{
  "schema_version": "1.2",
  "updated": "2026-10-08",
  "field_model": {
    "principle": "Only explicitly supported values are stored. Absence of evidence is unknown, not false.",
    "evidence_binding": "field_level",
    "confidence_values": [
      "high",
      "medium",
      "low"
    ],
    "taxonomy": "data/agent-deep-taxonomy.json",
    "unknown_semantics": "A missing canonical field is unknown. False is allowed only when an explicit reliable primary source documents nonexistence or a restriction.",
    "canonical_path_policy": "New curated claims must use active canonical taxonomy paths; deprecated aliases are rejected."
  },
  "agents": [
    {
      "agent_id": "AI-0001",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "openai_deep_research_responses_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – Deep research",
              "url": "https://developers.openai.com/api/docs/guides/deep-research",
              "note": "OpenAI documents running deep-research workflows through the Responses API, including HTTPS requests to /v1/responses.",
              "evidence_type": "api_docs",
              "source_section": "Deep research / Kick off a deep research task"
            }
          ],
          "note": "OpenAI deep research is programmatically available through the Responses API."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "chatgpt_enterprise_compliance_platform",
          "evidence": [
            {
              "title": "OpenAI Help – Compliance Platform for Enterprise and Edu",
              "url": "https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers",
              "note": "OpenAI documents programmatic access to audit and compliance data through the Compliance/Admin API.",
              "evidence_type": "api_docs",
              "source_section": "Compliance API documentation / How it works"
            }
          ],
          "note": "ChatGPT Enterprise audit/compliance data is accessible through API.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "chatgpt_enterprise_compliance_platform",
          "evidence": [
            {
              "title": "OpenAI Help – Compliance Platform for Enterprise and Edu",
              "url": "https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers",
              "note": "OpenAI documents immutable compliance log events and audit/authentication/app logs for ChatGPT workspaces.",
              "evidence_type": "security_trust",
              "source_section": "How it works"
            }
          ],
          "note": "ChatGPT Enterprise provides compliance/audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 30,
          "scope": "chatgpt_enterprise_compliance_logs_platform",
          "evidence": [
            {
              "title": "OpenAI Help – Compliance Platform for Enterprise and Edu",
              "url": "https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers",
              "note": "OpenAI states the Compliance Logs Platform retains data for 30 days.",
              "evidence_type": "technical_docs",
              "source_section": "Data Retention with the Compliance API"
            }
          ],
          "note": "The ChatGPT Compliance Logs Platform documents 30-day retention.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "chatgpt_enterprise_compliance_platform",
          "evidence": [
            {
              "title": "OpenAI Help – Compliance Platform for Enterprise and Edu",
              "url": "https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers",
              "note": "OpenAI documents connecting Compliance Platform logs and metadata with SIEM tools and lists supported security integrations.",
              "evidence_type": "security_trust",
              "source_section": "How it works / Partner integrations"
            }
          ],
          "note": "ChatGPT Enterprise compliance logs can feed SIEM tooling.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "chatgpt_enterprise",
          "evidence": [
            {
              "title": "OpenAI Help – Managing feature access with RBAC in ChatGPT",
              "url": "https://help.openai.com/en/articles/11750701-managing-feature-access-with-role-based-access-control-in-chatgpt",
              "note": "OpenAI explicitly documents creating reusable custom roles with granular feature permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Overview / custom roles"
            }
          ],
          "note": "ChatGPT Enterprise supports custom roles.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "chatgpt_enterprise",
          "evidence": [
            {
              "title": "OpenAI Help – Managing feature access with RBAC in ChatGPT",
              "url": "https://help.openai.com/en/articles/11750701-managing-feature-access-with-role-based-access-control-in-chatgpt",
              "note": "OpenAI documents role-based access control for ChatGPT Enterprise with reusable roles and group-based assignments.",
              "evidence_type": "technical_docs",
              "source_section": "Overview / Availability"
            }
          ],
          "note": "ChatGPT Enterprise supports RBAC.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "chatgpt_enterprise",
          "evidence": [
            {
              "title": "OpenAI – Enterprise privacy",
              "url": "https://openai.com/enterprise-privacy/",
              "note": "OpenAI explicitly documents enterprise authentication via SAML SSO.",
              "evidence_type": "security_trust",
              "source_section": "Control"
            }
          ],
          "note": "ChatGPT Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "openai_chatgpt_business_products",
          "evidence": [
            {
              "title": "OpenAI – Enterprise privacy",
              "url": "https://openai.com/enterprise-privacy/",
              "note": "OpenAI documents ChatGPT business products as OpenAI-hosted enterprise services with organization controls and managed data handling.",
              "evidence_type": "security_trust",
              "source_section": "Our commitments / General FAQ"
            }
          ],
          "note": "ChatGPT business features are delivered as managed OpenAI services.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "chatgpt_enterprise_edu",
          "evidence": [
            {
              "title": "OpenAI Help – Data residency and inference residency for ChatGPT",
              "url": "https://help.openai.com/en/articles/9903489-data-residency-for-chatgpt",
              "note": "OpenAI documents ChatGPT data residency that keeps in-scope customer content stored at rest in a specified geographic region for eligible Enterprise/Edu customers.",
              "evidence_type": "technical_docs",
              "source_section": "Overview / Eligibility"
            }
          ],
          "note": "Eligible ChatGPT Enterprise/Edu customers can use data residency.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "chatgpt_enterprise_edu",
          "evidence": [
            {
              "title": "OpenAI Help – Data residency and inference residency for ChatGPT",
              "url": "https://help.openai.com/en/articles/9903489-data-residency-for-chatgpt",
              "note": "OpenAI states eligible ChatGPT Enterprise/Edu customers can choose supported countries/regions for in-scope customer content.",
              "evidence_type": "technical_docs",
              "source_section": "Eligibility / supported regions"
            }
          ],
          "note": "Eligible customers can select a supported ChatGPT data-residency region.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "chatgpt_enterprise_edu",
          "evidence": [
            {
              "title": "OpenAI Help – Enterprise Key Management overview",
              "url": "https://help.openai.com/en/articles/20000943",
              "note": "OpenAI documents BYOK Enterprise Key Management for ChatGPT Enterprise/Edu using customer-managed AWS KMS, GCP, or Azure Key Vault keys.",
              "evidence_type": "security_trust",
              "source_section": "Overview"
            }
          ],
          "note": "ChatGPT Enterprise/Edu supports customer-managed encryption keys through EKM.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "openai_chatgpt_business_products",
          "evidence": [
            {
              "title": "OpenAI – Enterprise privacy",
              "url": "https://openai.com/enterprise-privacy/",
              "note": "OpenAI documents AES-256 encryption at rest for business data.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "OpenAI documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "openai_chatgpt_business_products",
          "evidence": [
            {
              "title": "OpenAI – Enterprise privacy",
              "url": "https://openai.com/enterprise-privacy/",
              "note": "OpenAI documents TLS 1.2+ encryption in transit between customers, OpenAI, and service providers.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "OpenAI documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "openai_chatgpt_business_products",
          "evidence": [
            {
              "title": "OpenAI – Security and privacy",
              "url": "https://openai.com/security-and-privacy/",
              "note": "OpenAI states its API and ChatGPT business products have undergone an independent SOC 2 Type 2 examination.",
              "evidence_type": "security_trust",
              "source_section": "Our accreditations / SOC 2 Type 2"
            }
          ],
          "note": "OpenAI documents SOC 2 Type 2 coverage for ChatGPT business products.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0002",
      "claims": [
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "gemini_apps_deep_research",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Gemini Apps Help – Use Deep Research in Gemini Apps",
              "url": "https://support.google.com/gemini/answer/15719111?hl=en",
              "note": "Google documents Deep Research as a feature of the hosted Gemini Apps service, used while signed in to the Gemini app and producing research reports in the service.",
              "evidence_type": "technical_docs",
              "source_section": "Use Deep Research in Gemini Apps / What you need"
            }
          ],
          "note": "Gemini Deep Research is delivered as a Google-managed Gemini Apps service."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "gemini_deep_research_workspace_core_service",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Gemini Apps Help – Use Gemini Apps with a work or school Google Account",
              "url": "https://support.google.com/gemini/answer/14620100?co=DASHER._Family%3DBusiness-Enterprise&hl=en",
              "note": "Google documents Deep Research availability inside Gemini Apps for Workspace users and states Workspace licenses that include Gemini Apps as a core service provide enterprise-grade data protections.",
              "evidence_type": "technical_docs",
              "source_section": "Gemini Apps by Workspace editions / Check if you have enterprise-grade data protections"
            },
            {
              "title": "Google Workspace – Digital Data Sovereignty",
              "url": "https://workspace.google.com/security/digital-sovereignty/",
              "note": "Google Workspace lists SOC 1/2/3 among the industry standards/certifications applying to the Workspace cloud service.",
              "evidence_type": "security_trust",
              "source_section": "Compliance with industry standards"
            }
          ],
          "note": "For Workspace deployments where Gemini Apps is a core service, Deep Research is covered by the Workspace service security/compliance posture that includes SOC 2."
        }
      ]
    },
    {
      "agent_id": "AI-0003",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "claude_research_enterprise_compliance_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – What is the Enterprise plan?",
              "url": "https://support.claude.com/en/articles/9797531-what-is-the-enterprise-plan",
              "note": "Anthropic documents a Compliance API providing programmatic access to Claude activity logs, chat histories, and file content.",
              "evidence_type": "api_docs",
              "source_section": "What's included in the Enterprise plan?"
            }
          ],
          "note": "Claude Enterprise exposes organization activity logs programmatically through the Compliance API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "claude_research_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – What is the Enterprise plan?",
              "url": "https://support.claude.com/en/articles/9797531-what-is-the-enterprise-plan",
              "note": "Anthropic documents Enterprise audit logs covering user actions, system events, and data access.",
              "evidence_type": "security_trust",
              "source_section": "What's included in the Enterprise plan?"
            },
            {
              "title": "Claude Help – Use research on Claude",
              "url": "https://support.claude.com/en/articles/11088861-use-research-on-claude",
              "note": "Research is available within Claude Enterprise organizations.",
              "evidence_type": "technical_docs",
              "source_section": "Availability"
            }
          ],
          "note": "Enterprise organizations using Research have Claude organization audit logs."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "claude_research_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Manage custom roles on Enterprise plans",
              "url": "https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans",
              "note": "Anthropic documents Enterprise custom roles with granular Claude capability and organization permissions.",
              "evidence_type": "technical_docs",
              "source_section": "What are custom roles?"
            },
            {
              "title": "Claude Help – Use research on Claude",
              "url": "https://support.claude.com/en/articles/11088861-use-research-on-claude",
              "note": "Research is documented as available within Claude Enterprise.",
              "evidence_type": "technical_docs",
              "source_section": "Availability"
            }
          ],
          "note": "Claude Enterprise custom roles govern access and permissions in organizations where Research is available."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "claude_research_team_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Use research on Claude",
              "url": "https://support.claude.com/en/articles/11088861-use-research-on-claude",
              "note": "Anthropic documents Research as a feature inside paid Claude Team and Enterprise organizations.",
              "evidence_type": "technical_docs",
              "source_section": "Availability"
            },
            {
              "title": "Claude Help – Roles and permissions",
              "url": "https://support.claude.com/en/articles/9267276-roles-and-permissions",
              "note": "Anthropic documents built-in Claude Team and Enterprise roles with distinct permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Roles and permissions"
            }
          ],
          "note": "Research is used inside Claude organizations governed by documented role-based permissions."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "claude_research_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Use research on Claude",
              "url": "https://support.claude.com/en/articles/11088861-use-research-on-claude",
              "note": "Anthropic documents Research as available to Enterprise users.",
              "evidence_type": "technical_docs",
              "source_section": "Availability"
            },
            {
              "title": "Claude Help – Set up JIT or SCIM provisioning",
              "url": "https://support.claude.com/en/articles/13133195-set-up-jit-or-scim-provisioning",
              "note": "Anthropic documents SCIM provisioning and deprovisioning for Claude Enterprise organizations.",
              "evidence_type": "technical_docs",
              "source_section": "SCIM provisioning"
            }
          ],
          "note": "Claude Enterprise organizations using Research can provision users through SCIM."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "claude_research_team_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Use research on Claude",
              "url": "https://support.claude.com/en/articles/11088861-use-research-on-claude",
              "note": "Anthropic documents Research as available on Team and Enterprise plans.",
              "evidence_type": "technical_docs",
              "source_section": "Availability"
            },
            {
              "title": "Claude Help – Set up single sign-on (SSO)",
              "url": "https://support.claude.com/en/articles/13132885-set-up-single-sign-on-sso",
              "note": "Anthropic documents SAML SSO for Claude Team and Enterprise organizations.",
              "evidence_type": "technical_docs",
              "source_section": "Set up SSO with your Identity Provider"
            }
          ],
          "note": "Team and Enterprise users accessing Research can use Claude's SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "claude_research_cloud_service",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Use research on Claude",
              "url": "https://support.claude.com/en/articles/11088861-use-research-on-claude",
              "note": "Anthropic documents Research as a Claude feature available through Claude on the web, desktop, and mobile.",
              "evidence_type": "technical_docs",
              "source_section": "Use research on Claude"
            },
            {
              "title": "Claude Help – Get started with custom connectors using remote MCP",
              "url": "https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp",
              "note": "Anthropic documents Claude remote-connector traffic, including Research tool use, as originating from Anthropic cloud infrastructure.",
              "evidence_type": "technical_docs",
              "source_section": "Network requirements / Using Claude with Research"
            }
          ],
          "note": "Claude Research runs as an Anthropic-managed Claude service."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "claude_research_remote_connectors",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Get started with custom connectors using remote MCP",
              "url": "https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp",
              "note": "Anthropic states Research can automatically invoke tools from custom connectors backed by remote MCP servers.",
              "evidence_type": "technical_docs",
              "source_section": "Using Claude with Research"
            }
          ],
          "note": "Claude Research can act as an MCP client through remote custom connectors."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "claude_research_enterprise_content",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – What are customer-managed encryption keys (CMEK)?",
              "url": "https://support.claude.com/en/articles/15505325-what-are-customer-managed-encryption-keys-cmek",
              "note": "Anthropic documents customer-managed keys for Enterprise that encrypt Claude chats, projects, and files using keys controlled in the customer's cloud provider.",
              "evidence_type": "security_trust",
              "source_section": "What are customer-managed encryption keys?"
            }
          ],
          "note": "Eligible Enterprise organizations can protect Claude content used by Research with customer-managed encryption keys."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "claude_research_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Anthropic Trust Center",
              "url": "https://trust.anthropic.com/",
              "note": "Anthropic's Trust Center lists Claude Enterprise as covered by SOC 2 Type 2.",
              "evidence_type": "security_trust",
              "source_section": "Compliance scope"
            }
          ],
          "note": "Claude Research used under Claude Enterprise inherits the Claude Enterprise SOC 2 Type 2 scope."
        }
      ]
    },
    {
      "agent_id": "AI-0004",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "perplexity_enterprise_research",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity lists Audit Logs as an organization-wide Enterprise Max security feature.",
              "evidence_type": "technical_docs",
              "source_section": "Premium security features"
            }
          ],
          "note": "Perplexity Enterprise provides audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "perplexity_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Perplexity – Role-based access controls, API credentials, Brain for Max",
              "url": "https://www.perplexity.ai/en-GB/changelog/role-based-access-controls-api-credentials-and-brain-for-max",
              "note": "Perplexity documents Enterprise custom roles with granular permissions, SCIM group sync, and per-group controls.",
              "evidence_type": "official_release",
              "source_section": "Control Enterprise access with custom roles and SCIM groups"
            }
          ],
          "note": "Perplexity Enterprise supports custom roles with granular permissions."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "perplexity_enterprise_research",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents role-based access controls for Enterprise organizations alongside its Research/Comet workflows.",
              "evidence_type": "technical_docs",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity Enterprise provides role-based access controls.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "perplexity_enterprise_research",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity states Enterprise Max includes organization-wide SCIM and explicitly includes Research and Comet Assistant among its product capabilities.",
              "evidence_type": "technical_docs",
              "source_section": "Key Features / Premium security features"
            }
          ],
          "note": "Perplexity Enterprise supports SCIM for the product suite including Research and Comet.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "perplexity_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Perplexity – Enterprise security foundation",
              "url": "https://www.perplexity.ai/de/hub/blog/computer-for-enterprise",
              "note": "Perplexity explicitly states its Enterprise foundation includes SAML SSO, audit logs, and administrative controls.",
              "evidence_type": "official_release",
              "source_section": "Computer for Enterprise / Enterprise infrastructure"
            }
          ],
          "note": "Perplexity Enterprise supports SAML SSO; this applies to Enterprise products including Research and Comet."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "perplexity_deep_research_in_computer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Perplexity – Deep Research",
              "url": "https://www.perplexity.ai/de/hub/products/deep-research",
              "note": "Perplexity documents Deep Research as a capability inside its Computer product, launched and used through Perplexity's hosted product surface.",
              "evidence_type": "official_product_page",
              "source_section": "Deep Research – entwickelt für die schwierigsten Fragen / Erste Schritte"
            }
          ],
          "note": "Perplexity Deep Research is delivered as a managed Perplexity Computer capability."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents AES-256 encryption for data at rest.",
              "evidence_type": "security_trust",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.3",
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents TLS 1.3 for data in transit.",
              "evidence_type": "security_trust",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity documents TLS 1.3 encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity states Enterprise Max has SOC 2 Type II certification.",
              "evidence_type": "security_trust",
              "source_section": "How safe is Enterprise Max?"
            }
          ],
          "note": "Perplexity documents SOC 2 Type II compliance.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0005",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "microsoft_365_copilot_unified_audit_log",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – CopilotInteraction schema",
              "url": "https://learn.microsoft.com/en-us/office/office-365-management-api/copilot-schema",
              "note": "Microsoft documents the CopilotInteraction audit schema and Copilot events in the Microsoft 365 unified audit log.",
              "evidence_type": "api_docs",
              "source_section": "Copilot interaction events overview"
            },
            {
              "title": "Microsoft Learn – Office 365 Management Activity API reference",
              "url": "https://learn.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference",
              "note": "Microsoft documents the Office 365 Management Activity API as a REST web service for retrieving audit actions and events.",
              "evidence_type": "api_docs",
              "source_section": "Overview"
            }
          ],
          "note": "Microsoft 365 Copilot audit events can be retrieved programmatically through the Management Activity API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "microsoft_365_copilot",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Audit Microsoft 365 Copilot interactions",
              "url": "https://learn.microsoft.com/en-us/purview/audit-copilot",
              "note": "Microsoft documents audit records for Microsoft 365 Copilot user interactions and AI activities in Microsoft Purview Audit.",
              "evidence_type": "technical_docs",
              "source_section": "Copilot audit events"
            }
          ],
          "note": "Microsoft 365 Copilot interactions are represented in Microsoft Purview audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 180,
          "scope": "microsoft_purview_audit_standard_copilot",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Audit logs for Copilot and AI applications",
              "url": "https://learn.microsoft.com/en-us/purview/audit-copilot",
              "note": "Microsoft states Microsoft applications and Microsoft Copilots are included in Audit Standard.",
              "evidence_type": "technical_docs",
              "source_section": "Billing / Microsoft applications"
            },
            {
              "title": "Microsoft Learn – Get started with auditing solutions",
              "url": "https://learn.microsoft.com/en-us/purview/audit-get-started",
              "note": "Microsoft states Audit Standard logs generated after October 17, 2023 have a default retention of 180 days.",
              "evidence_type": "technical_docs",
              "source_section": "Retention"
            }
          ],
          "note": "Microsoft 365 Copilot audit records are in Audit Standard, whose documented default retention is 180 days."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "microsoft_365_copilot_audit",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Copilot auditing and logging",
              "url": "https://learn.microsoft.com/en-us/microsoft-365/copilot/employee-self-service/auditing-logging",
              "note": "Microsoft documents SIEM integration paths for Copilot/agent auditing through Microsoft security/telemetry services.",
              "evidence_type": "technical_docs",
              "source_section": "Security information and event management (SIEM)"
            }
          ],
          "note": "Microsoft documents SIEM integration for Copilot/agent audit telemetry."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "microsoft_365_copilot",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Microsoft 365 Copilot architecture, data protection, and auditing",
              "url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing",
              "note": "Microsoft states Copilot respects existing Microsoft 365 permissions, access controls, and identity authorization.",
              "evidence_type": "security_trust",
              "source_section": "Permissions and access controls"
            }
          ],
          "note": "Researcher/Analyst operate under Microsoft 365 role- and permission-based access controls."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "microsoft_365_copilot_researcher",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft 365 Blog – Researcher and Analyst are now generally available",
              "url": "https://www.microsoft.com/en-us/microsoft-365/blog/2025/06/02/researcher-and-analyst-are-now-generally-available-in-microsoft-365-copilot/",
              "note": "Microsoft documents Researcher as a built-in, pre-pinned reasoning agent in the Microsoft 365 Copilot app for licensed users.",
              "evidence_type": "official_release",
              "source_section": "How to get started with Researcher and Analyst"
            }
          ],
          "note": "Researcher is delivered as a managed agent inside Microsoft 365 Copilot."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "microsoft_365_copilot_service_boundary",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Data, Privacy, and Security for Microsoft 365 Copilot",
              "url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy",
              "note": "Microsoft documents Microsoft 365 Copilot within the Microsoft 365 service boundary and applicable geographic/data residency commitments.",
              "evidence_type": "security_trust",
              "source_section": "Data residency and processing"
            }
          ],
          "note": "Microsoft 365 Copilot provides documented data-residency commitments."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "microsoft_365_multi_geo",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Microsoft 365 Multi-Geo",
              "url": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-multi-geo?view=o365-worldwide",
              "note": "Microsoft documents Multi-Geo controls for placing Microsoft 365 user data in selected supported geographies; Copilot operates within this service boundary.",
              "evidence_type": "technical_docs",
              "source_section": "Multi-Geo capabilities"
            }
          ],
          "note": "Eligible Microsoft 365 organizations can configure supported data geographies used by the Copilot service boundary."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "microsoft_365_copilot_service_boundary",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Microsoft 365 Copilot architecture, data protection, and auditing",
              "url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing",
              "note": "Microsoft states Copilot data is protected by Microsoft 365 encryption controls, including encryption at rest.",
              "evidence_type": "security_trust",
              "source_section": "Data protection"
            }
          ],
          "note": "Microsoft 365 Copilot data is protected by Microsoft 365 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "microsoft_365_copilot_service_boundary",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Microsoft 365 Copilot architecture, data protection, and auditing",
              "url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing",
              "note": "Microsoft states Copilot data is protected by Microsoft 365 encryption controls, including encryption in transit.",
              "evidence_type": "security_trust",
              "source_section": "Data protection"
            }
          ],
          "note": "Microsoft 365 Copilot data is protected by Microsoft 365 encryption in transit."
        }
      ]
    },
    {
      "agent_id": "AI-0006",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "enterprise_and_edu",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "The Enterprise/Edu feature matrix lists the Compliance API alongside audit logs.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Compliance API access is documented in the enterprise feature matrix."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "enterprise_and_edu",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "The Enterprise/Edu feature matrix lists Compliance API and audit logs.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Enterprise/Edu audit logs are documented in the Codex/ChatGPT feature matrix."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 30,
          "scope": "enterprise_and_edu",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI – ChatGPT Work admin FAQ",
              "url": "https://learn.chatgpt.com/docs/enterprise/work-admin-faq",
              "note": "OpenAI documents a 30-day availability window for records in the Compliance Logs Platform and discusses Codex activity within the same enterprise governance context.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "The documented Compliance Logs Platform retention window is 30 days."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "enterprise_and_edu",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI – Compliance API",
              "url": "https://learn.chatgpt.com/docs/enterprise/compliance-api",
              "note": "OpenAI documents exporting auditable records through the Compliance API and ingesting or streaming them into SIEM and data-lake systems.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Codex workspace audit data can be exported into SIEM/data-lake workflows through the compliance interfaces."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "Enterprise feature rows list custom roles.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Custom roles are documented."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "Enterprise feature rows list RBAC and custom roles.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "RBAC is documented for Enterprise."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "Enterprise feature rows list SCIM.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "SCIM provisioning is documented."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "business_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "Business and Enterprise feature rows list SAML SSO.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "SAML SSO is documented for managed ChatGPT/Codex workspaces."
        },
        {
          "path": "hosting.cloud",
          "value": true,
          "scope": "chatgpt_plans",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "The feature matrix lists Codex Cloud and cloud environments.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Codex Cloud is documented."
        },
        {
          "path": "hosting.local",
          "value": true,
          "scope": "cli_and_desktop",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "The feature matrix lists Codex CLI, IDE extension and local capabilities.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Codex also has local execution surfaces."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – ChatGPT and Codex pricing/features",
              "url": "https://developers.openai.com/de-DE/docs/pricing",
              "note": "Enterprise feature rows list enterprise data retention and data residency settings.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Enterprise residency controls are documented."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "codex_cli_and_ide",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI Developers – Docs MCP",
              "url": "https://developers.openai.com/learn/docs-mcp",
              "note": "OpenAI documents connecting Codex CLI/IDE to remote MCP servers.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Codex can act as an MCP client."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "chatgpt_enterprise_where_ekm_available",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI – Business data privacy, security, and compliance",
              "url": "https://openai.com/business-data/",
              "note": "OpenAI documents Enterprise Key Management for customers to manage their own encryption keys.",
              "evidence_type": "security_trust"
            },
            {
              "title": "OpenAI – ChatGPT Work Overview",
              "url": "https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview",
              "note": "OpenAI states Work and Codex share core security boundaries and that Enterprise Key Management covers supported stored content in eligible workspaces.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Customer-managed encryption keys are available through OpenAI Enterprise Key Management where supported."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "chatgpt_enterprise_including_codex",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI – Business data privacy, security, and compliance",
              "url": "https://openai.com/business-data/",
              "note": "OpenAI documents AES-256 encryption at rest for business data.",
              "evidence_type": "security_trust"
            },
            {
              "title": "OpenAI – ChatGPT Work admin FAQ",
              "url": "https://learn.chatgpt.com/docs/enterprise/work-admin-faq",
              "note": "OpenAI states ChatGPT Enterprise workspace commitments include encryption at rest and in transit, and notes that enterprise controls can extend to Codex activity.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Codex under ChatGPT Enterprise inherits the documented enterprise encryption controls."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "chatgpt_enterprise_including_codex",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI – Business data privacy, security, and compliance",
              "url": "https://openai.com/business-data/",
              "note": "OpenAI documents TLS 1.2 or higher for business data in transit.",
              "evidence_type": "security_trust"
            },
            {
              "title": "OpenAI – ChatGPT Work admin FAQ",
              "url": "https://learn.chatgpt.com/docs/enterprise/work-admin-faq",
              "note": "OpenAI states ChatGPT Enterprise workspace commitments include encryption at rest and in transit, and notes that enterprise controls can extend to Codex activity.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Codex under ChatGPT Enterprise inherits the documented enterprise transport encryption controls."
        }
      ]
    },
    {
      "agent_id": "AI-0007",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "claude_enterprise_including_claude_code",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Anthropic – Claude Enterprise",
              "url": "https://claude.com/solutions/enterprise",
              "note": "Anthropic documents the Compliance API for programmatic access to activity logs, chats, files, and projects.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Claude Enterprise exposes programmatic audit/activity access through the Compliance API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "claude_code_enterprise_and_cloud_sessions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Code Docs – Security",
              "url": "https://code.claude.com/docs/en/security",
              "note": "Anthropic states all operations in Anthropic-hosted Claude Code cloud sessions are logged for compliance and audit purposes.",
              "evidence_type": "security_trust"
            },
            {
              "title": "Anthropic – Claude Enterprise",
              "url": "https://claude.com/solutions/enterprise",
              "note": "Anthropic lists audit logs as an Enterprise visibility and logging control covering the Enterprise suite including Claude Code.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Claude Code activity has documented audit logging in cloud sessions and Enterprise governance."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "claude_code_opentelemetry",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Code Docs – Monitoring",
              "url": "https://code.claude.com/docs/en/monitoring-usage",
              "note": "Anthropic documents Claude Code OpenTelemetry audit events and states OTLP logs can be delivered to any SIEM with an OTLP receiver or via an OpenTelemetry Collector.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Claude Code audit events can be exported to SIEM systems through OpenTelemetry."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "claude_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help Center – Claude Code on Console to Enterprise migration",
              "url": "https://support.claude.com/en/articles/14128775-claude-code-on-console-to-enterprise-migration",
              "note": "Anthropic explicitly documents custom roles (RBAC) in Claude Enterprise for scoping feature and administrative access.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Claude Enterprise supports custom roles applicable to Claude Code governance."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "claude_enterprise_including_claude_code",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Anthropic – Claude Enterprise",
              "url": "https://claude.com/solutions/enterprise",
              "note": "Anthropic documents role-based access control for fine-grained user, feature, and spend management, with Claude Code included in Enterprise entitlements.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Claude Code Enterprise access and entitlements are governed through RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "claude_enterprise_including_claude_code",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Anthropic – Claude Enterprise",
              "url": "https://claude.com/solutions/enterprise",
              "note": "Anthropic documents SCIM provisioning for Claude Enterprise and states Claude Code is included under the same enterprise identity and admin controls.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Claude Enterprise SCIM provisioning governs Claude Code users."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "claude_enterprise_including_claude_code",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Anthropic – Claude Enterprise",
              "url": "https://claude.com/solutions/enterprise",
              "note": "Anthropic lists single sign-on (SSO/SAML) as an Enterprise security and administration control and includes Claude Code in the Enterprise suite.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Claude Code under Claude Enterprise is governed by Enterprise SSO/SAML."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "claude_code_cloud_sessions_anthropic_hosted",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Code Docs – Security",
              "url": "https://code.claude.com/docs/en/security",
              "note": "Anthropic documents cloud sessions running in isolated Anthropic-managed virtual machines.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Claude Code cloud sessions can run in Anthropic-managed environments."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "claude_code_cloud_sessions_self_hosted_environment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Code Docs – Security",
              "url": "https://code.claude.com/docs/en/security",
              "note": "Anthropic explicitly documents organization-routed cloud sessions running in a self-hosted environment on customer infrastructure.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Organizations can route Claude Code cloud sessions to a self-hosted environment."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "claude_code",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Code Docs – Connect Claude Code to tools via MCP",
              "url": "https://code.claude.com/docs/en/mcp",
              "note": "Anthropic documents Claude Code connecting to remote and local MCP servers to access tools, databases, and APIs.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Claude Code is a documented MCP client."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "claude_code_stdio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Code Docs – Connect Claude Code to tools via MCP",
              "url": "https://code.claude.com/docs/en/mcp",
              "note": "Anthropic documents `claude mcp serve`, which runs Claude Code itself as a stdio MCP server for other applications.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Claude Code can expose its tools as an MCP server."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "claude_enterprise_including_claude_code",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Anthropic – Claude Enterprise",
              "url": "https://claude.com/solutions/enterprise",
              "note": "Anthropic lists customer-managed encryption keys among Enterprise data controls and includes Claude Code in the same Enterprise suite.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Claude Enterprise offers customer-managed encryption keys for its Enterprise suite."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "claude_code_security_program",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Code Docs – Security",
              "url": "https://code.claude.com/docs/en/security",
              "note": "Anthropic's Claude Code security documentation explicitly references its SOC 2 Type 2 report in the Trust Center.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Claude Code is covered by Anthropic's documented SOC 2 Type 2 security program."
        }
      ]
    },
    {
      "agent_id": "AI-0008",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "copilot_cloud_agent_management",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – REST API endpoints for Copilot cloud agent management",
              "url": "https://docs.github.com/en/rest/copilot/copilot-coding-agent-management?apiVersion=2026-03-10",
              "note": "GitHub exposes REST endpoints to manage Copilot cloud agent policies and repository access.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "GitHub provides REST APIs for cloud-agent administration."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "github_enterprise_agentic_activity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Audit log events for agents",
              "url": "https://docs.github.com/en/copilot/reference/enterprise-administrators/agentic-audit-log-events",
              "note": "GitHub documents enterprise audit-log events for agentic activity, including the initiating user and agent session ID.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Enterprise agentic activity is represented in GitHub audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 180,
          "scope": "github_enterprise_agentic_activity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Audit log events for agents",
              "url": "https://docs.github.com/en/copilot/reference/enterprise-administrators/agentic-audit-log-events",
              "note": "GitHub states enterprise owners can view agentic activity over the last 180 days.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "The documented enterprise agentic audit-log view covers 180 days."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "eligible_enterprises_public_preview",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Monitoring agentic activity in your enterprise",
              "url": "https://docs.github.com/en/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-agents/monitor-agentic-activity",
              "note": "GitHub documents streaming agentic audit-log activity to an external destination; the feature is in public preview for specified enterprise configurations.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Eligible enterprises can stream agentic audit events to an external destination."
        },
        {
          "path": "governance.observability",
          "value": true,
          "scope": "github_enterprise_agent_monitoring",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Monitoring agentic activity in your enterprise",
              "url": "https://docs.github.com/en/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-agents/monitor-agentic-activity",
              "note": "GitHub documents enterprise views for recent agent sessions, audit-log tracking, and OpenTelemetry monitoring.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "GitHub Enterprise provides centralized agent-session and telemetry monitoring."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "github_enterprise_agent_management",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Agent management for enterprises",
              "url": "https://docs.github.com/en/copilot/concepts/enterprise/agent-management",
              "note": "GitHub documents distinct enterprise-owner and AI-manager roles for controlling agent policies and enterprise custom agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Enterprise agent management is role-governed through GitHub owner and AI-manager permissions."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "github_enterprise_managed_users_with_copilot",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Enterprise accounts for Copilot Business",
              "url": "https://docs.github.com/en/copilot/concepts/enterprise/about-enterprise-accounts-for-copilot-business",
              "note": "GitHub documents provisioning Enterprise Managed Users from an identity provider using SCIM for Copilot Business access.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "SCIM provisioning is supported for Enterprise Managed Users with Copilot."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "github_enterprise_copilot_access",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Enterprise accounts for Copilot Business",
              "url": "https://docs.github.com/en/copilot/concepts/enterprise/about-enterprise-accounts-for-copilot-business",
              "note": "GitHub documents optional SAML SSO for enterprise users with Copilot Business.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Enterprise Copilot access can be protected with SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "copilot_cloud_agent_execution",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Configure the development environment",
              "url": "https://docs.github.com/en/copilot/how-tos/copilot-on-github/customize-copilot/customize-cloud-agent/customize-the-agent-environment",
              "note": "GitHub documents an ephemeral development environment powered by GitHub Actions and a default GitHub-hosted runner.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Copilot cloud agent uses a managed ephemeral GitHub Actions execution environment by default."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "github_enterprise_cloud_with_data_residency",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – GitHub Copilot with data residency",
              "url": "https://docs.github.com/en/enterprise-cloud@latest/admin/data-residency/github-copilot-with-data-residency",
              "note": "GitHub documents regional routing and storage for Copilot when enterprise data residency is enforced.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Copilot supports regional processing/storage under GitHub Enterprise Cloud data-residency configurations."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "copilot_cloud_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitHub Docs – Configure MCP servers for your repository",
              "url": "https://docs.github.com/en/copilot/how-tos/copilot-on-github/customize-copilot/configure-mcp-servers",
              "note": "GitHub documents repository MCP server configuration that gives Copilot cloud agent access to external tools and data sources.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Copilot cloud agent can consume configured MCP servers."
