[
  {
    "clientId": "demo-client-0002",
    "stamp": "2026-08-19T07:32:15.295Z",
    "catalogVersion": "2026.10.0-graph1",
    "controlVersions": {
      "mfa_all": "2026.07.0",
      "priv": "2026.07.0",
      "edr": "2026.07.0",
      "eol": "2026.07.0",
      "backup": "2026.07.0",
      "encrypt": "2026.07.0",
      "email": "2026.07.0",
      "surface": "2026.07.0",
      "patch": "2026.07.0",
      "vuln": "2026.07.0",
      "ir": "2026.07.0",
      "log": "2026.07.0",
      "train": "2026.07.0"
    },
    "declarations": {
      "edr": {
        "controlId": "edr",
        "claim": "in_place",
        "statement": "Illustrative sample. In a real deployment this is where the provider records which EDR product is deployed and to how many endpoints.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": [
          {
            "kind": "vendor_console",
            "ref": "internal://example/edr-coverage",
            "note": "Sample evidence pointer, not a real link"
          }
        ]
      },
      "backup": {
        "controlId": "backup",
        "claim": "not_in_place",
        "statement": "Illustrative sample of a declared gap. The provider is recording on the record that something is missing, rather than leaving it blank.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "ir": {
        "controlId": "ir",
        "claim": "in_place",
        "statement": "Illustrative sample. A written incident response plan, with the date of the last tabletop exercise recorded here.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "train": {
        "controlId": "train",
        "claim": "in_place",
        "statement": "Illustrative sample of security awareness training and phishing simulations.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "vuln": {
        "controlId": "vuln",
        "claim": "in_place",
        "statement": "Illustrative sample of an EXPIRED claim. It is still reported, and it deliberately does not count as accounted for.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2025-08-01T12:00:00.000Z",
        "expiresAt": "2026-02-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      }
    },
    "declarationStates": {
      "edr": "declared",
      "backup": "declared",
      "ir": "declared",
      "train": "declared",
      "vuln": "declared_expired"
    },
    "score": 65,
    "tierKey": "cond",
    "tierLabel": "Conditional",
    "knockoutFailures": [],
    "coverage": {
      "verified": [
        "mfa_all",
        "priv"
      ],
      "notVerified": [
        "edr",
        "eol",
        "backup",
        "encrypt",
        "email",
        "surface",
        "patch",
        "vuln",
        "ir",
        "log",
        "train"
      ],
      "notVerifiable": [],
      "verifiedCount": 2,
      "totalCount": 13,
      "declared": [
        "edr",
        "backup",
        "ir",
        "train"
      ],
      "declaredNotCurrent": [
        "vuln"
      ],
      "declaredCount": 4,
      "accountedForCount": 6
    },
    "states": {
      "mfa_all": "partial",
      "priv": "pass",
      "edr": "not_verified",
      "eol": "not_verified",
      "backup": "not_verified",
      "encrypt": "not_verified",
      "email": "not_verified",
      "surface": "not_verified",
      "patch": "not_verified",
      "vuln": "not_verified",
      "ir": "not_verified",
      "log": "not_verified",
      "train": "not_verified"
    },
    "prevHash": "e1ce24ef0eec3ca7eeac4a49c39149523f0f0f5757e85d8696513a93e429b6f8",
    "hash": "ae1ee372878963c6d58de38a277772e8bad78c7f6fb9e85231201f5caa47e2e2",
    "signature": "MEUCICBiI57yUGka4rJeH9gnGw0mOWGko32A4H2AnY6kHqsXAiEAxY+kUvKzQzdXfPyUX83J0KCGlKG7DoP982yO8ETGCLc=",
    "signingKeyId": "local-dev-key-v1",
    "signingMode": "dev",
    "graphMode": "mock"
  },
  {
    "clientId": "demo-client-0002",
    "stamp": "2026-08-19T07:32:16.410Z",
