":"/api/security/compliance-pack/v1","hitlAudit":"/api/governance/hitl-audit","hitlAttest":"/api/governance/hitl/attest","systemOfRecord":"/api/governance/system-of-record","redTeamReadiness":"/api/governance/red-team-readiness"},"honestLimits":["NOT_HELD and DESIGN_INTENT postures are intentional — do not market as certifications held.","IRON RULE 9 alignment matrix has UNVERIFIED rows; run compliance:audit for current gap list.","FedRAMP/ATO/CJIS/SOC2 require sponsor or third-party assessor action beyond software artifacts."]},"audits":{"alignmentMatrix":{"ok":true,"hardFail":false,"mode":"dev","matrixPath":"docs/alignment/capability-matrix.md","summary":{"total":20,"passing":8,"unverified":12,"missing_columns":0},"errors":[],"warnings":["L37 WARN: \"Cyber response engine (CVE NVD, MITRE ATT&CK)\" has UNVERIFIED citation","L38 WARN: \"Battle Rhythm automation (recurring tasks, AAR)\" has UNVERIFIED citation","L40 WARN: \"CIA Factbook ASCOPE/PMESII grounding (261 countries)\" has UNVERIFIED citation","L41 WARN: \"Natural-hazard fusion (USGS quake, NOAA SWPC, NOAA NHC)\" has UNVERIFIED citation","L42 WARN: \"METOC weather fusion\" has UNVERIFIED citation","L43 WARN: \"Cyclone model (ATCF, GRIB2 ingest stub)\" has UNVERIFIED citation","L44 WARN: \"Voice tactical reports (CFF / 9-line / SALUTE / SITREP / SPOT)\" has UNVERIFIED citation","L45 WARN: \"CAP/IPAWS authoring (drafts only)\" has UNVERIFIED citation","L46 WARN: \"Drone OSINT auto-fetcher (24h cycle)\" has UNVERIFIED citation","L47 WARN: \"OGC WMS/WFS/WMTS geospatial services\" has UNVERIFIED citation","L48 WARN: \"MIL-STD-2525D APP-6D symbology rendering\" has UNVERIFIED citation","L49 WARN: \"TAK / CoT bridge (ATAK interop)\" has UNVERIFIED citation"]},"capabilityClaims":{"policyVersion":"1.0.0","auditedAt":"2026-07-29T05:12:29.053Z","totals":{"hard":2,"warn":0,"ok":12,"total":14},"findings":[{"id":"voice-tactical-cff","claim":"Call for Fire / 9-line MEDEVAC / SALUTE / SITREP / SPOT structured voice reports","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"voice-tactical-ptt-roadmap","claim":"Hands-free voice push-to-talk / WebRTC voice room","severity":"HARD","status":"UNLABELED_ROADMAP","notes":["roadmap/design-intent claim missing honest label on any surface; expected one of: ROADMAP"]},{"id":"nl-cop-filter-roadmap","claim":"Natural-language COP filtering (\"show me all Group 1 UAS within 5 km\")","severity":"HARD","status":"UNLABELED_ROADMAP","notes":["roadmap/design-intent claim missing honest label on any surface; expected one of: ROADMAP"]},{"id":"drone-intel-scheduler","claim":"24h drone OSINT auto-fetcher","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"factbook-ascope-pmesii","claim":"ASCOPE / PMESII country reference grounding (CIA World Factbook)","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"natural-hazard-usgs-noaa","claim":"USGS earthquake + NOAA SWPC space-weather + NOAA NHC tropical-cyclone feeds","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"cyber-cve-kev-feed","claim":"CISA KEV + NVD recent CVE cyber threat feed","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"world-maritime-ais","claim":"World maritime AIS / AISStream live vessel tracking","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"live-eq-tsunami-volcano","claim":"USGS earthquake, NOAA tsunami, Smithsonian volcano live feeds","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"remote-id-faa","claim":"FAA Remote ID UAS tracking","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"rag-corpus-grounding","claim":"Internal RAG corpus grounding (doc count surfaced live)","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"sbir-pipeline","claim":"DoD SBIR / DSIP pipeline + draft generation","severity":"OK","status":"GREEN","notes":["backing files + endpoints verified"]},{"id":"stanag-link16-vmf","claim":"STANAG 4586 / Link 16 / VMF / NFFI ingest","severity":"OK","status":"GREEN","notes":["honest roadmap/design-intent label present"]},{"id":"fire-mission-auto-release","claim":"Automated fire-mission release","severity":"OK","status":"GREEN","notes":["honest roadmap/design-intent label present"]}]}},"citeableArtifacts":["data/compliance-framework-registry.json","docs/alignment/capability-matrix.md","docs/canonical/00_operator_identity.md","docs/canonical/20_full_stack_validation_blueprint.md","docs/canonical/06_responsible_ai_governance_wedge.md","scripts/compliance-audit.mjs","scripts/alignment-matrix-audit.mjs","scripts/capability-claim-audit.mjs"],"proofCommands":["npm run compliance:audit","curl -s /api/compliance/status | jq .readinessScore","curl -s /api/governance/red-team-readiness | jq .pass","curl -s /api/platform/authorities | jq .authoritiesNotHeld"]}