        }
      ]
    },
    {
      "agent_id": "AI-0009",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "cursor_enterprise",
          "evidence": [
            {
              "title": "Cursor Docs – Compliance and Monitoring",
              "url": "https://prod.cursor.com/docs/enterprise/compliance-and-monitoring",
              "note": "Cursor documents Admin API endpoints GET /teams/audit-logs and GET /organizations/audit-logs.",
              "evidence_type": "api_docs",
              "source_section": "Accessing audit logs"
            }
          ],
          "note": "Cursor exposes audit logs programmatically through the Admin API.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "cursor_enterprise",
          "evidence": [
            {
              "title": "Cursor Docs – Compliance and Monitoring",
              "url": "https://prod.cursor.com/docs/enterprise/compliance-and-monitoring",
              "note": "Cursor documents Enterprise audit logs for sign-ins, membership, roles, settings, integrations, Cloud Agent environments, and related surfaces.",
              "evidence_type": "technical_docs",
              "source_section": "Audit logs"
            }
          ],
          "note": "Cursor Enterprise provides administrative/security audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "cursor_enterprise",
          "evidence": [
            {
              "title": "Cursor Docs – Compliance and Monitoring",
              "url": "https://prod.cursor.com/docs/enterprise/compliance-and-monitoring",
              "note": "Cursor documents streaming audit events to Splunk, Sumo Logic, HTTPS webhooks including SIEM endpoints, or S3.",
              "evidence_type": "technical_docs",
              "source_section": "Streaming audit logs"
            }
          ],
          "note": "Cursor Enterprise can stream audit events to SIEM/security tooling.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "cursor_enterprise",
          "evidence": [
            {
              "title": "Cursor Docs – Enterprise",
              "url": "https://prod.cursor.com/docs/enterprise",
              "note": "Cursor documents SCIM provisioning and access gating for Enterprise.",
              "evidence_type": "technical_docs",
              "source_section": "Identity and access / SCIM"
            }
          ],
          "note": "Cursor Enterprise supports SCIM.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "cursor_teams_enterprise",
          "evidence": [
            {
              "title": "Cursor – Pricing",
              "url": "https://cursor.com/pricing",
              "note": "Cursor explicitly lists SAML/OIDC SSO for Teams and Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Teams / Enterprise"
            }
          ],
          "note": "Cursor supports OIDC SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "cursor_teams_enterprise",
          "evidence": [
            {
              "title": "Cursor Docs – Enterprise",
              "url": "https://prod.cursor.com/docs/enterprise",
              "note": "Cursor documents SSO (SAML/OIDC) for Teams and Enterprise.",
              "evidence_type": "technical_docs",
              "source_section": "Plan Comparison / SSO (SAML/OIDC)"
            }
          ],
          "note": "Cursor business plans support SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "cursor_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cursor Docs – Model Context Protocol (MCP)",
              "url": "https://cursor.com/docs/mcp",
              "note": "Cursor documents that MCP enables Cursor to connect to external tools and data sources and that the Agent automatically uses available MCP tools.",
              "evidence_type": "technical_docs",
              "source_section": "What is MCP? / Using MCP in chat"
            }
          ],
          "note": "Cursor Agent consumes tools and data from configured MCP servers."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "cursor_enterprise_cloud_agent_data",
          "evidence": [
            {
              "title": "Cursor Docs – Privacy and Data Governance",
              "url": "https://cursor.com/docs/enterprise/privacy-and-data-governance",
              "note": "Cursor documents Customer Managed Encryption Keys for Enterprise, including Cloud Agent data encrypted with the customer key.",
              "evidence_type": "security_trust",
              "source_section": "Data encryption / CMEK"
            }
          ],
          "note": "Cursor Enterprise supports CMEK for Cloud Agent data.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "cursor_infrastructure",
          "evidence": [
            {
              "title": "Cursor Docs – Network Configuration",
              "url": "https://prod.cursor.com/docs/enterprise/network-configuration",
              "note": "Cursor documents AES-256 encryption for stored data, vector storage, and Cloud Agent code storage.",
              "evidence_type": "security_trust",
              "source_section": "Encryption / At rest"
            }
          ],
          "note": "Cursor documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "cursor_services",
          "evidence": [
            {
              "title": "Cursor Docs – Network Configuration",
              "url": "https://prod.cursor.com/docs/enterprise/network-configuration",
              "note": "Cursor documents TLS 1.2 or higher for connections to Cursor services.",
              "evidence_type": "security_trust",
              "source_section": "Encryption / In transit"
            }
          ],
          "note": "Cursor documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "cursor_platform",
          "evidence": [
            {
              "title": "Cursor – Security",
              "url": "https://cursor.com/en-US/security",
              "note": "Cursor states it holds a SOC 2 Type II attestation.",
              "evidence_type": "security_trust",
              "source_section": "Certifications and third-party assessments"
            }
          ],
          "note": "Cursor documents SOC 2 Type II compliance.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0010",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "windsurf_enterprise_analytics",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Windsurf Docs – Analytics API",
              "url": "https://docs.windsurf.com/de/windsurf/accounts/api-reference/analytics-api-introduction",
              "note": "Windsurf documents an Enterprise Analytics API for programmatic access to usage data including Cascade activity, with authenticated API endpoints.",
              "evidence_type": "api_docs",
              "source_section": "Analytics API / Überblick"
            }
          ],
          "note": "Windsurf Enterprise exposes an authenticated analytics API covering Cascade usage."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "windsurf_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Windsurf – Enterprise comparison",
              "url": "https://windsurf.com/switch/cursor",
              "note": "Windsurf explicitly lists RBAC as an Enterprise governance control.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security"
            }
          ],
          "note": "Windsurf Enterprise provides RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "windsurf_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Windsurf – Enterprise comparison",
              "url": "https://windsurf.com/switch/cursor",
              "note": "Windsurf explicitly lists SCIM/SSO as Enterprise identity controls.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security"
            }
          ],
          "note": "Windsurf Enterprise supports SCIM."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "windsurf_enterprise_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Windsurf – Enterprise comparison",
              "url": "https://windsurf.com/switch/cursor",
              "note": "Windsurf documents Cloud deployment as an Enterprise deployment choice for Windsurf/Cascade.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise & Deployment"
            }
          ],
          "note": "Windsurf Cascade is available through a managed cloud deployment."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "windsurf_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Windsurf – Enterprise comparison",
              "url": "https://windsurf.com/switch/cursor",
              "note": "Windsurf explicitly lists Hybrid and Self-hosted Enterprise deployment choices.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise & Deployment"
            }
          ],
          "note": "Windsurf Enterprise supports self-hosted deployment."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "windsurf_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Windsurf – Enterprise comparison",
              "url": "https://windsurf.com/switch/cursor",
              "note": "Windsurf explicitly lists an EU cluster / EU residency option for Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise & Deployment"
            }
          ],
          "note": "Windsurf Enterprise provides an EU residency option."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "windsurf_enterprise_deployment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Windsurf – Enterprise comparison",
              "url": "https://windsurf.com/switch/cursor",
              "note": "Windsurf presents EU cluster/residency as an Enterprise deployment choice alongside Cloud, Hybrid, and Self-hosted options.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise & Deployment"
            }
          ],
          "note": "Enterprise customers can choose the documented EU cluster deployment option."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "windsurf_cascade",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Devin Docs – Cascade",
              "url": "https://docs.devin.ai/desktop/cascade/cascade",
              "note": "The current official Cascade documentation describes MCP servers as extensions to the agent's capabilities.",
              "evidence_type": "technical_docs",
              "source_section": "Cascade / MCP"
            }
          ],
          "note": "Cascade can consume capabilities exposed through configured MCP servers."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "windsurf_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Windsurf – Master Subscription Agreement",
              "url": "https://windsurf.com/MSA",
              "note": "Windsurf states Customer Data is encrypted during transit as part of its security safeguards.",
              "evidence_type": "security_trust",
              "source_section": "Security / Customer Data"
            }
          ],
          "note": "Windsurf documents encryption of customer data in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "windsurf_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Windsurf – Enterprise comparison",
              "url": "https://windsurf.com/switch/cursor",
              "note": "Windsurf explicitly lists SOC 2 Type II among Enterprise compliance controls.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise security and compliance"
            }
          ],
          "note": "Windsurf documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0011",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "replit_enterprise_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit Enterprise",
              "url": "https://replit.com/enterprise",
              "note": "Replit documents full organization audit logging.",
              "evidence_type": "official_product_page",
              "source_section": "Audit Logging"
            }
          ],
          "note": "Replit Enterprise provides audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 30,
          "scope": "replit_enterprise_audit_logs_default",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit – Govern Replit at scale",
              "url": "https://replit.com/blog/new-enterprise-governance-tools",
              "note": "Replit states default audit-log retention is 30 days, with longer retention available by arrangement.",
              "evidence_type": "official_release",
              "source_section": "Audit logs that work with your existing tooling"
            }
          ],
          "note": "Replit Enterprise audit logs have a documented 30-day default retention."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "replit_enterprise_agent_activity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit – Govern Replit at scale",
              "url": "https://replit.com/blog/new-enterprise-governance-tools",
              "note": "Replit documents native streaming of audit events, including agent activity, to Datadog, Splunk, Amazon S3, or generic HTTP endpoints.",
              "evidence_type": "official_release",
              "source_section": "Audit logs that work with your existing tooling"
            }
          ],
          "note": "Replit Enterprise audit events including agent activity can stream to SIEM/observability destinations."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "replit_enterprise_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit Enterprise",
              "url": "https://replit.com/enterprise",
              "note": "Replit documents granular role-based permissions across enterprise organizations.",
              "evidence_type": "official_product_page",
              "source_section": "Role-Based Access Control"
            }
          ],
          "note": "Replit Enterprise provides RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "replit_enterprise_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit Enterprise",
              "url": "https://replit.com/enterprise",
              "note": "Replit documents SCIM provisioning and deprovisioning.",
              "evidence_type": "official_product_page",
              "source_section": "SCIM"
            }
          ],
          "note": "Replit Enterprise supports SCIM."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "replit_enterprise_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit Enterprise",
              "url": "https://replit.com/enterprise",
              "note": "Replit explicitly documents OIDC Enterprise SSO.",
              "evidence_type": "official_product_page",
              "source_section": "SSO"
            }
          ],
          "note": "Replit Enterprise supports OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "replit_enterprise_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit Enterprise",
              "url": "https://replit.com/enterprise",
              "note": "Replit explicitly documents SAML Enterprise SSO.",
              "evidence_type": "official_product_page",
              "source_section": "SSO"
            }
          ],
          "note": "Replit Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "replit_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit – Agent",
              "url": "https://replit.com/products/agent",
              "note": "Replit documents Agent as part of the Replit platform where users build, refine, and launch production-ready apps from one workspace.",
              "evidence_type": "official_product_page",
              "source_section": "Build & refine your app with Agent / Turn your next idea into a working app"
            }
          ],
          "note": "Replit Agent is delivered within Replit's managed application platform."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "replit_enterprise_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit Enterprise",
              "url": "https://replit.com/enterprise",
              "note": "Replit lists connectors and MCP together with Agent 4 as included Enterprise platform capabilities.",
              "evidence_type": "official_product_page",
              "source_section": "Self-Serve Enterprise"
            }
          ],
          "note": "Replit Enterprise Agent can use MCP-enabled connectors on the Replit platform."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "replit_platform_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Replit – Security",
              "url": "https://replit.com/security",
              "note": "Replit states it holds SOC 2 Type II certification.",
              "evidence_type": "security_trust",
              "source_section": "Compliant and certified"
            }
          ],
          "note": "Replit documents SOC 2 Type II certification."
        }
      ]
    },
    {
      "agent_id": "AI-0012",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "devin_api_v3",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Devin Docs – API Authentication",
              "url": "https://docs.devin.ai/es/api-reference/authentication",
              "note": "Devin documents authenticated HTTPS API endpoints such as POST /v3/organizations/{org_id}/sessions for creating sessions.",
              "evidence_type": "api_docs",
              "source_section": "API endpoint examples"
            }
          ],
          "note": "Devin exposes a documented HTTPS REST-style API."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "devin_enterprise_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Devin Docs – API Authentication",
              "url": "https://docs.devin.ai/es/api-reference/authentication",
              "note": "Devin documents Enterprise service-user access to /v3/enterprise/* and organization endpoints including audit-log resources.",
              "evidence_type": "api_docs",
              "source_section": "Enterprise service users"
            }
          ],
          "note": "Devin Enterprise exposes audit-related resources through its API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "devin_enterprise_and_government",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Devin Government",
              "url": "https://devin.ai/government",
              "note": "Cognition documents audit trails that distinguish human actions from AI actions.",
              "evidence_type": "security_trust",
              "source_section": "Security and auditability"
            }
          ],
          "note": "Devin provides audit trails for human and AI activity."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "devin_enterprise_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Devin Docs – API Authentication",
              "url": "https://docs.devin.ai/es/api-reference/authentication",
              "note": "Devin documents service-user roles that determine which API endpoints and organization resources the identity can access.",
              "evidence_type": "api_docs",
              "source_section": "Service user roles"
            }
          ],
          "note": "Devin Enterprise uses role-based permissions for API/service identities."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "devin_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Devin – Official Site",
              "url": "https://devin.ai/",
              "note": "Cognition presents Devin Cloud as the hosted environment where users delegate engineering work to Devin.",
              "evidence_type": "official_product_page",
              "source_section": "Devin Cloud"
            }
          ],
          "note": "Devin is available as Cognition's managed Devin Cloud service."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "devin_customer_dedicated_deployment",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Devin Docs – Enterprise Deployment",
              "url": "https://docs.devin.ai/enterprise/deployment/overview",
              "note": "Cognition documents Customer Dedicated Deployment in a customer-isolated single-tenant VPC connected to private customer resources through AWS PrivateLink or an IPSec tunnel.",
              "evidence_type": "technical_docs",
              "source_section": "Customer Dedicated Deployment Architecture"
            }
          ],
          "note": "Devin supports private-network access through a dedicated single-tenant VPC with PrivateLink or IPSec connectivity."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "devin_government_onprem_airgapped",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Devin Government",
              "url": "https://devin.ai/government",
              "note": "Cognition documents Devin deployment in customer environments including GovCloud, on-premises, and air-gapped operation.",
              "evidence_type": "official_product_page",
              "source_section": "On-Prem & Air-Gapped"
            }
          ],
          "note": "Devin supports on-premises and air-gapped deployment in its government/regulated offering."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "devin_sessions",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Devin Docs – Devin MCP servers and marketplace",
              "url": "https://docs.devin.ai/work-with-devin/mcp",
              "note": "Cognition documents Devin connecting to external tools and data sources through configured MCP servers using stdio, SSE, or HTTP transports.",
              "evidence_type": "technical_docs",
              "source_section": "Devin MCP servers and marketplace"
            }
          ],
          "note": "Devin can act as an MCP client for configured external MCP servers."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "devin_customer_dedicated_deployment",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Devin Docs – Enterprise Deployment",
              "url": "https://docs.devin.ai/enterprise/deployment/overview",
              "note": "Cognition states customer data in Customer Dedicated Deployment remains encrypted at rest.",
              "evidence_type": "security_trust",
              "source_section": "Customer Dedicated Deployment Architecture"
            }
          ],
          "note": "Current Devin documentation explicitly states customer data is encrypted at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "devin_customer_dedicated_deployment",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Devin Docs – Enterprise Deployment",
              "url": "https://docs.devin.ai/enterprise/deployment/overview",
              "note": "Cognition states customer data in Customer Dedicated Deployment remains encrypted in transit.",
              "evidence_type": "security_trust",
              "source_section": "Customer Dedicated Deployment Architecture"
            }
          ],
          "note": "Current Devin documentation explicitly states customer data is encrypted in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "devin_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Devin Government",
              "url": "https://devin.ai/government",
              "note": "Cognition lists SOC 2 Type II among Devin's security/compliance assurances.",
              "evidence_type": "security_trust",
              "source_section": "Security and compliance"
            }
          ],
          "note": "Devin documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0013",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "amazon_q_developer_api_activity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Logging Amazon Q Developer API calls using AWS CloudTrail",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/logging-using-cloudtrail.html",
              "note": "AWS documents that Amazon Q Developer Pro is integrated with CloudTrail and that all Amazon Q Developer API actions generate CloudTrail events.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Amazon Q Developer API activity is auditable through AWS CloudTrail."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "amazon_q_developer_resources",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Identity and access management for Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/security-iam.html",
              "note": "AWS documents IAM identities and policies for controlling authentication and authorization to Amazon Q Developer resources.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Amazon Q Developer access is governed through AWS IAM permissions and roles."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "amazon_q_developer_service",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Infrastructure security in Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/infrastructure-security.html",
              "note": "AWS explicitly describes Amazon Q as a managed service protected by AWS global network security.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Amazon Q Developer is an AWS-managed service."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "amazon_q_developer_ide_features_via_privatelink",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Amazon Q Developer and interface endpoints (AWS PrivateLink)",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/vpc-interface-endpoints.html",
              "note": "AWS documents private VPC connectivity to Amazon Q Developer APIs through interface VPC endpoints powered by AWS PrivateLink, without public internet routing.",
              "evidence_type": "technical_docs",
              "source_section": "Amazon Q Developer and interface endpoints"
            }
          ],
          "note": "Supported Amazon Q Developer IDE/API features can be accessed privately through AWS PrivateLink."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "q_developer_pro_supported_features",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Data storage in Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/data-storage.html",
              "note": "AWS documents that supported Amazon Q Developer Pro features store content in the AWS Region where the customer's Q Developer profile was created.",
              "evidence_type": "security_trust",
              "source_section": "AWS Regions where content is processed and stored"
            }
          ],
          "note": "For documented Pro features, content can be stored in the profile's AWS Region."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "q_developer_profile_supported_regions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Supported Regions for Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/regions.html",
              "note": "AWS lists supported Regions and directs administrators to use the Region selector for the Amazon Q Developer profile.",
              "evidence_type": "technical_docs",
              "source_section": "Supported Regions"
            },
            {
              "title": "AWS Docs – Data storage in Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/data-storage.html",
              "note": "For supported Pro features, content storage follows the AWS Region where the Q Developer profile was created.",
              "evidence_type": "security_trust",
              "source_section": "AWS Regions where content is processed and stored"
            }
          ],
          "note": "Administrators can create/manage Q Developer profiles in supported AWS Regions, with documented regional storage for supported Pro features."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "amazon_q_developer_cli_and_ide",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Using MCP with Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/qdev-mcp.html",
              "note": "AWS documents Amazon Q Developer CLI as an MCP host/client connecting to local and remote MCP servers; IDE support is also documented.",
              "evidence_type": "technical_docs",
              "source_section": "MCP configuration"
            }
          ],
          "note": "Amazon Q Developer can consume local and remote MCP servers."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "q_developer_pro_supported_features",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Data encryption in Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/data-encryption.html",
              "note": "AWS documents customer-managed KMS keys for specified Amazon Q Developer Pro features including Agents in the IDE.",
              "evidence_type": "security_trust",
              "source_section": "Using customer managed KMS keys"
            }
          ],
          "note": "Supported Amazon Q Developer Pro features can use customer-managed AWS KMS keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AWS encryption with AWS-owned KMS keys by default",
          "scope": "amazon_q_developer_stored_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Data encryption in Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/data-encryption.html",
              "note": "AWS states Amazon Q Developer data at rest is encrypted by default using AWS encryption solutions and AWS-owned KMS keys.",
              "evidence_type": "security_trust",
              "source_section": "Encryption at rest"
            }
          ],
          "note": "Amazon Q Developer encrypts stored data at rest by default."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "amazon_q_developer_communications",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Data encryption in Amazon Q Developer",
              "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/data-encryption.html",
              "note": "AWS states all communication between customers and Amazon Q and its downstream dependencies is protected with TLS 1.2 or higher.",
              "evidence_type": "security_trust",
              "source_section": "Encryption in transit"
            }
          ],
          "note": "Amazon Q Developer uses TLS 1.2 or higher for communications."
        }
      ]
    },
    {
      "agent_id": "AI-0014",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "jules_rest_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Jules Docs – REST API Quickstart",
              "url": "https://jules.google/docs/api/reference/",
              "note": "Google documents the Jules REST API for programmatic creation and management of sources, sessions, activities, and development workflows.",
              "evidence_type": "api_docs",
              "source_section": "Quickstart / API concepts"
            },
            {
              "title": "Jules Docs – Introducing the Jules API",
              "url": "https://jules.google/docs/changelog/2025-10-03/",
              "note": "Google documents programmatic Jules access via HTTPS REST endpoints.",
              "evidence_type": "official_release",
              "source_section": "Introducing the Jules API"
            }
          ],
          "note": "Jules provides a documented REST API."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "jules_task_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Jules Docs – Environment setup",
              "url": "https://jules.google/docs/environment/",
              "note": "Google states each Jules task runs inside a secure, short-lived virtual machine with preinstalled development tools.",
              "evidence_type": "technical_docs",
              "source_section": "Environment setup"
            },
            {
              "title": "Jules Docs – FAQ",
              "url": "https://jules.google/docs/faq/",
              "note": "Google states Jules executes code in a secure cloud-based virtual machine.",
              "evidence_type": "technical_docs",
              "source_section": "How does Jules run code, and what should I know about security?"
            }
          ],
          "note": "Jules tasks run in Google-managed cloud virtual machines."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "google_jules_sessions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Jules Docs – MCP support comes to Jules",
              "url": "https://jules.google/docs/changelog/2026-02-02",
              "note": "Google documents Jules connecting to supported MCP servers and invoking their tools during sessions.",
              "evidence_type": "official_release",
              "source_section": "MCP support comes to Jules"
            }
          ],
          "note": "Jules acts as an MCP client for supported MCP server integrations."
        }
      ]
    },
    {
      "agent_id": "AI-0015",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "kiro_crew_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – Crew SDK / API reference",
              "url": "https://kiro.dev/docs/crew/apps/sdk/",
              "note": "Kiro documents direct Gateway REST endpoints using GET/POST/PUT/PATCH/DELETE for Crew applications and services.",
              "evidence_type": "api_docs",
              "source_section": "Gateway REST endpoints"
            }
          ],
          "note": "Kiro Crew exposes documented REST endpoints."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "kiro_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – Monitoring and tracking",
              "url": "https://kiro.dev/docs/enterprise/monitor-and-track/",
              "note": "Kiro documents user activity reports, prompt logs, AWS CloudTrail events, and CloudWatch monitoring for enterprise activity.",
              "evidence_type": "technical_docs",
              "source_section": "Monitoring and tracking"
            }
          ],
          "note": "Kiro Enterprise provides activity and prompt logging for audit/monitoring."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "kiro_enterprise_prompt_logs",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – Logging user prompts",
              "url": "https://kiro.dev/docs/enterprise/monitor-and-track/prompt-logging/",
              "note": "Kiro stores enterprise prompt logs in a customer-selected Amazon S3 bucket, enabling downstream enterprise security/analytics ingestion.",
              "evidence_type": "technical_docs",
              "source_section": "About prompt logs / Enabling prompt logging"
            }
          ],
          "note": "Kiro enterprise prompt logs can be exported to customer-controlled S3 for downstream SIEM/analytics workflows."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "kiro_cloud_sessions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – How Kiro works",
              "url": "https://kiro.dev/docs/how-kiro-works/",
              "note": "Kiro documents Web and Mobile sessions running the agent harness in a managed cloud sandbox, and IDE/CLI sessions can also create and attach to cloud sessions.",
              "evidence_type": "technical_docs",
              "source_section": "Where the agent runs"
            }
          ],
          "note": "Kiro supports a managed cloud-sandbox runtime."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "kiro_api_private_connectivity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – VPC endpoints (AWS PrivateLink)",
              "url": "https://kiro.dev/docs/privacy-and-security/vpc-endpoints/",
              "note": "Kiro documents interface VPC endpoints via AWS PrivateLink so traffic to Kiro APIs stays on the Amazon network without public internet.",
              "evidence_type": "security_trust",
              "source_section": "Kiro and interface endpoints"
            }
          ],
          "note": "Kiro supports private VPC connectivity via AWS PrivateLink."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "kiro_ide_cli_local_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – How Kiro works",
              "url": "https://kiro.dev/docs/how-kiro-works/",
              "note": "Kiro documents IDE and CLI agent sessions running on the user's local environment, distinct from managed cloud sessions.",
              "evidence_type": "technical_docs",
              "source_section": "Where the agent runs"
            }
          ],
          "note": "Kiro IDE/CLI can run in the user's local/customer-managed environment."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "kiro_ide_cli_web",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – MCP",
              "url": "https://kiro.dev/docs/mcp/",
              "note": "Kiro documents configuring MCP servers whose tools become available to the Kiro agent.",
              "evidence_type": "technical_docs",
              "source_section": "MCP / Configuration"
            }
          ],
          "note": "Kiro acts as an MCP client."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "kiro_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – Data protection",
              "url": "https://kiro.dev/docs/privacy-and-security/data-protection/",
              "note": "Kiro Enterprise administrators can create and use customer-managed AWS KMS keys to encrypt their data.",
              "evidence_type": "security_trust",
              "source_section": "Encryption at rest / customer managed keys"
            }
          ],
          "note": "Kiro Enterprise supports customer-managed KMS keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "kiro_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – Data protection",
              "url": "https://kiro.dev/docs/privacy-and-security/data-protection/",
              "note": "Kiro documents encryption at rest using AWS KMS-owned encryption keys.",
              "evidence_type": "security_trust",
              "source_section": "Encryption at rest"
            }
          ],
          "note": "Kiro encrypts service data at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "kiro_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kiro Docs – Data protection",
              "url": "https://kiro.dev/docs/privacy-and-security/data-protection/",
              "note": "Kiro states all communication between customers, Kiro, and downstream dependencies uses TLS 1.2 or higher.",
              "evidence_type": "security_trust",
              "source_section": "Encryption in transit"
            }
          ],
          "note": "Kiro documents TLS 1.2+ encryption in transit."
        }
      ]
    },
    {
      "agent_id": "AI-0016",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "cline_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline Docs – Cline API",
              "url": "https://docs.cline.bot/api/overview",
              "note": "Cline documents an OpenAI-compatible Chat Completions API with an HTTPS POST endpoint.",
              "evidence_type": "api_docs",
              "source_section": "Cline API / Quick Start"
            }
          ],
          "note": "Cline provides a documented HTTP API endpoint for programmatic model access."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "cline_enterprise_observability",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline – Pricing",
              "url": "https://cline.bot/pricing",
              "note": "Cline lists audit logs among Enterprise security capabilities.",
              "evidence_type": "official_product_page",
              "source_section": "When do I need Enterprise?"
            },
            {
              "title": "Cline – Enterprise infrastructure",
              "url": "https://cline.bot/blog/enterprise-ai-coding-that-uses-your-infrastructure-not-ours",
              "note": "Cline documents centralized audit trails for user activity, configuration changes, model usage, and tool executions.",
              "evidence_type": "official_release",
              "source_section": "Real-time monitoring and audit trails"
            }
          ],
          "note": "Cline Enterprise provides centralized audit trails."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "cline_enterprise_observability",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline – Enterprise infrastructure",
              "url": "https://cline.bot/blog/enterprise-ai-coding-that-uses-your-infrastructure-not-ours",
              "note": "Cline documents OpenTelemetry export to observability platforms including Splunk, Datadog, Grafana Cloud, and New Relic.",
              "evidence_type": "official_release",
              "source_section": "Real-time monitoring and audit trails"
            }
          ],
          "note": "Cline Enterprise can export telemetry/audit data to external observability and SIEM tooling including Splunk."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "cline_enterprise_governance",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline – Pricing",
              "url": "https://cline.bot/pricing",
              "note": "Cline lists Role Based Access Control as an Enterprise feature.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "Cline Enterprise documents role-based access control."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "cline_enterprise_identity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline – Pricing",
              "url": "https://cline.bot/pricing",
              "note": "Cline lists SCIM provisioning among Enterprise security capabilities.",
              "evidence_type": "official_product_page",
              "source_section": "When do I need Enterprise?"
            }
          ],
          "note": "Cline Enterprise documents SCIM provisioning."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "cline_enterprise_identity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline – Pricing",
              "url": "https://cline.bot/pricing",
              "note": "Cline lists OIDC among Enterprise security capabilities.",
              "evidence_type": "official_product_page",
              "source_section": "When do I need Enterprise?"
            },
            {
              "title": "Cline – Install / Enterprise",
              "url": "https://cline.bot/install",
              "note": "Cline explicitly lists SSO using SAML/OIDC for Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "Cline Enterprise documents OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "cline_enterprise_identity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline – Install / Enterprise",
              "url": "https://cline.bot/install",
              "note": "Cline explicitly lists SSO using SAML/OIDC for Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "Cline Enterprise documents SAML SSO."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "cline_enterprise_deployment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline – Install / Enterprise",
              "url": "https://cline.bot/install",
              "note": "Cline documents private networking through VPC/private link for Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            },
            {
              "title": "Cline Enterprise",
              "url": "https://cline.bot/enterprise",
              "note": "Cline documents running Cline in a customer's own VPC.",
              "evidence_type": "official_product_page",
              "source_section": "Your data flows the way you choose"
            }
          ],
          "note": "Cline Enterprise supports private-network deployment in customer VPC environments."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "cline_enterprise_deployment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline – Install / Enterprise",
              "url": "https://cline.bot/install",
              "note": "Cline documents self-hosted or on-prem deployments for Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            },
            {
              "title": "Cline Enterprise",
              "url": "https://cline.bot/enterprise",
              "note": "Cline documents deployment in VPC, on-prem, and air-gapped environments.",
              "evidence_type": "official_product_page",
              "source_section": "Deploy where you want"
            }
          ],
          "note": "Cline Enterprise supports customer-managed self-hosted/on-prem deployment."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "cline_ide_cli_and_desktop",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cline Docs – MCP",
              "url": "https://docs.cline.bot/mcp/mcp-overview",
              "note": "Cline documents adding local and remote MCP servers and using their external tools and data sources from Cline.",
              "evidence_type": "technical_docs",
              "source_section": "MCP / Add servers"
            }
          ],
          "note": "Cline acts as an MCP client for local and remote MCP servers."
        }
      ]
    },
    {
      "agent_id": "AI-0017",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "make_enterprise_including_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make Help – Audit logs",
              "url": "https://help.make.com/audit-logs",
              "note": "Make documents Enterprise organization/team audit logs covering user and configuration activity.",
              "evidence_type": "technical_docs",
              "source_section": "Audit logs"
            }
          ],
          "note": "Make Enterprise provides audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "make_enterprise_audit_logs",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make Help – Audit logs",
              "url": "https://help.make.com/audit-logs",
              "note": "Make states Enterprise audit logs are stored for 12 months.",
              "evidence_type": "technical_docs",
              "source_section": "Audit logs"
            }
          ],
          "note": "Make Enterprise audit logs are retained for 12 months (365 days)."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "make_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make – Governance updates",
              "url": "https://www.make.com/en/blog/governance-in-make",
              "note": "Make documents Enterprise Custom Roles with administrator-defined permissions at organization or team level.",
              "evidence_type": "official_release",
              "source_section": "Custom roles for every team"
            }
          ],
          "note": "Make Enterprise supports custom roles."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "make_enterprise_including_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make – Enterprise",
              "url": "https://www.make.com/en/enterprise",
              "note": "Make documents role-based access as an Enterprise security and governance capability.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise-ready security and governance"
            }
          ],
          "note": "Make Enterprise provides role-based access control."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "make_enterprise_including_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make Help – Single Sign-on",
              "url": "https://help.make.com/single-sign-on",
              "note": "Make documents OpenID Connect as a supported Enterprise SSO protocol.",
              "evidence_type": "technical_docs",
              "source_section": "Supported protocols"
            }
          ],
          "note": "Make Enterprise supports OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "make_enterprise_including_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make Help – Single Sign-on",
              "url": "https://help.make.com/single-sign-on",
              "note": "Make documents SAML 2.0 as a supported Enterprise SSO protocol.",
              "evidence_type": "technical_docs",
              "source_section": "Supported protocols"
            }
          ],
          "note": "Make Enterprise supports SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "make_ai_agents_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make – Enterprise",
              "url": "https://www.make.com/en/enterprise",
              "note": "Make documents Make AI Agents as part of the cloud-first Make Enterprise automation platform.",
              "evidence_type": "official_product_page",
              "source_section": "AI Automation / Enterprise"
            }
          ],
          "note": "Make AI Agents run within Make's managed cloud platform."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "make_ai_agent_new",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make Help – Create your first AI agent",
              "url": "https://help.make.com/create-your-first-ai-agent",
              "note": "Make documents adding MCP servers and selecting MCP tools for Make AI Agent (New), which then uses those tools during tasks.",
              "evidence_type": "technical_docs",
              "source_section": "Add MCP servers"
            }
          ],
          "note": "Make AI Agent (New) can act as an MCP client for configured MCP servers."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "make_platform_including_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make – Security and Compliance",
              "url": "https://www.make.com/en/security",
              "note": "Make documents full-disk AES-256 encryption and AWS KMS for cryptographic key management.",
              "evidence_type": "security_trust",
              "source_section": "Data at rest"
            }
          ],
          "note": "Make documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2/1.3",
          "scope": "make_platform_including_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make – Security and Compliance",
              "url": "https://www.make.com/en/security",
              "note": "Make documents TLS 1.2 and 1.3 for network communication.",
              "evidence_type": "security_trust",
              "source_section": "Data in transit"
            }
          ],
          "note": "Make documents TLS 1.2/1.3 encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "make_platform_including_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Make – Security and Compliance",
              "url": "https://www.make.com/en/security",
              "note": "Make states it has completed SOC 2 Type II audits.",
              "evidence_type": "security_trust",
              "source_section": "Compliance"
            }
          ],
          "note": "Make documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0018",
      "claims": [
        {
          "path": "api.auth.api_key",
          "value": true,
          "scope": "platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Source control environments",
              "url": "https://docs.n8n.io/source-control-environments/create-environments/",
              "note": "The official source-control tutorial authenticates an n8n API call with X-N8N-API-KEY.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "API-key authentication is documented."
        },
        {
          "path": "api.public_access",
          "value": true,
          "scope": "platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Security audit",
              "url": "https://docs.n8n.io/hosting/securing/security-audit/",
              "note": "The security-audit documentation explicitly describes use through the public API.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "A public API is documented."
        },
        {
          "path": "api.rest",
          "value": true,
          "scope": "n8n_public_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Disable the public API",
              "url": "https://docs.n8n.io/deploy/host-n8n/configure-n8n/security/disable-the-public-api",
              "note": "n8n explicitly documents the n8n public REST API and states it can programmatically perform many GUI tasks.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "n8n exposes a documented public REST API."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "n8n_workflows",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Webhook node",
              "url": "https://docs.n8n.io/integrations/builtin/core-nodes/n8n-nodes-base.webhook",
              "note": "n8n documents production webhook URLs that receive HTTP requests and trigger workflows.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Published n8n workflows can expose production webhooks."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Role-based access control",
              "url": "https://docs.n8n.io/user-management/rbac/",
              "note": "The RBAC documentation includes custom roles.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Custom roles are documented."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Role-based access control",
              "url": "https://docs.n8n.io/user-management/rbac/",
              "note": "n8n documents role-based access control with instance and project roles.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Role-based access control is documented."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Set up OIDC",
              "url": "https://docs.n8n.io/user-management/oidc/setup/",
              "note": "Official n8n documentation describes configuring OIDC SSO.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "OIDC SSO is supported."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Set up SAML",
              "url": "https://docs.n8n.io/user-management/saml/setup/",
              "note": "Official n8n documentation describes configuring SAML SSO.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "SAML SSO is supported."
        },
        {
          "path": "hosting.cloud",
          "value": true,
          "scope": "platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Overview",
              "url": "https://docs.n8n.io/",
              "note": "n8n documentation presents Cloud as a supported deployment option.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "n8n Cloud is available."
        },
        {
          "path": "hosting.docker",
          "value": true,
          "scope": "self_hosted",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Overview",
              "url": "https://docs.n8n.io/",
              "note": "n8n documentation lists Docker as an installation option.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Docker deployment is documented."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "n8n_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Choose how to use n8n",
              "url": "https://docs.n8n.io/choose-how-to-use-n8n",
              "note": "n8n explicitly describes n8n Cloud as fully managed, with hosting, updates and scaling handled by n8n.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "n8n Cloud is an official fully managed deployment option."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Overview",
              "url": "https://docs.n8n.io/",
              "note": "n8n documentation explicitly presents self-hosting as an option.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Self-hosting is supported."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "n8n_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – MCP Client Tool",
              "url": "https://docs.n8n.io/integrations/builtin/cluster-nodes/sub-nodes/n8n-nodes-langchain.toolmcp",
              "note": "n8n documents the MCP Client Tool as an MCP client that exposes external MCP server tools to n8n AI Agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "n8n AI agents can consume tools from external MCP servers."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "n8n_workflows_and_tools",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – MCP Server Trigger",
              "url": "https://docs.n8n.io/integrations/builtin/core-nodes/n8n-nodes-langchain.mcptrigger",
              "note": "n8n documents an MCP Server Trigger that makes n8n tools and workflows available to MCP clients over SSE or streamable HTTP.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "n8n can expose workflows and tools as an MCP server."
        },
        {
          "path": "security.security_audit",
          "value": true,
          "scope": "platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "n8n Docs – Security audit",
              "url": "https://docs.n8n.io/hosting/securing/security-audit/",
              "note": "n8n provides a security audit via CLI, public API, or n8n node.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "A built-in security audit capability is documented."
        }
      ]
    },
    {
      "agent_id": "AI-0019",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "zapier_team_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier Help – Use the audit log to review your account activity",
              "url": "https://help.zapier.com/hc/en-us/articles/13295074298125-Use-the-audit-log-to-review-your-account-activity",
              "note": "Zapier documents account-wide audit logs for Team and Enterprise plans.",
              "evidence_type": "technical_docs",
              "source_section": "View account activity"
            }
          ],
          "note": "Zapier provides account-wide audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "zapier_enterprise_audit_log",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier Help – Use the audit log to review your account activity",
              "url": "https://help.zapier.com/hc/en-us/articles/13295074298125-Use-the-audit-log-to-review-your-account-activity",
              "note": "Zapier states Enterprise audit-log access covers the past 12 months.",
              "evidence_type": "technical_docs",
              "source_section": "Limitations"
            }
          ],
          "note": "Enterprise audit-log history is documented as 12 months (365 days)."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "zapier_enterprise_log_streams",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier Help – Set up log streams to monitor Zap activity",
              "url": "https://help.zapier.com/hc/en-us/articles/43732241361421-Set-up-log-streams-to-monitor-Zap-activity",
              "note": "Zapier documents Enterprise log streams that send real-time account and execution events to customer HTTPS endpoints for monitoring and alerting.",
              "evidence_type": "technical_docs",
              "source_section": "Log streams / Available event types"
            },
            {
              "title": "Zapier – Security & Compliance",
              "url": "https://zapier.com/security-compliance",
              "note": "Zapier describes real-time activity data being sent to monitoring tools through Log Streaming.",
              "evidence_type": "security_trust",
              "source_section": "Governance and observability"
            }
          ],
          "note": "Zapier Enterprise can stream audit/operational activity to external monitoring or SIEM tooling."
        },
        {
          "path": "governance.policy_controls",
          "value": true,
          "scope": "zapier_ai_and_agent_security",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "Zapier – Security & Compliance",
              "url": "https://zapier.com/security-compliance",
              "note": "Zapier documents AI guardrails that can scan AI steps, agents, and MCP connections for PII, prompt injection, and toxicity, with block, route, or detect-only handling.",
              "evidence_type": "security_trust",
              "source_section": "AI & Agent Security"
            }
          ],
          "note": "Zapier documents configurable AI guardrails and model controls across workflows, agents and AI steps."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "zapier_team_enterprise_including_ai_by_zapier",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier Help – User roles and permissions in Team and Enterprise accounts",
              "url": "https://help.zapier.com/hc/en-us/articles/39698983334797-User-roles-and-permissions-in-Team-and-Enterprise-accounts",
              "note": "Zapier documents Owner, Super Admin, Admin, and Member roles with distinct permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Account user roles / Account permissions by role"
            }
          ],
          "note": "Zapier uses documented role-based permissions."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "zapier_enterprise_including_ai_by_zapier",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier Help – Domain verification in workspaces and organizations",
              "url": "https://help.zapier.com/hc/en-us/articles/36605430464269-Domain-verification-in-workspaces-and-organizations",
              "note": "Zapier documents organization-level SCIM provisioning for Enterprise workspaces.",
              "evidence_type": "technical_docs",
              "source_section": "SAML and SCIM configuration"
            }
          ],
          "note": "Zapier Enterprise supports SCIM provisioning."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "zapier_enterprise_including_ai_by_zapier",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier Help – Set up single sign-on with SAML",
              "url": "https://help.zapier.com/hc/en-us/articles/8496279747085-Set-up-single-sign-on-with-SAML",
              "note": "Zapier documents SAML SSO configuration for Enterprise accounts.",
              "evidence_type": "technical_docs",
              "source_section": "Manually configure SSO with SAML"
            }
          ],
          "note": "Zapier Enterprise supports SAML SSO."
