{
  "schema": "longtermcapabilities-trust/v3",
  "version": "1.48.0",
  "releaseId": "lts-1.48.0-first-run-admin-bootstrap",
  "generated": "2026-07-25T13:00:00Z",
  "trustStatements": [
    {
      "id": "public-site-architecture",
      "name": "Public-site architecture",
      "status": "Public",
      "summary": "Static-first public content, local assets, local search, optional first-party public-safe lead intake, and no configured advertising pixels, external analytics, hosted search, external fonts, third-party lead platform, public chatbot, or live MCP transport.",
      "evidence": [
        "public site source",
        "trust-profile.json"
      ],
      "lastReviewed": "2026-07-25"
    },
    {
      "id": "data-handling",
      "name": "Data-handling boundaries",
      "status": "Public",
      "summary": "The optional public form stores only consented public-safe qualification in a private single-tenant system. Confidential or regulated evidence requires an approved channel after scope and responsibility are clear.",
      "evidence": [
        "contact form warning",
        "privacy notice"
      ],
      "lastReviewed": "2026-07-25"
    },
    {
      "id": "ai-human-authority",
      "name": "AI use and human authority",
      "status": "Public",
      "summary": "AI output is proposed work. Consequential actions require explicit authority, source support, review, and blocked-action criteria appropriate to the engagement.",
      "evidence": [
        "Trust Center",
        "proof model"
      ],
      "lastReviewed": "2026-07-25"
    },
    {
      "id": "secure-development",
      "name": "Secure software practices",
      "status": "Conditional",
      "summary": "Engagement controls are selected for the system and may include least authority, version control, dependency review, test and release gates, rollback, environment separation, and secret exclusion.",
      "evidence": [
        "engagement scope",
        "technical decision records"
      ],
      "lastReviewed": "2026-07-25"
    },
    {
      "id": "framework-alignment",
      "name": "Framework alignment",
      "status": "Public",
      "summary": "The practice can map technical work to public frameworks for readiness and evidence discussions. Certification, attestation, approval, and universal compliance are not asserted.",
      "evidence": [
        "standards alignment page"
      ],
      "lastReviewed": "2026-07-25"
    },
    {
      "id": "procurement-status",
      "name": "Procurement and insurance status",
      "status": "Private on request",
      "summary": "Verified entity, registration, insurance, and legal documents are shared through an approved procurement channel when relevant. Unverified values are not displayed.",
      "evidence": [
        "current procurement packet when available"
      ],
      "lastReviewed": "2026-07-25"
    }
  ],
  "frameworkReferences": [
    {
      "id": "nist-ai-rmf",
      "name": "NIST AI Risk Management Framework",
      "statusLabel": "Engineering alignment",
      "description": "Use the voluntary framework as a risk-management vocabulary for ownership, context, measurement, monitoring, response, and documentation.",
      "publicSource": "https://www.nist.gov/itl/ai-risk-management-framework",
      "claimBoundary": "LongTermCapabilities does not claim NIST certification or universal conformance."
    },
    {
      "id": "nist-ssdf",
      "name": "NIST Secure Software Development Framework",
      "statusLabel": "Practice reference",
      "description": "Use secure-development concepts to structure software lifecycle, review, dependency, release, and acquisition conversations.",
      "publicSource": "https://csrc.nist.gov/pubs/sp/800/218/final",
      "claimBoundary": "Framework reference does not constitute certification, attestation, or a security guarantee."
    },
    {
      "id": "section-508",
      "name": "Section 508 and accessible ICT guidance",
      "statusLabel": "Accessibility-aware delivery",
      "description": "Use official accessibility guidance to inform design, development, testing, and procurement evidence when public-sector requirements apply.",
      "publicSource": "https://www.section508.gov/",
      "claimBoundary": "No Section 508 or WCAG certification is asserted."
    },
    {
      "id": "iso-42001",
      "name": "ISO/IEC 42001 readiness concepts",
      "statusLabel": "Readiness support only",
      "description": "Organize technical inventories, system descriptions, human oversight, evaluation evidence, and change records that may support a qualified management-system program.",
      "publicSource": "",
      "claimBoundary": "LongTermCapabilities is not a certification body and does not issue ISO/IEC 42001 certificates."
