FedRAMP Trust Center — off-CSO mirror

Advent Business Company Inc. · Enablement® · FedRAMP ID FR2628647239

Mirrored public certification data

ArtifactCopiedAuthoritative SHA-256 (first 16)
Trust center landing page
trust.html
0 seconds ago
2026-08-07T03:28:48Z
live source243cc1dcd59f4f23
Certification Package Overview (CPO)
package.json
0 seconds ago
2026-08-07T03:28:49Z
live sourcef70d86164990c7b1
Secure Configuration Guide
scg.md
0 seconds ago
2026-08-07T03:28:49Z
live source03f5dd0f34ccf651
Availability report (machine-readable)
availability.json
0 seconds ago
2026-08-07T03:28:49Z
live source48e7e2f0371cd4b5
Availability report (human-readable)
status.html
0 seconds ago
2026-08-07T03:28:49Z
live source8a91602c909a8173

SHA-256 is over the exact bytes the offering served. The mirrored files are byte-identical copies — nothing is rewritten, annotated or reformatted — so you can fetch the live URL and compare hashes to confirm this copy is faithful. One consequence, stated rather than hidden: because trust.html and status.html are unmodified, the links and the logo inside them still point at enablement.cc and will not resolve while the offering is down. Use this page, not those, as the entry point during an outage — it loads nothing from anywhere.

Is the offering up? — observed from outside it

Every public trust-center URL answered HTTP 200 to an unauthenticated GET from outside the offering.

100.0% of 15 external observations found every public URL answering since 2026-08-07T00:28:16Z. Machine-readable: mirror-availability.json · external-probe-history.json. The offering’s own, finer-grained availability report is mirrored above as availability.json; it measures a 5-minute probe series but is served from the host it measures, so it cannot report its own outage. This observation can, and that difference is the point.

What is deliberately NOT here

Only artifacts that are already public without authentication are mirrored. Token-gated certification data — the evidence index, the individual package documents, and the SDR, KSI, VDR, AVI, OCR, historical, assessor and query services — is not mirrored and never will be. A static bucket has no token gate, so anything placed here would be world-readable. Those artifacts stay on the live trust center under bearer-token control with per-access logging. Agencies and assessors request a token at rajesh@adventbusiness.com.

The copy list is an explicit allow-list of 9 object keys, and the bucket policy grants read on exactly those object ARNs with no wildcard — so an object outside the list is not reachable from the internet even if one were somehow uploaded. The list is published in mirror-manifest.json under publicSurface.allowList.