        },
        {
          "path": "governance.tool_permissions",
          "value": true,
          "scope": "zapier_ai_agents_workspace_permissions",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "Zapier – Security & Compliance",
              "url": "https://zapier.com/security-compliance",
              "note": "Zapier states administrators can decide which apps and actions are available by user, team, and workspace.",
              "evidence_type": "security_trust",
              "source_section": "AI & Agent Security / Agent permissions"
            }
          ],
          "note": "Zapier documents scoped app and action permissions for agents by user, team and workspace."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "zapier_platform_including_ai_by_zapier",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier – Security & Compliance",
              "url": "https://zapier.com/security-compliance",
              "note": "Zapier states its products are hosted on Amazon Web Services and describes AI-powered automation as part of the managed Zapier platform.",
              "evidence_type": "security_trust",
              "source_section": "FAQs / Cloud service provider"
            }
          ],
          "note": "AI by Zapier runs within Zapier's managed cloud platform."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "zapier_platform_including_ai_by_zapier",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier – Security & Compliance",
              "url": "https://zapier.com/security-compliance",
              "note": "Zapier states data at rest is encrypted with AES-256.",
              "evidence_type": "security_trust",
              "source_section": "Data security / FAQ"
            }
          ],
          "note": "Zapier documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "zapier_platform_including_ai_by_zapier",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier – Security & Compliance",
              "url": "https://zapier.com/security-compliance",
              "note": "Zapier states web application communications use TLS 1.2 and above.",
              "evidence_type": "security_trust",
              "source_section": "FAQ"
            }
          ],
          "note": "Zapier documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "zapier_platform_including_ai_by_zapier",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zapier Help – Security and Compliance",
              "url": "https://help.zapier.com/hc/en-us/articles/8496181993613-Security-and-Compliance",
              "note": "Zapier documents independent SOC 2 Type II certification and annual audits.",
              "evidence_type": "security_trust",
              "source_section": "Security and Compliance"
            }
          ],
          "note": "Zapier documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0020",
      "claims": [
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "lindy_webhook_trigger",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy – Changelog",
              "url": "https://www.lindy.ai/changelog",
              "note": "Lindy documents a Webhook Trigger that lets a Lindy be triggered by an API call.",
              "evidence_type": "official_release",
              "source_section": "Lindy Webhooks"
            }
          ],
          "note": "Lindy agents support inbound webhook/API-call triggers."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "lindy_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy Enterprise",
              "url": "https://www.lindy.ai/enterprise",
              "note": "Lindy states every action Lindy takes is logged with what happened, when, and why.",
              "evidence_type": "official_product_page",
              "source_section": "Audit visibility"
            },
            {
              "title": "Lindy – Pricing",
              "url": "https://www.lindy.ai/pricing",
              "note": "Lindy lists audit logs as an Enterprise capability.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "Lindy Enterprise provides action-level audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "lindy_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy Enterprise",
              "url": "https://www.lindy.ai/enterprise",
              "note": "Lindy documents workspace roles and seats with distinct permissions, including who can approve external actions.",
              "evidence_type": "official_product_page",
              "source_section": "Roles and seats"
            },
            {
              "title": "Lindy Enterprise: The new standard for enterprise AI",
              "url": "https://www.lindy.ai/blog/lindy-enterprise-announcement",
              "note": "Lindy documents centralized agent management and precise per-user app permissions controlled by admins.",
              "evidence_type": "official_release",
              "source_section": "Security & Governance"
            }
          ],
          "note": "Lindy Enterprise uses role-based permissions for workspace and agent governance."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "lindy_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy Enterprise",
              "url": "https://www.lindy.ai/enterprise",
              "note": "Lindy explicitly documents SCIM user provisioning through the enterprise identity provider.",
              "evidence_type": "official_product_page",
              "source_section": "SSO & SCIM"
            },
            {
              "title": "Lindy Enterprise: The new standard for enterprise AI",
              "url": "https://www.lindy.ai/blog/lindy-enterprise-announcement",
              "note": "Lindy documents SCIM as an Enterprise access-management capability.",
              "evidence_type": "official_release",
              "source_section": "Security & Governance"
            }
          ],
          "note": "Lindy Enterprise supports SCIM provisioning."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "lindy_platform_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy Enterprise",
              "url": "https://www.lindy.ai/enterprise",
              "note": "Lindy documents a centralized hosted workspace for deploying and managing agents, integrations, guardrails, roles, memory, and team sources.",
              "evidence_type": "official_product_page",
              "source_section": "Centralized management"
            },
            {
              "title": "Lindy Enterprise: The new standard for enterprise AI",
              "url": "https://www.lindy.ai/blog/lindy-enterprise-announcement",
              "note": "Lindy documents centrally managed agents deployed and governed through Lindy Enterprise.",
              "evidence_type": "official_release",
              "source_section": "Centrally Managed Agents"
            }
          ],
          "note": "Lindy provides a managed platform for deploying and operating agents."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "lindy_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy – Enterprise Security & Compliance",
              "url": "https://www.lindy.ai/security",
              "note": "Lindy explicitly states that data residency requirements are supported as part of its privacy controls.",
              "evidence_type": "security_trust",
              "source_section": "Privacy Controls"
            }
          ],
          "note": "Lindy supports enterprise data-residency requirements."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "lindy_hosted_mcp_integrations",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy – Official Site",
              "url": "https://www.lindy.ai/",
              "note": "Lindy states that hosted MCP servers can plug into Lindy as integrations.",
              "evidence_type": "official_product_page",
              "source_section": "What does Lindy connect to?"
            }
          ],
          "note": "Lindy can consume tools/services exposed through hosted MCP servers."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "lindy_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy Enterprise",
              "url": "https://www.lindy.ai/enterprise",
              "note": "Lindy states data is encrypted at rest.",
              "evidence_type": "security_trust",
              "source_section": "Data protection"
            }
          ],
          "note": "Lindy documents encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "lindy_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy Enterprise",
              "url": "https://www.lindy.ai/enterprise",
              "note": "Lindy states data is encrypted in transit.",
              "evidence_type": "security_trust",
              "source_section": "Data protection"
            }
          ],
          "note": "Lindy documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "lindy_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lindy – Enterprise Security & Compliance",
              "url": "https://www.lindy.ai/security",
              "note": "Lindy states it is SOC 2 Type II certified and independently audited.",
              "evidence_type": "security_trust",
              "source_section": "Compliance & Certifications"
            },
            {
              "title": "Lindy Enterprise",
              "url": "https://www.lindy.ai/enterprise",
              "note": "Lindy lists SOC 2 Type II as independently audited enterprise security compliance.",
              "evidence_type": "security_trust",
              "source_section": "Security by design"
            }
          ],
          "note": "Lindy documents SOC 2 Type II certification."
        }
      ]
    },
    {
      "agent_id": "AI-0021",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "relevance_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI Docs – Conversation API for Agents",
              "url": "https://relevanceai.com/docs/build/agents/extend-your-agent/conversation",
              "note": "Relevance AI documents HTTPS API endpoints for triggering agents, polling jobs, continuing conversations, and listing messages.",
              "evidence_type": "api_docs",
              "source_section": "Conversation API for Agents"
            }
          ],
          "note": "Relevance AI exposes programmatic HTTP API access for agent execution and conversations."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "relevance_ai_agent_triggers",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – Product",
              "url": "https://relevanceai.com/product",
              "note": "Relevance AI explicitly documents webhooks as a native trigger for agents alongside schedules and app events.",
              "evidence_type": "official_product_page",
              "source_section": "Triggers and scheduling"
            }
          ],
          "note": "Relevance AI agents can be triggered through webhooks."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "relevance_ai_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – Enterprise",
              "url": "https://relevanceai.com/enterprise",
              "note": "Relevance AI explicitly lists audit logs and audit trails among enterprise governance controls.",
              "evidence_type": "security_trust",
              "source_section": "Security & data privacy"
            }
          ],
          "note": "Relevance AI Enterprise provides audit logs."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "relevance_ai_enterprise_audit_stream",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI Docs – Changelog",
              "url": "https://relevanceai.com/docs/changelog",
              "note": "Relevance AI documents streaming AI audit logs and execution traces in OpenTelemetry format to a customer-controlled destination for enterprise governance and compliance.",
              "evidence_type": "official_release",
              "source_section": "OpenTelemetry Event Streaming for AI Audit Logs and Execution Traces"
            },
            {
              "title": "Relevance AI – Product",
              "url": "https://relevanceai.com/product",
              "note": "Relevance AI lists OTEL and Delta Share export under enterprise monitoring and oversight.",
              "evidence_type": "official_product_page",
              "source_section": "Monitoring & oversight"
            }
          ],
          "note": "Enterprise audit logs and traces can be exported to customer-controlled observability/SIEM destinations through OpenTelemetry."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "relevance_ai_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – Enterprise",
              "url": "https://relevanceai.com/enterprise",
              "note": "Relevance AI explicitly lists role-based access control as an enterprise capability.",
              "evidence_type": "security_trust",
              "source_section": "Access & controls"
            }
          ],
          "note": "Relevance AI Enterprise supports role-based access control."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "relevance_ai_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – Enterprise",
              "url": "https://relevanceai.com/enterprise",
              "note": "Relevance AI explicitly lists SSO / SAML under enterprise access controls.",
              "evidence_type": "security_trust",
              "source_section": "Access & controls"
            }
          ],
          "note": "Relevance AI Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "relevance_ai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI Docs – Features",
              "url": "https://relevanceai.com/docs/features",
              "note": "Relevance AI describes itself as a fully managed service handling infrastructure management, hosting, and scaling.",
              "evidence_type": "technical_docs",
              "source_section": "Fully Managed Service"
            },
            {
              "title": "Relevance AI – API",
              "url": "https://relevanceai.com/api",
              "note": "Relevance AI documents fully managed infrastructure that auto-scales for agent API deployments.",
              "evidence_type": "official_product_page",
              "source_section": "Managed API / Fully managed services"
            }
          ],
          "note": "Relevance AI provides managed hosting and scaling for agents."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "relevance_ai_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – Enterprise",
              "url": "https://relevanceai.com/enterprise",
              "note": "Relevance AI explicitly lists data residency as an enterprise security and privacy capability.",
              "evidence_type": "security_trust",
              "source_section": "Security & data privacy"
            }
          ],
          "note": "Relevance AI Enterprise documents data-residency capability."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "relevance_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – Product",
              "url": "https://relevanceai.com/product",
              "note": "Relevance AI documents that agents can access native connectors plus MCP support and MCP servers.",
              "evidence_type": "official_product_page",
              "source_section": "All of your agents on one stack / What can my agents access?"
            }
          ],
          "note": "Relevance AI agents can consume MCP-connected tools and servers."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "relevance_ai_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – FAQ",
              "url": "https://relevanceai.com/frequently-asked-questions",
              "note": "Relevance AI states all data is encrypted at rest.",
              "evidence_type": "security_trust",
              "source_section": "How does Relevance AI handle data security?"
            }
          ],
          "note": "Relevance AI documents encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "relevance_ai_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – FAQ",
              "url": "https://relevanceai.com/frequently-asked-questions",
              "note": "Relevance AI states all data is encrypted in transit.",
              "evidence_type": "security_trust",
              "source_section": "How does Relevance AI handle data security?"
            }
          ],
          "note": "Relevance AI documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "relevance_ai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Relevance AI – Enterprise",
              "url": "https://relevanceai.com/enterprise",
              "note": "Relevance AI explicitly states SOC 2 Type II compliance.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise security"
            },
            {
              "title": "Relevance AI Docs – Features",
              "url": "https://relevanceai.com/docs/features",
              "note": "Relevance AI states the platform is SOC 2 Type 2 certified.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise-Grade Security"
            }
          ],
          "note": "Relevance AI documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0023",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "gumloop_agents_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop Support – How to Find and Generate Your Gumloop API Key",
              "url": "https://support.gumloop.com/articles/9675038509-how-to-find-and-generate-your-gumloop-api-key",
              "note": "Gumloop documents API keys for triggering workflows and agents programmatically and links to its API Reference.",
              "evidence_type": "api_docs",
              "source_section": "API key / Related Docs"
            }
          ],
          "note": "Gumloop provides programmatic API access for agents and workflows."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "gumloop_agent_workflow_triggers",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop Support – How to Find and Generate Your Gumloop API Key",
              "url": "https://support.gumloop.com/articles/9675038509-how-to-find-and-generate-your-gumloop-api-key",
              "note": "Gumloop documents ready-to-use webhook URLs for triggering workflows that can contain agents.",
              "evidence_type": "api_docs",
              "source_section": "Webhook Button"
            }
          ],
          "note": "Gumloop provides webhook endpoints for agent-containing workflows."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "gumloop_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop Support – Roll out an Agent to your team or company",
              "url": "https://support.gumloop.com/articles/4970577938-how-do-i-roll-out-an-agent-to-my-whole-team-or-company",
              "note": "Gumloop documents enterprise audit logging for company-wide agent activity oversight.",
              "evidence_type": "technical_docs",
              "source_section": "Oversight and Audit Logs"
            }
          ],
          "note": "Gumloop Enterprise provides organization-wide audit logging."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "gumloop_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop – Enterprise",
              "url": "https://www.gumloop.com/enterprise",
              "note": "Gumloop documents reusable roles, permissions, credentials, and secrets with scoped access.",
              "evidence_type": "official_product_page",
              "source_section": "Roles and permissions"
            }
          ],
          "note": "Gumloop Enterprise provides role-based permissions."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "gumloop_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop – Enterprise",
              "url": "https://www.gumloop.com/enterprise",
              "note": "Gumloop explicitly lists SCIM for Enterprise identity and access management.",
              "evidence_type": "official_product_page",
              "source_section": "SAML SSO and SCIM"
            }
          ],
          "note": "Gumloop Enterprise supports SCIM."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "gumloop_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop – Enterprise",
              "url": "https://www.gumloop.com/enterprise",
              "note": "Gumloop explicitly lists SAML SSO for Enterprise identity management.",
              "evidence_type": "official_product_page",
              "source_section": "SAML SSO and SCIM"
            }
          ],
          "note": "Gumloop Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "gumloop_enterprise_vpc_deployment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop – Enterprise",
              "url": "https://www.gumloop.com/enterprise",
              "note": "Gumloop documents VPC deployments in the customer's own cloud to keep data in the customer's network.",
              "evidence_type": "official_product_page",
              "source_section": "VPC deployments"
            }
          ],
          "note": "Gumloop supports private-network/VPC deployment."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "gumloop_enterprise_vpc_deployment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop – Enterprise",
              "url": "https://www.gumloop.com/enterprise",
              "note": "Gumloop states Enterprise customers can deploy Gumloop inside their own AWS, Azure, or Google Cloud environment.",
              "evidence_type": "official_product_page",
              "source_section": "VPC deployments"
            }
          ],
          "note": "Gumloop Enterprise supports customer-cloud deployment."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "gumloop_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop Docs – Gamma MCP",
              "url": "https://docs.gumloop.com/nodes/mcp/gamma",
              "note": "Gumloop documents adding MCP tools to an agent via Add tools → Connect an app with MCP.",
              "evidence_type": "technical_docs",
              "source_section": "In Agents (Recommended)"
            }
          ],
          "note": "Gumloop Agents can consume tools from MCP servers."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "gumloop_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop – AI support agent",
              "url": "https://www.gumloop.com/use-cases/support-agent",
              "note": "Gumloop states it is SOC 2 Type II certified.",
              "evidence_type": "security_trust",
              "source_section": "SOC 2 Type II Certified"
            }
          ],
          "note": "Gumloop documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0024",
      "claims": [
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "gumloop_gumball_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gumloop – Meet Gumball",
              "url": "https://www.gumloop.com/blog/meet-gumball",
              "note": "Gumloop explicitly states Gumball works in the cloud and keeps working in the background when the user's laptop is closed.",
              "evidence_type": "official_release",
              "source_section": "An always-active agent for your own cloud"
            }
          ],
          "note": "Gumball runs as a cloud-hosted agent."
        }
      ]
    },
    {
      "agent_id": "AI-0025",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "copilot_studio_direct_line_integration",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Integrate Copilot Studio with web or native apps",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/publication-integrate-web-or-native-app-m365-agents-sdk",
              "note": "Microsoft documents connecting external web or native applications to a Copilot Studio agent through the Direct Line API.",
              "evidence_type": "api_docs"
            },
            {
              "title": "Microsoft Learn – Direct Line API 3.0 reference",
              "url": "https://learn.microsoft.com/en-us/azure/bot-service/rest-api/bot-framework-rest-direct-line-3-0-api-reference?view=azure-bot-service-4.0",
              "note": "Microsoft states Direct Line API 3.0 uses industry-standard REST and JSON over HTTPS.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Copilot Studio agents can be integrated through the REST-based Direct Line API."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "office_365_management_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Audit Copilot Studio activities in Microsoft Purview",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-logging-copilot-studio",
              "note": "Microsoft states that developers can access Copilot Studio audit logs through the Office 365 Management API.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Programmatic audit-log access is documented through the Office 365 Management API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "copilot_studio_tenant",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Audit Copilot Studio activities in Microsoft Purview",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-logging-copilot-studio",
              "note": "Microsoft documents Purview audit events for Copilot Studio administrative, maker, and user interactions.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Copilot Studio activities are available as audit events in Microsoft Purview."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "power_platform_environment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Secure your Copilot Studio projects",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/sec-gov-phase3",
              "note": "Microsoft explicitly documents assigning a custom role when predefined Copilot Studio authoring roles do not fit.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Custom Dataverse security roles are supported for Copilot Studio permissions."
        },
        {
          "path": "governance.dlp",
          "value": true,
          "scope": "power_platform_tenant",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Copilot Studio security and governance",
              "url": "https://learn.microsoft.com/de-de/microsoft-copilot-studio/security-and-governance",
              "note": "Copilot Studio security/governance explicitly includes Data Loss Prevention controls.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "DLP governance is documented."
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "confidence": "high",
          "scope": "agent_flows_ai_approvals",
          "verified_at": "2026-10-03",
          "note": "AI approval stages can be combined with human stages so people oversee and finalize critical or exceptional cases.",
          "evidence": [
            {
              "title": "Microsoft Learn – FAQ for AI approvals",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/faqs-ai-approvals",
              "evidence_type": "technical_docs",
              "source_section": "What are AI approvals capabilities?"
            }
          ]
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "power_platform_environment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Secure your Copilot Studio projects",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/sec-gov-phase3",
              "note": "Microsoft instructs organizations to assign Copilot Studio authoring permissions with Dataverse security roles.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Copilot Studio authoring access is governed with environment security roles."
        },
        {
          "path": "identity.agent_identity.provider",
          "value": "Microsoft Entra Agent ID",
          "scope": "new_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Copilot Studio agent identities",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/govern-agents-identities-overview",
              "note": "The identity type is a Microsoft Entra service principal with Agent subtype.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Microsoft Entra Agent ID is the documented identity provider."
        },
        {
          "path": "identity.agent_identity",
          "value": true,
          "scope": "new_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Copilot Studio agent identities",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/govern-agents-identities-overview",
              "note": "All new Copilot Studio agents automatically receive an Entra Agent ID.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agents receive a dedicated managed identity."
        },
        {
          "path": "memory.persistent",
          "value": true,
          "confidence": "high",
          "scope": "copilot_studio_memory_preview",
          "verified_at": "2026-10-03",
          "note": "Memory records interaction details and reuses them in future interactions; inactive user memories are deleted after 28 days.",
          "evidence": [
            {
              "title": "Microsoft Learn – Memory (preview)",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/agents-experience/memory-overview",
              "evidence_type": "technical_docs",
              "source_section": "How memory works"
            }
          ]
        },
        {
          "path": "memory.user_scoped",
          "value": true,
          "confidence": "high",
          "scope": "copilot_studio_memory_preview",
          "verified_at": "2026-10-03",
          "note": "Each agent keeps a separate memory store for every user; one user's context is not shared with another.",
          "evidence": [
            {
              "title": "Microsoft Learn – Memory (preview)",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/agents-experience/memory-overview",
              "evidence_type": "technical_docs",
              "source_section": "Memory (preview)"
            }
          ]
        },
        {
          "path": "operations.rate_limits_documented",
          "value": true,
          "confidence": "high",
          "scope": "standard_harness_agents",
          "verified_at": "2026-10-03",
          "note": "Copilot Studio documents agent request quotas in RPM/RPH for the Dataverse environment.",
          "evidence": [
            {
              "title": "Microsoft Learn – Quotas and limits",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/requirements-quotas",
              "evidence_type": "technical_docs",
              "source_section": "Quotas"
            }
          ]
        },
        {
          "path": "operations.service_quotas_documented",
          "value": true,
          "confidence": "high",
          "scope": "standard_harness_agents",
          "verified_at": "2026-10-03",
          "note": "Microsoft publishes quotas and limits for standard-harness Copilot Studio agents.",
          "evidence": [
            {
              "title": "Microsoft Learn – Quotas and limits",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/requirements-quotas",
              "evidence_type": "technical_docs",
              "source_section": "Quotas and limits"
            }
          ]
        },
        {
          "path": "orchestration.handoffs",
          "value": true,
          "confidence": "high",
          "scope": "copilot_studio_agents",
          "verified_at": "2026-10-03",
          "note": "Microsoft documents that Copilot Studio agents can hand off to other agents.",
          "evidence": [
            {
              "title": "Microsoft Learn – Agents overview",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/agents-overview",
              "evidence_type": "technical_docs",
              "source_section": "Agents overview"
            }
          ]
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "copilot_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Geographic data residency in Copilot Studio",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/geo-data-residency",
              "note": "Microsoft documents geographic data residency for Copilot Studio.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Geographic data residency is documented."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "copilot_studio_environment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Geographic data residency in Copilot Studio",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/geo-data-residency",
              "note": "Organizations can choose where Copilot Studio data is stored across supported Azure geographies.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Customer-selectable geography is documented."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "copilot_studio_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Add MCP tools to Copilot Studio agents",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-components-to-agent",
              "note": "Copilot Studio can connect an existing MCP server and add its tools/resources to an agent.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Copilot Studio agents can consume MCP servers."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "managed_power_platform_environments",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Configure customer-managed encryption keys",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-customer-managed-keys",
              "note": "Copilot Studio supports the Power Platform customer-managed key implementation for Managed Environments.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "CMK is supported through the Power Platform implementation for Managed Environments."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "Microsoft-managed keys by default",
          "scope": "copilot_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Configure customer-managed encryption keys",
              "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-customer-managed-keys",
              "note": "Microsoft documents that Copilot Studio customer data is encrypted at rest with Microsoft-managed keys by default.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Copilot Studio encrypts stored customer data at rest by default."
        }
      ]
    },
    {
      "agent_id": "AI-0026",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "watsonx_orchestrate_platform_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM API Hub – watsonx Orchestrate API",
              "url": "https://developer.ibm.com/apis/catalog/watsonorchestrate--custom-assistants/api/API--watsonorchestrate--ibm-watsonx-orchestrate-api",
              "note": "IBM publishes REST-style watsonx Orchestrate API endpoints for agent management, execution, tools, workspaces and observability.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "watsonx Orchestrate has a documented programmatic HTTP API surface."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "watsonx_orchestrate_message_processing",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM Docs – Call a service before processing a message",
              "url": "https://www.ibm.com/docs/en/watsonx/watson-orchestrate/base?topic=message-calling-service-before-processing-watsonx-orchestrate",
              "note": "IBM documents configurable pre-message webhooks that send HTTPS POST requests to external services.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "watsonx Orchestrate supports configurable message-processing webhooks."
        },
        {
          "path": "deployment.low_code",
          "value": true,
          "scope": "watsonx_orchestrate",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM watsonx Orchestrate – AI agent development and deployment",
              "url": "https://www.ibm.com/products/watsonx-orchestrate/developers",
              "note": "IBM documents both low-code and pro-code agent creation paths.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Low-code agent creation is documented alongside the Agent Development Kit."
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "scope": "agentic_workflows",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM watsonx Orchestrate – AI agent development and deployment",
              "url": "https://www.ibm.com/products/watsonx-orchestrate/developers",
              "note": "IBM documents human-in-the-loop workflow approvals that pause, capture context, and resume with audit-ready traceability.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Human approval steps are a documented workflow capability."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "watsonx_orchestrate",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM watsonx Orchestrate – AI agent development and deployment",
              "url": "https://www.ibm.com/products/watsonx-orchestrate/developers",
              "note": "IBM lists role-based access among the platform controls for securely scaling agents.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Role-based access is documented for the platform."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "watsonx_orchestrate_ibm_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM Docs – Logging in to watsonx Orchestrate",
              "url": "https://www.ibm.com/docs/en/watsonx/watson-orchestrate/base?topic=started-logging-in-watsonx-orchestrate",
              "note": "IBM documents SSO login and references SAML federation with IBM Cloud IAM for the IBM Cloud offering.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "SAML-federated SSO is supported for the IBM Cloud deployment path."
        },
        {
          "path": "governance.tracing",
          "value": true,
          "scope": "watsonx_orchestrate",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM watsonx Orchestrate – AI agent development and deployment",
              "url": "https://www.ibm.com/products/watsonx-orchestrate/developers",
              "note": "IBM documents real-time monitoring with OpenTelemetry traces and audit-ready dashboards.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "OpenTelemetry traces are documented for agent observability."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "watsonx_orchestrate_saas",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM Docs – Regional availability and outbound IP addresses",
              "url": "https://www.ibm.com/docs/en/watsonx/watson-orchestrate/base?topic=notes-regional-availability-outbound-ip-addresses",
              "note": "IBM documents watsonx Orchestrate as a managed SaaS offering on IBM Cloud and AWS regions.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "IBM offers watsonx Orchestrate as a managed SaaS service."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "watsonx_orchestrate_on_premises",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM Docs – Installing watsonx Orchestrate on-premises",
              "url": "https://www.ibm.com/docs/en/watsonx/watson-orchestrate/base?topic=notes-installing-watsonx-orchestrate-premises",
              "note": "IBM documents installation on IBM Software Hub or Cloud Pak for Data on customer infrastructure.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "watsonx Orchestrate supports customer-managed on-premises deployment."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "watsonx_orchestrate_saas",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM Docs – Regional availability and outbound IP addresses",
              "url": "https://www.ibm.com/docs/en/watsonx/watson-orchestrate/base?topic=notes-regional-availability-outbound-ip-addresses",
              "note": "IBM states the SaaS service is deployed across multiple global regions to support data residency, performance and compliance needs.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Regional watsonx Orchestrate SaaS deployments support data-residency requirements."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "watsonx_orchestrate_published_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM API Hub – Agent-to-Agent (A2A) Protocol",
              "url": "https://developer.ibm.com/apis/catalog/watsonorchestrate--custom-assistants/api/API--watsonorchestrate--agent-to-agent-a2a-protocol",
              "note": "IBM exposes A2A discovery and agent-specific interaction endpoints for watsonx Orchestrate agents.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Published watsonx Orchestrate agents expose authenticated A2A interaction endpoints."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "watsonx_orchestrate_control_plane",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM watsonx Orchestrate – AI agent development and deployment",
              "url": "https://www.ibm.com/products/watsonx-orchestrate/developers",
              "note": "IBM states that native, imported LangGraph, and external A2A agents can be governed in the same control plane.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "watsonx Orchestrate explicitly supports external A2A agents in its governed agent portfolio."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "watsonx_orchestrate_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "IBM Docs – Importing tools from an MCP server",
              "url": "https://www.ibm.com/docs/en/watsonx/watson-orchestrate/base?topic=servers-importing-from-mcp-server",
              "note": "IBM documents importing local or remote MCP server tools into watsonx Orchestrate agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "watsonx Orchestrate agents can consume MCP server tools."
        }
      ]
    },
    {
      "agent_id": "AI-0027",
      "claims": [
        {
          "path": "api.async",
          "value": true,
          "scope": "external_agent_invocation",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Fusion AI – Enable applications to access Fusion Applications agents",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/access-agents-beyond-fusion.html",
              "note": "Oracle documents external access to Fusion Applications agents through the /invokeAsync API.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "External applications can invoke agent teams asynchronously."
        },
        {
          "path": "api.auth.oauth",
          "value": true,
          "scope": "external_agent_invocation",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Fusion AI – Enable applications to access Fusion Applications agents",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/access-agents-beyond-fusion.html",
              "note": "Oracle requires OCI/Fusion IAM authentication with an OAuth 2.0 bearer token for /invokeAsync.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "OAuth 2.0 bearer-token authentication is documented for external agent invocation."
        },
        {
          "path": "api.rest",
          "value": true,
          "scope": "external_agent_invocation",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Fusion AI – Enable applications to access Fusion Applications agents",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/access-agents-beyond-fusion.html",
              "note": "Oracle documents the /invokeAsync API and points to Agent Team REST Endpoints for external agent invocation.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "External applications can invoke Fusion AI agent teams through documented REST endpoints."
        },
        {
          "path": "composition.tool",
          "value": "Document Tool",
          "confidence": "high",
          "scope": "oracle_ai_agent_studio",
          "verified_at": "2026-10-03",
          "note": "AI Agent Studio exposes Document as an explicit tool type that can be assigned to agents.",
          "evidence": [
            {
              "title": "Oracle AI Agent Studio – Add Document Tool",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26c/aiaas/add-document-tool.html",
              "evidence_type": "technical_docs",
              "source_section": "Add Document Tool"
            }
          ]
        },
        {
          "path": "deployment.import_export",
          "value": true,
          "scope": "agent_teams_between_instances",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Migrate AI Agents between instances",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/migrate-ai-agents-from-one-instance-to-another.html",
              "note": "Agent teams can be exported and imported between Oracle environments and then republished.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Cross-instance import/export is documented."
        },
        {
          "path": "governance.approval.pre_action",
          "value": true,
          "confidence": "high",
          "scope": "document_tool_actions",
          "verified_at": "2026-10-03",
          "note": "Document Tool can require a person to review and approve an action before the tool runs.",
          "evidence": [
            {
              "title": "Oracle AI Agent Studio – Add Document Tool",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26c/aiaas/add-document-tool.html",
              "evidence_type": "technical_docs",
              "source_section": "Require Human Approval"
            }
          ]
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "fusion_security_console",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Access Requirements for AI Agent Studio",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/access-ai-agent-studio.html",
              "note": "Oracle instructs admins to create or edit custom roles for AI Agent Studio privileges.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Custom roles are supported."
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "scope": "agent_actions_and_workflows",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Get Started with AI Agent Studio",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/get-started.html",
              "note": "Oracle documents adding a human-in-the-loop approval step for selected agent actions.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Human approval steps can be added for oversight of agent actions."
        },
        {
          "path": "governance.monitoring_access_control",
          "value": true,
          "scope": "monitoring_and_evaluation",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Access Requirements for AI Agent Studio",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/access-ai-agent-studio.html",
              "note": "Viewing monitored agent records requires an additional permission group.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Monitoring records are access-controlled."
        },
        {
          "path": "governance.observability",
          "value": true,
          "scope": "monitoring_and_evaluation",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Monitor Agents",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/monitor-agents.html",
              "note": "Oracle documents aggregated metrics and per-session monitoring for all AI Agent Studio agent runs, including draft agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "AI Agent Studio includes run-level monitoring and metrics."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "fusion_roles",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Access Requirements for AI Agent Studio",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/access-ai-agent-studio.html",
              "note": "AI Agent Studio access is granted through predefined duty roles assigned to job roles.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Role-based access is documented."
        },
        {
          "path": "governance.tracing",
          "value": true,
          "scope": "monitoring_and_evaluation",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Monitor Agents",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/monitor-agents.html",
              "note": "Oracle's detailed trace view shows the step-by-step conversation, tool calls, duration, and metrics for each step.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Detailed per-session tracing is documented."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "oracle_fusion_ai_platform_for_ai_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Oracle AI Platform for Fusion Applications",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/aiaqa/what-is-the-oracle-fusion-ai-platform.html",
              "note": "Oracle documents a securely partitioned Oracle-managed AI platform instance for each organization in its local OCI region.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Oracle Docs – AI Agent Studio adoption principles",
              "url": "https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/epmce/adoption_principles.html",
              "note": "Oracle states AI Agent Studio is a native component of Oracle Fusion Cloud Applications and operates within the same security framework and data model.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "AI Agent Studio runs as a native capability of Oracle Fusion Cloud Applications on the Oracle AI Platform for Fusion Applications."
        },
        {
          "path": "operations.max_files_per_conversation",
          "value": 5,
          "confidence": "high",
          "scope": "chat_file_upload",
          "verified_at": "2026-10-03",
          "note": "Oracle documents a maximum of five files uploaded per chat conversation.",
          "evidence": [
            {
              "title": "Oracle AI Agent Studio – File types and limits",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26c/aiaas/what-file-types-limits-and-processing-capabilities-are-supported-in-ai-agent-studio.html",
              "evidence_type": "technical_docs",
              "source_section": "Recommended patterns"
            }
          ]
        },
        {
          "path": "operations.max_interactions_configurable",
          "value": true,
          "confidence": "high",
          "scope": "agent_configuration",
          "verified_at": "2026-10-03",
          "note": "Agent Settings expose a Maximum Interactions field controlling how many times an agent can interact with assigned topics and tools.",
          "evidence": [
            {
              "title": "Oracle AI Agent Studio – Create and Configure AI Agents",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26c/aiaas/create-and-configure-ai-agents.html",
              "evidence_type": "technical_docs",
              "source_section": "Agent Settings"
            }
          ]
        },
        {
          "path": "operations.max_upload_mb_per_conversation",
          "value": 50,
          "confidence": "high",
          "scope": "chat_file_upload",
          "verified_at": "2026-10-03",
          "note": "Oracle documents a combined 50 MB upload limit across files in one chat conversation.",
          "evidence": [
            {
              "title": "Oracle AI Agent Studio – File types and limits",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26c/aiaas/what-file-types-limits-and-processing-capabilities-are-supported-in-ai-agent-studio.html",
              "evidence_type": "technical_docs",
              "source_section": "Recommended patterns"
            }
          ]
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "fusion_ai_platform_instance_local_oci_region_at_rest",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Oracle AI Platform for Fusion Applications",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/aiaqa/what-is-the-oracle-fusion-ai-platform.html",
              "note": "Oracle states each organization receives a securely partitioned platform instance within its local OCI region; model input/output processing may occur in a secure OCI environment outside that local region.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "The Fusion AI platform instance is region-local. This claim does not assert that generative-model processing always remains in the local OCI region."
        },
        {
          "path": "protocols.a2a.client",
          "value": true,
          "scope": "fusion_ai_agent_studio_26c",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Collaborate across platforms using A2A",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26c/aiaas/collaborate-with-ai-agents-across-platforms-using-agent2agent-a2a-protocol.html",
              "note": "Oracle's example states that an Oracle AI agent can reach out to a third-party agent using A2A.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Fusion Applications agents can call external A2A agents."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "fusion_ai_agent_studio_26c",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Collaborate across platforms using A2A",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26c/aiaas/collaborate-with-ai-agents-across-platforms-using-agent2agent-a2a-protocol.html",
              "note": "Oracle documents third-party platforms calling Fusion Applications agents through authenticated A2A endpoints and Agent Cards.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Published Fusion Applications agents can be invoked by external A2A clients."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "fusion_ai_agent_studio_26c",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Collaborate across platforms using A2A",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26c/aiaas/collaborate-with-ai-agents-across-platforms-using-agent2agent-a2a-protocol.html",
              "note": "Oracle documents A2A as the standard mechanism for cross-platform collaboration between Fusion Applications agents and external agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Oracle AI Agent Studio supports A2A cross-platform agent interoperability."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "ai_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Add MCP Tool",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/add-mcp-tool.html",
              "note": "Oracle documents adding an MCP tool that connects AI Agent Studio agents and nodes to external MCP servers.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "AI Agent Studio can consume external MCP servers."
        },
        {
          "path": "protocols.mcp.remote",
          "value": true,
          "scope": "ai_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Add MCP Tool",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/add-mcp-tool.html",
              "note": "Oracle requires an external MCP server endpoint URL when configuring an MCP tool.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Remote MCP server connections are supported."
        },
        {
          "path": "protocols.mcp.transport.sse",
          "value": true,
          "scope": "mcp_tools",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Add MCP Tool",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/add-mcp-tool.html",
              "note": "Oracle lists Server Sent Events (SSE) as an MCP transport type.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "SSE is a documented MCP transport option."
        },
        {
          "path": "protocols.mcp.transport.streamable_http",
          "value": true,
          "scope": "mcp_tools",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Add MCP Tool",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/add-mcp-tool.html",
              "note": "Oracle lists StreamableHTTP as an MCP transport type.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Streamable HTTP is a documented MCP transport option."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "Oracle Transparent Data Encryption (TDE)",
          "scope": "oracle_fusion_applications_data_layer_used_by_ai_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – AI Agent Studio adoption principles",
              "url": "https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/epmce/adoption_principles.html",
              "note": "Oracle states AI Agent Studio is native to Fusion Cloud Applications and uses the same security framework and data model.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Oracle Docs – Advanced Data Security",
              "url": "https://docs.oracle.com/en/cloud/saas/applications-common/25c/facsa/advanced-data-security.html",
              "note": "Oracle documents Transparent Data Encryption for Fusion Applications data at rest, including database files, backups, temporary files, redo and undo data.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "AI Agent Studio's native Fusion Applications data layer is protected by Oracle TDE at rest."
        },
        {
          "path": "tools.external_rest",
          "value": true,
          "scope": "ai_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Oracle Docs – Access Requirements for AI Agent Studio",
              "url": "https://docs.oracle.com/en/cloud/saas/fusion-ai/26b/aiaas/access-ai-agent-studio.html",
              "note": "Oracle documents a privilege specifically for creating External REST API tools.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "External REST tools are supported."
        }
      ]
    },
    {
      "agent_id": "AI-0028",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "automation_cloud_audit",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Automation Cloud – Audit Logs API",
              "url": "https://docs.uipath.com/automation-cloud/automation-cloud/latest/api-guide/audit-logs",
              "note": "UiPath provides organization- and tenant-level APIs to list and download audit events.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Automation Cloud exposes audit logs through documented APIs."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "uipath_agent_activity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Docs – MCP servers compliance",
              "url": "https://docs.uipath.com/agents/automation-cloud/latest/user-guide/mcp-servers-compliance",
              "note": "UiPath states that agent activities, including tool usage and data passed to tools, are logged within the platform.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Agent activities have documented platform logging and audit support."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 60,
          "scope": "ai_trust_layer_agent_operations",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Automation Cloud – Viewing AI Trust Layer audit logs",
              "url": "https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/viewing-audit-logs",
              "note": "UiPath states AI Trust Layer audit entries are viewable for the last 60 days and include Agents inputs and outputs.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "The documented AI Trust Layer log window for agent operations is 60 days."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "uipath_agents_and_mcp_integrations",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Docs – MCP servers compliance",
              "url": "https://docs.uipath.com/agents/automation-cloud/latest/user-guide/mcp-servers-compliance",
              "note": "UiPath explicitly directs administrators to use Orchestrator RBAC and least-privilege roles for agent/MCP integrations.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "RBAC is documented for controlling agent integration access."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "uipath_automation_cloud_org_access",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Automation Cloud – Configuring SCIM User Sync with Microsoft Entra ID",
              "url": "https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/configuring-scim-with-microsoft-entra-id",
              "note": "UiPath documents SCIM user synchronization/provisioning for Automation Cloud organizations.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Automation Cloud organization identities used to access Agents can be provisioned with SCIM."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "uipath_automation_cloud_org_access",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Automation Cloud – Configuring the SAML integration",
              "url": "https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/configuring-the-saml-integration",
              "note": "UiPath documents SAML 2.0 SSO for Automation Cloud organizations; the feature is available with Enterprise licensing.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "UiPath Agents running in Automation Cloud inherit organization SAML SSO access controls."