    "catalogVersion": "2026.10.0-graph1",
    "controlVersions": {
      "mfa_all": "2026.07.0",
      "priv": "2026.07.0",
      "edr": "2026.07.0",
      "eol": "2026.07.0",
      "backup": "2026.07.0",
      "encrypt": "2026.07.0",
      "email": "2026.07.0",
      "surface": "2026.07.0",
      "patch": "2026.07.0",
      "vuln": "2026.07.0",
      "ir": "2026.07.0",
      "log": "2026.07.0",
      "train": "2026.07.0"
    },
    "declarations": {
      "edr": {
        "controlId": "edr",
        "claim": "in_place",
        "statement": "Illustrative sample. In a real deployment this is where the provider records which EDR product is deployed and to how many endpoints.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": [
          {
            "kind": "vendor_console",
            "ref": "internal://example/edr-coverage",
            "note": "Sample evidence pointer, not a real link"
          }
        ]
      },
      "backup": {
        "controlId": "backup",
        "claim": "not_in_place",
        "statement": "Illustrative sample of a declared gap. The provider is recording on the record that something is missing, rather than leaving it blank.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "ir": {
        "controlId": "ir",
        "claim": "in_place",
        "statement": "Illustrative sample. A written incident response plan, with the date of the last tabletop exercise recorded here.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "train": {
        "controlId": "train",
        "claim": "in_place",
        "statement": "Illustrative sample of security awareness training and phishing simulations.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "vuln": {
        "controlId": "vuln",
        "claim": "in_place",
        "statement": "Illustrative sample of an EXPIRED claim. It is still reported, and it deliberately does not count as accounted for.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2025-08-01T12:00:00.000Z",
        "expiresAt": "2026-02-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      }
    },
    "declarationStates": {
      "edr": "declared",
      "backup": "declared",
      "ir": "declared",
      "train": "declared",
      "vuln": "declared_expired"
    },
    "score": 65,
    "tierKey": "cond",
    "tierLabel": "Conditional",
    "knockoutFailures": [],
    "coverage": {
      "verified": [
        "mfa_all",
        "priv"
      ],
      "notVerified": [
        "edr",
        "eol",
        "backup",
        "encrypt",
        "email",
        "surface",
        "patch",
        "vuln",
        "ir",
        "log",
        "train"
      ],
      "notVerifiable": [],
      "verifiedCount": 2,
      "totalCount": 13,
      "declared": [
        "edr",
        "backup",
        "ir",
        "train"
      ],
      "declaredNotCurrent": [
        "vuln"
      ],
      "declaredCount": 4,
      "accountedForCount": 6
    },
    "states": {
      "mfa_all": "partial",
      "priv": "pass",
      "edr": "not_verified",
      "eol": "not_verified",
      "backup": "not_verified",
      "encrypt": "not_verified",
      "email": "not_verified",
      "surface": "not_verified",
      "patch": "not_verified",
      "vuln": "not_verified",
      "ir": "not_verified",
      "log": "not_verified",
      "train": "not_verified"
    },
    "prevHash": "ae1ee372878963c6d58de38a277772e8bad78c7f6fb9e85231201f5caa47e2e2",
    "hash": "cb477c9601beb07e398a1e2a53f240a5c94e5476f3b7ee7ad6d796c7c869c162",
    "signature": "MEQCIGP9XNduyZqc11vXm5/ZYkkpIr3JZO633NQU29QzVaNYAiBPeJPKXUECLg1Fx58DLlpSwRTjje6FZLZs4X8PirdWpg==",
    "signingKeyId": "local-dev-key-v1",
    "signingMode": "dev",
    "graphMode": "mock"
  },
  {
    "clientId": "demo-client-0002",
    "stamp": "2026-08-19T07:32:17.518Z",
    "catalogVersion": "2026.10.0-graph1",
    "controlVersions": {
      "mfa_all": "2026.07.0",
