[
  {
    "clientId": "demo-client-0002",
    "stamp": "2026-08-19T07:06:59.861Z",
    "catalogVersion": "2026.09.0-graph1",
    "controlVersions": {
      "mfa_all": "2026.07.0",
      "priv": "2026.07.0",
      "edr": "2026.07.0",
      "eol": "2026.07.0",
      "backup": "2026.07.0",
      "encrypt": "2026.07.0",
      "email": "2026.07.0",
      "surface": "2026.07.0",
      "patch": "2026.07.0",
      "vuln": "2026.07.0",
      "ir": "2026.07.0",
      "log": "2026.07.0",
      "train": "2026.07.0"
    },
    "declarations": {
      "edr": {
        "controlId": "edr",
        "claim": "in_place",
        "statement": "Illustrative sample. In a real deployment this is where the provider records which EDR product is deployed and to how many endpoints.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": [
          {
            "kind": "vendor_console",
            "ref": "internal://example/edr-coverage",
            "note": "Sample evidence pointer, not a real link"
          }
        ]
      },
      "backup": {
        "controlId": "backup",
        "claim": "not_in_place",
        "statement": "Illustrative sample of a declared gap. The provider is recording on the record that something is missing, rather than leaving it blank.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "ir": {
        "controlId": "ir",
        "claim": "in_place",
        "statement": "Illustrative sample. A written incident response plan, with the date of the last tabletop exercise recorded here.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "train": {
        "controlId": "train",
        "claim": "in_place",
        "statement": "Illustrative sample of security awareness training and phishing simulations.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "vuln": {
        "controlId": "vuln",
        "claim": "in_place",
        "statement": "Illustrative sample of an EXPIRED claim. It is still reported, and it deliberately does not count as accounted for.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2025-08-01T12:00:00.000Z",
        "expiresAt": "2026-02-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      }
    },
    "declarationStates": {
      "edr": "declared",
      "backup": "declared",
      "ir": "declared",
      "train": "declared",
      "vuln": "declared_expired"
    },
    "score": 65,
    "tierKey": "cond",
    "tierLabel": "Conditional",
    "knockoutFailures": [],
    "coverage": {
      "verified": [
        "mfa_all",
        "priv"
      ],
      "notVerified": [
        "edr",
        "eol",
        "backup",
        "encrypt",
        "email",
        "surface",
        "patch",
        "vuln",
        "ir",
        "log",
        "train"
      ],
      "notVerifiable": [],
      "verifiedCount": 2,
      "totalCount": 13,
      "declared": [
        "edr",
        "backup",
        "ir",
        "train"
      ],
      "declaredNotCurrent": [
        "vuln"
      ],
      "declaredCount": 4,
      "accountedForCount": 6
    },
    "states": {
      "mfa_all": "partial",
      "priv": "pass",
      "edr": "not_verified",
      "eol": "not_verified",
      "backup": "not_verified",
      "encrypt": "not_verified",
      "email": "not_verified",
      "surface": "not_verified",
      "patch": "not_verified",
      "vuln": "not_verified",
      "ir": "not_verified",
      "log": "not_verified",
      "train": "not_verified"
    },
    "prevHash": "e1ce24ef0eec3ca7eeac4a49c39149523f0f0f5757e85d8696513a93e429b6f8",
    "hash": "ba407d003d89b9b13f7172759523da1f05e55efd01191df057045a377ca24f5f",
    "signature": "MEUCIEM56igkaDzx6fHqw2ptE7qg2eN+J94dTffBK+wS7MOOAiEA2bv4JpNpI97AncRnuDNta4yqvh0sjD9JA3yIjfjBwfg=",
    "signingKeyId": "local-dev-key-v1",
    "signingMode": "dev",
    "graphMode": "mock"
  },
  {
    "clientId": "demo-client-0002",
    "stamp": "2026-08-19T07:07:00.966Z",
    "catalogVersion": "2026.09.0-graph1",
    "controlVersions": {
      "mfa_all": "2026.07.0",
      "priv": "2026.07.0",
      "edr": "2026.07.0",
      "eol": "2026.07.0",
      "backup": "2026.07.0",
      "encrypt": "2026.07.0",
      "email": "2026.07.0",
      "surface": "2026.07.0",
      "patch": "2026.07.0",
      "vuln": "2026.07.0",
      "ir": "2026.07.0",
      "log": "2026.07.0",
      "train": "2026.07.0"
    },
    "declarations": {
      "edr": {
        "controlId": "edr",
        "claim": "in_place",
        "statement": "Illustrative sample. In a real deployment this is where the provider records which EDR product is deployed and to how many endpoints.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": [
          {
            "kind": "vendor_console",
            "ref": "internal://example/edr-coverage",
            "note": "Sample evidence pointer, not a real link"
          }
        ]
      },
      "backup": {
        "controlId": "backup",
        "claim": "not_in_place",
        "statement": "Illustrative sample of a declared gap. The provider is recording on the record that something is missing, rather than leaving it blank.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "ir": {
        "controlId": "ir",
        "claim": "in_place",
        "statement": "Illustrative sample. A written incident response plan, with the date of the last tabletop exercise recorded here.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "train": {
        "controlId": "train",
        "claim": "in_place",
        "statement": "Illustrative sample of security awareness training and phishing simulations.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "vuln": {
        "controlId": "vuln",
        "claim": "in_place",