        },
        {
          "path": "governance.tracing",
          "value": true,
          "scope": "uipath_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Docs – Agent traces",
              "url": "https://docs.uipath.com/agents/automation-cloud/latest/user-guide/agent-traces",
              "note": "UiPath documents complete agent-run traces covering steps, decisions, inputs/outputs, errors, and metadata.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agent traces provide detailed run-level observability and auditability."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "uipath_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Docs – MCP Servers",
              "url": "https://docs.uipath.com/agents/automation-cloud/latest/user-guide/mcp-servers",
              "note": "UiPath documents adding UiPath-hosted and external MCP servers as tools in Agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "UiPath Agents can consume MCP servers as tools."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "agent_traces_opt_in",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Docs – Agent traces",
              "url": "https://docs.uipath.com/agents/automation-cloud/latest/user-guide/agent-traces",
              "note": "UiPath documents optional Customer-Managed Key encryption for Agent trace data.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "CMK encryption is available for Agent trace data as an opt-in feature."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "uipath_agents_traces_and_ai_trust_layer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Automation Cloud – Encryption",
              "url": "https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/encryption",
              "note": "UiPath's encryption matrix explicitly lists Agents traces with AES-256 TDE at rest.",
              "evidence_type": "security_trust"
            },
            {
              "title": "UiPath Automation Cloud – About AI Trust Layer",
              "url": "https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/about-ai-trust-layer",
              "note": "UiPath states data flowing through AI Trust Layer is encrypted with AES-256 at rest.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "UiPath explicitly documents AES-256 at-rest encryption for Agents trace data and AI Trust Layer data flows."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "uipath_agents_traces_and_ai_trust_layer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "UiPath Automation Cloud – Encryption",
              "url": "https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/encryption",
              "note": "UiPath's encryption matrix explicitly lists Agents traces with TLS 1.2 or higher in transit.",
              "evidence_type": "security_trust"
            },
            {
              "title": "UiPath Automation Cloud – About AI Trust Layer",
              "url": "https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/about-ai-trust-layer",
              "note": "UiPath states all data flowing through AI Trust Layer uses TLS 1.2 or higher in transit.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "UiPath explicitly documents TLS 1.2+ for Agents trace and AI Trust Layer traffic."
        }
      ]
    },
    {
      "agent_id": "AI-0029",
      "claims": [
        {
          "path": "api.auth.oauth",
          "value": true,
          "scope": "agent_api_external_client_app",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Developers – Get Started with the Agent API",
              "url": "https://developer.salesforce.com/docs/ai/agentforce/guide/agent-api-get-started.html",
              "note": "Salesforce requires an external client app supporting the client-credentials flow for Agent API access.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Agent API access uses an OAuth client-credentials application flow."
        },
        {
          "path": "api.rest",
          "value": true,
          "scope": "supported_agent_types",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Developers – Get Started with the Agent API",
              "url": "https://developer.salesforce.com/docs/ai/agentforce/guide/agent-api-get-started.html",
              "note": "Salesforce documents direct communication with supported Agentforce agents through the REST Agent API; Agentforce (Default) agents are explicitly excluded.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "A REST Agent API is available for supported Agentforce agent types."
        },
        {
          "path": "governance.approval.pre_action",
          "value": true,
          "confidence": "high",
          "scope": "record_changing_custom_actions",
          "verified_at": "2026-10-03",
          "note": "When enabled, the agent must ask the user to confirm a record-changing action before it executes.",
          "evidence": [
            {
              "title": "Salesforce Help – Create a Custom Action",
              "url": "https://help.salesforce.com/s/articleView?id=ai.agent_actions_custom.htm&language=en_US&type=5",
              "evidence_type": "technical_docs",
              "source_section": "Require user confirmation"
            }
          ]
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "agent_actions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Agent context vs user context in Agentforce",
              "url": "https://help.salesforce.com/s/articleView?id=005314096&language=en&type=1",
              "note": "Salesforce states that actions are attributed in the audit trail to the agent or specific user depending on execution context.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agent action attribution is documented."
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "confidence": "high",
          "scope": "record_changing_custom_actions",
          "verified_at": "2026-10-03",
          "note": "Custom Agent Actions can require user confirmation for record-changing actions.",
          "evidence": [
            {
              "title": "Salesforce Help – Create a Custom Action",
              "url": "https://help.salesforce.com/s/articleView?id=ai.agent_actions_custom.htm&language=en_US&type=5",
              "evidence_type": "technical_docs",
              "source_section": "Require user confirmation"
            }
          ]
        },
        {
          "path": "governance.permission_sets",
          "value": true,
          "scope": "external_service_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Agent context vs user context in Agentforce",
              "url": "https://help.salesforce.com/s/articleView?id=005314096&language=en&type=1",
              "note": "Agent-context execution requires explicit permission grants through permission sets.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Permission-set control is documented."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "agentforce_salesforce_org_access",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Agentforce Security and the Shared Responsibility Model",
              "url": "https://help.salesforce.com/s/articleView?id=005315874&language=en_US&type=1",
              "note": "Salesforce states Agentforce administrators configure access through Profiles, Permission Sets, field-level security and least-privilege controls.",
              "evidence_type": "security_trust"
            },
            {
              "title": "Salesforce Help – Trust and Agentforce",
              "url": "https://help.salesforce.com/s/articleView?id=sf.copilot_trust.htm&language=en_US&type=5",
              "note": "Salesforce states Agentforce agents respect standard Salesforce access controls.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Agentforce access and agent capabilities are governed by Salesforce role/permission controls."
        },
        {
          "path": "governance.tracing",
          "value": true,
          "scope": "agent_platform_tracing",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce GitHub – Agent Platform Tracing",
              "url": "https://github.com/salesforce/sf-pi/blob/main/extensions/sf-data360/references/agent-platform-tracing.md",
              "note": "Salesforce's official repository documents Agent Platform Tracing as backend execution traces represented as OpenTelemetry-style spans in Data Cloud.",
              "evidence_type": "official_github"
            }
          ],
          "note": "Agentforce execution tracing is documented through Agent Platform Tracing."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "agentforce_on_hyperforce",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce – What is Hyperforce?",
              "url": "https://www.salesforce.com/platform/what-is-hyperforce/",
              "note": "Salesforce describes Hyperforce as the cloud-native infrastructure that runs Agentforce and Customer 360 on trusted public-cloud infrastructure.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Agentforce is offered on Salesforce-managed Hyperforce cloud infrastructure."
        },
        {
          "path": "identity.agent_user",
          "value": true,
          "scope": "external_service_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Agent context vs user context in Agentforce",
              "url": "https://help.salesforce.com/s/articleView?id=005314096&language=en&type=1",
              "note": "External Service Agents run as a system user/agent user.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agent-user execution identity is documented."
        },
        {
          "path": "memory.session_state",
          "value": true,
          "confidence": "high",
          "scope": "agent_script",
          "verified_at": "2026-10-03",
          "note": "Agent Script variables retain state across conversation turns and are accessible to subagents in the agent.",
          "evidence": [
            {
              "title": "Salesforce Developers – Agent Script Variables",
              "url": "https://developer.salesforce.com/docs/ai/agentforce/guide/ascript-ref-variables.html",
              "evidence_type": "technical_docs",
              "source_section": "Variables"
            }
          ]
        },
        {
          "path": "operations.execution_timeout_seconds",
          "value": 120,
          "confidence": "high",
          "scope": "agent_api",
          "verified_at": "2026-10-03",
          "note": "Salesforce documents a 120-second timeout for Agent API calls.",
          "evidence": [
            {
              "title": "Salesforce Developers – Agent API Considerations",
              "url": "https://developer.salesforce.com/docs/ai/agentforce/guide/agent-api-considerations.html",
              "evidence_type": "api_docs",
              "source_section": "Agent API Considerations"
            }
          ]
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "agentforce_on_hyperforce_supported_regions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce – Agentforce 360 Platform global infrastructure",
              "url": "https://www.salesforce.com/platform/infrastructure/",
              "note": "Salesforce documents Hyperforce data residency and regional storage/processing controls for the platform powering Agentforce.",
              "evidence_type": "official_product_page"
            },
            {
              "title": "Salesforce – Agentforce local data residency on Hyperforce",
              "url": "https://www.salesforce.com/ap/news/press-releases/2025/07/16/salesforce-brings-local-data-residency-for-agentforce-to-indonesia/",
              "note": "Salesforce explicitly documents local data residency for Agentforce on Hyperforce.",
              "evidence_type": "official_release"
            }
          ],
          "note": "Agentforce can use Hyperforce regional data-residency capabilities where available."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "hyperforce_supported_regions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce – Agentforce 360 Platform global infrastructure",
              "url": "https://www.salesforce.com/platform/infrastructure/",
              "note": "Salesforce states customers can choose the geographic region where Salesforce customer data is stored and processed.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Hyperforce provides customer choice of supported geographic regions."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "agentforce_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – MCP for Agentforce",
              "url": "https://help.salesforce.com/s/articleView?id=ai.agent_mcp.htm&language=en_US&type=5",
              "note": "Agentforce can register and use third-party MCP tools.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agentforce can act as an MCP client."
        },
        {
          "path": "protocols.mcp.registry",
          "value": true,
          "scope": "agentforce_registry",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Register an MCP Server in Agentforce Registry",
              "url": "https://help.salesforce.com/s/articleView?id=ai.agent_mcp_connect_register.htm&language=en_US&type=5",
              "note": "Salesforce documents registering Salesforce-hosted and external MCP servers in Agentforce Registry and allowlisting tools.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agentforce provides an MCP server registry and governed tool allowlisting."
        },
        {
          "path": "protocols.mcp.remote",
          "value": true,
          "scope": "externally_hosted_servers",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – MCP for Agentforce",
              "url": "https://help.salesforce.com/s/articleView?id=ai.agent_mcp.htm&language=en_US&type=5",
              "note": "MCP for Agentforce connects to third-party server tools across systems.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Remote MCP integrations are documented."
        },
        {
          "path": "sdk.python",
          "value": true,
          "scope": "agentforce_development",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce GitHub – Agentforce SDK",
              "url": "https://github.com/salesforce/agent-sdk",
              "note": "Salesforce's official Agentforce SDK repository documents the Python SDK for creating, managing, testing, and deploying agents.",
              "evidence_type": "official_github"
            }
          ],
          "note": "A first-party Agentforce Python SDK is documented in Salesforce's official repository."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "agentforce_customer_data_on_hyperforce",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce – What is Hyperforce?",
              "url": "https://www.salesforce.com/platform/what-is-hyperforce/",
              "note": "Salesforce explicitly states Hyperforce, which runs Agentforce, includes encryption at rest.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Customer data supporting Agentforce on Hyperforce is covered by Hyperforce encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "agentforce_customer_data_on_hyperforce",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce – What is Hyperforce?",
              "url": "https://www.salesforce.com/platform/what-is-hyperforce/",
              "note": "Salesforce explicitly states Hyperforce, which runs Agentforce, includes encryption in transit.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Customer data supporting Agentforce on Hyperforce is covered by Hyperforce encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "einstein_platform_and_agentforce_on_hyperforce",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Compliance – SOC 2 Report: Einstein Platform and Agentforce on Hyperforce",
              "url": "https://compliance.salesforce.com/en/documents/a006e0000115nJkAAI",
              "note": "Salesforce publishes a current SOC 2 report specifically covering Einstein Platform and Agentforce on Hyperforce.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Salesforce publishes SOC 2 coverage specifically for Agentforce on Hyperforce."
        }
      ]
    },
    {
      "agent_id": "AI-0030",
      "claims": [
        {
          "path": "api.async",
          "value": true,
          "scope": "joule_studio_code_editor_sample",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Samples – BTP Agentic AI Use Cases",
              "url": "https://github.com/SAP-samples/btp-agentic-ai-use-cases",
              "note": "SAP's official samples include asynchronous API integration with a code-based agent.",
              "evidence_type": "official_github"
            }
          ],
          "note": "Async API integration is demonstrated."
        },
        {
          "path": "deployment.low_code",
          "value": true,
          "scope": "joule_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Samples – BTP Agentic AI Use Cases",
              "url": "https://github.com/SAP-samples/btp-agentic-ai-use-cases",
              "note": "The official SAP samples describe Joule Studio Agent Builder and Code Editor low-code approaches.",
              "evidence_type": "official_github"
            }
          ],
          "note": "Low-code agent building is documented."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "joule_studio_classic",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – Implementing Functions / Audit Logging",
              "url": "https://help.sap.com/docs/joule-studio-classic/joule-studio-classic-edition/implementing-functions?q=joule+studio",
              "note": "SAP documents audit logging for Joule Studio, including configuration-change events.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Joule Studio documents audit logging for product-specific events."
        },
        {
          "path": "governance.mcp.control_tower_registration",
          "value": true,
          "scope": "joule_studio_classic",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – Add MCP Servers to Your Joule Agent",
              "url": "https://help.sap.com/docs/Joule_Studio/45f9d2b8914b4f0ba731570ff9a85313/3d9dfad0bc39468292d508f0808a12fe.html",
              "note": "SAP requires MCP destinations to be created in BTP Cockpit and registered in the control tower before use by a Joule agent.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "MCP destinations are governed through control-tower registration."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "joule_studio_classic",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – Assign Users to Roles",
              "url": "https://help.sap.com/docs/joule-studio-classic/joule-studio-classic-edition/assign-users-to-roles",
              "note": "SAP documents Joule Studio access through SAP BTP role collections, user groups, and permissions.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Joule Studio access is controlled through assigned roles and role collections."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "joule_btp_trust_configuration",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – Constraints for Joule",
              "url": "https://help.sap.com/docs/joule/integrating-joule-with-sap/constraints-for-joule?locale=en-US&state=PRODUCTION&version=CLOUD",
              "note": "SAP states Joule requires an OpenID Connect trust configuration with the SAP Identity Authentication tenant.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "OIDC trust with SAP Identity Authentication is required for Joule."
        },
        {
          "path": "governance.sso.saml",
          "value": false,
          "scope": "joule_btp_trust_configuration",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – Constraints for Joule",
              "url": "https://help.sap.com/docs/joule/integrating-joule-with-sap/constraints-for-joule?locale=en-US&state=PRODUCTION&version=CLOUD",
              "note": "SAP explicitly states that a SAML-based trust relationship is not supported for Joule; the required trust type is OIDC.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Explicit negative: SAP documents that SAML-based trust is not supported for the Joule BTP trust configuration."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "sap_joule_btp_cloud_foundry",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – What Is Joule?",
              "url": "https://help.sap.com/docs/joule/serviceguide/guidelines-for-capability-development",
              "note": "SAP documents Joule as a multi-tenant service running in SAP BTP Cloud Foundry.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "SAP operates Joule as a managed multi-tenant service on SAP BTP Cloud Foundry."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "sap_joule_supported_data_centers",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – Data Centers Supported by Joule",
              "url": "https://help.sap.com/docs/joule/serviceguide/data-centers-supported-by-joule",
              "note": "SAP lists Joule data centers and associated subprocessor regions across multiple geographies and discusses data-security and legal-compliance considerations when selecting a data center.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Joule is available in region-specific data centers with documented subprocessor regions."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "sap_joule_cross_consumption_data_center_selection",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – Data Centers Supported by Joule",
              "url": "https://help.sap.com/docs/joule/serviceguide/data-centers-supported-by-joule",
              "note": "SAP explicitly discusses customers choosing a Joule data center based on region, legal restrictions, hyperscaler preference and proximity to business applications.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Customers can select a supported Joule data center when provisioning/cross-consuming Joule, subject to availability and product constraints."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "joule_studio_and_code_editor",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Samples – BTP Agentic AI Use Cases",
              "url": "https://github.com/SAP-samples/btp-agentic-ai-use-cases",
              "note": "SAP's official samples include Joule integration with a code-based agent through A2A.",
              "evidence_type": "official_github"
            }
          ],
          "note": "A2A integration is demonstrated by SAP."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "joule_studio_agent_builder",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Samples – Joule Studio MCP agent configuration",
              "url": "https://github.com/SAP-samples/btp-agentic-ai-use-cases/blob/main/10-escalation-assistant-joule-studio/agent-builder/WEB_SEARCHER.md",
              "note": "SAP's official sample shows a Joule Studio Agent Builder configuration using Tavily and Exa MCP server tools.",
              "evidence_type": "official_github"
            }
          ],
          "note": "SAP's official Joule Studio sample demonstrates MCP server tools used by a Joule agent."
        },
        {
          "path": "protocols.mcp.remote",
          "value": true,
          "scope": "joule_studio_classic",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – Add MCP Servers to Your Joule Agent",
              "url": "https://help.sap.com/docs/Joule_Studio/45f9d2b8914b4f0ba731570ff9a85313/3d9dfad0bc39468292d508f0808a12fe.html",
              "note": "SAP documents adding MCP servers to Joule agents to connect them with external applications.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Joule Studio classic supports remote MCP server connections."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS",
          "scope": "joule_user_access_on_sap_btp",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "SAP Help – What Is Joule?",
              "url": "https://help.sap.com/docs/joule/serviceguide/guidelines-for-capability-development",
              "note": "SAP documents Joule as running on SAP BTP Cloud Foundry.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "SAP BTP Administrator's Guide – Security Concepts",
              "url": "https://help.sap.com/docs/btp/btp-admin-guide/security-concepts?version=Cloud",
              "note": "SAP states all user access to SAP BTP is protected with transport layer security (TLS).",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Joule runs on SAP BTP Cloud Foundry, where SAP documents TLS protection for all user access."
        }
      ]
    },
    {
      "agent_id": "AI-0031",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "rovo_organization_audit_events",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian Support – Audit log activities",
              "url": "https://support.atlassian.com/security-and-access-policies/docs/accessing-audit-log-activities/",
              "note": "Atlassian lists Rovo admin and user activity in organization audit logs.",
              "evidence_type": "security_trust"
            },
            {
              "title": "Atlassian Developer – Organizations REST API events",
              "url": "https://developer.atlassian.com/cloud/admin/organization/rest/api-group-events/",
              "note": "The Organizations REST API exposes paginated audit-log events through the events-stream endpoint.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Rovo audit activity is available through Atlassian organization audit-log APIs."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "rovo_admin_and_user_actions",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Atlassian Support – Audit log activities",
              "url": "https://support.atlassian.com/security-and-access-policies/docs/accessing-audit-log-activities/",
              "note": "Atlassian documents Rovo admin and user actions among organization audit-log activities, including agent creation, updates, deletion, chat starts, and connector changes.",
              "evidence_type": "security_trust",
              "source_section": "Rovo audit activities"
            }
          ],
          "note": "Rovo admin and user actions are recorded in Atlassian organization audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "rovo_agent_creation_editing_and_usage",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian Support – Rovo agent permissions and governance",
              "url": "https://support.atlassian.com/rovo/docs/rovo-agent-permissions-and-governance/",
              "note": "Atlassian documents Studio admin controls plus owner, editor and manager roles with distinct permissions for Rovo agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Rovo agent administration and editing use explicit role-based permissions."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "atlassian_org_users_accessing_rovo",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian Support – Understand user provisioning",
              "url": "https://support.atlassian.com/provisioning-users/docs/understand-user-provisioning/",
              "note": "Atlassian documents SCIM 2.0 provisioning for managed accounts and groups in Atlassian organizations.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Atlassian – AI Trust",
              "url": "https://www.atlassian.com/trust/ai",
              "note": "Atlassian states Rovo inherits security practices from the Atlassian Cloud Platform.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Rovo access can be governed through Atlassian organization SCIM provisioning."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "atlassian_org_users_accessing_rovo",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian Support – Configure SAML single sign-on",
              "url": "https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-sign-on-with-an-identity-provider",
              "note": "Atlassian documents SAML SSO for users logging in to Atlassian Cloud apps.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Atlassian – AI Trust",
              "url": "https://www.atlassian.com/trust/ai",
              "note": "Atlassian states Rovo inherits security practices from the Atlassian Cloud Platform.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Rovo user access inherits Atlassian organization SAML SSO controls."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "rovo_in_scope_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian Support – Understand data residency",
              "url": "https://support.atlassian.com/security-and-access-policies/docs/understand-data-residency/",
              "note": "Atlassian documents data-residency controls for Rovo and pinning of in-scope Rovo data.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Rovo supports data residency for in-scope data."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "rovo_in_scope_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Atlassian Support – Understand data residency",
              "url": "https://support.atlassian.com/security-and-access-policies/docs/understand-data-residency/",
              "note": "Atlassian documents data-residency controls for Rovo and pinning in-scope Rovo data to supported geographic locations.",
              "evidence_type": "security_trust",
              "source_section": "Data residency for Rovo"
            }
          ],
          "note": "Organizations can pin in-scope Rovo data to supported geographic regions through Atlassian data-residency controls."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "rovo_out_of_box_third_party_mcp_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian Support – Out-of-the-box third-party MCP agents",
              "url": "https://support.atlassian.com/rovo/docs/out-of-the-box-third-party-mcp-agents/",
              "note": "Atlassian documents Rovo agents using vendor-provided MCP servers for tool invocation, with admins enabling each server in Rovo Admin Hub.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Rovo can consume external MCP servers for agent tool invocation."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "rovo_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian – Security Practices",
              "url": "https://www.atlassian.com/trust/security/security-practices",
              "note": "Atlassian explicitly includes Rovo among cloud products whose customer-data drives use AES-256 encryption at rest.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Rovo customer data is covered by Atlassian's AES-256 encryption-at-rest control."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "rovo_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian – Security Practices",
              "url": "https://www.atlassian.com/trust/security/security-practices",
              "note": "Atlassian requires TLS 1.2 or higher for customer data in transit across Atlassian cloud products.",
              "evidence_type": "security_trust"
            },
            {
              "title": "Atlassian – AI Trust",
              "url": "https://www.atlassian.com/trust/ai",
              "note": "Atlassian states Rovo inherits Atlassian Cloud Platform security practices.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Rovo inherits Atlassian Cloud TLS 1.2+ transport encryption."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "rovo_and_atlassian_ai",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Atlassian Support – Rovo data, privacy, and usage guidelines",
              "url": "https://support.atlassian.com/rovo/docs/rovo-data-privacy-and-usage-guidelines/",
              "note": "Atlassian states Rovo and AI have completed external SOC 2 and ISO 27001 assessments/certifications.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Atlassian documents completed SOC 2 assessment for Rovo and AI."
        }
      ]
    },
    {
      "agent_id": "AI-0032",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "glean_agents_platform_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – API Tokens",
              "url": "https://docs.glean.com/administration/developer/api-tokens",
              "note": "Glean documents REST API tokens for the Client API, including agents and other user-facing functionality.",
              "evidence_type": "api_docs",
              "source_section": "API Tokens"
            },
            {
              "title": "Glean Developer Platform",
              "url": "https://developers.glean.com/",
              "note": "Glean documents Agents as a generally available Platform API capability.",
              "evidence_type": "api_docs",
              "source_section": "Glean Platform APIs / Agents"
            }
          ],
          "note": "Glean exposes programmatic REST/Platform API access for agent functionality."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "glean_platform_including_agent_governance",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Audit Logs",
              "url": "https://docs.glean.com/administration/management/audit-logs/admin-audit-logs",
              "note": "Glean documents administrative audit logs and export/reporting in the Admin Console.",
              "evidence_type": "technical_docs",
              "source_section": "Access Audit Logs / Export and Reporting"
            }
          ],
          "note": "Glean provides administrative audit logs for platform governance."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 30,
          "scope": "glean_admin_audit_logs_default",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Audit Logs",
              "url": "https://docs.glean.com/administration/management/audit-logs/admin-audit-logs",
              "note": "Glean states the default audit-log retention period is 30 days, with custom longer retention available by request.",
              "evidence_type": "technical_docs",
              "source_section": "Audit Log Retention"
            }
          ],
          "note": "Glean's documented default audit-log retention is 30 days."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "glean_customer_hosted_aws",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Log monitoring for AWS environments",
              "url": "https://docs.glean.com/security/cloud-prem/aws/log-monitoring",
              "note": "Glean documents an audit-log CloudWatch log group and explicitly instructs customers to integrate it with their SIEM.",
              "evidence_type": "security_trust",
              "source_section": "Audit log"
            }
          ],
          "note": "Customer-hosted AWS deployments can export Glean audit logs to SIEM tooling."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "glean_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Manage agent access",
              "url": "https://docs.glean.com/administration/managing-agents/agent-access",
              "note": "Glean documents agent-specific roles, access tiers, publishing permissions, and RBAC-controlled administration.",
              "evidence_type": "technical_docs",
              "source_section": "Agent access tiers / Agent roles"
            }
          ],
          "note": "Glean Agents have explicit role-based access and publishing controls."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "glean_identity_provisioning",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Okta (SAML)",
              "url": "https://docs.glean.com/administration/identity/sso/configuration/okta-saml",
              "note": "Glean documents SCIM 2.0 provisioning and deprovisioning for users.",
              "evidence_type": "technical_docs",
              "source_section": "Optional SCIM provisioning"
            }
          ],
          "note": "Glean supports SCIM 2.0 user provisioning/deprovisioning."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "glean_platform_users_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Entra ID (OIDC)",
              "url": "https://docs.glean.com/administration/identity/sso/configuration/entra-id-oidc",
              "note": "Glean documents OpenID Connect SSO using Microsoft Entra ID and states OIDC is a supported/preferred SSO method.",
              "evidence_type": "technical_docs",
              "source_section": "Entra ID (OIDC)"
            }
          ],
          "note": "Glean supports OIDC SSO for platform access."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "glean_platform_users_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – About OIDC and SAML",
              "url": "https://docs.glean.com/administration/identity/sso/oidc-saml",
              "note": "Glean documents SAML as a supported SSO protocol.",
              "evidence_type": "technical_docs",
              "source_section": "About OIDC and SAML"
            }
          ],
          "note": "Glean supports SAML SSO for platform access."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "glean_platform_including_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Glean Deployment Models",
              "url": "https://docs.glean.com/get-started/build/about-self-hosted",
              "note": "Glean documents a Glean Hosted deployment model equivalent to a SaaS service with no customer infrastructure responsibility.",
              "evidence_type": "technical_docs",
              "source_section": "Glean Hosted"
            }
          ],
          "note": "Glean Agents can run on Glean's managed SaaS deployment."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "glean_customer_managed_deployment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean – AWARE and customer-managed deployment",
              "url": "https://www.glean.com/blog/agentic-security-aware",
              "note": "Glean documents customer-managed deployment with private connectivity where requests, responses, and logs can remain on the customer's private network.",
              "evidence_type": "official_release",
              "source_section": "Customer-managed deployment"
            }
          ],
          "note": "Glean supports private-network/VPC deployment for customer-managed environments."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "glean_platform_including_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Customer-hosted deployment",
              "url": "https://docs.glean.com/security/cloud-prem",
              "note": "Glean documents customer-hosted deployment in the customer's own GCP or AWS account.",
              "evidence_type": "technical_docs",
              "source_section": "Customer-hosted deployment"
            }
          ],
          "note": "Glean supports customer-hosted deployment of the platform that provides Glean Agents."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "glean_platform_including_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Glean Deployment Models",
              "url": "https://docs.glean.com/get-started/build/about-self-hosted",
              "note": "Glean documents deployment choices for organizations with strict data residency requirements and notes alternative geographic regions for SaaS.",
              "evidence_type": "technical_docs",
              "source_section": "When should you choose this?"
            }
          ],
          "note": "Glean provides deployment options intended to satisfy data-residency requirements."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "glean_tenant_deployment",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Supported GCP Regions",
              "url": "https://docs.glean.com/get-started/build/gcp/supported-gcp-regions",
              "note": "Glean lists supported tenant deployment regions and instructs customers to advise Glean when they want a tenant deployed in a different region.",
              "evidence_type": "technical_docs",
              "source_section": "Considerations for Region Selection"
            }
          ],
          "note": "Customers can select among supported deployment regions for their Glean tenant."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "glean_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Connect remote MCP servers to Glean",
              "url": "https://docs.glean.com/administration/actions/connect-remote-mcp-servers-to-glean",
              "note": "Glean documents itself as an MCP host that connects to remote MCP-compliant servers and exposes those tools to Assistant and Glean Agents.",
              "evidence_type": "technical_docs",
              "source_section": "Connect remote MCP servers / Security and hosting considerations"
            }
          ],
          "note": "Glean Agents can consume tools from remote MCP servers through Glean's MCP host integration."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "glean_customer_hosted_aws",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – AWS account access and deployment model",
              "url": "https://docs.glean.com/security/cloud-prem/aws/account-access-and-deployment-model",
              "note": "Glean documents customer-managed AWS KMS keys and states customers own and control the keys used to encrypt data at rest.",
              "evidence_type": "security_trust",
              "source_section": "Customer controls"
            }
          ],
          "note": "Glean supports customer-managed KMS keys in customer-hosted AWS deployments."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "glean_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean – Legal and Security Commitments",
              "url": "https://www.glean.com/legal",
              "note": "Glean states customer data is encrypted at rest using AES-256 with FIPS 140-2 validated cryptography.",
              "evidence_type": "security_trust",
              "source_section": "Secure Encryption"
            }
          ],
          "note": "Glean documents AES-256 encryption for customer data at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "glean_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean – Legal and Security Commitments",
              "url": "https://www.glean.com/legal",
              "note": "Glean states all data in transit is encrypted using TLS 1.2 or later.",
              "evidence_type": "security_trust",
              "source_section": "Secure Encryption"
            }
          ],
          "note": "Glean documents TLS 1.2+ encryption for data in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "glean_platform_including_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Glean Docs – Upgrade model and SDLC",
              "url": "https://docs.glean.com/security/architecture/sdlc",
              "note": "Glean states it maintains SOC 2 Type II compliance and makes detailed reports available through the account team.",
              "evidence_type": "security_trust",
              "source_section": "Security testing and compliance"
            }
          ],
          "note": "Glean documents SOC 2 Type II compliance for its platform."
        }
      ]
    },
    {
      "agent_id": "AI-0033",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "notion_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – Audit log",
              "url": "https://www.notion.com/help/audit-log",
              "note": "Notion documents Enterprise organization/workspace audit logs and agent-attributed activity.",
              "evidence_type": "technical_docs",
              "source_section": "Audit log"
            }
          ],
          "note": "Notion Enterprise provides workspace and organization audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "notion_enterprise_audit_log",
          "evidence": [
            {
              "title": "Notion Help – Audit log",
              "url": "https://www.notion.com/help/audit-log",
              "note": "Notion states audit-log history is retained for up to 365 days.",
              "evidence_type": "technical_docs",
              "source_section": "Filter audit logs / Date"
            }
          ],
          "note": "Notion documents 365 days of audit-log history.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "notion_enterprise_audit_log",
          "evidence": [
            {
              "title": "Notion Help – Audit log",
              "url": "https://www.notion.com/help/audit-log",
              "note": "Notion documents a custom SIEM integration that streams audit events as they occur.",
              "evidence_type": "technical_docs",
              "source_section": "Audit log / real-time events"
            }
          ],
          "note": "Notion audit events can be streamed to a customer SIEM.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "notion_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – Provision users & groups with SCIM",
              "url": "https://www.notion.com/help/provision-users-and-groups-with-scim",
              "note": "Notion documents Enterprise SCIM provisioning for users, groups, and memberships.",
              "evidence_type": "technical_docs",
              "source_section": "Prerequisites for SCIM with Notion"
            }
          ],
          "note": "Notion Enterprise supports SCIM provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "notion_business_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – SAML SSO",
              "url": "https://www.notion.com/help/saml-sso-configuration",
              "note": "Notion documents SAML 2.0 SSO for Business and Enterprise workspaces.",
              "evidence_type": "technical_docs",
              "source_section": "SAML SSO"
            }
          ],
          "note": "Notion supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "notion_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Notion Help – Notion Agent",
              "url": "https://www.notion.com/de/help/notion-agent",
              "note": "Notion documents Notion Agent as an AI teammate built into Notion and available as a Notion AI capability on Business and Enterprise plans.",
              "evidence_type": "technical_docs",
              "source_section": "Notion Agent"
            }
          ],
          "note": "Notion Agent is delivered as a managed capability inside Notion."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "notion_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – Data residency",
              "url": "https://www.notion.com/help/data-residency",
              "note": "Notion documents Enterprise data-residency options for storing workspace data in supported data regions.",
              "evidence_type": "technical_docs",
              "source_section": "Who is eligible?"
            }
          ],
          "note": "Notion Enterprise provides data-residency options.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "notion_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – Data residency",
              "url": "https://www.notion.com/help/data-residency",
              "note": "Notion states eligible Enterprise workspace owners can request migration of existing workspace data to a chosen data region.",
              "evidence_type": "technical_docs",
              "source_section": "Who is eligible?"
            }
          ],
          "note": "Eligible Enterprise customers can choose/request a Notion data region.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "notion_platform_data_including_agent_content",
          "evidence": [
            {
              "title": "Notion Trust Center – Terms and Privacy",
              "url": "https://trust.notion.com/terms-and-privacy",
              "note": "Notion documents AES-256 encryption at rest for Customer Data.",
              "evidence_type": "security_trust",
              "source_section": "Data protection and architecture"
            }
          ],
          "note": "Notion documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "notion_platform_data_including_agent_content",
          "evidence": [
            {
              "title": "Notion Trust Center – Terms and Privacy",
              "url": "https://trust.notion.com/terms-and-privacy",
              "note": "Notion documents TLS 1.2 or higher encryption in transit.",
              "evidence_type": "security_trust",
              "source_section": "Data protection and architecture"
            }
          ],
          "note": "Notion documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0034",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "notion_custom_agents_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Notion Help – Workspace audit log",
              "url": "https://www.notion.com/help/audit-log",
              "note": "Notion documents dedicated Custom Agent audit-log events covering configuration, access, triggers, executions, and agent-attributed page actions.",
              "evidence_type": "technical_docs",
              "source_section": "Custom Agent events"
            }
          ],
          "note": "Notion Enterprise records Custom Agent governance and execution-related events in the workspace audit log."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "notion_enterprise_audit_log",
          "evidence": [
            {
              "title": "Notion Help – Audit log",
              "url": "https://www.notion.com/help/audit-log",
              "note": "Notion states audit-log history is retained for up to 365 days.",
              "evidence_type": "technical_docs",
              "source_section": "Filter audit logs / Date"
            }
          ],
          "note": "Notion documents 365 days of audit-log history.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "notion_enterprise_audit_log",
          "evidence": [
            {
              "title": "Notion Help – Audit log",
              "url": "https://www.notion.com/help/audit-log",
              "note": "Notion documents a custom SIEM integration that streams audit events as they occur.",
              "evidence_type": "technical_docs",
              "source_section": "Audit log / real-time events"
            }
          ],
          "note": "Notion audit events can be streamed to a customer SIEM.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "notion_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – Provision users & groups with SCIM",
              "url": "https://www.notion.com/help/provision-users-and-groups-with-scim",
              "note": "Notion documents Enterprise SCIM provisioning for users, groups, and memberships.",
              "evidence_type": "technical_docs",
              "source_section": "Prerequisites for SCIM with Notion"
            }
          ],
          "note": "Notion Enterprise supports SCIM provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "notion_business_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – SAML SSO",
              "url": "https://www.notion.com/help/saml-sso-configuration",
              "note": "Notion documents SAML 2.0 SSO for Business and Enterprise workspaces.",
              "evidence_type": "technical_docs",
              "source_section": "SAML SSO"
            }
          ],
          "note": "Notion supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "notion_platform_including_agents",
          "evidence": [
            {
              "title": "Notion Help – Security practices",
              "url": "https://www.notion.com/help/security-and-privacy",
              "note": "Notion documents that its infrastructure and customer data are hosted on AWS in its secured production environment.",
              "evidence_type": "security_trust",
              "source_section": "Infrastructure"
            }
          ],
          "note": "Notion Agents run on Notion's managed AWS-hosted platform.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "notion_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – Data residency",
              "url": "https://www.notion.com/help/data-residency",
              "note": "Notion documents Enterprise data-residency options for storing workspace data in supported data regions.",
              "evidence_type": "technical_docs",
              "source_section": "Who is eligible?"
            }
          ],
          "note": "Notion Enterprise provides data-residency options.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "notion_enterprise_including_agents",
          "evidence": [
            {
              "title": "Notion Help – Data residency",
              "url": "https://www.notion.com/help/data-residency",
              "note": "Notion states eligible Enterprise workspace owners can request migration of existing workspace data to a chosen data region.",
              "evidence_type": "technical_docs",
              "source_section": "Who is eligible?"
            }
          ],
          "note": "Eligible Enterprise customers can choose/request a Notion data region.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "notion_platform_data_including_agent_content",
          "evidence": [
            {
              "title": "Notion Trust Center – Terms and Privacy",
              "url": "https://trust.notion.com/terms-and-privacy",
              "note": "Notion documents AES-256 encryption at rest for Customer Data.",
              "evidence_type": "security_trust",
              "source_section": "Data protection and architecture"
            }
          ],
          "note": "Notion documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "notion_platform_data_including_agent_content",
          "evidence": [
            {
              "title": "Notion Trust Center – Terms and Privacy",
              "url": "https://trust.notion.com/terms-and-privacy",
              "note": "Notion documents TLS 1.2 or higher encryption in transit.",
              "evidence_type": "security_trust",
              "source_section": "Data protection and architecture"
            }
          ],
          "note": "Notion documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0035",
      "claims": [
        {
          "path": "governance.ai_control_tower",
          "value": true,
          "scope": "servicenow_ai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – AI Control Tower",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/aict-landing.html",
              "note": "ServiceNow documents AI Control Tower as the centralized experience to discover, govern, monitor, and manage enterprise AI assets.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Centralized AI governance is documented."
        },
        {
          "path": "governance.approval.pre_action",
          "value": true,
          "confidence": "high",
          "scope": "supervised_tool_execution",
          "verified_at": "2026-10-03",
          "note": "In supervised mode, human approval is required before the tool action executes.",
          "evidence": [
            {
              "title": "ServiceNow Docs – Security for AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/aia-security-implementation.html",
              "evidence_type": "security_trust",
              "source_section": "Supervised execution mode"
            }
          ]
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "now_assist_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Agentic AI security and governance",
              "url": "https://www.servicenow.com/docs/r/platform-security/now-assist-security.html",
              "note": "ServiceNow documents AI Control Tower and detailed agent activity logs for auditable agent traceability.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Agent activity logs are documented for Now Assist AI agents."
