FedRAMP Trust Center — off-CSO mirror
Advent Business Company Inc. · Enablement® · FedRAMP ID
FR2628647239
Mirrored public certification data
| Artifact | Copied | Authoritative | SHA-256 (first 16) |
|---|---|---|---|
Trust center landing pagetrust.html | 0 seconds ago 2026-08-07T03:28:48Z | live source | 243cc1dcd59f4f23 |
Certification Package Overview (CPO)package.json | 0 seconds ago 2026-08-07T03:28:49Z | live source | f70d86164990c7b1 |
Secure Configuration Guidescg.md | 0 seconds ago 2026-08-07T03:28:49Z | live source | 03f5dd0f34ccf651 |
Availability report (machine-readable)availability.json | 0 seconds ago 2026-08-07T03:28:49Z | live source | 48e7e2f0371cd4b5 |
Availability report (human-readable)status.html | 0 seconds ago 2026-08-07T03:28:49Z | live source | 8a91602c909a8173 |
SHA-256 is over the exact bytes the offering served. The
mirrored files are byte-identical copies — nothing is rewritten,
annotated or reformatted — so you can fetch the live URL and compare
hashes to confirm this copy is faithful. One consequence, stated rather than
hidden: because trust.html and status.html are
unmodified, the links and the logo inside them still point at
enablement.cc and will not resolve while the offering is down.
Use this page, not those, as the entry point during an outage — it loads
nothing from anywhere.
Is the offering up? — observed from outside it
Every public trust-center URL answered HTTP 200 to an unauthenticated GET from outside the offering.
100.0% of 15 external observations found every public URL answering since
2026-08-07T00:28:16Z. Machine-readable:
mirror-availability.json ·
external-probe-history.json.
The offering’s own, finer-grained availability report is mirrored above as
availability.json; it measures a 5-minute probe series but is
served from the host it measures, so it cannot report its own outage. This
observation can, and that difference is the point.
What is deliberately NOT here
Only artifacts that are already public without authentication are mirrored. Token-gated certification data — the evidence index, the individual package documents, and the SDR, KSI, VDR, AVI, OCR, historical, assessor and query services — is not mirrored and never will be. A static bucket has no token gate, so anything placed here would be world-readable. Those artifacts stay on the live trust center under bearer-token control with per-access logging. Agencies and assessors request a token at rajesh@adventbusiness.com.
The copy list is an explicit allow-list of
9 object keys, and the bucket policy grants read on exactly
those object ARNs with no wildcard — so an object outside the list is not
reachable from the internet even if one were somehow uploaded. The list is
published in mirror-manifest.json under
publicSurface.allowList.