      "priv": "2026.07.0",
      "edr": "2026.07.0",
      "eol": "2026.07.0",
      "backup": "2026.07.0",
      "encrypt": "2026.07.0",
      "email": "2026.07.0",
      "surface": "2026.07.0",
      "patch": "2026.07.0",
      "vuln": "2026.07.0",
      "ir": "2026.07.0",
      "log": "2026.07.0",
      "train": "2026.07.0"
    },
    "declarations": {
      "edr": {
        "controlId": "edr",
        "claim": "in_place",
        "statement": "Illustrative sample. In a real deployment this is where the provider records which EDR product is deployed and to how many endpoints.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": [
          {
            "kind": "vendor_console",
            "ref": "internal://example/edr-coverage",
            "note": "Sample evidence pointer, not a real link"
          }
        ]
      },
      "backup": {
        "controlId": "backup",
        "claim": "not_in_place",
        "statement": "Illustrative sample of a declared gap. The provider is recording on the record that something is missing, rather than leaving it blank.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "ir": {
        "controlId": "ir",
        "claim": "in_place",
        "statement": "Illustrative sample. A written incident response plan, with the date of the last tabletop exercise recorded here.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "train": {
        "controlId": "train",
        "claim": "in_place",
        "statement": "Illustrative sample of security awareness training and phishing simulations.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2026-08-01T12:00:00.000Z",
        "expiresAt": "2027-08-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      },
      "vuln": {
        "controlId": "vuln",
        "claim": "in_place",
        "statement": "Illustrative sample of an EXPIRED claim. It is still reported, and it deliberately does not count as accounted for.",
        "attestedBy": {
          "name": "Sample Attester",
          "role": "Security Lead",
          "org": "Sample MSP (demonstration)"
        },
        "attestedAt": "2025-08-01T12:00:00.000Z",
        "expiresAt": "2026-02-01T12:00:00.000Z",
        "controlVersion": "2026.07.0",
        "evidence": []
      }
    },
    "declarationStates": {
      "edr": "declared",
      "backup": "declared",
      "ir": "declared",
      "train": "declared",
      "vuln": "declared_expired"
    },
    "score": 65,
    "tierKey": "cond",
    "tierLabel": "Conditional",
    "knockoutFailures": [],
    "coverage": {
      "verified": [
        "mfa_all",
        "priv"
      ],
      "notVerified": [
        "edr",
        "eol",
        "backup",
        "encrypt",
        "email",
        "surface",
        "patch",
        "vuln",
        "ir",
        "log",
        "train"
      ],
      "notVerifiable": [],
      "verifiedCount": 2,
      "totalCount": 13,
      "declared": [
        "edr",
        "backup",
        "ir",
        "train"
      ],
      "declaredNotCurrent": [
        "vuln"
      ],
      "declaredCount": 4,
      "accountedForCount": 6
    },
    "states": {
      "mfa_all": "partial",
      "priv": "pass",
      "edr": "not_verified",
      "eol": "not_verified",
      "backup": "not_verified",
      "encrypt": "not_verified",
      "email": "not_verified",
      "surface": "not_verified",
      "patch": "not_verified",
      "vuln": "not_verified",
      "ir": "not_verified",
      "log": "not_verified",
      "train": "not_verified"
    },
    "prevHash": "cb477c9601beb07e398a1e2a53f240a5c94e5476f3b7ee7ad6d796c7c869c162",
    "hash": "9afa8ddb888bacdc3e79089cf9d3ce5581b4078213e3d036055d2cfaef98a390",
    "signature": "MEUCIQDZGQVYC9k5Xw9w1YT0WqTRxW66WTfOTqCTAkSHaPQ/rgIgSfrotD+qbQs097SkIoRYpZfvlL/RGlfwx8lKQ6u984o=",
    "signingKeyId": "local-dev-key-v1",
    "signingMode": "dev",
    "graphMode": "mock"
  }
]