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "confidence": "high",
          "scope": "supervised_tool_execution",
          "verified_at": "2026-10-03",
          "note": "Supervised execution mode requires human approval for critical or sensitive tool actions.",
          "evidence": [
            {
              "title": "ServiceNow Docs – Security for AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/aia-security-implementation.html",
              "evidence_type": "security_trust",
              "source_section": "Supervised execution mode"
            }
          ]
        },
        {
          "path": "governance.observability",
          "value": true,
          "scope": "ai_control_tower",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – AI Control Tower",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/aict-landing.html",
              "note": "ServiceNow documents AI Control Tower monitoring and evaluation capabilities for enterprise AI assets.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agent observability is documented."
        },
        {
          "path": "governance.permission_controls",
          "value": true,
          "confidence": "high",
          "scope": "agent_workflow_tool_access_controls",
          "verified_at": "2026-10-03",
          "note": "ServiceNow documents ACLs, user identities and role masking as access-control components at workflow, agent and tool levels.",
          "evidence": [
            {
              "title": "ServiceNow Docs – Security for AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/aia-security-implementation.html",
              "evidence_type": "security_trust",
              "source_section": "Security for AI agents overview"
            }
          ]
        },
        {
          "path": "governance.policy_controls",
          "value": true,
          "scope": "ai_control_tower",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Activate and install AI Control Tower",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/ai-control-tower/activation-and-installation-of-ai-control-tower.html",
              "note": "ServiceNow documents AI Control Tower Risk and Compliance capabilities including regulatory mapping, continuous monitoring, and policy compliance.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Policy/governance controls are documented."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "servicenow_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – ServiceNow Otto AI agents reference",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/na-aia-reference.html?contentId=4tS9w1m4NiMCL4HYrVaNfw",
              "note": "ServiceNow documents distinct AI Agent admin, viewer, and role-configuration roles for Otto AI agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "AI agent configuration and monitoring access is role-based."
        },
        {
          "path": "governance.tool_permissions",
          "value": true,
          "confidence": "high",
          "scope": "tool_execution_acl",
          "verified_at": "2026-10-03",
          "note": "Tool/component execution is checked against ACLs and the configured user identity.",
          "evidence": [
            {
              "title": "ServiceNow Docs – Security for AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/aia-security-implementation.html",
              "evidence_type": "security_trust",
              "source_section": "Execution Flow and Security Checks"
            }
          ]
        },
        {
          "path": "identity.agent_identity",
          "value": true,
          "confidence": "high",
          "scope": "ai_agent_runtime_identity",
          "verified_at": "2026-10-03",
          "note": "Each AI agent/workflow has a user identity configuration and may run as the dynamic user or a dedicated AI user with fixed roles.",
          "evidence": [
            {
              "title": "ServiceNow Docs – Security for AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/aia-security-implementation.html",
              "evidence_type": "security_trust",
              "source_section": "User identity"
            }
          ]
        },
        {
          "path": "memory.long_term",
          "value": true,
          "confidence": "high",
          "scope": "ai_agent_studio",
          "verified_at": "2026-10-03",
          "note": "ServiceNow AI Agent Studio can retain user preferences/facts from previous interactions as long-term memory.",
          "evidence": [
            {
              "title": "ServiceNow Docs – Set up long-term memory",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/long-term-memory-aia.html",
              "evidence_type": "technical_docs",
              "source_section": "Set up long-term memory"
            }
          ]
        },
        {
          "path": "memory.past_execution_outcomes",
          "value": true,
          "confidence": "high",
          "scope": "ai_agent_studio",
          "verified_at": "2026-10-03",
          "note": "Long-term memory settings can allow AI agents to learn from past execution outcomes.",
          "evidence": [
            {
              "title": "ServiceNow Docs – Set up long-term memory",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/long-term-memory-aia.html",
              "evidence_type": "technical_docs",
              "source_section": "Past executions outcomes"
            }
          ]
        },
        {
          "path": "protocols.a2a.client",
          "value": true,
          "scope": "servicenow_ai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Integrating external AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/external-agent-protocols.html",
              "note": "ServiceNow documents allowing the ServiceNow AI Platform to access external agents through A2A.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ServiceNow can consume external A2A agents."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "servicenow_ai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Integrating external AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/external-agent-protocols.html",
              "note": "ServiceNow documents allowing third parties to access ServiceNow AI agents through A2A.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ServiceNow AI agents can be exposed to third-party A2A systems."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "servicenow_ai_agents_external_agent_protocols",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Integrating external AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/external-agent-protocols.html",
              "note": "ServiceNow documents bidirectional Agent2Agent integration for ServiceNow AI agents and external agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ServiceNow AI agents support A2A interoperability with external agents."
        },
        {
          "path": "protocols.mcp.auth.required",
          "value": true,
          "scope": "ai_agent_studio_mcp_tools",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Add an MCP server tool to an AI agent",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/add-mcp-server-tool.html",
              "note": "ServiceNow explicitly requires an MCP server to be authenticated before its tool can be added to an AI agent.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Authenticated MCP servers are required for AI Agent Studio MCP tools."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "servicenow_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Add an MCP server tool to an AI agent",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/add-mcp-server-tool.html",
              "note": "ServiceNow documents adding authenticated MCP server tools to AI agents, establishing the AI agent as a consumer of MCP server capabilities.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ServiceNow AI agents can consume authenticated MCP server tools."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "servicenow_ai_platform_action_fabric",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Newsroom – Action Fabric and MCP Server",
              "url": "https://newsroom.servicenow.com/press-releases/details/2026/ServiceNow-opens-its-full-system-of-action-to-every-AI-Agent-in-the-enterprise/default.aspx",
              "note": "ServiceNow describes its generally available MCP Server exposing governed enterprise actions.",
              "evidence_type": "official_release"
            }
          ],
          "note": "ServiceNow provides MCP server capability at platform level."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "servicenow_platform_encryption_for_ai_agent_accessible_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Data protection",
              "url": "https://www.servicenow.com/docs/r/platform-security/naai-data-protection.html",
              "note": "ServiceNow documents Key Management Framework and Field Encryption as data-protection controls for Now Assist and AI-agent workflows.",
              "evidence_type": "security_trust"
            },
            {
              "title": "ServiceNow Docs – Cloud Encryption with Key Management",
              "url": "https://www.servicenow.com/docs/r/platform-security/cloud-encryption/dare-overview.html",
              "note": "ServiceNow documents customer-managed keys/BYOK for ServiceNow Cloud Encryption, including customer key rotation and withdrawal controls.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "ServiceNow platform data used by AI agents can be protected with the platform's customer-managed-key/BYOK encryption option where licensed."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "ServiceNow Field Encryption for protected instance fields",
          "scope": "sensitive_instance_fields_accessed_by_now_assist_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Data protection",
              "url": "https://www.servicenow.com/docs/r/platform-security/naai-data-protection.html",
              "note": "ServiceNow documents Field Encryption for sensitive data at rest and explicitly states AI agents require appropriate permissions to access encrypted fields.",
              "evidence_type": "security_trust"
            },
            {
              "title": "ServiceNow Docs – Agentic AI security and governance",
              "url": "https://www.servicenow.com/docs/r/platform-security/now-assist-security.html",
              "note": "ServiceNow states Now Assist AI agents inherit the ServiceNow AI Platform security model and its data-protection controls.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Sensitive ServiceNow instance fields used by AI agents can be protected at rest with ServiceNow Field Encryption."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2",
          "scope": "now_assist_ai_workloads",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – User data usage policy for Now Assist",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/enable-ai-experiences/user-data-usage-policy-now-assist.html",
              "note": "ServiceNow documents TLS 1.2 for AI workloads sent from the instance to ServiceNow compute hubs.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Now Assist AI workloads use TLS 1.2 in transit."
        }
      ]
    },
    {
      "agent_id": "AI-0036",
      "claims": [
        {
          "path": "deployment.license_requirement",
          "value": "ServiceNow Otto Pro Plus or Enterprise entitlement",
          "scope": "servicenow_otto_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Set up AI agents",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/set-up-na-aia.html",
              "note": "ServiceNow lists ServiceNow Otto Pro Plus or Enterprise entitlement as a licensing requirement for AI agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Otto AI agent setup requires the documented Pro Plus or Enterprise entitlement."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "servicenow_instance_logs_including_otto_actions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow – What is the ServiceNow AI Platform?",
              "url": "https://www.servicenow.com/platform/what-is-servicenow-ai-platform.html",
              "note": "ServiceNow states every Otto action is logged and governed.",
              "evidence_type": "official_product_page",
              "source_section": "ServiceNow Otto"
            },
            {
              "title": "ServiceNow – Securing the Now Platform",
              "url": "https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/ebook/ebk-how-servicenow-delivers-safe-and-secure-cloud-services.pdf",
              "note": "ServiceNow documents direct web-service access to log tables as a supported method for exporting platform log and audit data.",
              "evidence_type": "security_trust",
              "source_section": "Logging and monitoring"
            }
          ],
          "note": "Otto actions are logged, and ServiceNow platform log/audit tables can be accessed through web services for export."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "servicenow_otto_actions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow – Otto",
              "url": "https://www.servicenow.com/platform/otto.html",
              "note": "ServiceNow states that every Otto action is logged and governed.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "ServiceNow explicitly documents action logging and governance for Otto."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "servicenow_instance_logs_including_otto_actions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow – What is the ServiceNow AI Platform?",
              "url": "https://www.servicenow.com/platform/what-is-servicenow-ai-platform.html",
              "note": "ServiceNow states every Otto action is logged and governed.",
              "evidence_type": "official_product_page",
              "source_section": "ServiceNow Otto"
            },
            {
              "title": "ServiceNow – Securing the Now Platform",
              "url": "https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/ebook/ebk-how-servicenow-delivers-safe-and-secure-cloud-services.pdf",
              "note": "ServiceNow documents forwarding logs/events to customer logging or SIEM systems via syslog probe, MID Server, web-service calls, or Log Export Service.",
              "evidence_type": "security_trust",
              "source_section": "Logging and monitoring"
            }
          ],
          "note": "ServiceNow platform logs that include governed Otto activity can be exported to external SIEM/logging systems."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "servicenow_otto_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – ServiceNow Otto AI agents reference",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/na-aia-reference.html?contentId=4tS9w1m4NiMCL4HYrVaNfw",
              "note": "ServiceNow documents installed AI Agent admin, viewer, and role-configuration roles for ServiceNow Otto AI agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ServiceNow Otto AI agents use role-based administration and viewing permissions."
        },
        {
          "path": "governance.roles.admin",
          "value": "sn_aia.admin",
          "scope": "servicenow_otto_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – ServiceNow Otto AI agents reference",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/na-aia-reference.html?contentId=4tS9w1m4NiMCL4HYrVaNfw",
              "note": "ServiceNow identifies sn_aia.admin as the AI Agent administrator role.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "The documented AI Agent administrator role is sn_aia.admin."
        },
        {
          "path": "governance.roles.viewer",
          "value": "sn_aia.viewer",
          "scope": "servicenow_otto_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – ServiceNow Otto AI agents reference",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/na-aia-reference.html?contentId=4tS9w1m4NiMCL4HYrVaNfw",
              "note": "ServiceNow identifies sn_aia.viewer as the read-only AI Agent viewer role.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "The documented read-only AI Agent viewer role is sn_aia.viewer."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "servicenow_ai_platform_users_accessing_otto",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Create an OIDC configuration for SSO",
              "url": "https://www.servicenow.com/docs/r/platform-security/authentication/create-OIDC-configuration-SSO.html",
              "note": "ServiceNow documents OpenID Connect SSO for users logging in to ServiceNow applications.",
              "evidence_type": "technical_docs",
              "source_section": "OpenID Connect SSO"
            },
            {
              "title": "ServiceNow – What is the ServiceNow AI Platform?",
              "url": "https://www.servicenow.com/platform/what-is-servicenow-ai-platform.html",
              "note": "ServiceNow states Otto is built on and operates through the ServiceNow AI Platform.",
              "evidence_type": "official_product_page",
              "source_section": "ServiceNow Otto"
            }
          ],
          "note": "Users accessing Otto through the ServiceNow AI Platform can use the platform's documented OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "servicenow_ai_platform_users_accessing_otto",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Multi-Provider single sign-on (SSO)",
              "url": "https://www.servicenow.com/docs/r/platform-security/authentication/c_MultipleProviderSingleSignOn.html",
              "note": "ServiceNow documents SAML 2.0 as a supported SSO method for access to ServiceNow instances.",
              "evidence_type": "technical_docs",
              "source_section": "Supported SSO methods"
            },
            {
              "title": "ServiceNow – What is the ServiceNow AI Platform?",
              "url": "https://www.servicenow.com/platform/what-is-servicenow-ai-platform.html",
              "note": "ServiceNow states Otto is built on and operates through the ServiceNow AI Platform.",
              "evidence_type": "official_product_page",
              "source_section": "ServiceNow Otto"
            }
          ],
          "note": "Users accessing Otto through the ServiceNow AI Platform can use the platform's documented SAML 2.0 SSO."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "servicenow_platform_data_accessed_by_otto_where_cloud_encryption_is_licensed",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Data protection",
              "url": "https://www.servicenow.com/docs/r/platform-security/naai-data-protection.html",
              "note": "ServiceNow documents Key Management Framework and encryption-key controls for sensitive data used by AI agents and agentic workflows.",
              "evidence_type": "security_trust"
            },
            {
              "title": "ServiceNow Docs – Cloud Encryption with Key Management",
              "url": "https://www.servicenow.com/docs/r/platform-security/cloud-encryption/dare-overview.html",
              "note": "ServiceNow documents customer-managed keys/BYOK for platform data, including customer rotation and key-withdrawal controls.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Where the relevant ServiceNow encryption option is licensed, platform data used by Otto can be protected with customer-managed/BYOK keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "ServiceNow Field Encryption for protected instance fields",
          "scope": "sensitive_instance_fields_accessed_by_otto_and_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – Data protection",
              "url": "https://www.servicenow.com/docs/r/platform-security/naai-data-protection.html",
              "note": "ServiceNow documents Field Encryption for sensitive data at rest and explicitly states AI agents require appropriate permissions to access encrypted fields; the same data-protection section includes ServiceNow Otto for Vault.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Sensitive ServiceNow instance fields accessible to Otto/AI agents can be protected at rest with Field Encryption."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2",
          "scope": "servicenow_otto_now_assist_ai_workloads",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow Docs – User data usage policy",
              "url": "https://www.servicenow.com/docs/r/intelligent-experiences/user-data-usage-policy-now-assist.html?contentId=30BXSb9eeIvaC5CPPsPhIQ",
              "note": "ServiceNow documents AI workloads being sent from the ServiceNow instance to compute hubs using TLS 1.2; the current page also uses ServiceNow Otto naming for affected AI features.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "ServiceNow documents TLS 1.2 transport protection for the AI workload path used by Otto/Now Assist capabilities."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "servicenow_ai_environment_including_otto_ai_workloads",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "ServiceNow – Securing the Now Platform",
              "url": "https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/ebook/ebk-how-servicenow-delivers-safe-and-secure-cloud-services.pdf",
              "note": "ServiceNow states its Artificial Intelligence services environment has a SOC 2 Type 2 attestation covering the GenAI stack, AI/ML stack, and DART environment.",
              "evidence_type": "security_trust",
              "source_section": "Artificial Intelligence (AI) Products"
            },
            {
              "title": "ServiceNow – ServiceNow Otto",
              "url": "https://www.servicenow.com/platform/otto.html",
              "note": "ServiceNow documents Otto as the AI experience operating on the ServiceNow AI Platform.",
              "evidence_type": "official_product_page",
              "source_section": "What is ServiceNow Otto?"
            }
          ],
          "note": "Otto AI workloads run on ServiceNow's attested AI environment, which ServiceNow documents as SOC 2 Type 2."
        }
      ]
    },
    {
      "agent_id": "AI-0037",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "microsoft_365_copilot_unified_audit_log",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – CopilotInteraction schema",
              "url": "https://learn.microsoft.com/en-us/office/office-365-management-api/copilot-schema",
              "note": "Microsoft documents the CopilotInteraction audit schema and Copilot events in the Microsoft 365 unified audit log.",
              "evidence_type": "api_docs",
              "source_section": "Copilot interaction events overview"
            },
            {
              "title": "Microsoft Learn – Office 365 Management Activity API reference",
              "url": "https://learn.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference",
              "note": "Microsoft documents the Office 365 Management Activity API as a REST web service for retrieving audit actions and events.",
              "evidence_type": "api_docs",
              "source_section": "Overview"
            }
          ],
          "note": "Microsoft 365 Copilot audit events can be retrieved programmatically through the Management Activity API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "microsoft_365_copilot",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Audit Microsoft 365 Copilot interactions",
              "url": "https://learn.microsoft.com/en-us/purview/audit-copilot",
              "note": "Microsoft documents audit records for Microsoft 365 Copilot user interactions and AI activities in Microsoft Purview Audit.",
              "evidence_type": "technical_docs",
              "source_section": "Copilot audit events"
            }
          ],
          "note": "Microsoft 365 Copilot interactions are represented in Microsoft Purview audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 180,
          "scope": "microsoft_purview_audit_standard_copilot",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Audit logs for Copilot and AI applications",
              "url": "https://learn.microsoft.com/en-us/purview/audit-copilot",
              "note": "Microsoft states Microsoft applications and Microsoft Copilots are included in Audit Standard.",
              "evidence_type": "technical_docs",
              "source_section": "Billing / Microsoft applications"
            },
            {
              "title": "Microsoft Learn – Get started with auditing solutions",
              "url": "https://learn.microsoft.com/en-us/purview/audit-get-started",
              "note": "Microsoft states Audit Standard logs generated after October 17, 2023 have a default retention of 180 days.",
              "evidence_type": "technical_docs",
              "source_section": "Retention"
            }
          ],
          "note": "Microsoft 365 Copilot audit records are in Audit Standard, whose documented default retention is 180 days."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "microsoft_365_copilot_audit",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Copilot auditing and logging",
              "url": "https://learn.microsoft.com/en-us/microsoft-365/copilot/employee-self-service/auditing-logging",
              "note": "Microsoft documents SIEM integration paths for Copilot/agent auditing through Microsoft security/telemetry services.",
              "evidence_type": "technical_docs",
              "source_section": "Security information and event management (SIEM)"
            }
          ],
          "note": "Microsoft documents SIEM integration for Copilot/agent audit telemetry."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "microsoft_365_copilot",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Microsoft 365 Copilot architecture, data protection, and auditing",
              "url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing",
              "note": "Microsoft states Copilot respects existing Microsoft 365 permissions, access controls, and identity authorization.",
              "evidence_type": "security_trust",
              "source_section": "Permissions and access controls"
            }
          ],
          "note": "Researcher/Analyst operate under Microsoft 365 role- and permission-based access controls."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "microsoft_365_copilot_analyst",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft 365 Blog – Researcher and Analyst are now generally available",
              "url": "https://www.microsoft.com/en-us/microsoft-365/blog/2025/06/02/researcher-and-analyst-are-now-generally-available-in-microsoft-365-copilot/",
              "note": "Microsoft documents Analyst as a built-in, pre-pinned reasoning agent in the Microsoft 365 Copilot app for licensed users.",
              "evidence_type": "official_release",
              "source_section": "How to get started with Researcher and Analyst"
            }
          ],
          "note": "Analyst is delivered as a managed agent inside Microsoft 365 Copilot."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "microsoft_365_copilot_service_boundary",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Data, Privacy, and Security for Microsoft 365 Copilot",
              "url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy",
              "note": "Microsoft documents Microsoft 365 Copilot within the Microsoft 365 service boundary and applicable geographic/data residency commitments.",
              "evidence_type": "security_trust",
              "source_section": "Data residency and processing"
            }
          ],
          "note": "Microsoft 365 Copilot provides documented data-residency commitments."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "microsoft_365_multi_geo",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Microsoft 365 Multi-Geo",
              "url": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-multi-geo?view=o365-worldwide",
              "note": "Microsoft documents Multi-Geo controls for placing Microsoft 365 user data in selected supported geographies; Copilot operates within this service boundary.",
              "evidence_type": "technical_docs",
              "source_section": "Multi-Geo capabilities"
            }
          ],
          "note": "Eligible Microsoft 365 organizations can configure supported data geographies used by the Copilot service boundary."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "microsoft_365_copilot_service_boundary",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Microsoft 365 Copilot architecture, data protection, and auditing",
              "url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing",
              "note": "Microsoft states Copilot data is protected by Microsoft 365 encryption controls, including encryption at rest.",
              "evidence_type": "security_trust",
              "source_section": "Data protection"
            }
          ],
          "note": "Microsoft 365 Copilot data is protected by Microsoft 365 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "microsoft_365_copilot_service_boundary",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Microsoft 365 Copilot architecture, data protection, and auditing",
              "url": "https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing",
              "note": "Microsoft states Copilot data is protected by Microsoft 365 encryption controls, including encryption in transit.",
              "evidence_type": "security_trust",
              "source_section": "Data protection"
            }
          ],
          "note": "Microsoft 365 Copilot data is protected by Microsoft 365 encryption in transit."
        }
      ]
    },
    {
      "agent_id": "AI-0038",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "perplexity_enterprise_computer",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity lists Audit Logs as an organization-wide Enterprise Max security feature.",
              "evidence_type": "technical_docs",
              "source_section": "Premium security features"
            }
          ],
          "note": "Perplexity Enterprise provides audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "perplexity_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Perplexity – Role-based access controls, API credentials, Brain for Max",
              "url": "https://www.perplexity.ai/en-GB/changelog/role-based-access-controls-api-credentials-and-brain-for-max",
              "note": "Perplexity documents Enterprise custom roles with granular permissions, SCIM group sync, and per-group controls.",
              "evidence_type": "official_release",
              "source_section": "Control Enterprise access with custom roles and SCIM groups"
            }
          ],
          "note": "Perplexity Enterprise supports custom roles with granular permissions."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "perplexity_enterprise_computer",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents role-based access controls for Enterprise organizations alongside its Research/Comet workflows.",
              "evidence_type": "technical_docs",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity Enterprise provides role-based access controls.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "perplexity_enterprise_computer",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity states Enterprise Max includes organization-wide SCIM and explicitly includes Research and Comet Assistant among its product capabilities.",
              "evidence_type": "technical_docs",
              "source_section": "Key Features / Premium security features"
            }
          ],
          "note": "Perplexity Enterprise supports SCIM for the product suite including Research and Comet.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "perplexity_enterprise_computer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Perplexity – How we built security into Computer",
              "url": "https://www.perplexity.ai/de/hub/blog/how-we-built-security-into-computer",
              "note": "Perplexity states Computer inherits Enterprise security features including SAML SSO.",
              "evidence_type": "official_release",
              "source_section": "Enterprise governance"
            }
          ],
          "note": "Perplexity Computer inherits SAML SSO from the Enterprise platform."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "perplexity_computer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Perplexity – Computer",
              "url": "https://www.perplexity.ai/products/computer",
              "note": "Perplexity documents Computer as its subscription digital-worker product available across desktop, mobile, Slack, and Microsoft 365 and capable of persistent background execution.",
              "evidence_type": "official_product_page",
              "source_section": "What Computer does for you / Put Computer to work"
            }
          ],
          "note": "Perplexity Computer is delivered as a managed Perplexity service."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "perplexity_computer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Perplexity – Introducing Perplexity Computer workshop",
              "url": "https://www.perplexity.ai/de/hub/workshops/introducing-perplexity-computer",
              "note": "Perplexity explicitly states Computer supports custom local and remote MCP servers/connectors.",
              "evidence_type": "technical_docs",
              "source_section": "Connectors and integrations"
            }
          ],
          "note": "Perplexity Computer can act as an MCP client for local or remote MCP servers."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents AES-256 encryption for data at rest.",
              "evidence_type": "security_trust",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.3",
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents TLS 1.3 for data in transit.",
              "evidence_type": "security_trust",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity documents TLS 1.3 encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity states Enterprise Max has SOC 2 Type II certification.",
              "evidence_type": "security_trust",
              "source_section": "How safe is Enterprise Max?"
            }
          ],
          "note": "Perplexity documents SOC 2 Type II compliance.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0039",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "intercom_workspace_activity_logs",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – Teammate activity logs",
              "url": "https://www.intercom.com/help/en/articles/4667982-review-actions-taken-in-your-workspace-with-teammate-activity-logs",
              "note": "Intercom explicitly documents programmatic retrieval through the Activity Logs API.",
              "evidence_type": "api_docs",
              "source_section": "Accessing activity logs via API"
            }
          ],
          "note": "Intercom exposes activity logs via API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "intercom_workspace_including_fin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – Teammate activity logs",
              "url": "https://www.intercom.com/help/en/articles/4667982-review-actions-taken-in-your-workspace-with-teammate-activity-logs",
              "note": "Intercom documents teammate activity logs for auditing and troubleshooting workspace actions.",
              "evidence_type": "technical_docs",
              "source_section": "Viewing activity logs"
            }
          ],
          "note": "Intercom provides workspace activity/audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "intercom_teammate_activity_logs_ui",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – Teammate activity logs",
              "url": "https://www.intercom.com/help/en/articles/4667982-review-actions-taken-in-your-workspace-with-teammate-activity-logs",
              "note": "Intercom states Teammate Activity Logs are available for one year in the UI.",
              "evidence_type": "technical_docs",
              "source_section": "Viewing activity logs"
            }
          ],
          "note": "Intercom documents one year (365 days) of activity logs in the UI."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "intercom_workspace_activity_logs",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – Export teammate and activity log data to cloud storage",
              "url": "https://www.intercom.com/help/en/articles/16528353-export-teammate-and-activity-log-data-to-cloud-storage",
              "note": "Intercom documents scheduled export of teammate/activity logs to S3, GCS, or Azure Blob for security monitoring and SIEM workflows.",
              "evidence_type": "technical_docs",
              "source_section": "Use cases / scheduled cloud storage exports"
            }
          ],
          "note": "Intercom activity logs can be exported for SIEM/security monitoring."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "intercom_workspace_including_fin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – Set up custom roles with recommended permissions",
              "url": "https://www.intercom.com/help/en/articles/7054403-set-up-custom-roles-with-recommended-permissions",
              "note": "Intercom explicitly documents custom roles with configurable permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Custom roles"
            }
          ],
          "note": "Intercom supports custom roles."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "intercom_workspace_including_fin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – Your workspace settings",
              "url": "https://www.intercom.com/help/en/articles/15432088-your-workspace-settings",
              "note": "Intercom documents roles, permissions, and workspace access controls for teammates.",
              "evidence_type": "technical_docs",
              "source_section": "Teammates / Security"
            }
          ],
          "note": "Intercom uses role- and permission-based workspace access."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "intercom_workspace_including_fin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – SCIM Provisioning",
              "url": "https://www.intercom.com/help/en/articles/5798401-system-for-cross-domain-identity-management-scim-provisioning",
              "note": "Intercom documents SCIM provisioning for teammates through an identity provider.",
              "evidence_type": "technical_docs",
              "source_section": "SCIM Provisioning"
            }
          ],
          "note": "Intercom supports SCIM provisioning."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "intercom_workspace_including_fin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – Integrate with an identity provider and log in with SAML SSO",
              "url": "https://www.intercom.com/help/en/articles/3974587-integrate-with-an-identity-provider-and-log-in-with-saml-sso",
              "note": "Intercom documents SAML SSO for workspace access.",
              "evidence_type": "technical_docs",
              "source_section": "Enable SAML SSO"
            }
          ],
          "note": "Intercom workspaces using Fin support SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "intercom_fin_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – Fin AI Agent FAQs",
              "url": "https://www.intercom.com/help/en/articles/7837535-fin-ai-agent-faqs",
              "note": "Intercom documents Fin AI Agent as a hosted Intercom service available on US, EU, and AU workspaces.",
              "evidence_type": "technical_docs",
              "source_section": "Setup / Regional hosting"
            }
          ],
          "note": "Fin is delivered as a managed Intercom service."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "intercom_fin_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – The Fin AI Engine",
              "url": "https://www.intercom.com/help/en/articles/9929230-the-fin-ai-engine",
              "note": "Intercom states Fin AI Agent is available on US-, EU-, and AU-hosted workspaces.",
              "evidence_type": "security_trust",
              "source_section": "Regional hosting"
            }
          ],
          "note": "Fin supports regional hosting options."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "intercom_platform_including_fin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Intercom Help – The Fin AI Engine",
              "url": "https://www.intercom.com/help/en/articles/9929230-the-fin-ai-engine",
              "note": "Intercom states Fin's service is covered by a SOC 2 Type II audit report.",
              "evidence_type": "security_trust",
              "source_section": "Compliance"
            }
          ],
          "note": "Intercom documents SOC 2 Type II coverage for Fin-related service controls."
        }
      ]
    },
    {
      "agent_id": "AI-0040",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "zendesk_ai_agents_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Developer Docs – AI Agents API Introduction",
              "url": "https://developer.zendesk.com/api-reference/ai-agents/introduction/",
              "note": "Zendesk documents APIs for programmatically managing AI-powered conversations, ticket workflows, escalations, data exports, and user data.",
              "evidence_type": "api_docs",
              "source_section": "AI Agents API Introduction"
            }
          ],
          "note": "Zendesk AI Agents expose documented programmatic API endpoints."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "zendesk_ai_agents_chat_and_ticket_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Developer Docs – AI Agents Chat API Webhook",
              "url": "https://developer.zendesk.com/api-reference/ai-agents/chat/chat-webhook/",
              "note": "Zendesk documents asynchronous AI Agent Chat API events delivered to configured webhook endpoints.",
              "evidence_type": "api_docs",
              "source_section": "AI Agents Chat API Webhook"
            },
            {
              "title": "Zendesk Developer Docs – AI Agents Ticket API Webhook",
              "url": "https://developer.zendesk.com/api-reference/ai-agents/ticket/ticket-webhook/",
              "note": "Zendesk documents real-time AI Agent Ticket API webhook delivery.",
              "evidence_type": "api_docs",
              "source_section": "AI Agents Ticket API Webhook"
            }
          ],
          "note": "Zendesk AI Agents support webhook-based event delivery."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "zendesk_enterprise_account",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Developer Docs – Audit Logs",
              "url": "https://developer.zendesk.com/api-reference/ticketing/account-configuration/audit_logs/",
              "note": "Zendesk documents GET endpoints for listing/showing audit logs and a POST endpoint for exporting audit logs.",
              "evidence_type": "api_docs",
              "source_section": "List Audit Logs / Show Audit Log / Export Audit Logs"
            }
          ],
          "note": "Zendesk exposes audit logs programmatically through documented API endpoints."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "zendesk_enterprise_account",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Developer Docs – Audit Logs",
              "url": "https://developer.zendesk.com/api-reference/ticketing/account-configuration/audit_logs/",
              "note": "Zendesk documents Enterprise audit logs covering account changes since account creation.",
              "evidence_type": "api_docs",
              "source_section": "Audit Logs"
            }
          ],
          "note": "Zendesk Enterprise provides audit logs."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "zendesk_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Help – Creating custom roles and assigning agents",
              "url": "https://support.zendesk.com/hc/en-us/articles/4408882153882-Creating-custom-roles-and-assigning-agents",
              "note": "Zendesk documents creating Enterprise custom agent roles with granular permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Creating custom agent roles"
            }
          ],
          "note": "Zendesk Enterprise supports custom roles."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "zendesk_team_member_access",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Help – Setting roles and access in Admin Center",
              "url": "https://support.zendesk.com/hc/en-us/articles/4408824375450-Setting-roles-and-access-in-Zendesk-Admin-Center",
              "note": "Zendesk documents role-based product access and permissions for account owners, admins, agents, light agents, and custom roles.",
              "evidence_type": "technical_docs",
              "source_section": "About team member roles and access"
            }
          ],
          "note": "Zendesk uses role-based permissions to govern product access."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "zendesk_user_provisioning",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Help – Does Zendesk support SCIM?",
              "url": "https://support.zendesk.com/hc/en-us/articles/8966513066138-Does-Zendesk-support-SCIM",
              "note": "Zendesk states it supports SCIM 2.0 through automated user provisioning with providers such as Okta and Microsoft Entra.",
              "evidence_type": "technical_docs",
              "source_section": "Answer"
            }
          ],
          "note": "Zendesk supports SCIM 2.0 provisioning."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "zendesk_account_access_for_ai_agents_admins_and_users",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Help – Single sign-on options",
              "url": "https://support.zendesk.com/hc/en-us/articles/4408883587226-Single-sign-on-SSO-options-in-Zendesk",
              "note": "Zendesk explicitly lists OpenID Connect (OIDC) as an enterprise SSO option.",
              "evidence_type": "technical_docs",
              "source_section": "Enterprise SSO options"
            }
          ],
          "note": "Zendesk supports OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "zendesk_account_access_for_ai_agents_admins_and_users",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Help – Enabling SAML single sign-on",
              "url": "https://support.zendesk.com/hc/en-us/articles/4408887505690-Enabling-SAML-single-sign-on",
              "note": "Zendesk explicitly documents SAML enterprise SSO for Zendesk accounts.",
              "evidence_type": "technical_docs",
              "source_section": "Enabling SAML SSO"
            }
          ],
          "note": "Zendesk supports SAML SSO."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "zendesk_service_data_including_ai_agent_account_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Help – Data Hosting Locations",
              "url": "https://support.zendesk.com/hc/en-us/articles/4408825765530-Data-Hosting-Locations-for-Your-Zendesk-Service-Data",
              "note": "Zendesk documents multiple regional AWS hosting locations and regional data-hosting commitments for eligible service data.",
              "evidence_type": "security_trust",
              "source_section": "AWS Regions / Data locality agreements"
            }
          ],
          "note": "Zendesk offers regional data-hosting options for eligible service data."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "zendesk_data_center_location_add_on",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Help – Choose account data hosting location",
              "url": "https://support.zendesk.com/hc/en-us/articles/4408833725722-Can-I-choose-the-location-where-my-account-data-is-hosted",
              "note": "Zendesk states eligible customers can purchase Data Center Location and select the region where some service data is hosted.",
              "evidence_type": "technical_docs",
              "source_section": "Answer"
            }
          ],
          "note": "Eligible Zendesk customers can select a supported hosting region for covered service data."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "zendesk_service_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Trust Center",
              "url": "https://www.zendesk.com/trust-center/",
              "note": "Zendesk states Service Data is encrypted at rest in AWS using AES-256.",
              "evidence_type": "security_trust",
              "source_section": "Encryption / At Rest"
            }
          ],
          "note": "Zendesk documents AES-256 encryption at rest for Service Data."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "zendesk_ui_and_api_communications",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Trust Center",
              "url": "https://www.zendesk.com/trust-center/",
              "note": "Zendesk states communications with the UI and APIs are encrypted via HTTPS/TLS 1.2 or higher over public networks.",
              "evidence_type": "security_trust",
              "source_section": "Encryption / In Transit"
            }
          ],
          "note": "Zendesk documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "zendesk_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Trust Center",
              "url": "https://www.zendesk.com/trust-center/",
              "note": "Zendesk states it undergoes routine audits and maintains current SOC 2 Type II reports.",
              "evidence_type": "security_trust",
              "source_section": "Global Standards / SOC 2 Type II"
            }
          ],
          "note": "Zendesk documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0041",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "forethought_ai_agents_platform",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "Forethought's current solutions documentation explicitly lists audit trails as a built-in governance safeguard for its agentic AI platform.",
          "evidence": [
            {
              "title": "Forethought – AI Solutions for Customer Support Automation",
              "url": "https://forethought.ai/solutions",
              "note": "Forethought states that its enterprise-ready agentic AI uses built-in encryption, access controls, and audit trails for governance.",
              "evidence_type": "official_product_page",
              "source_section": "Built for trust, backed by standards"
            },
            {
              "title": "Zendesk – Announcing Forethought AI agents by Zendesk for customers",
              "url": "https://support.zendesk.com/hc/en-us/articles/10850639885082-Announcing-Forethought-AI-agents-by-Zendesk-for-customers",
              "note": "Zendesk documents Forethought AI agents by Zendesk as the acquired Forethought product and its current autonomous support-agent suite.",
              "evidence_type": "official_release",
              "source_section": "What's changing?"
            }
          ]
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "forethought_ai_agents_platform",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "Forethought's current platform documentation explicitly identifies role-based access as a control protecting sensitive data; Zendesk documents Forethought AI Agents by Zendesk as the Forethought product suite.",
          "evidence": [
            {
              "title": "Forethought – Multi-Agent System",
              "url": "https://forethought.ai/platform",
              "note": "Forethought states its platform protects PII and sensitive data with encryption, role-based access, and enterprise-grade safeguards.",
              "evidence_type": "official_product_page",
              "source_section": "Leading the pack on security and trust"
            },
            {
              "title": "Zendesk – Announcing Forethought AI agents by Zendesk for customers",
              "url": "https://support.zendesk.com/hc/en-us/articles/10850639885082-Announcing-Forethought-AI-agents-by-Zendesk-for-customers",
              "note": "Zendesk documents Forethought AI agents by Zendesk as the acquired Forethought product and its current autonomous support-agent suite.",
              "evidence_type": "official_release",
              "source_section": "What's changing?"
            }
          ]
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "forethought_ai_agents_by_zendesk",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zendesk Help – Announcing Forethought AI agents by Zendesk for customers",
              "url": "https://support.zendesk.com/hc/en-us/articles/10850639885082-Announcing-Forethought-AI-agents-by-Zendesk-for-customers",
              "note": "Zendesk documents Forethought AI agents as a purchasable Zendesk add-on that autonomously responds to and resolves customer inquiries.",
              "evidence_type": "official_release",
              "source_section": "What's changing?"