        "statement": "Illustrative sample of an EXPIRED claim. It is still reported, and it deliberately does not count as accounted for.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2025-08-01T12:00:00.000Z",
        "expiresAt": "2026-02-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      }
    },
    "declarationStates": {
      "edr": "declared",
      "backup": "declared",
      "ir": "declared",
      "train": "declared",
      "vuln": "declared_expired"
    },
    "score": 65,
    "tierKey": "cond",
    "tierLabel": "Conditional",
    "knockoutFailures": [],
    "coverage": {
      "verified": [
        "mfa_all",
        "priv"
      ],
      "notVerified": [
        "edr",
        "eol",
        "backup",
        "encrypt",
        "email",
        "surface",
        "patch",
        "vuln",
        "ir",
        "log",
        "train"
      ],
      "notVerifiable": [],
      "verifiedCount": 2,
      "totalCount": 13,
      "declared": [
        "edr",
        "backup",
        "ir",
        "train"
      ],
      "declaredNotCurrent": [
        "vuln"
      ],
      "declaredCount": 4,
      "accountedForCount": 6
    },
    "states": {
      "mfa_all": "partial",
      "priv": "pass",
      "edr": "not_verified",
      "eol": "not_verified",
      "backup": "not_verified",
      "encrypt": "not_verified",
      "email": "not_verified",
      "surface": "not_verified",
      "patch": "not_verified",
      "vuln": "not_verified",
      "ir": "not_verified",
      "log": "not_verified",
      "train": "not_verified"
    },
    "prevHash": "ba407d003d89b9b13f7172759523da1f05e55efd01191df057045a377ca24f5f",
    "hash": "64851c0f95a764cc3c581e88e809e46f840d195a8bb1d0aa0adfa2d4bb9ee41c",
    "signature": "MEUCIQDHw0wBH13FKjFLaih8gTbFxb7pZCgXbSPu/pBeQ8EDFAIgLcHD+dKjeivatGnl7EzGirIbX8DiFbIm8EsXtwQSwoE=",
    "signingKeyId": "local-dev-key-v1",
    "signingMode": "dev",
    "graphMode": "mock"
  },
  {
    "clientId": "demo-client-0002",
    "stamp": "2026-08-19T07:07:02.076Z",
    "catalogVersion": "2026.09.0-graph1",
    "controlVersions": {
      "mfa_all": "2026.07.0",
      "priv": "2026.07.0",
      "edr": "2026.07.0",
      "eol": "2026.07.0",
      "backup": "2026.07.0",
      "encrypt": "2026.07.0",
      "email": "2026.07.0",
      "surface": "2026.07.0",
      "patch": "2026.07.0",
      "vuln": "2026.07.0",
      "ir": "2026.07.0",
      "log": "2026.07.0",
      "train": "2026.07.0"
    },
    "declarations": {
      "edr": {
        "controlId": "edr",
        "claim": "in_place",
        "statement": "Illustrative sample. In a real deployment this is where the provider records which EDR product is deployed and to how many endpoints.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": [
          {
            "kind": "vendor_console",
            "ref": "internal://example/edr-coverage",
            "note": "Sample evidence pointer, not a real link"
          }
        ]
      },
      "backup": {
        "controlId": "backup",
        "claim": "not_in_place",
        "statement": "Illustrative sample of a declared gap. The provider is recording on the record that something is missing, rather than leaving it blank.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "ir": {
        "controlId": "ir",
        "claim": "in_place",
        "statement": "Illustrative sample. A written incident response plan, with the date of the last tabletop exercise recorded here.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "train": {
        "controlId": "train",
        "claim": "in_place",
        "statement": "Illustrative sample of security awareness training and phishing simulations.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "vuln": {
        "controlId": "vuln",
        "claim": "in_place",
        "statement": "Illustrative sample of an EXPIRED claim. It is still reported, and it deliberately does not count as accounted for.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2025-08-01T12:00:00.000Z",
        "expiresAt": "2026-02-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      }
    },
    "declarationStates": {
      "edr": "declared",
      "backup": "declared",
      "ir": "declared",
      "train": "declared",
      "vuln": "declared_expired"
    },
    "score": 65,
    "tierKey": "cond",
    "tierLabel": "Conditional",
    "knockoutFailures": [],
    "coverage": {
      "verified": [
        "mfa_all",
        "priv"
      ],
      "notVerified": [
        "edr",
        "eol",
        "backup",
        "encrypt",
        "email",
        "surface",
        "patch",
        "vuln",
        "ir",
        "log",
        "train"
      ],
      "notVerifiable": [],
      "verifiedCount": 2,
      "totalCount": 13,
      "declared": [
        "edr",
        "backup",
        "ir",
        "train"
      ],
      "declaredNotCurrent": [
        "vuln"
      ],
      "declaredCount": 4,
      "accountedForCount": 6
    },
    "states": {
      "mfa_all": "partial",
      "priv": "pass",
      "edr": "not_verified",
      "eol": "not_verified",
      "backup": "not_verified",
      "encrypt": "not_verified",
      "email": "not_verified",
      "surface": "not_verified",
      "patch": "not_verified",
      "vuln": "not_verified",
      "ir": "not_verified",
      "log": "not_verified",
      "train": "not_verified"
    },
    "prevHash": "64851c0f95a764cc3c581e88e809e46f840d195a8bb1d0aa0adfa2d4bb9ee41c",
    "hash": "f55d8f6f1edd9ed6f4a8e98581f010b3946c180865df7e1a56a5fa70c3c4849b",
    "signature": "MEYCIQCgbZgfxphqX1cBjkg63M81x2F3Ope+kqC+bQDrnVFRUAIhAJQNY3R6zyoMnsGCl+9H0Zw8AV/TqrpEFmdRlyXbx/fJ",
    "signingKeyId": "local-dev-key-v1",
    "signingMode": "dev",
    "graphMode": "mock"
  }
]