    },
    {
      "id": "zero-trust",
      "name": "Least-authority and Zero Trust principles",
      "statusLabel": "Architecture principle",
      "description": "Use explicit identity, authorization, segmentation, data minimization, verification, and separation of approval from execution where appropriate.",
      "publicSource": "",
      "claimBoundary": "No formal Zero Trust compliance or government approval is asserted."
    }
  ],
  "publicConfiguration": {
    "externalAnalytics": false,
    "thirdPartyFormProcessor": false,
    "hostedSearchService": false,
    "externalFonts": false,
    "autonomousTools": false,
    "liveMcpTransport": false,
    "firstPartyLeadIntake": true,
    "leadIntakeConsentRequired": true,
    "leadPayloadEncryptionAtRest": true,
    "defaultLeadRetentionDays": 730
  },
  "documentCatalog": [
    {
      "id": "security-overview",
      "name": "Security overview",
      "access": "public",
      "accessLabel": "Public",
      "buyerQuestion": "What public security and delivery practices are currently described?",
      "boundary": "A public operating overview, not an audit, certification, penetration test, or security guarantee.",
      "href": "/downloads/LongTermCapabilities_SecurityOverview.pdf",
      "actionLabel": "Download PDF"
    },
    {
      "id": "public-operating-boundaries",
      "name": "Public data, AI, privacy, accessibility, and continuity boundaries",
      "access": "public",
      "accessLabel": "Public",
      "buyerQuestion": "What can be reviewed before sharing confidential or regulated information?",
      "boundary": "Public statements describe current practices and limits; they do not establish universal compliance.",
      "href": "/trust/#data-handling",
      "actionLabel": "Review boundaries"
    },
    {
      "id": "security-questionnaire",
      "name": "Security or customer-assurance questionnaire response",
      "access": "requestable",
      "accessLabel": "Requestable",
      "buyerQuestion": "Can LongTermCapabilities answer the questions relevant to a specific procurement or engagement?",
      "boundary": "Responses are scoped to the actual service, tools, data, responsibilities, and available evidence; no blanket attestation is implied.",
      "href": "/contact/?type=trust&document=security-questionnaire&purpose=security-review&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "data-handling-boundary",
      "name": "Engagement data-flow and handling boundary",
      "access": "requestable",
      "accessLabel": "Requestable",
      "buyerQuestion": "Which data, environments, tools, people, transfers, retention rules, and exclusions apply to the proposed work?",
      "boundary": "The useful answer depends on a bounded engagement and client requirements; sensitive detail moves through an approved channel.",
      "href": "/contact/?type=trust&document=data-handling-boundary&purpose=privacy-architecture&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "ai-human-authority",
      "name": "AI use and human-authority walkthrough",
      "access": "requestable",
      "accessLabel": "Requestable",
      "buyerQuestion": "Where may AI assist, who reviews it, and who retains authority over consequential action?",
      "boundary": "The walkthrough describes the proposed engagement and does not certify the buyer's broader AI program.",
      "href": "/contact/?type=trust&document=ai-human-authority&purpose=ai-governance&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "secure-delivery-continuity",
      "name": "Secure delivery, continuity, and exit response",
      "access": "requestable",
      "accessLabel": "Requestable",
      "buyerQuestion": "How will change, access, evidence, handoff, continuity, and exit be handled for the workstream?",
      "boundary": "Controls and artifacts are selected for the scoped work; no 24/7 operations or universal recovery guarantee is implied.",
      "href": "/contact/?type=trust&document=secure-delivery-continuity&purpose=procurement&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "tools-subprocessors",
      "name": "Engagement-specific tool, dependency, and subprocessor disclosure",
      "access": "requestable",
      "accessLabel": "After scope",
      "buyerQuestion": "Which third-party tools or services would actually be used for the proposed engagement?",
      "boundary": "No universal list is asserted before scope. The applicable set is disclosed and approved for the engagement.",
      "href": "/contact/?type=trust&document=tools-subprocessors&purpose=procurement&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "independent-assurance",
      "name": "Independent assurance reports and certifications",
      "access": "not-asserted",
      "accessLabel": "Not asserted",
      "buyerQuestion": "Is an independent audit, SOC report, ISO certificate, penetration-test report, or comparable assurance artifact publicly claimed?",
      "boundary": "No such artifact is publicly asserted as currently held. Unknown or unavailable evidence is not presented as complete.",
      "href": "",
      "actionLabel": ""
    }
  ],
  "documentRequestPath": "/contact/?type=trust&source=trust-center"
}