            }
          ],
          "note": "Forethought AI agents are delivered as a managed Zendesk add-on service."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "forethought_ai_agents_platform",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "Forethought's current platform documentation states that the platform meets SOC 2 Type II; Zendesk documents Forethought AI Agents by Zendesk as the current Forethought product suite.",
          "evidence": [
            {
              "title": "Forethought – Multi-Agent System",
              "url": "https://forethought.ai/platform",
              "note": "Forethought states its platform meets SOC 2 Type II among its current enterprise security and privacy standards.",
              "evidence_type": "security_trust",
              "source_section": "Leading the pack on security and trust"
            },
            {
              "title": "Zendesk – Announcing Forethought AI agents by Zendesk for customers",
              "url": "https://support.zendesk.com/hc/en-us/articles/10850639885082-Announcing-Forethought-AI-agents-by-Zendesk-for-customers",
              "note": "Zendesk documents Forethought AI agents by Zendesk as the acquired Forethought product and its current autonomous support-agent suite.",
              "evidence_type": "official_release",
              "source_section": "What's changing?"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0042",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "hubspot_account_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – View and export account activity history",
              "url": "https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history",
              "note": "HubSpot documents centralized audit logs for reviewing, filtering, and exporting user actions and security-related account activity.",
              "evidence_type": "technical_docs",
              "source_section": "View, filter, and export a centralized audit log"
            }
          ],
          "note": "HubSpot provides centralized account audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Create and assign permission sets",
              "url": "https://knowledge.hubspot.com/user-management/create-permission-sets",
              "note": "HubSpot documents creating custom permission sets from templates or from scratch with granular permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Create a permission set"
            }
          ],
          "note": "HubSpot Enterprise supports custom reusable permission sets/roles.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Create and assign permission sets",
              "url": "https://knowledge.hubspot.com/user-management/create-permission-sets",
              "note": "HubSpot documents reusable permission sets based on roles that grant consistent access to users.",
              "evidence_type": "technical_docs",
              "source_section": "Create a permission set"
            }
          ],
          "note": "HubSpot Enterprise provides role-oriented permission sets for access control.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot explicitly documents SCIM-based provisioning through Okta.",
              "evidence_type": "security_trust",
              "source_section": "Frequently Asked Questions / identity provider"
            }
          ],
          "note": "HubSpot Enterprise supports SCIM-based provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot explicitly documents SAML-based SSO for major identity providers.",
              "evidence_type": "security_trust",
              "source_section": "Frequently Asked Questions / identity provider"
            }
          ],
          "note": "HubSpot Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "hubspot_breeze_customer_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "HubSpot Marketplace – Customer Agent",
              "url": "https://ecosystem.hubspot.com/marketplace/listing/customer-agent",
              "note": "HubSpot lists Customer Agent as a HubSpot-built Agent installed into the HubSpot environment and used across its supported channels.",
              "evidence_type": "official_product_page",
              "source_section": "Customer Agent / Overview"
            }
          ],
          "note": "Breeze Customer Agent is delivered as a managed HubSpot agent."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "hubspot_platform_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Cloud Infrastructure and Data Hosting FAQ",
              "url": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
              "note": "HubSpot documents regional product infrastructure and account hosting in US, EU, Canada, and Australia.",
              "evidence_type": "security_trust",
              "source_section": "Where is HubSpot's product infrastructure hosted?"
            }
          ],
          "note": "HubSpot provides regional data-hosting options for the platform that hosts Breeze agents.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "hubspot_paid_accounts",
          "evidence": [
            {
              "title": "HubSpot Cloud Infrastructure and Data Hosting FAQ",
              "url": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
              "note": "HubSpot states Starter, Professional, and Enterprise accounts can change their assigned data center.",
              "evidence_type": "technical_docs",
              "source_section": "How are data centers assigned?"
            }
          ],
          "note": "Eligible paid HubSpot customers can change their account data-center region.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Security Program",
              "url": "https://legal.hubspot.com/security",
              "note": "HubSpot documents AES-256 encryption for product-server disks and long-term storage such as AWS S3.",
              "evidence_type": "security_trust",
              "source_section": "How does HubSpot encrypt data?"
            }
          ],
          "note": "HubSpot documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Security Program",
              "url": "https://legal.hubspot.com/security",
              "note": "HubSpot documents TLS 1.2 or 1.3 for sensitive product interactions including API calls and authenticated sessions.",
              "evidence_type": "security_trust",
              "source_section": "How does HubSpot encrypt data?"
            }
          ],
          "note": "HubSpot documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot states its Trust Center provides the HubSpot SOC 2 Type II report and that HubSpot AI runs on the same secure platform infrastructure.",
              "evidence_type": "security_trust",
              "source_section": "Security & compliance / HubSpot AI"
            }
          ],
          "note": "HubSpot documents SOC 2 Type II coverage for the platform hosting its AI features.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0043",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "sierra_agent_integrations_and_invocation",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Sierra – Your agent, laid bare",
              "url": "https://sierra.ai/jp/blog/your-agent-laid-bare-and-why-it-matters",
              "note": "Sierra documents agent integrations through REST and states other agents can invoke Sierra capabilities through APIs.",
              "evidence_type": "official_release",
              "source_section": "Build on what you already have"
            }
          ],
          "note": "Sierra supports REST/API integration and agent invocation."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "sierra_agent_observability",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Sierra – Your agent, laid bare",
              "url": "https://sierra.ai/jp/blog/your-agent-laid-bare-and-why-it-matters",
              "note": "Sierra documents export APIs for conversation logs and performance data.",
              "evidence_type": "api_docs",
              "source_section": "Keep the value it creates"
            }
          ],
          "note": "Sierra exposes agent observability/history data through export APIs."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "sierra_agent_observability",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Sierra – Your agent, laid bare",
              "url": "https://sierra.ai/jp/blog/your-agent-laid-bare-and-why-it-matters",
              "note": "Sierra documents conversation logs, traces, version history, performance data, and a complete record for investigating agent decisions.",
              "evidence_type": "official_release",
              "source_section": "Know exactly what happened / Keep the value it creates"
            }
          ],
          "note": "Sierra provides detailed agent logs and trace history."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "sierra_agent_observability",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Sierra – Your agent, laid bare",
              "url": "https://sierra.ai/jp/blog/your-agent-laid-bare-and-why-it-matters",
              "note": "Sierra documents sending agent data to external observability/data infrastructure through OpenTelemetry, Amazon EventBridge, Google Cloud Pub/Sub, or export API.",
              "evidence_type": "technical_docs",
              "source_section": "Use the tools you trust"
            }
          ],
          "note": "Sierra agent telemetry can be exported to external observability/SIEM infrastructure."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "sierra_platform_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Sierra – Your agent, laid bare",
              "url": "https://sierra.ai/jp/blog/your-agent-laid-bare-and-why-it-matters",
              "note": "Sierra explicitly documents roles and permissions controlling who can change agents and release changes.",
              "evidence_type": "official_release",
              "source_section": "Keep the value it creates"
            }
          ],
          "note": "Sierra provides role- and permission-based governance."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "sierra_platform_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Sierra Trust Center",
              "url": "https://trust.sierra.ai/",
              "note": "Sierra lists AWS cloud hosting with localization available in the US, EU, Southeast Asia, Japan, and Australia.",
              "evidence_type": "security_trust",
              "source_section": "Subprocessors / AWS"
            }
          ],
          "note": "Sierra documents localized hosting availability in multiple regions."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "sierra_agents_integrations",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Sierra – Your agent, laid bare",
              "url": "https://sierra.ai/jp/blog/your-agent-laid-bare-and-why-it-matters",
              "note": "Sierra states agents connect existing systems through MCP, REST, GraphQL, or custom integrations and can call tools elsewhere in the customer's stack.",
              "evidence_type": "official_release",
              "source_section": "Build on what you already have"
            }
          ],
          "note": "Sierra agents can consume external tools/systems through MCP."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "sierra_platform_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Sierra Trust Center",
              "url": "https://trust.sierra.ai/",
              "note": "Sierra's Trust Center identifies its conversational AI platform for customer-facing agents and publishes a current SOC 2 Type II audit report.",
              "evidence_type": "security_trust",
              "source_section": "Compliance / 3rd Party Assessments and Certifications"
            }
          ],
          "note": "Sierra documents SOC 2 Type II coverage for its AI-agent platform."
        }
      ]
    },
    {
      "agent_id": "AI-0044",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "gorgias_platform_ai_agent_data_and_actions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias Developers – REST API access tokens",
              "url": "https://developers.gorgias.com/docs/access-tokens-api-keys",
              "note": "Gorgias documents its REST API and role-scoped access tokens; the API exposes resources that include AI Agent-managed ticket fields and actions.",
              "evidence_type": "api_docs",
              "source_section": "Access Tokens / REST API"
            },
            {
              "title": "Gorgias Developers – Update ticket fields values",
              "url": "https://developers.gorgias.com/reference/update-ticket-custom-fields",
              "note": "The Gorgias REST API explicitly documents system-managed AI Agent Outcome and AI Intent ticket fields.",
              "evidence_type": "api_docs",
              "source_section": "Update ticket fields values"
            }
          ],
          "note": "Gorgias exposes REST API access to platform data that includes AI Agent-managed fields."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "gorgias_ai_agent_and_helpdesk",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias Help – View event logs for AI Agent Actions",
              "url": "https://helpcenter.gorgias.com/en-US/view-event-logs-for-ai-agent-actions-1059784",
              "note": "Gorgias documents per-action event logs whenever AI Agent makes an HTTP request to a connected app.",
              "evidence_type": "technical_docs",
              "source_section": "View an Action's event logs"
            },
            {
              "title": "Gorgias Help – View an audit log of changes to your account",
              "url": "https://helpcenter.gorgias.com/en-US/view-an-audit-log-of-changes-to-your-account-81841",
              "note": "Gorgias documents chronological account audit logs.",
              "evidence_type": "technical_docs",
              "source_section": "Audit logs"
            }
          ],
          "note": "Gorgias provides AI-action event logs and account audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "gorgias_account_audit_logs",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias Help – View an audit log of changes to your account",
              "url": "https://helpcenter.gorgias.com/en-US/view-an-audit-log-of-changes-to-your-account-81841",
              "note": "Gorgias states audit-log events are available for the past 12 months and are not kept beyond that period.",
              "evidence_type": "technical_docs",
              "source_section": "Audit log retention"
            }
          ],
          "note": "Gorgias account audit logs are retained for 12 months (365 days)."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "gorgias_helpdesk_including_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias – Security Policy",
              "url": "https://www.gorgias.com/security",
              "note": "Gorgias documents user roles and permissions controlling access to helpdesk areas and actions.",
              "evidence_type": "security_trust",
              "source_section": "User roles and permissions"
            }
          ],
          "note": "Gorgias provides role-based permissions."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "gorgias_helpdesk_including_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias Help – Set up custom SSO",
              "url": "https://helpcenter.gorgias.com/en-US/set-up-custom-sso-for-gorgias-2553083",
              "note": "Gorgias documents custom SSO using the OpenID Connect Discovery Protocol.",
              "evidence_type": "technical_docs",
              "source_section": "Configure Gorgias as an OIDC app"
            }
          ],
          "note": "Gorgias supports OIDC SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "gorgias_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias Help – How Gorgias's AI Agent works",
              "url": "https://helpcenter.gorgias.com/en-US/how-gorgiass-ai-agent-works-1997817",
              "note": "Gorgias states AI Agent data is maintained on Google Cloud Platform with globally distributed servers.",
              "evidence_type": "technical_docs",
              "source_section": "Regional hosting"
            }
          ],
          "note": "Gorgias AI Agent is delivered on Gorgias-managed GCP infrastructure."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "gorgias_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias Help – Security and privacy FAQ for Gorgias AI Agent",
              "url": "https://helpcenter.gorgias.com/en-US/security-and-privacy-faq-for-gorgias-ai-agent-1997987",
              "note": "Gorgias states AI Agent data is hosted on the closest regional server and EU merchants are hosted in the EU.",
              "evidence_type": "security_trust",
              "source_section": "Where Is My Data Stored?"
            }
          ],
          "note": "Gorgias AI Agent provides regional hosting, including EU hosting for EU merchants."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "gorgias_platform_including_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias Data Processing Agreement",
              "url": "https://www.gorgias.com/legal/data-processing-agreement",
              "note": "Gorgias documents industry-standard encryption technologies for Personal Data at rest as part of its Subscription Services security measures.",
              "evidence_type": "security_trust",
              "source_section": "Security of Personal Data / technical and organizational measures"
            }
          ],
          "note": "Gorgias documents encryption at rest for Subscription Services data."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS",
          "scope": "gorgias_platform_including_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias – Security Policy",
              "url": "https://www.gorgias.com/security",
              "note": "Gorgias states app data is sent exclusively through HTTPS TLS-encrypted connections.",
              "evidence_type": "security_trust",
              "source_section": "Security controls"
            }
          ],
          "note": "Gorgias documents TLS-encrypted connections."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "gorgias_ai_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gorgias Help – Security and privacy FAQ for Gorgias AI Agent",
              "url": "https://helpcenter.gorgias.com/en-US/security-and-privacy-faq-for-gorgias-ai-agent-1997987",
              "note": "Gorgias explicitly states Gorgias is SOC 2 Type II compliant in the security and privacy FAQ for AI Agent.",
              "evidence_type": "security_trust",
              "source_section": "Does AI Agent comply with data protection laws and AI regulations?"
            }
          ],
          "note": "Gorgias documents SOC 2 Type II compliance for the platform operating AI Agent."
        }
      ]
    },
    {
      "agent_id": "AI-0045",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "hubspot_account_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – View and export account activity history",
              "url": "https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history",
              "note": "HubSpot documents centralized audit logs for reviewing, filtering, and exporting user actions and security-related account activity.",
              "evidence_type": "technical_docs",
              "source_section": "View, filter, and export a centralized audit log"
            }
          ],
          "note": "HubSpot provides centralized account audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Create and assign permission sets",
              "url": "https://knowledge.hubspot.com/user-management/create-permission-sets",
              "note": "HubSpot documents creating custom permission sets from templates or from scratch with granular permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Create a permission set"
            }
          ],
          "note": "HubSpot Enterprise supports custom reusable permission sets/roles.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Create and assign permission sets",
              "url": "https://knowledge.hubspot.com/user-management/create-permission-sets",
              "note": "HubSpot documents reusable permission sets based on roles that grant consistent access to users.",
              "evidence_type": "technical_docs",
              "source_section": "Create a permission set"
            }
          ],
          "note": "HubSpot Enterprise provides role-oriented permission sets for access control.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot explicitly documents SCIM-based provisioning through Okta.",
              "evidence_type": "security_trust",
              "source_section": "Frequently Asked Questions / identity provider"
            }
          ],
          "note": "HubSpot Enterprise supports SCIM-based provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot explicitly documents SAML-based SSO for major identity providers.",
              "evidence_type": "security_trust",
              "source_section": "Frequently Asked Questions / identity provider"
            }
          ],
          "note": "HubSpot Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "hubspot_breeze_prospecting_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "HubSpot Marketplace – Prospecting Agent",
              "url": "https://ecosystem.hubspot.com/marketplace/listing/prospecting-agent",
              "note": "HubSpot lists Prospecting Agent as a HubSpot-built Breeze agent installed and operated in HubSpot, with workflow enrollment, monitoring, research, and outreach.",
              "evidence_type": "official_product_page",
              "source_section": "Prospecting Agent / Overview"
            }
          ],
          "note": "Breeze Prospecting Agent is delivered as a managed HubSpot agent."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "hubspot_platform_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Cloud Infrastructure and Data Hosting FAQ",
              "url": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
              "note": "HubSpot documents regional product infrastructure and account hosting in US, EU, Canada, and Australia.",
              "evidence_type": "security_trust",
              "source_section": "Where is HubSpot's product infrastructure hosted?"
            }
          ],
          "note": "HubSpot provides regional data-hosting options for the platform that hosts Breeze agents.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "hubspot_paid_accounts",
          "evidence": [
            {
              "title": "HubSpot Cloud Infrastructure and Data Hosting FAQ",
              "url": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
              "note": "HubSpot states Starter, Professional, and Enterprise accounts can change their assigned data center.",
              "evidence_type": "technical_docs",
              "source_section": "How are data centers assigned?"
            }
          ],
          "note": "Eligible paid HubSpot customers can change their account data-center region.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Security Program",
              "url": "https://legal.hubspot.com/security",
              "note": "HubSpot documents AES-256 encryption for product-server disks and long-term storage such as AWS S3.",
              "evidence_type": "security_trust",
              "source_section": "How does HubSpot encrypt data?"
            }
          ],
          "note": "HubSpot documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Security Program",
              "url": "https://legal.hubspot.com/security",
              "note": "HubSpot documents TLS 1.2 or 1.3 for sensitive product interactions including API calls and authenticated sessions.",
              "evidence_type": "security_trust",
              "source_section": "How does HubSpot encrypt data?"
            }
          ],
          "note": "HubSpot documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot states its Trust Center provides the HubSpot SOC 2 Type II report and that HubSpot AI runs on the same secure platform infrastructure.",
              "evidence_type": "security_trust",
              "source_section": "Security & compliance / HubSpot AI"
            }
          ],
          "note": "HubSpot documents SOC 2 Type II coverage for the platform hosting its AI features.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0046",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "salesforce_org_including_agentforce",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Monitor Setup Changes with Setup Audit Trail",
              "url": "https://help.salesforce.com/s/articleView?id=admin_monitorsetup.htm&language=en_US&type=5",
              "note": "Salesforce documents Setup Audit Trail and explicitly records changes made through AI agents in Setup with Agentforce.",
              "evidence_type": "technical_docs",
              "source_section": "Setup Audit Trail"
            }
          ],
          "note": "Salesforce provides audit trails that include Agentforce-mediated setup actions."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 180,
          "scope": "salesforce_setup_audit_trail",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Monitor Setup Changes with Setup Audit Trail",
              "url": "https://help.salesforce.com/s/articleView?id=admin_monitorsetup.htm&language=en_US&type=5",
              "note": "Salesforce states complete setup history is downloadable for the past 180 days and setup records are deleted after 180 days.",
              "evidence_type": "technical_docs",
              "source_section": "Setup Audit Trail retention"
            }
          ],
          "note": "Salesforce Setup Audit Trail retains setup records for 180 days."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "salesforce_org_including_agentforce_prospecting",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Set Up Record Access for Your Users",
              "url": "https://help.salesforce.com/s/articleView?id=sf.users_manage_sharing.htm&language=en_US&type=5",
              "note": "Salesforce documents creating and managing user roles within a role hierarchy to define record access.",
              "evidence_type": "technical_docs",
              "source_section": "Extend Record Access Vertically with the Role Hierarchy"
            }
          ],
          "note": "Salesforce organizations support administrator-defined roles and role hierarchies."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "salesforce_org_including_agentforce_prospecting",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Control Who Sees What",
              "url": "https://help.salesforce.com/s/articleView?id=security_data_access.htm&language=en_US&type=5",
              "note": "Salesforce documents role hierarchy, profiles, permission sets, and sharing rules as layered role/access controls.",
              "evidence_type": "technical_docs",
              "source_section": "Role hierarchy / permissions"
            }
          ],
          "note": "Salesforce provides role-based access control through roles, profiles, and permission sets."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "salesforce_org_including_agentforce_prospecting",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – SAML SSO with Salesforce as Service Provider",
              "url": "https://help.salesforce.com/s/articleView?id=sso_saml_setting_up.htm&language=de&type=0",
              "note": "Salesforce documents SAML-based SSO for Salesforce organizations.",
              "evidence_type": "technical_docs",
              "source_section": "SAML SSO"
            }
          ],
          "note": "Salesforce supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "salesforce_agentforce_prospecting",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Learn About Agentforce Prospecting",
              "url": "https://help.salesforce.com/s/articleView?id=sales.sales_agent_prospecting_learn_about.htm&language=de&type=5",
              "note": "Salesforce documents Agentforce Prospecting as a Salesforce sales agent enabled, built, managed, and monitored inside Salesforce.",
              "evidence_type": "technical_docs",
              "source_section": "Prospecting / Set Up Agentforce Prospecting"
            }
          ],
          "note": "Agentforce Prospecting is delivered within Salesforce's managed Agentforce/Sales Cloud environment."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "salesforce_hyperforce_org_including_agentforce",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Hyperforce General Information",
              "url": "https://help.salesforce.com/s/articleView?id=000388902&language=en_US&type=1",
              "note": "Salesforce documents Hyperforce as giving customers choice and control over where organization data resides.",
              "evidence_type": "technical_docs",
              "source_section": "What Is Salesforce Hyperforce?"
            }
          ],
          "note": "Salesforce Hyperforce provides data-residency options for Salesforce organizations."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "salesforce_hyperforce_org_including_agentforce",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Help – Hyperforce General Information",
              "url": "https://help.salesforce.com/s/articleView?id=000388902&language=en_US&type=1",
              "note": "Salesforce states customers can choose the region where their data resides on Hyperforce.",
              "evidence_type": "technical_docs",
              "source_section": "Hyperforce benefits"
            }
          ],
          "note": "Hyperforce customers can choose supported data regions."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "salesforce_shield_platform_encryption",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Salesforce Help – Customer Managed Key Options",
              "url": "https://help.salesforce.com/s/articleView?id=xcloud.security_shield_pe_cmk_options.htm&language=en_US&type=5",
              "note": "Salesforce documents customer-supplied and customer-managed key options for Shield Platform Encryption, including EKM, BYOK, and Cache-Only Keys.",
              "evidence_type": "technical_docs",
              "source_section": "Customer Managed Key Options"
            }
          ],
          "note": "Salesforce supports customer-managed encryption keys through Shield Platform Encryption."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "salesforce_hyperforce_org_including_agentforce",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Salesforce Architects – Data Protection Patterns",
              "url": "https://architect.salesforce.com/docs/architect/well-architected/guide/trust-data-protection-patterns.html",
              "note": "Salesforce states all Hyperforce data is encrypted at rest at the infrastructure level.",
              "evidence_type": "security_trust",
              "source_section": "Encryption at rest"
            }
          ],
          "note": "Hyperforce encrypts data at rest."
        }
      ]
    },
    {
      "agent_id": "AI-0047",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "hubspot_account_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – View and export account activity history",
              "url": "https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history",
              "note": "HubSpot documents centralized audit logs for reviewing, filtering, and exporting user actions and security-related account activity.",
              "evidence_type": "technical_docs",
              "source_section": "View, filter, and export a centralized audit log"
            }
          ],
          "note": "HubSpot provides centralized account audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Create and assign permission sets",
              "url": "https://knowledge.hubspot.com/user-management/create-permission-sets",
              "note": "HubSpot documents creating custom permission sets from templates or from scratch with granular permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Create a permission set"
            }
          ],
          "note": "HubSpot Enterprise supports custom reusable permission sets/roles.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Create and assign permission sets",
              "url": "https://knowledge.hubspot.com/user-management/create-permission-sets",
              "note": "HubSpot documents reusable permission sets based on roles that grant consistent access to users.",
              "evidence_type": "technical_docs",
              "source_section": "Create a permission set"
            }
          ],
          "note": "HubSpot Enterprise provides role-oriented permission sets for access control.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot explicitly documents SCIM-based provisioning through Okta.",
              "evidence_type": "security_trust",
              "source_section": "Frequently Asked Questions / identity provider"
            }
          ],
          "note": "HubSpot Enterprise supports SCIM-based provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot explicitly documents SAML-based SSO for major identity providers.",
              "evidence_type": "security_trust",
              "source_section": "Frequently Asked Questions / identity provider"
            }
          ],
          "note": "HubSpot Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "hubspot_data_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "HubSpot Marketplace – Data Agent",
              "url": "https://ecosystem.hubspot.com/marketplace/listing/data-agent",
              "note": "HubSpot lists Data Agent as a HubSpot-built Breeze agent that researches and writes insights directly into HubSpot CRM properties, Data Studio, and automations.",
              "evidence_type": "official_product_page",
              "source_section": "Data Agent / Overview / Features"
            }
          ],
          "note": "HubSpot Data Agent is delivered as a managed agent inside HubSpot."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "hubspot_platform_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Cloud Infrastructure and Data Hosting FAQ",
              "url": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
              "note": "HubSpot documents regional product infrastructure and account hosting in US, EU, Canada, and Australia.",
              "evidence_type": "security_trust",
              "source_section": "Where is HubSpot's product infrastructure hosted?"
            }
          ],
          "note": "HubSpot provides regional data-hosting options for the platform that hosts Breeze agents.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "hubspot_paid_accounts",
          "evidence": [
            {
              "title": "HubSpot Cloud Infrastructure and Data Hosting FAQ",
              "url": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
              "note": "HubSpot states Starter, Professional, and Enterprise accounts can change their assigned data center.",
              "evidence_type": "technical_docs",
              "source_section": "How are data centers assigned?"
            }
          ],
          "note": "Eligible paid HubSpot customers can change their account data-center region.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Security Program",
              "url": "https://legal.hubspot.com/security",
              "note": "HubSpot documents AES-256 encryption for product-server disks and long-term storage such as AWS S3.",
              "evidence_type": "security_trust",
              "source_section": "How does HubSpot encrypt data?"
            }
          ],
          "note": "HubSpot documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Security Program",
              "url": "https://legal.hubspot.com/security",
              "note": "HubSpot documents TLS 1.2 or 1.3 for sensitive product interactions including API calls and authenticated sessions.",
              "evidence_type": "security_trust",
              "source_section": "How does HubSpot encrypt data?"
            }
          ],
          "note": "HubSpot documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot states its Trust Center provides the HubSpot SOC 2 Type II report and that HubSpot AI runs on the same secure platform infrastructure.",
              "evidence_type": "security_trust",
              "source_section": "Security & compliance / HubSpot AI"
            }
          ],
          "note": "HubSpot documents SOC 2 Type II coverage for the platform hosting its AI features.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0048",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "hubspot_account_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – View and export account activity history",
              "url": "https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history",
              "note": "HubSpot documents centralized audit logs for reviewing, filtering, and exporting user actions and security-related account activity.",
              "evidence_type": "technical_docs",
              "source_section": "View, filter, and export a centralized audit log"
            }
          ],
          "note": "HubSpot provides centralized account audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Create and assign permission sets",
              "url": "https://knowledge.hubspot.com/user-management/create-permission-sets",
              "note": "HubSpot documents creating custom permission sets from templates or from scratch with granular permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Create a permission set"
            }
          ],
          "note": "HubSpot Enterprise supports custom reusable permission sets/roles.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Create and assign permission sets",
              "url": "https://knowledge.hubspot.com/user-management/create-permission-sets",
              "note": "HubSpot documents reusable permission sets based on roles that grant consistent access to users.",
              "evidence_type": "technical_docs",
              "source_section": "Create a permission set"
            }
          ],
          "note": "HubSpot Enterprise provides role-oriented permission sets for access control.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot explicitly documents SCIM-based provisioning through Okta.",
              "evidence_type": "security_trust",
              "source_section": "Frequently Asked Questions / identity provider"
            }
          ],
          "note": "HubSpot Enterprise supports SCIM-based provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "hubspot_enterprise_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot explicitly documents SAML-based SSO for major identity providers.",
              "evidence_type": "security_trust",
              "source_section": "Frequently Asked Questions / identity provider"
            }
          ],
          "note": "HubSpot Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "hubspot_company_research_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "HubSpot Knowledge Base – Set up and use the company research agent",
              "url": "https://knowledge.hubspot.com/ai/use-the-company-research-agent",
              "note": "HubSpot documents the Company Research Agent as an agent installed, configured, and run inside HubSpot Agent Hub / HubSpot accounts.",
              "evidence_type": "technical_docs",
              "source_section": "Set up / Configure / Use the company research agent"
            }
          ],
          "note": "The Company Research Agent is delivered and operated inside HubSpot's managed Agent Hub."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "hubspot_platform_including_breeze_agents",
          "evidence": [
            {
              "title": "HubSpot Cloud Infrastructure and Data Hosting FAQ",
              "url": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
              "note": "HubSpot documents regional product infrastructure and account hosting in US, EU, Canada, and Australia.",
              "evidence_type": "security_trust",
              "source_section": "Where is HubSpot's product infrastructure hosted?"
            }
          ],
          "note": "HubSpot provides regional data-hosting options for the platform that hosts Breeze agents.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "hubspot_paid_accounts",
          "evidence": [
            {
              "title": "HubSpot Cloud Infrastructure and Data Hosting FAQ",
              "url": "https://knowledge.hubspot.com/account-security/hubspot-cloud-infrastructure-and-data-hosting-frequently-asked-questions",
              "note": "HubSpot states Starter, Professional, and Enterprise accounts can change their assigned data center.",
              "evidence_type": "technical_docs",
              "source_section": "How are data centers assigned?"
            }
          ],
          "note": "Eligible paid HubSpot customers can change their account data-center region.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Security Program",
              "url": "https://legal.hubspot.com/security",
              "note": "HubSpot documents AES-256 encryption for product-server disks and long-term storage such as AWS S3.",
              "evidence_type": "security_trust",
              "source_section": "How does HubSpot encrypt data?"
            }
          ],
          "note": "HubSpot documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot Security Program",
              "url": "https://legal.hubspot.com/security",
              "note": "HubSpot documents TLS 1.2 or 1.3 for sensitive product interactions including API calls and authenticated sessions.",
              "evidence_type": "security_trust",
              "source_section": "How does HubSpot encrypt data?"
            }
          ],
          "note": "HubSpot documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "hubspot_platform_including_ai_features",
          "evidence": [
            {
              "title": "HubSpot – Security and Compliance",
              "url": "https://www.hubspot.com/security-and-compliance",
              "note": "HubSpot states its Trust Center provides the HubSpot SOC 2 Type II report and that HubSpot AI runs on the same secure platform infrastructure.",
              "evidence_type": "security_trust",
              "source_section": "Security & compliance / HubSpot AI"
            }
          ],
          "note": "HubSpot documents SOC 2 Type II coverage for the platform hosting its AI features.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0049",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "harvey_platform_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey – Security",
              "url": "https://www.harvey.ai/security",
              "note": "Harvey explicitly lists audit logs among enterprise-grade controls.",
              "evidence_type": "security_trust",
              "source_section": "Purpose-Built Security"
            },
            {
              "title": "Harvey – Security Addendum",
              "url": "https://www.harvey.ai/legal/security-addendum",
              "note": "Harvey contractually documents audit logging sufficient for monitoring, analysis, investigation, and reporting.",
              "evidence_type": "security_trust",
              "source_section": "Audit Logging"
            }
          ],
          "note": "Harvey provides platform audit logging."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "harvey_workspace",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey Help – Admin Guides",
              "url": "https://help.harvey.ai/topics/admin-guides",
              "note": "Harvey explicitly documents custom roles in Access Control & Permission Management.",
              "evidence_type": "technical_docs",
              "source_section": "Access Control & Permission Management"
            }
          ],
          "note": "Harvey supports custom roles."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "harvey_workspace",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey Help – Admin Guides",
              "url": "https://help.harvey.ai/topics/admin-guides",
              "note": "Harvey documents user roles, permissions, and access controls in workspace administration.",
              "evidence_type": "technical_docs",
              "source_section": "Access Control & Permission Management"
            }
          ],
          "note": "Harvey provides role-based access control."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "harvey_workspace",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey Help – Admin Guides",
              "url": "https://help.harvey.ai/topics/admin-guides",
              "note": "Harvey documents SCIM integration for automated user provisioning, deprovisioning, and group-based access management.",
              "evidence_type": "technical_docs",
              "source_section": "User & Access Management"
            }
          ],
          "note": "Harvey supports SCIM provisioning."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "harvey_platform_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey – Security",
              "url": "https://www.harvey.ai/security",
              "note": "Harvey explicitly lists SAML SSO among enterprise-grade controls.",
              "evidence_type": "security_trust",
              "source_section": "Purpose-Built Security"
            }
          ],
          "note": "Harvey supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "harvey_platform_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey – Security Addendum",
              "url": "https://www.harvey.ai/legal/security-addendum",
              "note": "Harvey states the computing services used to provide the Service are cloud-based and supplied through cloud service providers.",
              "evidence_type": "security_trust",
              "source_section": "Cloud Environment"
            }
          ],
          "note": "Harvey is delivered through a managed cloud environment."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "harvey_customer_data_and_content",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey – Security Addendum",
              "url": "https://www.harvey.ai/legal/security-addendum",
              "note": "Harvey documents regional storage and processing commitments for Customer Data and Content.",
              "evidence_type": "security_trust",
              "source_section": "Hosting Location of Customer Data and Content"
            }
          ],
          "note": "Harvey provides regional data-residency controls."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "harvey_customer_data_and_content",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey – Security Addendum",
              "url": "https://www.harvey.ai/legal/security-addendum",
              "note": "Harvey states the geographic region is specified in the order form and customers may request a separate specific geographic region where supported.",
              "evidence_type": "security_trust",
              "source_section": "Hosting Location of Customer Data and Content"
            }
          ],
          "note": "Harvey customers can select/request a supported geographic region."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "harvey_customer_data_and_content",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey – Security Addendum",
              "url": "https://www.harvey.ai/legal/security-addendum",
              "note": "Harvey states Customer Data and Content are encrypted at rest using AES 256-bit or better.",
              "evidence_type": "security_trust",
              "source_section": "Encryption"
            }
          ],
          "note": "Harvey documents AES-256-or-better encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "harvey_customer_data_and_content",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey – Security Addendum",
              "url": "https://www.harvey.ai/legal/security-addendum",
              "note": "Harvey states Customer Data and Content in transit over public or untrusted networks use TLS 1.2 or better.",
              "evidence_type": "security_trust",
              "source_section": "Encryption"
            }
          ],
          "note": "Harvey documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "harvey_platform_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Harvey – Security Addendum",
              "url": "https://www.harvey.ai/legal/security-addendum",
              "note": "Harvey contractually states its information security management system is assessed under SOC 2 Type II at least annually.",
              "evidence_type": "security_trust",
              "source_section": "Harvey Audits and Certifications"
            }
          ],
          "note": "Harvey documents annual SOC 2 Type II assessment."
        }
      ]
    },
    {
      "agent_id": "AI-0050",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "cocounsel_legal",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Thomson Reuters – How CoCounsel Legal delivers AI legal research you can trust",
              "url": "https://legal.thomsonreuters.com/blog/beyond-chatbots-how-cocounsel-legal-delivers-ai-legal-research-you-can-trust/",
              "note": "Thomson Reuters states CoCounsel Legal provides audit trails that document every AI interaction alongside access controls and compliance tracking.",
              "evidence_type": "official_release",
              "source_section": "The next generation of CoCounsel Legal"
            }
          ],
          "note": "CoCounsel Legal documents audit trails for AI interactions."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "cocounsel_legal_admin_permissions",
          "confidence": "medium",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Thomson Reuters CoCounsel Help – Administrator capabilities",
              "url": "https://www.thomsonreuters.com/en-us/help/cocounsel/legal/administration/admin-capabilities",
              "note": "CoCounsel administrators can configure granular user-level permissions to skills and capabilities.",
              "evidence_type": "technical_docs",
              "source_section": "Administrator capabilities"
            }
          ],
          "note": "CoCounsel supports administrator-configurable granular permissions; recorded as custom-role-like governance only within the documented admin-permission scope."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "cocounsel_legal",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Thomson Reuters CoCounsel Help – Administrator capabilities",
              "url": "https://www.thomsonreuters.com/en-us/help/cocounsel/legal/administration/admin-capabilities",
              "note": "CoCounsel documents an Administrator role with granular user-level permissions to skills and other CoCounsel capabilities.",
              "evidence_type": "technical_docs",
              "source_section": "Administrator capabilities"
            }
          ],
          "note": "CoCounsel Legal uses role-based administrative permissions."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "cocounsel_legal",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Thomson Reuters – CoCounsel Legal",
              "url": "https://legal.thomsonreuters.com/en/products/cocounsel-legal",
              "note": "Thomson Reuters documents CoCounsel Legal as its hosted legal AI product with secure access across web and Microsoft integrations.",
              "evidence_type": "official_product_page",
              "source_section": "CoCounsel Legal"
            }
          ],
          "note": "CoCounsel Legal is delivered as a managed Thomson Reuters service."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "cocounsel_legal",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "Thomson Reuters explicitly documents data-residency controls for CoCounsel Legal that keep information within required geographic boundaries.",
          "evidence": [
            {
              "title": "Thomson Reuters – Consumer vs. professional AI privacy standards for legal work",
              "url": "https://legal.thomsonreuters.com/blog/the-consumer-vs-professional-ai-privacy-standards-for-legal-work/",
              "note": "Thomson Reuters explicitly states in its official legal-industry privacy guidance that CoCounsel Legal provides data-residency controls to keep information within required geographic boundaries.",
              "evidence_type": "official_release",
              "source_section": "CoCounsel Legal addresses these corporate-specific needs"
            }
          ]
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "cocounsel_legal_user_content",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Thomson Reuters – CoCounsel",
              "url": "https://www.thomsonreuters.com/en/cocounsel",
              "note": "Thomson Reuters states symmetric AES-256 encryption protects CoCounsel user data at rest.",
              "evidence_type": "security_trust",
              "source_section": "How does Thomson Reuters protect user privacy and data?"
            }
          ],
          "note": "CoCounsel documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2",
          "scope": "cocounsel_legal_user_content",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Thomson Reuters – CoCounsel",
              "url": "https://www.thomsonreuters.com/en/cocounsel",
              "note": "Thomson Reuters states CoCounsel data in transit is secured using TLS 1.2.",
              "evidence_type": "security_trust",
              "source_section": "How does Thomson Reuters protect user privacy and data?"
            }
          ],
          "note": "CoCounsel documents TLS 1.2 encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "cocounsel_legal",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Thomson Reuters – CoCounsel Legal",
              "url": "https://legal.thomsonreuters.com/en/products/cocounsel-legal",
              "note": "The CoCounsel Legal product page explicitly states enterprise-grade security is SOC 2 certified.",
              "evidence_type": "security_trust",
              "source_section": "Security / SOC 2 and ISO 42001 certified"
            }
          ],
          "note": "Thomson Reuters documents SOC 2 certification for CoCounsel Legal."
