{
  "schema_version": "1.0.0",
  "contract": "stablemind.trust-center.v1",
  "build": "SIO18",
  "version": "11.18.0",
  "source_class": "BUILD_SCOPED_SECURITY_ASSURANCE_MODEL",
  "control_objectives": 24,
  "families": [
    {
      "id": "AUTHORITY_POLICY",
      "objective_count": 3,
      "objectives": [
        {
          "id": "CTRL-AUTH-01",
          "name": "Explicit delegated machine authority",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-AUTH-02",
          "name": "Deterministic policy lifecycle and testing",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-AUTH-03",
          "name": "Exact approvals and single-use permits",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "CRYPTO_CREDENTIAL",
      "objective_count": 2,
      "objectives": [
        {
          "id": "CTRL-CRYPTO-01",
          "name": "Just-in-time credential brokerage",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-CRYPTO-02",
          "name": "Release and package signing",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "CUSTOMER_ASSURANCE",
      "objective_count": 1,
      "objectives": [
        {
          "id": "CTRL-CUST-01",
          "name": "Customer security review and assurance dossier",
          "criticality": "HIGH",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "DATA_TENANT",
      "objective_count": 2,
      "objectives": [
        {
          "id": "CTRL-DATA-01",
          "name": "Tenant and environment isolation",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-DATA-02",
          "name": "Context and instruction provenance",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "DEPLOYMENT",
      "objective_count": 2,
      "objectives": [
        {
          "id": "CTRL-DEP-01",
          "name": "Deployment-boundary security",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-DEP-02",
          "name": "Air-gap, hybrid, and managed locality controls",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "GOVERNANCE",
      "objective_count": 2,
      "objectives": [
        {
          "id": "CTRL-GOV-01",
          "name": "Security governance and accountable ownership",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-GOV-02",
          "name": "Threat model and residual-risk governance",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "IDENTITY_ACCESS",
      "objective_count": 2,
      "objectives": [
        {
          "id": "CTRL-IAM-01",
          "name": "Enterprise human and workload identity",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-IAM-02",
          "name": "Separation of duties and strong authorization",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "INCIDENT_RESPONSE",
      "objective_count": 1,
      "objectives": [
        {
          "id": "CTRL-IR-01",
          "name": "Security incident response and evidence preservation",
          "criticality": "HIGH",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "LOGGING_DETECTION",
      "objective_count": 3,
      "objectives": [
        {
          "id": "CTRL-LOG-01",
          "name": "Tamper-evident evidence and forensic replay",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-LOG-02",
          "name": "Tenant-safe observability and redaction",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-LOG-03",
          "name": "Security detection and incident workflow",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "RESILIENCE",
      "objective_count": 2,
      "objectives": [
        {
          "id": "CTRL-RES-01",
          "name": "Revocation and emergency control",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-RES-02",
          "name": "Availability, ambiguity, and fenced recovery",
          "criticality": "CRITICAL",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "SECURE_DEVELOPMENT",
      "objective_count": 2,
      "objectives": [
        {
          "id": "CTRL-SDLC-01",
          "name": "Protected source and review workflow",
          "criticality": "HIGH",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-SDLC-02",
          "name": "Automated regression and security campaigns",
          "criticality": "HIGH",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    },
    {
      "id": "SUPPLY_CHAIN",
      "objective_count": 2,
      "objectives": [
        {
          "id": "CTRL-SUP-01",
          "name": "Software bill of materials and release integrity",
          "criticality": "HIGH",
          "mandatory": true,
          "review_interval_days": 30
        },
        {
          "id": "CTRL-SUP-02",
          "name": "Artifact verification and reproducibility",
          "criticality": "HIGH",
          "mandatory": true,
          "review_interval_days": 30
        }
      ]
    }
  ],
  "warning": "These are StableMind-authored engineering control objectives and do not constitute independent certification, external audit, or customer validation."
}
