{
  "schema": "longtermcapabilities-trust-document-catalog/v1",
  "version": "1.48.0",
  "releaseId": "lts-1.48.0-first-run-admin-bootstrap",
  "generated": "2026-07-25T13:00:00Z",
  "lastReviewed": "2026-07-25",
  "publicOnly": true,
  "requestPath": "/contact/?type=trust&source=trust-center",
  "documents": [
    {
      "id": "security-overview",
      "name": "Security overview",
      "access": "public",
      "accessLabel": "Public",
      "buyerQuestion": "What public security and delivery practices are currently described?",
      "boundary": "A public operating overview, not an audit, certification, penetration test, or security guarantee.",
      "href": "/downloads/LongTermCapabilities_SecurityOverview.pdf",
      "actionLabel": "Download PDF"
    },
    {
      "id": "public-operating-boundaries",
      "name": "Public data, AI, privacy, accessibility, and continuity boundaries",
      "access": "public",
      "accessLabel": "Public",
      "buyerQuestion": "What can be reviewed before sharing confidential or regulated information?",
      "boundary": "Public statements describe current practices and limits; they do not establish universal compliance.",
      "href": "/trust/#data-handling",
      "actionLabel": "Review boundaries"
    },
    {
      "id": "security-questionnaire",
      "name": "Security or customer-assurance questionnaire response",
      "access": "requestable",
      "accessLabel": "Requestable",
      "buyerQuestion": "Can LongTermCapabilities answer the questions relevant to a specific procurement or engagement?",
      "boundary": "Responses are scoped to the actual service, tools, data, responsibilities, and available evidence; no blanket attestation is implied.",
      "href": "/contact/?type=trust&document=security-questionnaire&purpose=security-review&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "data-handling-boundary",
      "name": "Engagement data-flow and handling boundary",
      "access": "requestable",
      "accessLabel": "Requestable",
      "buyerQuestion": "Which data, environments, tools, people, transfers, retention rules, and exclusions apply to the proposed work?",
      "boundary": "The useful answer depends on a bounded engagement and client requirements; sensitive detail moves through an approved channel.",
      "href": "/contact/?type=trust&document=data-handling-boundary&purpose=privacy-architecture&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "ai-human-authority",
      "name": "AI use and human-authority walkthrough",
      "access": "requestable",
      "accessLabel": "Requestable",
      "buyerQuestion": "Where may AI assist, who reviews it, and who retains authority over consequential action?",
      "boundary": "The walkthrough describes the proposed engagement and does not certify the buyer's broader AI program.",
      "href": "/contact/?type=trust&document=ai-human-authority&purpose=ai-governance&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "secure-delivery-continuity",
      "name": "Secure delivery, continuity, and exit response",
      "access": "requestable",
      "accessLabel": "Requestable",
      "buyerQuestion": "How will change, access, evidence, handoff, continuity, and exit be handled for the workstream?",
      "boundary": "Controls and artifacts are selected for the scoped work; no 24/7 operations or universal recovery guarantee is implied.",
      "href": "/contact/?type=trust&document=secure-delivery-continuity&purpose=procurement&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "tools-subprocessors",
      "name": "Engagement-specific tool, dependency, and subprocessor disclosure",
      "access": "requestable",
      "accessLabel": "After scope",
      "buyerQuestion": "Which third-party tools or services would actually be used for the proposed engagement?",
      "boundary": "No universal list is asserted before scope. The applicable set is disclosed and approved for the engagement.",
      "href": "/contact/?type=trust&document=tools-subprocessors&purpose=procurement&source=trust-center",
      "actionLabel": "Prepare request"
    },
    {
      "id": "independent-assurance",
      "name": "Independent assurance reports and certifications",
      "access": "not-asserted",
      "accessLabel": "Not asserted",
      "buyerQuestion": "Is an independent audit, SOC report, ISO certificate, penetration-test report, or comparable assurance artifact publicly claimed?",
      "boundary": "No such artifact is publicly asserted as currently held. Unknown or unavailable evidence is not presented as complete.",
      "href": "",
      "actionLabel": ""
    }
  ],
  "boundary": "Catalog status describes public availability and request routing only. It does not assert certification, audit, authorization, insurance, procurement eligibility, or that a requestable artifact exists before scope is confirmed."
}