        }
      ]
    },
    {
      "agent_id": "AI-0051",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "chatgpt_enterprise_compliance_platform",
          "evidence": [
            {
              "title": "OpenAI Help – Compliance Platform for Enterprise and Edu",
              "url": "https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers",
              "note": "OpenAI documents programmatic access to audit and compliance data through the Compliance/Admin API.",
              "evidence_type": "api_docs",
              "source_section": "Compliance API documentation / How it works"
            }
          ],
          "note": "ChatGPT Enterprise audit/compliance data is accessible through API.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "chatgpt_enterprise_compliance_platform",
          "evidence": [
            {
              "title": "OpenAI Help – Compliance Platform for Enterprise and Edu",
              "url": "https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers",
              "note": "OpenAI documents immutable compliance log events and audit/authentication/app logs for ChatGPT workspaces.",
              "evidence_type": "security_trust",
              "source_section": "How it works"
            }
          ],
          "note": "ChatGPT Enterprise provides compliance/audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 30,
          "scope": "chatgpt_enterprise_compliance_logs_platform",
          "evidence": [
            {
              "title": "OpenAI Help – Compliance Platform for Enterprise and Edu",
              "url": "https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers",
              "note": "OpenAI states the Compliance Logs Platform retains data for 30 days.",
              "evidence_type": "technical_docs",
              "source_section": "Data Retention with the Compliance API"
            }
          ],
          "note": "The ChatGPT Compliance Logs Platform documents 30-day retention.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "chatgpt_enterprise_compliance_platform",
          "evidence": [
            {
              "title": "OpenAI Help – Compliance Platform for Enterprise and Edu",
              "url": "https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers",
              "note": "OpenAI documents connecting Compliance Platform logs and metadata with SIEM tools and lists supported security integrations.",
              "evidence_type": "security_trust",
              "source_section": "How it works / Partner integrations"
            }
          ],
          "note": "ChatGPT Enterprise compliance logs can feed SIEM tooling.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "chatgpt_enterprise",
          "evidence": [
            {
              "title": "OpenAI Help – Managing feature access with RBAC in ChatGPT",
              "url": "https://help.openai.com/en/articles/11750701-managing-feature-access-with-role-based-access-control-in-chatgpt",
              "note": "OpenAI explicitly documents creating reusable custom roles with granular feature permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Overview / custom roles"
            }
          ],
          "note": "ChatGPT Enterprise supports custom roles.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "chatgpt_enterprise",
          "evidence": [
            {
              "title": "OpenAI Help – Managing feature access with RBAC in ChatGPT",
              "url": "https://help.openai.com/en/articles/11750701-managing-feature-access-with-role-based-access-control-in-chatgpt",
              "note": "OpenAI documents role-based access control for ChatGPT Enterprise with reusable roles and group-based assignments.",
              "evidence_type": "technical_docs",
              "source_section": "Overview / Availability"
            }
          ],
          "note": "ChatGPT Enterprise supports RBAC.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "chatgpt_enterprise",
          "evidence": [
            {
              "title": "OpenAI – Enterprise privacy",
              "url": "https://openai.com/enterprise-privacy/",
              "note": "OpenAI explicitly documents enterprise authentication via SAML SSO.",
              "evidence_type": "security_trust",
              "source_section": "Control"
            }
          ],
          "note": "ChatGPT Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "chatgpt_work_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenAI – ChatGPT Work",
              "url": "https://openai.com/de-DE/chatgpt-work/",
              "note": "OpenAI documents ChatGPT Work as a ChatGPT service available on web, mobile, macOS, and Windows that carries out work across connected tools, files, and apps.",
              "evidence_type": "official_product_page",
              "source_section": "ChatGPT Work / Ideen in die Tat umsetzen"
            }
          ],
          "note": "ChatGPT Work is delivered as a managed ChatGPT service."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "chatgpt_enterprise_edu",
          "evidence": [
            {
              "title": "OpenAI Help – Data residency and inference residency for ChatGPT",
              "url": "https://help.openai.com/en/articles/9903489-data-residency-for-chatgpt",
              "note": "OpenAI documents ChatGPT data residency that keeps in-scope customer content stored at rest in a specified geographic region for eligible Enterprise/Edu customers.",
              "evidence_type": "technical_docs",
              "source_section": "Overview / Eligibility"
            }
          ],
          "note": "Eligible ChatGPT Enterprise/Edu customers can use data residency.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "chatgpt_enterprise_edu",
          "evidence": [
            {
              "title": "OpenAI Help – Data residency and inference residency for ChatGPT",
              "url": "https://help.openai.com/en/articles/9903489-data-residency-for-chatgpt",
              "note": "OpenAI states eligible ChatGPT Enterprise/Edu customers can choose supported countries/regions for in-scope customer content.",
              "evidence_type": "technical_docs",
              "source_section": "Eligibility / supported regions"
            }
          ],
          "note": "Eligible customers can select a supported ChatGPT data-residency region.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "chatgpt_enterprise_edu",
          "evidence": [
            {
              "title": "OpenAI Help – Enterprise Key Management overview",
              "url": "https://help.openai.com/en/articles/20000943",
              "note": "OpenAI documents BYOK Enterprise Key Management for ChatGPT Enterprise/Edu using customer-managed AWS KMS, GCP, or Azure Key Vault keys.",
              "evidence_type": "security_trust",
              "source_section": "Overview"
            }
          ],
          "note": "ChatGPT Enterprise/Edu supports customer-managed encryption keys through EKM.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "openai_chatgpt_business_products",
          "evidence": [
            {
              "title": "OpenAI – Enterprise privacy",
              "url": "https://openai.com/enterprise-privacy/",
              "note": "OpenAI documents AES-256 encryption at rest for business data.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "OpenAI documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "openai_chatgpt_business_products",
          "evidence": [
            {
              "title": "OpenAI – Enterprise privacy",
              "url": "https://openai.com/enterprise-privacy/",
              "note": "OpenAI documents TLS 1.2+ encryption in transit between customers, OpenAI, and service providers.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "OpenAI documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "openai_chatgpt_business_products",
          "evidence": [
            {
              "title": "OpenAI – Security and privacy",
              "url": "https://openai.com/security-and-privacy/",
              "note": "OpenAI states its API and ChatGPT business products have undergone an independent SOC 2 Type 2 examination.",
              "evidence_type": "security_trust",
              "source_section": "Our accreditations / SOC 2 Type 2"
            }
          ],
          "note": "OpenAI documents SOC 2 Type 2 coverage for ChatGPT business products.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0052",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "manus_api_v2",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Manus API – Introduction",
              "url": "https://open.manus.im/docs/v2/introduction",
              "note": "Manus documents an HTTP API at api.manus.ai with endpoint-based task, file, webhook, skill, and agent operations.",
              "evidence_type": "api_docs",
              "source_section": "Base URL / API reference"
            }
          ],
          "note": "Manus provides a programmatic HTTP API with resource/action endpoints."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "manus_api_v2_tasks",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Manus API – Webhooks Overview",
              "url": "https://open.manus.im/docs/v2/webhooks-overview",
              "note": "Manus documents HTTPS webhook callbacks for task creation and task state-change events.",
              "evidence_type": "api_docs",
              "source_section": "Webhooks Guide / How Webhook Events Work"
            },
            {
              "title": "Manus API – webhook.create",
              "url": "https://open.manus.im/docs/v2/webhook.create",
              "note": "Manus documents creating webhook subscriptions that receive task-event POST notifications.",
              "evidence_type": "api_docs",
              "source_section": "webhook.create"
            }
          ],
          "note": "Manus supports outbound webhooks for task lifecycle events."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "manus_enterprise_compliance_api",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Manus Help – Manus Compliance APIs",
              "url": "https://help.manus.im/en/articles/13644620-manus-compliance-apis",
              "note": "Manus documents secure compliance APIs for e-discovery, legal hold, investigations, and SIEM-oriented governance use cases.",
              "evidence_type": "api_docs",
              "source_section": "Available APIs"
            }
          ],
          "note": "Manus exposes approved compliance/audit-oriented APIs for enterprise governance."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "manus_team_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Manus – Team Plan",
              "url": "https://manus.im/team",
              "note": "Manus lists audit logs among Team/Enterprise governance and compliance capabilities.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise-Level security"
            }
          ],
          "note": "Manus Team/Enterprise provides audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "manus_team",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Manus Help – Team roles and functions",
              "url": "https://help.manus.im/en/articles/11711764-what-roles-are-in-the-team-version-and-what-are-the-functions-of-each-role",
              "note": "Manus documents distinct Team roles—Owner, Super Admin, Admin, and Member—with different access and management permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Team roles"
            }
          ],
          "note": "Manus Team uses documented role-based permissions for team administration and access."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "manus_team_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Manus Help – Service Change Overview",
              "url": "https://help.manus.im/en/articles/16147909-service-change-overview-refunds-timeline-calculation-and-special-cases",
              "note": "Manus explicitly lists SCIM as a distinct Team/Enterprise subscription capability in its service-change documentation.",
              "evidence_type": "technical_docs",
              "source_section": "Subscriptions Covered"
            }
          ],
          "note": "Manus documents SCIM as an enterprise/team capability."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "manus_standard_sandbox_and_cloud_computer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Manus Help – What is the Cloud Computer?",
              "url": "https://help.manus.im/en/articles/15392111-what-is-the-cloud-computer",
              "note": "Manus documents its standard temporary sandbox and a fully isolated cloud-hosted persistent virtual machine used by Manus for execution.",
              "evidence_type": "technical_docs",
              "source_section": "How It Differs from the Temporary Sandbox / Cloud Computer vs. Manus Desktop"
            }
          ],
          "note": "Manus provides managed cloud execution environments for agent tasks."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "manus_service",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Manus – Security",
              "url": "https://manus.im/security",
              "note": "Manus lists SOC 2 Type 2 certification and provides a SOC 2 Type 2 attestation resource.",
              "evidence_type": "security_trust",
              "source_section": "Security / Resources"
            }
          ],
          "note": "Manus documents SOC 2 Type 2 certification."
        }
      ]
    },
    {
      "agent_id": "AI-0053",
      "claims": [
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "gemini_spark",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google I/O 2026 – Gemini Spark",
              "url": "https://blog.google/intl/de-de/unternehmen/technologie/sundar-pichai-io-2026/",
              "note": "Google states Gemini Spark runs on dedicated virtual machines in Google Cloud and is available independently of the user's laptop.",
              "evidence_type": "official_release",
              "source_section": "Agents / Gemini Spark"
            }
          ],
          "note": "Gemini Spark runs on Google-managed dedicated cloud VMs."
        }
      ]
    },
    {
      "agent_id": "AI-0054",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "claude_enterprise_cowork_compliance_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Access audit logs",
              "url": "https://support.claude.com/en/articles/9970975-access-audit-logs",
              "note": "Anthropic explicitly states audit log events are available in the Compliance API.",
              "evidence_type": "api_docs",
              "source_section": "Access audit logs"
            },
            {
              "title": "Claude Help – Monitor Claude Cowork activity with OpenTelemetry",
              "url": "https://support.claude.com/en/articles/14477985-monitor-claude-cowork-activity-with-opentelemetry",
              "note": "Anthropic states the Compliance API covers Cowork sessions.",
              "evidence_type": "api_docs",
              "source_section": "Joining OpenTelemetry data with the Compliance API"
            }
          ],
          "note": "Cowork audit/session data is available programmatically through Anthropic's Compliance API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "claude_enterprise_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Access audit logs",
              "url": "https://support.claude.com/en/articles/9970975-access-audit-logs",
              "note": "Anthropic documents Enterprise organization audit logs and states audit-log events are available in the Compliance API.",
              "evidence_type": "security_trust",
              "source_section": "Access audit logs"
            },
            {
              "title": "Claude Help – Monitor Claude Cowork activity with OpenTelemetry",
              "url": "https://support.claude.com/en/articles/14477985-monitor-claude-cowork-activity-with-opentelemetry",
              "note": "Anthropic states the Compliance API covers Cowork and provides one audit trail with sessions attributable to individual users.",
              "evidence_type": "security_trust",
              "source_section": "Joining OpenTelemetry data with the Compliance API"
            }
          ],
          "note": "Claude Enterprise provides audit logs that cover Cowork activity."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "claude_team_enterprise_cowork_events",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Use Claude Cowork on Team and Enterprise plans",
              "url": "https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans",
              "note": "Anthropic states Team and Enterprise owners can stream Cowork events to SIEM and observability tools through OpenTelemetry.",
              "evidence_type": "security_trust",
              "source_section": "OpenTelemetry"
            },
            {
              "title": "Claude Help – Monitor Claude Cowork activity with OpenTelemetry",
              "url": "https://support.claude.com/en/articles/14477985-monitor-claude-cowork-activity-with-opentelemetry",
              "note": "Anthropic documents configuring an OTLP endpoint for Cowork security events and routing them to SIEM/observability systems.",
              "evidence_type": "security_trust",
              "source_section": "Configure OpenTelemetry / Security and privacy considerations"
            }
          ],
          "note": "Cowork security and activity events can be exported to SIEM tooling through OpenTelemetry."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "claude_enterprise_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Manage custom roles on Enterprise plans",
              "url": "https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans",
              "note": "Anthropic explicitly documents custom roles that can grant or restrict access to Claude Cowork and other capabilities.",
              "evidence_type": "technical_docs",
              "source_section": "What are custom roles?"
            }
          ],
          "note": "Claude Enterprise custom roles can explicitly control Cowork access."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "claude_team_enterprise_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Roles and permissions",
              "url": "https://support.claude.com/en/articles/9267276-roles-and-permissions",
              "note": "Anthropic documents built-in Team/Enterprise roles and their permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Roles and permissions"
            },
            {
              "title": "Claude Help – Use Claude Cowork on Team and Enterprise plans",
              "url": "https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans",
              "note": "Anthropic documents organization- and group-level controls for enabling Cowork and Cowork cloud execution.",
              "evidence_type": "technical_docs",
              "source_section": "Admin controls"
            }
          ],
          "note": "Cowork access is governed through Claude organization roles and permissions."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "claude_enterprise_access_to_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Set up JIT or SCIM provisioning",
              "url": "https://support.claude.com/en/articles/13133195-set-up-jit-or-scim-provisioning",
              "note": "Anthropic documents SCIM directory sync for Enterprise organizations, including provisioning, deprovisioning, groups, and role mappings.",
              "evidence_type": "technical_docs",
              "source_section": "SCIM provisioning"
            },
            {
              "title": "Claude Help – Manage custom roles on Enterprise plans",
              "url": "https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans",
              "note": "Anthropic documents Cowork as a capability controlled through Enterprise custom roles and groups.",
              "evidence_type": "technical_docs",
              "source_section": "What are custom roles?"
            }
          ],
          "note": "Enterprise organizations can provision Cowork users and groups through SCIM."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "claude_team_enterprise_access_to_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Set up single sign-on (SSO)",
              "url": "https://support.claude.com/en/articles/13132885-set-up-single-sign-on-sso",
              "note": "Anthropic documents SAML SSO setup for Claude Team and Enterprise organizations, including Okta, Entra ID, Google, OneLogin, JumpCloud, and Duo SAML configurations.",
              "evidence_type": "technical_docs",
              "source_section": "Set up SSO with your Identity Provider"
            },
            {
              "title": "Claude Help – Use Claude Cowork on Team and Enterprise plans",
              "url": "https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans",
              "note": "Cowork is available within Team and Enterprise organizations and governed through organization controls.",
              "evidence_type": "technical_docs",
              "source_section": "Availability / Admin controls"
            }
          ],
          "note": "Team and Enterprise users accessing Cowork can use Claude's documented SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "claude_cowork_cloud_sessions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Use Claude Cowork on Team and Enterprise plans",
              "url": "https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans",
              "note": "Anthropic documents Cowork cloud sessions running on Anthropic infrastructure.",
              "evidence_type": "technical_docs",
              "source_section": "Where Cowork runs"
            }
          ],
          "note": "Cowork supports Anthropic-managed cloud execution."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "claude_cowork_local_sessions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Use Claude Cowork on Team and Enterprise plans",
              "url": "https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans",
              "note": "Anthropic documents local Cowork sessions that execute on the user's computer in an isolated virtual machine.",
              "evidence_type": "technical_docs",
              "source_section": "Where Cowork runs"
            }
          ],
          "note": "Cowork supports local execution on customer/user-managed computers."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "claude_cowork_remote_connectors",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Claude Help – Get started with custom connectors using remote MCP",
              "url": "https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp",
              "note": "Anthropic states custom connectors using remote MCP are available in Cowork and let Claude connect to and use existing remote MCP servers.",
              "evidence_type": "technical_docs",
              "source_section": "Custom connectors / Remote MCP servers"
            }
          ],
          "note": "Claude Cowork can act as an MCP client through remote custom connectors."
        }
      ]
    },
    {
      "agent_id": "AI-0055",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "perplexity_enterprise_comet",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity lists Audit Logs as an organization-wide Enterprise Max security feature.",
              "evidence_type": "technical_docs",
              "source_section": "Premium security features"
            }
          ],
          "note": "Perplexity Enterprise provides audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "perplexity_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Perplexity – Role-based access controls, API credentials, Brain for Max",
              "url": "https://www.perplexity.ai/en-GB/changelog/role-based-access-controls-api-credentials-and-brain-for-max",
              "note": "Perplexity documents Enterprise custom roles with granular permissions, SCIM group sync, and per-group controls.",
              "evidence_type": "official_release",
              "source_section": "Control Enterprise access with custom roles and SCIM groups"
            }
          ],
          "note": "Perplexity Enterprise supports custom roles with granular permissions."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "perplexity_enterprise_comet",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents role-based access controls for Enterprise organizations alongside its Research/Comet workflows.",
              "evidence_type": "technical_docs",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity Enterprise provides role-based access controls.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "perplexity_enterprise_comet",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity states Enterprise Max includes organization-wide SCIM and explicitly includes Research and Comet Assistant among its product capabilities.",
              "evidence_type": "technical_docs",
              "source_section": "Key Features / Premium security features"
            }
          ],
          "note": "Perplexity Enterprise supports SCIM for the product suite including Research and Comet.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "perplexity_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Perplexity – Enterprise security foundation",
              "url": "https://www.perplexity.ai/de/hub/blog/computer-for-enterprise",
              "note": "Perplexity explicitly states its Enterprise foundation includes SAML SSO, audit logs, and administrative controls.",
              "evidence_type": "official_release",
              "source_section": "Computer for Enterprise / Enterprise infrastructure"
            }
          ],
          "note": "Perplexity Enterprise supports SAML SSO; this applies to Enterprise products including Research and Comet."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "perplexity_comet_cloud_processing",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Perplexity – Comet Data Privacy & Security FAQ",
              "url": "https://www.perplexity.ai/comet/resources/articles/comet-data-privacy-security-faq-s",
              "note": "Perplexity documents Comet Assistant sending relevant context to Perplexity servers and processing local data on Perplexity servers to fulfill requested tasks.",
              "evidence_type": "security_trust",
              "source_section": "What data is transferred between Comet and Perplexity? / Does Comet store email content?"
            }
          ],
          "note": "Comet combines local browser execution with Perplexity-managed server-side processing."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "perplexity_comet_local_browser",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Perplexity – Comet Browser",
              "url": "https://www.perplexity.ai/comet/de",
              "note": "Perplexity documents Comet as an installable AI-powered browser whose assistant operates directly in the user's browser, navigating pages, clicking, typing, sending, and filling forms.",
              "evidence_type": "official_product_page",
              "source_section": "Comet ist mächtig / Comet holen"
            }
          ],
          "note": "The Comet browser and its browser-side agent surface run on the user's installed desktop browser environment."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents AES-256 encryption for data at rest.",
              "evidence_type": "security_trust",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity documents AES-256 encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.3",
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity – Finding Alpha with Perplexity",
              "url": "https://www.perplexity.ai/en-GB/hub/workshops/finding-alpha-with-perplexity-how-finance-teams-use-spaces-labs-and-comet",
              "note": "Perplexity documents TLS 1.3 for data in transit.",
              "evidence_type": "security_trust",
              "source_section": "Security & Privacy"
            }
          ],
          "note": "Perplexity documents TLS 1.3 encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "perplexity_enterprise_platform",
          "evidence": [
            {
              "title": "Perplexity Help – What is Enterprise Max?",
              "url": "https://www.perplexity.ai/help-center/en/articles/12310544-what-is-enterprise-max",
              "note": "Perplexity states Enterprise Max has SOC 2 Type II certification.",
              "evidence_type": "security_trust",
              "source_section": "How safe is Enterprise Max?"
            }
          ],
          "note": "Perplexity documents SOC 2 Type II compliance.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0056",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "browser_use_cloud_api_v4",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – Developers",
              "url": "https://browser-use.com/developers",
              "note": "Browser Use documents its API V4 REST interface for fully managed hosted web agents.",
              "evidence_type": "api_docs",
              "source_section": "Hosted Web Agents / API V4"
            },
            {
              "title": "Browser Use – Web Agent API",
              "url": "https://browser-use.com/web-agent-api",
              "note": "Browser Use documents REST and SDK access to create and manage agent runs.",
              "evidence_type": "api_docs",
              "source_section": "Web agent API"
            }
          ],
          "note": "Browser Use provides a documented REST API for hosted agents."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "browser_use_cloud_events",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – Developers",
              "url": "https://browser-use.com/developers",
              "note": "Browser Use lists Webhooks as a first-party developer interface alongside API V4, SDK, MCP, and OpenAPI.",
              "evidence_type": "api_docs",
              "source_section": "Developer toolkit"
            },
            {
              "title": "Browser Use – Web Agent API",
              "url": "https://browser-use.com/web-agent-api",
              "note": "Browser Use states webhooks deliver agent events to customer backends.",
              "evidence_type": "api_docs",
              "source_section": "MCP, n8n, webhooks?"
            }
          ],
          "note": "Browser Use Cloud supports webhook delivery of agent events."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "browser_use_cloud_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – Developers",
              "url": "https://browser-use.com/developers",
              "note": "Browser Use describes Hosted Web Agents as fully managed and running on managed browser infrastructure.",
              "evidence_type": "official_product_page",
              "source_section": "Hosted Web Agents"
            },
            {
              "title": "Browser Use GitHub – CLOUD.md",
              "url": "https://github.com/browser-use/browser-use/blob/main/CLOUD.md",
              "note": "The official Browser Use repository describes Cloud as the fully hosted product where remote browsers and agents are spun up on demand.",
              "evidence_type": "official_github",
              "source_section": "What is Browser Use Cloud?"
            }
          ],
          "note": "Browser Use offers fully managed hosted agents and browser infrastructure."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "browser_use_open_source_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use GitHub – README",
              "url": "https://github.com/browser-use/browser-use/blob/main/README.md",
              "note": "The official Browser Use repository documents running the open-source Browser Use agent locally from Python and states the Python library and browsers can be hosted on customer infrastructure.",
              "evidence_type": "official_github",
              "source_section": "Path 3: Python Library / FAQ"
            }
          ],
          "note": "Browser Use's open-source agent can run on customer-managed local or server infrastructure."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "browser_use_enterprise_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – Enterprise",
              "url": "https://browser-use.com/enterprise",
              "note": "Browser Use states EU data residency for browsers and agents is available to enterprise customers on request.",
              "evidence_type": "security_trust",
              "source_section": "Data control"
            }
          ],
          "note": "Browser Use Enterprise offers an EU data-residency option for agents and browsers."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "browser_use_enterprise_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – Enterprise",
              "url": "https://browser-use.com/enterprise",
              "note": "Browser Use states EU data residency for browsers and agents is available to enterprise customers on request.",
              "evidence_type": "security_trust",
              "source_section": "Data control"
            }
          ],
          "note": "Enterprise customers can request EU residency for Browser Use agents and browsers, providing a customer-selected regional residency option."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "browser_use_cloud_and_local_mcp",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – MCP server for browser automation",
              "url": "https://browser-use.com/mcp",
              "note": "Browser Use documents a hosted HTTP MCP server plus a local stdio MCP server that expose browser-agent tools to MCP clients.",
              "evidence_type": "technical_docs",
              "source_section": "Cloud, or your own Chrome / The six tools"
            },
            {
              "title": "Browser Use – MCP Server changelog",
              "url": "https://browser-use.com/changelog/21-11-2025",
              "note": "Browser Use documents the hosted MCP server endpoint and free open-source local stdio MCP server.",
              "evidence_type": "official_release",
              "source_section": "Cloud MCP Server"
            }
          ],
          "note": "Browser Use exposes both hosted and local MCP servers."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "browser_use_enterprise_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – Data Processing Addendum",
              "url": "https://browser-use.com/dpa",
              "note": "Browser Use states customer personal data at rest is encrypted with the industry-standard AES-256 algorithm.",
              "evidence_type": "security_trust",
              "source_section": "Annex – Specific Measures / Encryption"
            }
          ],
          "note": "Browser Use documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "browser_use_enterprise_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – Data Processing Addendum",
              "url": "https://browser-use.com/dpa",
              "note": "Browser Use states all data in transit is secured using HTTPS with TLS 1.2 or greater.",
              "evidence_type": "security_trust",
              "source_section": "Annex – Specific Measures / Encryption"
            }
          ],
          "note": "Browser Use documents HTTPS/TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "browser_use_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Browser Use – SOC 2 Compliance",
              "url": "https://browser-use.com/security/soc2",
              "note": "Browser Use states it is SOC 2 Type II compliant and provides the audit period and report-access details.",
              "evidence_type": "security_trust",
              "source_section": "SOC 2 Type II compliant"
            }
          ],
          "note": "Browser Use documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0057",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "business_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust lists an Open API and a RESTful API for custom integrations.",
              "evidence_type": "api_docs"
            },
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "The integration architecture explicitly lists a RESTful API.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Dust documents a developer-facing RESTful API; the former api.public/api.type split is consolidated into api.rest."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "business_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust lists webhook support for event-driven workflows.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Webhook-based integrations are supported."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust lists audit logs as an enterprise security capability.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Audit logs are documented."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust specifies 365-day audit-log retention.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Audit-log retention is documented as 365 days."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust lists role-based access control/permissions.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "RBAC is documented."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust lists SCIM provisioning.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "SCIM provisioning is documented."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust explicitly lists SSO with OIDC.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "OIDC SSO is documented."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust explicitly lists SSO with SAML.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "SAML SSO is documented."
        },
        {
          "path": "hosting.single_tenant",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Pricing",
              "url": "https://dust.tt/home/pricing",
              "note": "Enterprise includes single-tenant deployment.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "A single-tenant deployment option is documented."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "business_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Pricing",
              "url": "https://dust.tt/home/pricing",
              "note": "Dust lists US and EU data residency.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Regional data residency is documented."
        },
        {
          "path": "privacy.residency.region",
          "value": "EU",
          "scope": "business_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Pricing",
              "url": "https://dust.tt/home/pricing",
              "note": "EU is listed as a supported data-residency region.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "EU residency is available."
        },
        {
          "path": "privacy.residency.region",
          "value": "US",
          "scope": "business_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Pricing",
              "url": "https://dust.tt/home/pricing",
              "note": "US is listed as a supported data-residency region.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "US residency is available."
        },
        {
          "path": "privacy.training.customer_data",
          "value": false,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust states zero model training on customer data.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Customer data is documented as not used for model training."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "business_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust states agents can connect to company tools through MCP servers.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Dust acts as an MCP client for agent tool access."
        },
        {
          "path": "protocols.mcp.remote",
          "value": true,
          "scope": "business_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Pricing",
              "url": "https://dust.tt/home/pricing",
              "note": "The plan comparison explicitly lists native and remote MCP servers.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Remote MCP servers are supported."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – MCP and Enterprise Agents",
              "url": "https://dust.tt/blog/mcp-and-enterprise-agents-building-the-ai-operating-system-for-work",
              "note": "Dust explicitly describes its approach as both an MCP client and server.",
              "evidence_type": "official_release"
            }
          ],
          "note": "Dust documents MCP server capability in addition to client use."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust specifies AES-256 encryption at rest.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Encryption at rest is documented as AES-256."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.3",
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust specifies TLS 1.3 in transit.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "Encryption in transit is documented as TLS 1.3."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dust – Enterprise AI Agents",
              "url": "https://dust.tt/home/enterprise",
              "note": "Dust states SOC 2 Type II certification.",
              "evidence_type": "official_product_page"
            }
          ],
          "note": "SOC 2 Type II is documented."
        }
      ]
    },
    {
      "agent_id": "AI-0058",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "ari_enterprise_you_com_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "You.com documents audit logs as an enterprise security capability in the same enterprise platform context that includes ARI as a pre-built workflow agent.",
          "evidence": [
            {
              "title": "You.com – You.com vs. Glean",
              "url": "https://about.you.com/resources/you-com-vs-glean",
              "note": "The official comparison lists audit logs under You.com Enterprise security and pre-built workflow agents including ARI under the same enterprise offering.",
              "evidence_type": "official_product_page",
              "source_section": "Features at a Glance"
            }
          ]
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "ari_enterprise_you_com_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "You.com identifies ARI Enterprise as its enterprise research agent and documents SCIM as an enterprise security capability of the You.com platform used for enterprise agents.",
          "evidence": [
            {
              "title": "You.com – You.com vs. Glean",
              "url": "https://about.you.com/resources/you-com-vs-glean",
              "note": "The official comparison describes You.com Enterprise as offering pre-built workflow agents including ARI and lists SCIM among You.com Enterprise security and privacy controls.",
              "evidence_type": "official_product_page",
              "source_section": "Features at a Glance / Workflow Automation"
            }
          ]
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "you_com_ari",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "You.com – Standard Security Addendum",
              "url": "https://home.you.com/hubfs/Legal/You.com%20Standard%20Security%20Addendum%20%28May%202025%29.pdf?hsLang=en",
              "note": "You.com documents its Managed Service architecture as running in the provider's AWS account with customer data stored in provider-controlled services.",
              "evidence_type": "security_trust",
              "source_section": "Architecture / Managed Service"
            }
          ],
          "note": "You.com ARI is delivered on You.com's managed AWS service."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "ari_enterprise_you_com_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "You.com documents regional hosting for its Enterprise offering and separately identifies ARI Enterprise as the enterprise research agent using that platform.",
          "evidence": [
            {
              "title": "You.com – You.com vs. OpenAI",
              "url": "https://you.com/resources/best-ai-for-enterprise-you-vs-openai",
              "note": "You.com identifies ARI Enterprise in its enterprise offering and states that You.com Enterprise provides regional hosting for regulated data-residency requirements.",
              "evidence_type": "official_product_page",
              "source_section": "Security & data privacy"
            }
          ]
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "you_com_enterprise_services",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "You.com – Standard Security Addendum",
              "url": "https://home.you.com/hubfs/Legal/You.com%20Standard%20Security%20Addendum%20%28May%202025%29.pdf?hsLang=en",
              "note": "You.com states stored customer data is protected with industry-standard encryption at rest.",
              "evidence_type": "security_trust",
              "source_section": "Security Controls / Data Encryption"
            }
          ],
          "note": "You.com documents encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS",
          "scope": "you_com_services",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "You.com – Privacy Policy",
              "url": "https://you.com/privacy",
              "note": "You.com states all communications and websites are encrypted using TLS.",
              "evidence_type": "security_trust",
              "source_section": "General Security"
            }
          ],
          "note": "You.com documents TLS encryption for communications."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "you_com_ari",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "You.com – Financial Services / ARI",
              "url": "https://home.you.com/solutions/finance",
              "note": "You.com lists ARI within its enterprise platform and explicitly states enterprise-grade trust includes SOC 2 Type II certification.",
              "evidence_type": "security_trust",
              "source_section": "You.com for Financial Services"
            }
          ],
          "note": "You.com documents SOC 2 Type II coverage for the enterprise platform that includes ARI."
        }
      ]
    },
    {
      "agent_id": "AI-0059",
      "claims": [
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "notebooklm_deep_research",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google – NotebookLM adds Deep Research",
              "url": "https://blog.google/innovation-and-ai/models-and-research/google-labs/notebooklm-deep-research-file-types/",
              "note": "Google documents Deep Research as a NotebookLM capability that runs research in the background, browses hundreds of websites, and returns reports and sources into the user's NotebookLM notebook.",
              "evidence_type": "official_release",
              "source_section": "Expand your sources with Deep Research"
            }
          ],
          "note": "NotebookLM Deep Research is delivered as a managed NotebookLM service."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "gemini_notebook_enterprise_deep_research",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "Deep Research runs directly inside Gemini Notebook, and Google's Enterprise documentation states that Gemini Notebook honors data regionalization for enterprise deployments.",
          "evidence": [
            {
              "title": "Google Gemini Notebook Help – Add or discover new sources for your notebook",
              "url": "https://support.google.com/gemininotebook/answer/16215270",
              "note": "Google explicitly documents Gemini Deep Research as an agentic feature used directly within Gemini Notebook.",
              "evidence_type": "technical_docs",
              "source_section": "Deep Research"
            },
            {
              "title": "Google Gemini Notebook Help – Upgrade Gemini Notebook",
              "url": "https://support.google.com/gemininotebook/answer/16213268?hl=en",
              "note": "Google states that Gemini Notebook for Enterprise keeps uploaded files within the customer's GCP project and honors data regionalization.",
              "evidence_type": "technical_docs",
              "source_section": "Applicable Terms of Services & data handling"
            }
          ]
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "notebooklm_workspace_core_service",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Google Workspace Help – Turn Gemini Notebook on or off for users",
              "url": "https://knowledge.workspace.google.com/admin/generative-ai/gemini-notebook/turn-gemini-notebook-on-or-off-for-users?hl=en",
              "note": "Google's current Workspace documentation states Gemini Notebook supports SOC 1, SOC 2, SOC 3 and other compliance certifications.",
              "evidence_type": "security_trust",
              "source_section": "Gemini Notebook availability & compliance"
            }
          ],
          "note": "Gemini Notebook (formerly NotebookLM), including its Deep Research capability in Workspace, is covered by the current Google Workspace compliance documentation that explicitly lists SOC 2."
        }
      ]
    },
    {
      "agent_id": "AI-0060",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "grok_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI API – Enterprise controls",
              "url": "https://x.ai/api",
              "note": "SpaceXAI documents audit logging for enterprise Grok teams.",
              "evidence_type": "api_docs",
              "source_section": "SSO and audit logging"
            }
          ],
          "note": "Grok Enterprise provides audit logging."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "grok_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI for Business",
              "url": "https://x.ai/grok/business",
              "note": "SpaceXAI explicitly lists Custom Role Based Access Control for Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise / Security & compliance"
            }
          ],
          "note": "Grok Enterprise supports custom RBAC roles."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "grok_business_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI for Business",
              "url": "https://x.ai/grok/business",
              "note": "SpaceXAI lists role-based access control for Business/Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Security & compliance"
            }
          ],
          "note": "Grok Business/Enterprise supports RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "grok_for_business",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "xAI – Grok for Business",
              "url": "https://x.ai/grok/business",
              "note": "xAI explicitly lists SCIM among Grok for Business enterprise controls.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise-grade AI"
            }
          ],
          "note": "Grok for Business supports SCIM."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "grok_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI API – Enterprise controls",
              "url": "https://x.ai/api",
              "note": "SpaceXAI explicitly documents SAML SSO for enterprise teams.",
              "evidence_type": "api_docs",
              "source_section": "Enterprise API controls / SSO and audit logging"
            }
          ],
          "note": "Grok Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "grok_deepsearch",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "xAI – Grok 3 Beta: The Age of Reasoning Agents",
              "url": "https://x.ai/news/grok-3",
              "note": "xAI documents DeepSearch as its first Grok agent, available through Grok.com and X to eligible users.",
              "evidence_type": "official_release",
              "source_section": "Grok Agents: Combining Reasoning and Tool Use / What's Next"
            }
          ],
          "note": "Grok DeepSearch is delivered through xAI's managed Grok service."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "grok_for_business_enterprise_vault",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "xAI – Grok for Business",
              "url": "https://x.ai/grok/business",
              "note": "xAI states Enterprise Vault data is encrypted with customer-controlled keys.",
              "evidence_type": "security_trust",
              "source_section": "Secure, Enterprise Vault"
            }
          ],
          "note": "Grok for Business documents customer-controlled encryption keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "grok_enterprise_vault",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI – Grok Business and Enterprise",
              "url": "https://x.ai/news/grok-business",
              "note": "SpaceXAI states Enterprise Vault data is encrypted at rest under customer-controlled keys.",
              "evidence_type": "official_release",
              "source_section": "Ultimate privacy with Enterprise Vault"
            }
          ],
          "note": "Grok Enterprise Vault documents encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "grok_enterprise_vault",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI – Grok Business and Enterprise",
              "url": "https://x.ai/news/grok-business",
              "note": "SpaceXAI states Enterprise Vault data is encrypted in transit.",
              "evidence_type": "official_release",
              "source_section": "Ultimate privacy with Enterprise Vault"
            }
          ],
          "note": "Grok Enterprise Vault documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "grok_for_business",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "xAI – Grok for Business",
              "url": "https://x.ai/grok/business",
              "note": "xAI explicitly lists SOC 2 Type II for Grok for Business.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise-grade security"
            }
          ],
          "note": "Grok for Business documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0061",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "elicit_research_agent_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Elicit – Introducing Elicit Research Agent",
              "url": "https://elicit.com/blog/introducing-elicit-research-agent",
              "note": "Elicit explicitly states Research Agent is available through elicit.com or via API for integration into workflows.",
              "evidence_type": "official_release",
              "source_section": "Introducing Research Agent and BioDecisionBench"
            }
          ],
          "note": "Elicit Research Agent has official programmatic API access."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "elicit_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Elicit – SOC 2 Type II compliance",
              "url": "https://elicit.com/blog/elicit-achieves-soc-2",
              "note": "Elicit states SAML 2.0 SSO is supported for larger organizations.",
              "evidence_type": "security_trust",
              "source_section": "Privacy controls"
            }
          ],
          "note": "Elicit Enterprise supports SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "elicit_research_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Elicit – Introducing Elicit Research Agent",
              "url": "https://elicit.com/blog/introducing-elicit-research-agent",
              "note": "Elicit documents Research Agent as available directly through elicit.com as a hosted service.",
              "evidence_type": "official_release",
              "source_section": "Introducing Research Agent"
            }
          ],
          "note": "Elicit Research Agent is delivered as a managed Elicit service."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "elicit_enterprise_single_tenant",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Elicit – SOC 2 Type II compliance",
              "url": "https://elicit.com/blog/elicit-achieves-soc-2",
              "note": "Elicit states Enterprise customers receive dedicated, logically isolated AWS clusters with single tenancy.",
              "evidence_type": "security_trust",
              "source_section": "Sensitive academic or corporate research materials"
            }
          ],
          "note": "Elicit Enterprise provides dedicated logically isolated single-tenant AWS clusters."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256-GCM",
          "scope": "elicit_enterprise_research_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Elicit – SOC 2 Type II compliance",
              "url": "https://elicit.com/blog/elicit-achieves-soc-2",
              "note": "Elicit states uploaded documents and research projects are encrypted at rest with AES-256-GCM.",
              "evidence_type": "security_trust",
              "source_section": "Sensitive academic or corporate research materials"
            }
          ],
          "note": "Elicit documents AES-256-GCM encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "elicit_enterprise_research_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Elicit – SOC 2 Type II compliance",
              "url": "https://elicit.com/blog/elicit-achieves-soc-2",
              "note": "Elicit states uploaded documents and research projects are encrypted in transit using TLS 1.2+.",
              "evidence_type": "security_trust",
              "source_section": "Sensitive academic or corporate research materials"
            }
          ],
          "note": "Elicit documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "elicit_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Elicit – SOC 2 Type II compliance",
              "url": "https://elicit.com/blog/elicit-achieves-soc-2",
              "note": "Elicit states it achieved SOC 2 Type II compliance with a clean audit opinion.",
              "evidence_type": "security_trust",
              "source_section": "SOC 2 Type II Compliance"
            }
          ],
          "note": "Elicit documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0062",
      "claims": [
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "consensus_research_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Consensus Help – Research Agent",
              "url": "https://help.consensus.app/en/articles/12641232-research-agent",
              "note": "Consensus documents Research Agent as its AI research assistant accessed at consensus.app and used through the hosted Consensus search experience.",
              "evidence_type": "technical_docs",
              "source_section": "How to use Research Agent"
            }
          ],
          "note": "Consensus Research Agent is delivered as a managed Consensus web service."
