File size: 6,043 Bytes
f037719
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
{
  "component-definition": {
    "uuid": "a11oy-comp-def-v11",
    "metadata": {
      "title": "a11oy Governed AI Orchestrator \u2014 OSCAL Component Definition",
      "last-modified": "2026-06-14T06:40:15.254257+00:00",
      "version": "v11",
      "oscal-version": "1.1.2",
      "remarks": "Coverage assessments reflect a11oy's INTERNAL analysis of its mechanisms against published framework control text. a11oy ALIGNS WITH / MAPS TO these frameworks; it does NOT claim certification. No third-party certification has been obtained for any framework as of Doctrine v11. Gaps are shown honestly. \u039b = Conjecture 1; locked-proven = 8 @ c7c0ba17; trust never 100%."
    },
    "components": [
      {
        "uuid": "a11oy-orchestrator",
        "type": "software",
        "title": "a11oy Governed AI Orchestrator",
        "description": "Governed agentic-AI orchestration layer emitting a DSSE-signed receipt per inference. ALIGNS WITH the controls below; not certified.",
        "props": [
          {
            "name": "doctrine",
            "ns": "https://szlholdings.ai/ns/oscal",
            "value": "v11"
          },
          {
            "name": "kernel-commit",
            "ns": "https://szlholdings.ai/ns/oscal",
            "value": "c7c0ba17"
          },
          {
            "name": "policy-bundle-digest",
            "ns": "https://szlholdings.ai/ns/oscal",
            "value": "sha256:4b035da9e752dcdb81c8390974752fc729da8192e60a0459de50a05d4c9563ba"
          },
          {
            "name": "eu-ai-act-class",
            "ns": "https://szlholdings.ai/ns/oscal",
            "value": "High-Risk (self-classified)"
          }
        ],
        "control-implementations": [
          {
            "uuid": "ci-800-53r5",
            "source": "https://raw.githubusercontent.com/usnistgov/oscal-content/main/nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_catalog.json",
            "description": "a11oy mechanism mapping to NIST SP 800-53 Rev 5 (alignment only).",
            "implemented-requirements": [
              {
                "uuid": "ir-95efdfab",
                "control-id": "au-2",
                "description": "[COVERED] DSSE-signed audit event per inference (verdict + rule ID) (a11oy Event logging).",
                "props": [
                  {
                    "name": "coverage",
                    "ns": "https://szlholdings.ai/ns/oscal",
                    "value": "COVERED"
                  }
                ]
              },
              {
                "uuid": "ir-941c0684",
                "control-id": "au-3",
                "description": "[COVERED] Timestamp + input/output hash in every receipt (a11oy Content of audit records).",
                "props": [
                  {
                    "name": "coverage",
                    "ns": "https://szlholdings.ai/ns/oscal",
                    "value": "COVERED"
                  }
                ]
              },
              {
                "uuid": "ir-a0f3ffcd",
                "control-id": "au-9",
                "description": "[COVERED] Records sealed in DSSE envelopes signed by ECDSA-P256; tamper-detectable (a11oy Protection of audit information).",
                "props": [
                  {
                    "name": "coverage",
                    "ns": "https://szlholdings.ai/ns/oscal",
                    "value": "COVERED"
                  }
                ]
              },
              {
                "uuid": "ir-80c2667f",
                "control-id": "cm-8",
                "description": "[COVERED] Model ID + version + digest recorded per inference (a11oy System component inventory).",
                "props": [
                  {
                    "name": "coverage",
                    "ns": "https://szlholdings.ai/ns/oscal",
                    "value": "COVERED"
                  }
                ]
              },
              {
                "uuid": "ir-76491072",
                "control-id": "ra-3",
                "description": "[COVERED] 13-axis \u039b trust score is the per-inference risk assessment (a11oy Risk assessment).",
                "props": [
                  {
                    "name": "coverage",
                    "ns": "https://szlholdings.ai/ns/oscal",
                    "value": "COVERED"
                  }
                ]
              },
              {
                "uuid": "ir-74879421",
                "control-id": "si-10",
                "description": "[PARTIAL] Input hash + classification-boundary gate (a11oy Information input validation).",
                "props": [
                  {
                    "name": "coverage",
                    "ns": "https://szlholdings.ai/ns/oscal",
                    "value": "PARTIAL"
                  }
                ]
              },
              {
                "uuid": "ir-rego-b4e45455",
                "control-id": "ac-3",
                "description": "Rego gate a11oy.gates.classification_boundary (controls: ISO42001/A.9.6, NIST80053/AC-3, EUAIAct/Art.14). Bundle digest sha256:4b035da9e752dcdb81c8390974752fc729da8192e60a0459de50a05d4c9563ba is cited in every DSSE receipt."
              },
              {
                "uuid": "ir-rego-0abacbce",
                "control-id": "ac-3",
                "description": "Rego gate a11oy.gates.human_override_required (controls: ISO42001/A.9.3, ISO42001/A.4.6, NIST80053/AU-2, EUAIAct/Art.14). Bundle digest sha256:4b035da9e752dcdb81c8390974752fc729da8192e60a0459de50a05d4c9563ba is cited in every DSSE receipt."
              },
              {
                "uuid": "ir-rego-864d6ebc",
                "control-id": "ac-3",
                "description": "Rego gate a11oy.gates.deployment_readiness (controls: ISO27001/8.25, NIST80053/CM-3, ISO42001/A.6.7). Bundle digest sha256:4b035da9e752dcdb81c8390974752fc729da8192e60a0459de50a05d4c9563ba is cited in every DSSE receipt."
              }
            ]
          }
        ]
      }
    ]
  }
}