        }
      ]
    },
    {
      "agent_id": "AI-0063",
      "claims": [
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "jetbrains_junie_local",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "JetBrains – Junie Local",
              "url": "https://blog.jetbrains.com/junie/2026/08/junie-local-launch/",
              "note": "JetBrains states Junie Local runs entirely on the user's Mac with the model and agent loop on-device and no code leaving the machine.",
              "evidence_type": "official_release",
              "source_section": "Our first step into on-device coding agents"
            }
          ],
          "note": "Junie supports a fully local user-managed runtime."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "jetbrains_junie_ide_cli",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Junie Documentation – Add and configure MCP servers",
              "url": "https://junie.jetbrains.com/docs/junie-cli-mcp-configuration.html",
              "note": "JetBrains documents Junie CLI connecting to local or remote MCP servers and using their tools.",
              "evidence_type": "technical_docs",
              "source_section": "Add an MCP server"
            }
          ],
          "note": "Junie acts as an MCP client for configured local and remote servers."
        }
      ]
    },
    {
      "agent_id": "AI-0064",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "gemini_cli_enterprise_telemetry",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gemini CLI Docs – Gemini CLI for the enterprise",
              "url": "https://geminicli.com/docs/cli/enterprise/",
              "note": "Google documents a Telemetry and auditing configuration for Gemini CLI that sends telemetry to a central location and tracks tool usage and other events.",
              "evidence_type": "technical_docs",
              "source_section": "Telemetry and auditing"
            }
          ],
          "note": "Gemini CLI provides configurable centralized telemetry specifically documented for auditing and monitoring."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "gemini_cli_enterprise_telemetry",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gemini CLI Docs – Observability with OpenTelemetry",
              "url": "https://geminicli.com/docs/cli/telemetry/",
              "note": "Google documents exporting Gemini CLI logs, metrics, and traces through OpenTelemetry to external backends including Datadog and other OTLP-compatible systems.",
              "evidence_type": "technical_docs",
              "source_section": "OpenTelemetry integration / Configuration"
            },
            {
              "title": "Gemini CLI Docs – Gemini CLI for the enterprise",
              "url": "https://geminicli.com/docs/cli/enterprise/",
              "note": "Google frames centralized telemetry as an enterprise auditing and monitoring mechanism for tracking tool usage and other events.",
              "evidence_type": "technical_docs",
              "source_section": "Telemetry and auditing"
            }
          ],
          "note": "Gemini CLI audit telemetry can be exported through OpenTelemetry to external observability/SIEM-compatible backends."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "gemini_cli_local_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gemini CLI Docs – Installation, execution, and releases",
              "url": "https://geminicli.com/docs/get-started/installation/",
              "note": "Google documents installing Gemini CLI on macOS, Windows, or Linux and running it locally with the gemini command, including execution from source or in a local container.",
              "evidence_type": "technical_docs",
              "source_section": "Install Gemini CLI / Run Gemini CLI"
            }
          ],
          "note": "Gemini CLI can run on user/customer-managed local infrastructure rather than requiring a managed hosted agent runtime."
        },
        {
          "path": "protocols.a2a.client",
          "value": true,
          "scope": "gemini_cli_remote_subagents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gemini CLI Docs – Remote Subagents",
              "url": "https://geminicli.com/docs/core/remote-agents/",
              "note": "Google documents Gemini CLI connecting to compliant remote subagents using the Agent-to-Agent (A2A) protocol and delegating tasks to them.",
              "evidence_type": "technical_docs",
              "source_section": "Remote Subagents / Agent-to-Agent (A2A)"
            }
          ],
          "note": "Gemini CLI acts as an A2A client when delegating to remote subagents."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "gemini_cli_a2a_server",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "note": "Gemini CLI ships a dedicated A2A server package that uses the official A2A JavaScript SDK; the current development-tool specification builds on the A2A protocol for clients communicating with the Gemini CLI agent.",
          "evidence": [
            {
              "title": "Google Gemini CLI – A2A server package",
              "url": "https://github.com/google-gemini/gemini-cli/blob/main/packages/a2a-server/package.json",
              "note": "The official Gemini CLI repository contains the packages/a2a-server package and declares @a2a-js/sdk as a runtime dependency.",
              "evidence_type": "official_github",
              "source_section": "packages/a2a-server/package.json"
            },
            {
              "title": "Google Gemini CLI – A2A Development-Tool Extension RFC",
              "url": "https://github.com/google-gemini/gemini-cli/blob/main/packages/a2a-server/development-extension-rfc.md",
              "note": "Google documents client-to-agent and server-to-client communication for the Gemini CLI agent as an extension built on the existing A2A protocol, including Agent Card and message/stream semantics.",
              "evidence_type": "official_github",
              "source_section": "Overview / Communication Flow"
            }
          ]
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "gemini_cli_remote_subagents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gemini CLI Docs – Remote Subagents",
              "url": "https://geminicli.com/docs/core/remote-agents/",
              "note": "Google explicitly states Gemini CLI supports connecting to remote subagents using the Agent-to-Agent (A2A) protocol.",
              "evidence_type": "technical_docs",
              "source_section": "Remote Subagents"
            }
          ],
          "note": "A2A is an explicitly supported interoperability protocol in Gemini CLI."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "gemini_cli",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Gemini CLI Docs – MCP servers",
              "url": "https://geminicli.com/docs/tools/mcp-server/",
              "note": "Google documents Gemini CLI discovering, connecting to, and executing tools from configured MCP servers.",
              "evidence_type": "technical_docs",
              "source_section": "Core integration architecture / MCP server configuration"
            }
          ],
          "note": "Gemini CLI acts as an MCP client for configured MCP servers."
        }
      ]
    },
    {
      "agent_id": "AI-0065",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "duo_agent_platform_flows",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – Flows API",
              "url": "https://docs.gitlab.com/api/duo_agent_platform_flows/",
              "note": "GitLab documents API endpoints for creating, managing, and triggering Duo Agent Platform flows.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Duo Agent Platform flows have a documented API surface."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "duo_related_gitlab_audit_events",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – Audit events",
              "url": "https://docs.gitlab.com/user/compliance/audit_events/",
              "note": "GitLab documents access to project audit events through the Audit Events API and identifies AI agent sessions as audit events.",
              "evidence_type": "api_docs"
            },
            {
              "title": "GitLab Docs – Audit event schema and examples",
              "url": "https://docs.gitlab.com/user/compliance/audit_event_schema/",
              "note": "GitLab documents duo_related audit-event fields for Duo Agent Platform activity, enabling identification in API/SIEM workflows.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Duo-related audit events are accessible through GitLab audit-event APIs."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "duo_agent_sessions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – Audit AI events",
              "url": "https://docs.gitlab.com/user/ai-governance/ai-audit-events/",
              "note": "GitLab documents a unified audit record for Duo agent activity, with comprehensive audit artifacts per agent session.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Duo Agent Platform sessions generate dedicated AI audit events."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "gitlab_self_managed_and_dedicated_ai_audit_events",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – Audit event streaming for instances",
              "url": "https://docs.gitlab.com/administration/compliance/audit_event_streaming/",
              "note": "GitLab documents streaming Duo Agent Platform AI audit events to active external audit-event destinations on Self-Managed and Dedicated.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "GitLab can stream AI audit events to external destinations suitable for SIEM ingestion."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "gitlab_duo_agent_platform_group_and_project_controls",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – Control GitLab Duo Agent Platform availability",
              "url": "https://docs.gitlab.com/user/duo_agent_platform/turn_on_off/",
              "note": "GitLab requires the Owner role to control Agent Platform availability at top-level group or instance scope.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "GitLab Docs – Custom agents",
              "url": "https://docs.gitlab.com/user/duo_agent_platform/agents/custom/",
              "note": "GitLab documents role-gated enablement and management of custom agents at group and project levels.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "GitLab Duo Agent Platform administration and agent enablement are governed by GitLab roles."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "gitlab_com_group_identity_governing_agent_platform_access",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – Configure SCIM for GitLab.com groups",
              "url": "https://docs.gitlab.com/user/group/saml_sso/scim_setup/",
              "note": "GitLab supports SCIM provisioning and deprovisioning of group members through the group identity layer.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "GitLab Docs – Control GitLab Duo Agent Platform availability",
              "url": "https://docs.gitlab.com/user/duo_agent_platform/turn_on_off/",
              "note": "Agent Platform availability is controlled at GitLab group scope, so group identity membership governs access.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "GitLab.com group membership used for Agent Platform access can be provisioned with SCIM."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "gitlab_com",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – Agents",
              "url": "https://docs.gitlab.com/user/duo_agent_platform/agents/",
              "note": "GitLab lists GitLab.com as a supported offering for Duo Agent Platform agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "GitLab.com provides a vendor-managed Duo Agent Platform deployment."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "gitlab_self_managed",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – Agents",
              "url": "https://docs.gitlab.com/user/duo_agent_platform/agents/",
              "note": "GitLab lists GitLab Self-Managed as a supported offering for Duo Agent Platform agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Duo Agent Platform is supported on GitLab Self-Managed."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "gitlab_duo_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – GitLab MCP clients",
              "url": "https://docs.gitlab.com/user/gitlab_duo/model_context_protocol/mcp_clients/",
              "note": "GitLab documents Duo Agentic Chat and Software Development Flow as MCP clients that connect to external MCP servers.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "GitLab Duo Agent Platform features can consume external MCP tools as MCP clients."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "gitlab_instance_with_duo_agent_platform_toolset",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "GitLab Docs – GitLab MCP server",
              "url": "https://docs.gitlab.com/user/model_context_protocol/mcp_server/",
              "note": "GitLab documents its MCP server and an opt-in duo_agent_platform toolset for exposing Duo Agent Platform operations to MCP-compatible clients.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "GitLab exposes an MCP server with a Duo Agent Platform toolset."
        }
      ]
    },
    {
      "agent_id": "AI-0066",
      "claims": [
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "augment_cloud_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment documents event-driven Cloud Agent automation triggered from webhooks, schedules, and repository/security events.",
              "evidence_type": "official_product_page",
              "source_section": "Event driven Automation"
            }
          ],
          "note": "Augment Cloud Agents support webhook-triggered automation."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists audit logs and versioned/auditable agent configuration history.",
              "evidence_type": "official_product_page",
              "source_section": "History / Audit logs + SIEM"
            }
          ],
          "note": "Augment Enterprise provides audit logs."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists 'Audit logs + SIEM' as an enterprise capability.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security capabilities"
            }
          ],
          "note": "Augment Enterprise supports audit/SIEM integration."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists granular RBAC.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security capabilities"
            }
          ],
          "note": "Augment Enterprise provides granular RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists SCIM among enterprise identity controls.",
              "evidence_type": "official_product_page",
              "source_section": "SAML / OIDC / SCIM"
            }
          ],
          "note": "Augment Enterprise supports SCIM."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists OIDC enterprise SSO.",
              "evidence_type": "official_product_page",
              "source_section": "SAML / OIDC / SCIM"
            }
          ],
          "note": "Augment Enterprise supports OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists SAML enterprise SSO.",
              "evidence_type": "official_product_page",
              "source_section": "SAML / OIDC / SCIM"
            }
          ],
          "note": "Augment Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "augment_cloud_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment documents managed Cloud Agents with sandboxed agent execution.",
              "evidence_type": "official_product_page",
              "source_section": "Cloud Agents / Sandboxed agent execution"
            }
          ],
          "note": "Augment provides managed Cloud Agent execution."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists VPC deployment and single-tenant instances.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security capabilities"
            }
          ],
          "note": "Augment Enterprise supports VPC/private deployment."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists on-prem deployment as an enterprise capability.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security capabilities"
            }
          ],
          "note": "Augment Enterprise supports on-prem deployment."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "augment_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists data-residency controls among enterprise capabilities.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security capabilities"
            }
          ],
          "note": "Augment Enterprise provides data-residency controls."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "augment_code_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Meet Augment Agent",
              "url": "https://www.augmentcode.com/blog/meet-augment-agent",
              "note": "Augment states the Agent embraces MCP to access external tools and systems, with examples of infrastructure MCP integrations.",
              "evidence_type": "official_release",
              "source_section": "The Power of Context – Memories & Tools"
            }
          ],
          "note": "Augment Agent consumes tools and context exposed through MCP."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "augment_enterprise_cmek",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Cloud Agents",
              "url": "https://www.augmentcode.com/product/cloud-agents",
              "note": "Augment explicitly lists CMEK encryption among enterprise security capabilities.",
              "evidence_type": "security_trust",
              "source_section": "CMEK encryption"
            }
          ],
          "note": "Augment Enterprise supports customer-managed encryption keys."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "augment_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Augment Code – Security & Privacy",
              "url": "https://www.augmentcode.com/security",
              "note": "Augment states it is SOC 2 Type II attested.",
              "evidence_type": "security_trust",
              "source_section": "Certifications & Compliance"
            }
          ],
          "note": "Augment documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0067",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "openhands_cloud_api",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "OpenHands Docs – Cloud API Overview",
              "url": "https://docs.openhands.dev/openhands/usage/cloud/cloud-api",
              "note": "OpenHands documents a Cloud REST API with authenticated V1 HTTP endpoints for starting conversations and retrieving their status.",
              "evidence_type": "api_docs",
              "source_section": "Cloud API Overview / API Usage Example (V1)"
            }
          ],
          "note": "OpenHands Cloud exposes a documented REST API for programmatic agent conversations."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "openhands_enterprise_agent_control_plane",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenHands – Enterprise Agent Control Plane",
              "url": "https://www.openhands.dev/blog/openhands-enterprise-agent-control-plane",
              "note": "OpenHands introduces Enterprise as an agent control plane built to provide centralized visibility and reliable audit trails for organization-wide agent activity.",
              "evidence_type": "official_release",
              "source_section": "From Agents to Systems / control and observe"
            }
          ],
          "note": "OpenHands Enterprise provides centralized auditability for agent activity."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "openhands_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenHands Enterprise",
              "url": "https://www.openhands.dev/enterprise",
              "note": "OpenHands explicitly lists RBAC and multi-user support as built-in Enterprise capabilities.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise integrations included"
            }
          ],
          "note": "OpenHands Enterprise provides RBAC."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "openhands_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenHands – Pricing",
              "url": "https://www.openhands.dev/pricing",
              "note": "OpenHands lists Enterprise SAML / SSO for its enterprise offering.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "OpenHands Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "openhands_saas",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenHands – Pricing",
              "url": "https://www.openhands.dev/pricing",
              "note": "OpenHands documents hosted SaaS cloud access alongside local and self-hosted options.",
              "evidence_type": "official_product_page",
              "source_section": "SaaS / Individual"
            }
          ],
          "note": "OpenHands offers a managed SaaS runtime."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "openhands_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenHands Enterprise",
              "url": "https://www.openhands.dev/enterprise",
              "note": "OpenHands documents Enterprise self-hosting inside the customer's VPC via Kubernetes.",
              "evidence_type": "official_product_page",
              "source_section": "Self-hosted in your VPC"
            }
          ],
          "note": "OpenHands Enterprise supports deployment inside a customer VPC."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "openhands_open_source_and_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenHands – Pricing",
              "url": "https://www.openhands.dev/pricing",
              "note": "OpenHands explicitly documents local open-source operation and an Enterprise self-hosted option, including deployment in the customer's VPC.",
              "evidence_type": "official_product_page",
              "source_section": "Local / SaaS or Self-hosted / Compare plans"
            }
          ],
          "note": "OpenHands supports local and enterprise self-hosted deployment."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "openhands_agent_sessions",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "OpenHands Docs – MCP Servers",
              "url": "https://docs.openhands.dev/openhands/usage/cli/mcp-servers",
              "note": "OpenHands documents adding HTTP, SSE, and stdio MCP servers; enabled server tools are automatically available to the agent.",
              "evidence_type": "technical_docs",
              "source_section": "Overview / Adding Servers / Workflow"
            }
          ],
          "note": "OpenHands agents can consume tools and context from configured MCP servers."
        }
      ]
    },
    {
      "agent_id": "AI-0068",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "qodo_git_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Pricing",
              "url": "https://www.qodo.ai/pricing/",
              "note": "Qodo Enterprise explicitly includes audit logs.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            },
            {
              "title": "Qodo – Official Site",
              "url": "https://www.qodo.ai/",
              "note": "Qodo describes an audit trail recording issues and compliance flags for traceability.",
              "evidence_type": "official_product_page",
              "source_section": "Governance layer / Audit trail"
            }
          ],
          "note": "Qodo Enterprise provides audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "qodo_git_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Qodo Git",
              "url": "https://www.qodo.ai/features/qodo-git/",
              "note": "Qodo documents RBAC for its enterprise code-review platform.",
              "evidence_type": "official_product_page",
              "source_section": "Secure and compliant"
            },
            {
              "title": "Qodo Docs – Users",
              "url": "https://docs.qodo.ai/qodo-documentation/management-portal/users",
              "note": "Qodo documents organization and team roles with scoped permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Understanding User Roles"
            }
          ],
          "note": "Qodo provides role-based access control."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "qodo_git_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Pricing",
              "url": "https://www.qodo.ai/pricing/",
              "note": "Qodo Enterprise explicitly includes SSO / SAML.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise / security & deployment"
            }
          ],
          "note": "Qodo Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "qodo_git",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Qodo Git",
              "url": "https://www.qodo.ai/features/qodo-git/",
              "note": "Qodo documents Qodo Git as its AI PR review system integrated into pull-request workflows and offered as part of Qodo's product platform.",
              "evidence_type": "official_product_page",
              "source_section": "AI code review built for real issues"
            }
          ],
          "note": "Qodo Git is delivered as a managed Qodo code-review service."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "qodo_git_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Enterprise",
              "url": "https://www.qodo.ai/solutions/enterprise/",
              "note": "Qodo documents VPC and air-gapped enterprise deployment options.",
              "evidence_type": "official_product_page",
              "source_section": "Secure, Private, and Enterprise-Ready"
            }
          ],
          "note": "Qodo supports private VPC and air-gapped deployment."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "qodo_git_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Qodo Git",
              "url": "https://www.qodo.ai/features/qodo-git/",
              "note": "Qodo documents on-prem deployment for Qodo's enterprise code-review platform.",
              "evidence_type": "official_product_page",
              "source_section": "Deploy anywhere / Enterprise security"
            }
          ],
          "note": "Qodo Git supports on-premises deployment."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "qodo_service_personal_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Data Processing Addendum",
              "url": "https://www.qodo.ai/data-processing-addendum/",
              "note": "Qodo's DPA explicitly requires encryption of processed personal data at rest as part of its additional safeguards.",
              "evidence_type": "security_trust",
              "source_section": "Part 3 – Additional Safeguards"
            }
          ],
          "note": "Qodo documents encryption at rest for service personal data."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "qodo_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Enterprise",
              "url": "https://www.qodo.ai/solutions/enterprise/",
              "note": "Qodo states enterprise data is encrypted in transit.",
              "evidence_type": "security_trust",
              "source_section": "Security and compliance"
            }
          ],
          "note": "Qodo documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "qodo_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qodo – Official Site",
              "url": "https://www.qodo.ai/",
              "note": "Qodo states it is SOC 2 Type II certified through independent audit.",
              "evidence_type": "security_trust",
              "source_section": "Security & compliance"
            }
          ],
          "note": "Qodo documents SOC 2 Type II certification."
        }
      ]
    },
    {
      "agent_id": "AI-0069",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Admin Audit Logs API",
              "url": "https://docs.mistral.ai/api/endpoint/beta/admin/audit-logs",
              "note": "Mistral documents GET /v1/admin/audit-logs for programmatic organization audit-log access.",
              "evidence_type": "api_docs",
              "source_section": "Get Audit Logs"
            }
          ],
          "note": "Mistral Enterprise exposes audit logs through Admin API.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Audit logs",
              "url": "https://docs.mistral.ai/admin/monitor-comply/audit-logs/overview",
              "note": "Mistral documents Enterprise audit logs across Studio and Vibe, including user, API-key, security, and Vibe interaction events.",
              "evidence_type": "technical_docs",
              "source_section": "Audit logs / What gets logged"
            }
          ],
          "note": "Mistral Enterprise provides audit logs covering Vibe.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Admin",
              "url": "https://docs.mistral.ai/admin",
              "note": "Mistral documents role-based access control for organization members, groups, roles, and permissions across workspaces including Vibe.",
              "evidence_type": "technical_docs",
              "source_section": "Identity and access (RBAC)"
            }
          ],
          "note": "Mistral Enterprise supports RBAC.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Admin SCIM API",
              "url": "https://docs.mistral.ai/api/endpoint/beta/admin/scim",
              "note": "Mistral documents SCIM user-provisioning mode and SCIM synchronization endpoints requiring SAML authentication.",
              "evidence_type": "api_docs",
              "source_section": "Beta Admin Scim Endpoints"
            }
          ],
          "note": "Mistral Enterprise supports SCIM provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Create your organization",
              "url": "https://docs.mistral.ai/getting-started/quickstarts/admin/create-organization",
              "note": "Mistral documents SAML-based SSO for Enterprise organization authentication across Studio and Vibe.",
              "evidence_type": "technical_docs",
              "source_section": "Security and monitoring"
            }
          ],
          "note": "Mistral Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "mistral_vibe",
          "evidence": [
            {
              "title": "Mistral – Vibe",
              "url": "https://mistral.ai/products/vibe/",
              "note": "Mistral documents Vibe as its hosted work-and-code agent and supports launching coding tasks directly in Vibe with remote agents.",
              "evidence_type": "official_product_page",
              "source_section": "Vibe / FAQ"
            }
          ],
          "note": "Mistral Vibe provides a managed service/runtime.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "mistral_vibe_code_local_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Mistral Docs – Vibe Code",
              "url": "https://docs.mistral.ai/vibe/code/overview",
              "note": "Mistral documents running Vibe Code against a local checkout through the CLI or VS Code extension with local filesystem and shell access.",
              "evidence_type": "technical_docs",
              "source_section": "Vibe Code overview"
            }
          ],
          "note": "Vibe Code supports a local customer/user-managed runtime via CLI or VS Code."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "mistral_vibe_enterprise",
          "evidence": [
            {
              "title": "Mistral – Vibe",
              "url": "https://mistral.ai/products/vibe/",
              "note": "Mistral states Enterprise Vibe supports full data residency across on-premises, private cloud, or Mistral Cloud deployments.",
              "evidence_type": "official_product_page",
              "source_section": "Intelligence you own / FAQ"
            }
          ],
          "note": "Mistral Vibe Enterprise supports data-residency controls.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "mistral_vibe_enterprise",
          "evidence": [
            {
              "title": "Mistral – Regional inference",
              "url": "https://mistral.ai/news/regional-inference-open-models-new-compute/",
              "note": "Mistral documents regional endpoints allowing customers to choose EU or US inference regions for regional control and data-residency requirements.",
              "evidence_type": "official_release",
              "source_section": "Regional control, production-grade reliability"
            }
          ],
          "note": "Mistral customers can choose supported regional inference locations.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "mistral_platform_including_vibe",
          "evidence": [
            {
              "title": "Mistral Help – SOC 2 and ISO certifications",
              "url": "https://help.mistral.ai/en/articles/347638-do-you-have-soc-2-or-iso-27001-certification",
              "note": "Mistral states it complies with SOC 2 Type II and ISO 27001/27701 frameworks.",
              "evidence_type": "security_trust",
              "source_section": "Answer"
            }
          ],
          "note": "Mistral documents SOC 2 Type II compliance.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0070",
      "claims": [
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "warp_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – Enterprise overview",
              "url": "https://docs.warp.dev/enterprise",
              "note": "Warp documents Team Owner, Team Admin, and Member roles with differentiated permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Enterprise administration"
            }
          ],
          "note": "Warp Enterprise provides role-based access control."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "warp_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – Single Sign-On",
              "url": "https://docs.warp.dev/enterprise/security-and-compliance/sso",
              "note": "Warp explicitly states Enterprise supports SCIM for user lifecycle management.",
              "evidence_type": "technical_docs",
              "source_section": "SCIM provisioning"
            }
          ],
          "note": "Warp Enterprise supports SCIM user lifecycle management."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "warp_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – Single Sign-On",
              "url": "https://docs.warp.dev/enterprise/security-and-compliance/sso",
              "note": "Warp supports any OpenID Connect compatible identity provider for Enterprise SSO.",
              "evidence_type": "technical_docs",
              "source_section": "Supported identity providers"
            }
          ],
          "note": "Warp Enterprise supports OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "warp_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – Single Sign-On",
              "url": "https://docs.warp.dev/enterprise/security-and-compliance/sso",
              "note": "Warp supports any SAML 2.0 compatible identity provider for Enterprise SSO.",
              "evidence_type": "technical_docs",
              "source_section": "Supported identity providers"
            }
          ],
          "note": "Warp Enterprise supports SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "warp_cloud_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – MCP servers CLI reference",
              "url": "https://docs.warp.dev/reference/cli/mcp-servers",
              "note": "Warp documents cloud-agent execution via agent run-cloud alongside local Agent CLI execution.",
              "evidence_type": "technical_docs",
              "source_section": "Cloud agents / --mcp"
            }
          ],
          "note": "Warp provides managed cloud-agent execution in addition to local Agent CLI."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "warp_agent_cli_local_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – Agent CLI overview",
              "url": "https://docs.warp.dev/agents/cli/",
              "note": "Warp documents Agent CLI as a standalone terminal program that runs the Warp Agent and works in any terminal emulator, including over SSH.",
              "evidence_type": "technical_docs",
              "source_section": "What is the Warp Agent CLI?"
            }
          ],
          "note": "Warp Agent CLI can run as a local/customer-managed terminal program."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "warp_agent_cli",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – MCP servers CLI reference",
              "url": "https://docs.warp.dev/reference/cli/mcp-servers",
              "note": "Warp documents connecting Agent CLI agents to external MCP servers via the --mcp flag.",
              "evidence_type": "technical_docs",
              "source_section": "MCP servers"
            }
          ],
          "note": "Warp Agent CLI acts as an MCP client."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "warp_enterprise_cloud_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – Security Overview",
              "url": "https://docs.warp.dev/enterprise/security-and-compliance/security-overview",
              "note": "Warp documents AES-256 encryption for cloud data at rest.",
              "evidence_type": "security_trust",
              "source_section": "Encryption"
            }
          ],
          "note": "Warp documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "warp_enterprise_cloud_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – Security Overview",
              "url": "https://docs.warp.dev/enterprise/security-and-compliance/security-overview",
              "note": "Warp documents TLS 1.2 or higher for data in transit.",
              "evidence_type": "security_trust",
              "source_section": "Encryption"
            }
          ],
          "note": "Warp documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "warp_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Warp Docs – Enterprise overview",
              "url": "https://docs.warp.dev/enterprise",
              "note": "Warp states it is SOC 2 Type II certified.",
              "evidence_type": "security_trust",
              "source_section": "Security and compliance"
            }
          ],
          "note": "Warp documents SOC 2 Type II certification."
        }
      ]
    },
    {
      "agent_id": "AI-0071",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "factory_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Security",
              "url": "https://docs.factory.ai/enterprise/security",
              "note": "Factory documents enterprise audit events and workflow logs for monitoring.",
              "evidence_type": "security_trust",
              "source_section": "Telemetry & Analytics"
            }
          ],
          "note": "Factory Enterprise provides audit events and workflow logs."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "factory_enterprise_telemetry",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Telemetry & Analytics",
              "url": "https://docs.factory.ai/enterprise/telemetry",
              "note": "Factory documents exporting OpenTelemetry metrics/traces to a customer-owned OTLP-compatible collector, with examples including enterprise observability systems.",
              "evidence_type": "technical_docs",
              "source_section": "Self-hosted OTEL metrics export"
            }
          ],
          "note": "Factory telemetry can be exported to customer-controlled observability/SIEM infrastructure."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "factory_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Identity & Access",
              "url": "https://docs.factory.ai/enterprise/identity-and-access",
              "note": "Factory documents user/group roles controlling access and policies.",
              "evidence_type": "technical_docs",
              "source_section": "Identity model and roles"
            }
          ],
          "note": "Factory Enterprise provides role-based access control."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "factory_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Identity & Access",
              "url": "https://docs.factory.ai/enterprise/identity-and-access",
              "note": "Factory documents Directory Sync/SCIM for enterprise identity management.",
              "evidence_type": "technical_docs",
              "source_section": "SSO and SCIM directory sync"
            }
          ],
          "note": "Factory Enterprise supports SCIM directory synchronization."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "factory_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Identity & Access",
              "url": "https://docs.factory.ai/enterprise/identity-and-access",
              "note": "Factory documents SSO using SAML/OIDC.",
              "evidence_type": "technical_docs",
              "source_section": "Identity model / SSO"
            }
          ],
          "note": "Factory Enterprise supports OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "factory_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Identity & Access",
              "url": "https://docs.factory.ai/enterprise/identity-and-access",
              "note": "Factory documents human users authenticating through SSO using SAML/OIDC.",
              "evidence_type": "technical_docs",
              "source_section": "Identity model / SSO"
            }
          ],
          "note": "Factory Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "factory_managed_droid_computers",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Droid Computers",
              "url": "https://docs.factory.ai/droid-computers/overview",
              "note": "Factory documents Managed Droid Computers provisioned and managed by Factory.",
              "evidence_type": "technical_docs",
              "source_section": "Managed Droid Computers"
            }
          ],
          "note": "Factory offers managed cloud compute for Droid sessions."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "factory_enterprise_hybrid_airgapped",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Deployment Patterns",
              "url": "https://docs.factory.ai/enterprise/network-and-deployment",
              "note": "Factory documents Hybrid deployments inside customer VMs/containers/CI and fully airgapped deployments with no outbound network dependency.",
              "evidence_type": "technical_docs",
              "source_section": "Hybrid / Fully airgapped"
            }
          ],
          "note": "Factory supports private-network and fully airgapped Droid deployments."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "factory_droids_private",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Deployment Patterns",
              "url": "https://docs.factory.ai/enterprise/network-and-deployment",
              "note": "Factory documents Droids running in customer VMs, containers, CI runners, Kubernetes clusters, and fully airgapped environments with no Factory cloud involvement at runtime.",
              "evidence_type": "technical_docs",
              "source_section": "Choose a pattern / Hybrid / Fully airgapped"
            }
          ],
          "note": "Factory Droids support customer-managed and fully airgapped deployment."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "factory_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Deployment Patterns",
              "url": "https://docs.factory.ai/enterprise/network-and-deployment",
              "note": "Factory documents a dedicated EU deployment with session content stored in Europe and EU-only inference endpoints.",
              "evidence_type": "technical_docs",
              "source_section": "EU deployment and data residency"
            }
          ],
          "note": "Factory Enterprise offers EU data residency."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "factory_enterprise_org",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Deployment Patterns",
              "url": "https://docs.factory.ai/enterprise/network-and-deployment",
              "note": "Factory documents organizations pinned to Global or EU regional deployments, with Enterprise customers provisioned into the EU region on request.",
              "evidence_type": "technical_docs",
              "source_section": "Region enforcement / EU deployment"
            }
          ],
          "note": "Enterprise organizations can be provisioned into the supported EU regional deployment."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "factory_droid",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Factory Docs – Model Context Protocol",
              "url": "https://docs.factory.ai/harness/mcp",
              "note": "Factory documents Droid connecting to MCP servers over stdio, HTTP, and SSE and using their tools.",
              "evidence_type": "technical_docs",
              "source_section": "Model Context Protocol"
            }
          ],
          "note": "Factory Droid acts as an MCP client."
        }
      ]
    },
    {
      "agent_id": "AI-0072",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "genspark_enterprise_admin_activity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark Enterprise documents Usage Logs and Login History for security audit and incident investigation.",
              "evidence_type": "technical_docs",
              "source_section": "Enterprise-only admin features"
            }
          ],
          "note": "Genspark Enterprise provides administrative usage/login logs for audit and investigation."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "genspark_team_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark documents Admin/Member roles and Enterprise agent-level permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Admin Controls & Governance"
            }
          ],
          "note": "Genspark organizations provide role-based access and agent-level permissions."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "genspark_team_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark documents SAML 2.0 SSO with Entra ID, Google Workspace, Okta, and generic SAML providers.",
              "evidence_type": "technical_docs",
              "source_section": "SSO setup"
            }
          ],
          "note": "Genspark Team and Enterprise support SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "genspark_code",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Genspark Code",
              "url": "https://www.genspark.ai/helpcenter/ai-developer",
              "note": "Genspark documents Code as a Genspark product workspace where the autonomous coding agent plans, codes, tests, deploys, and stores projects.",
              "evidence_type": "technical_docs",
              "source_section": "What is Genspark Code? / Projects tab"
            }
          ],
          "note": "Genspark Code is delivered as a managed Genspark workspace and agent service."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "genspark_enterprise_dedicated_vpc",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark documents an Enterprise dedicated VPC option for network isolation.",
              "evidence_type": "technical_docs",
              "source_section": "Enterprise additions"
            }
          ],
          "note": "Genspark Enterprise offers a dedicated VPC option."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "genspark_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark documents configurable Enterprise data residency in US, EU, or APAC.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise additions"
            }
          ],
          "note": "Genspark Enterprise supports configurable data residency."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "genspark_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Enterprise customers can configure data residency among US, EU, or APAC.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise additions"
            }
          ],
          "note": "Genspark Enterprise customers can select among documented regions."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256-GCM",
          "scope": "genspark_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark states data is encrypted at rest using AES-256-GCM.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "Genspark documents AES-256-GCM encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "genspark_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark states TLS 1.3 is preferred and TLS 1.2+ supported in transit.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "Genspark documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "genspark_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark states Team and Enterprise plans are SOC 2 Type II certified.",
              "evidence_type": "security_trust",
              "source_section": "Compliance & Certifications"
            }
          ],
          "note": "Genspark documents SOC 2 Type II certification."
        }
      ]
    },
    {
      "agent_id": "AI-0073",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "opencode_local_server",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenCode Docs – Server",
              "url": "https://dev.opencode.ai/docs/server/",
              "note": "OpenCode documents a headless HTTP server with an OpenAPI 3.1 specification and GET/POST/PATCH endpoints for projects, sessions, configuration, files, and commands.",
              "evidence_type": "api_docs",
              "source_section": "Server / APIs"
            }
          ],
          "note": "OpenCode exposes a documented HTTP/OpenAPI server API."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "opencode_local_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenCode – Official Site",
              "url": "https://opencode.ai/",
              "note": "OpenCode documents itself as an open-source coding agent installed locally and used in the terminal, IDE, or desktop, with support for local models.",
              "evidence_type": "official_product_page",
              "source_section": "What is OpenCode? / Install"
            }
          ],
          "note": "OpenCode supports a local user-managed agent runtime."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "opencode_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "OpenCode Docs – MCP servers",
              "url": "https://opencode.ai/docs/en/mcp-servers/",
              "note": "OpenCode documents adding local and remote MCP servers whose tools become available to the agent.",
              "evidence_type": "technical_docs",
              "source_section": "MCP servers"
            }
          ],
          "note": "OpenCode acts as an MCP client."
        }
      ]
    },
    {
      "agent_id": "AI-0074",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "coderabbit_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Pricing",
              "url": "https://www.coderabbit.ai/pricing",
              "note": "CodeRabbit Enterprise explicitly includes audit logging.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "CodeRabbit Enterprise provides audit logging."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "coderabbit_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – AI agent explainability",
              "url": "https://www.coderabbit.ai/guides/ai-agent-explainability",
              "note": "CodeRabbit states its Enterprise tier includes exportable audit logs and enterprise governance controls.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise explainability and governance"
            }
          ],
          "note": "CodeRabbit Enterprise audit logs are exportable for security/compliance workflows."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "coderabbit_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Pricing",
              "url": "https://www.coderabbit.ai/pricing",
              "note": "CodeRabbit explicitly describes its Enterprise access control as custom RBAC.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "CodeRabbit Enterprise provides customizable role-based access controls."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "coderabbit_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Pricing",
              "url": "https://www.coderabbit.ai/pricing",
              "note": "CodeRabbit Enterprise explicitly includes custom RBAC.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "CodeRabbit Enterprise provides RBAC."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "coderabbit_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Vercel breach lessons",
              "url": "https://www.coderabbit.ai/blog/vercel-breach-enterprise-code-security",
              "note": "CodeRabbit documents SSO and SAML support for Enterprise.",
              "evidence_type": "security_trust",
              "source_section": "Identity and access controls"
            }
          ],
          "note": "CodeRabbit Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "coderabbit_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Official Site",
              "url": "https://www.coderabbit.ai/",
              "note": "CodeRabbit documents its automated review and agent services as the CodeRabbit application integrated with GitHub and GitLab repositories and operated through app.coderabbit.ai.",
              "evidence_type": "official_product_page",
              "source_section": "Review every PR automatically / Get started"
            }
          ],
          "note": "CodeRabbit Agent is delivered as a managed CodeRabbit service."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "coderabbit_enterprise_self_hosted",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Vercel breach lessons",
              "url": "https://www.coderabbit.ai/blog/vercel-breach-enterprise-code-security",
              "note": "CodeRabbit describes its self-hosted Enterprise option for organizations that require code to remain within their network perimeter.",
              "evidence_type": "official_release",
              "source_section": "Identity and access controls / self-hosting"
            }
          ],
          "note": "CodeRabbit can be self-hosted within a customer network perimeter."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "coderabbit_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Pricing",
              "url": "https://www.coderabbit.ai/pricing",
              "note": "CodeRabbit Enterprise explicitly includes a self-hosting option.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "CodeRabbit Enterprise supports self-hosting."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "coderabbit_enterprise_saas",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Pricing",
              "url": "https://www.coderabbit.ai/pricing",
              "note": "CodeRabbit Enterprise explicitly lists an EU SaaS deployment option.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "CodeRabbit Enterprise offers an EU SaaS deployment option."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "coderabbit_enterprise_saas",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – Pricing",
              "url": "https://www.coderabbit.ai/pricing",
              "note": "CodeRabbit exposes EU SaaS deployment as an Enterprise deployment choice.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise"
            }
          ],
          "note": "Enterprise customers can select the documented EU SaaS deployment option."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "coderabbit_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CodeRabbit – AI agent explainability",
              "url": "https://www.coderabbit.ai/guides/ai-agent-explainability",
              "note": "CodeRabbit states its Enterprise tier includes SOC 2 Type II certification.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise tier"
            }
          ],
          "note": "CodeRabbit documents SOC 2 Type II certification."
        }
      ]
    },
    {
      "agent_id": "AI-0075",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "genspark_enterprise_admin_activity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark Enterprise documents Usage Logs and Login History for security audit and incident investigation.",
              "evidence_type": "technical_docs",
              "source_section": "Enterprise-only admin features"
            }
          ],
          "note": "Genspark Enterprise provides administrative usage/login logs for audit and investigation."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "genspark_team_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark documents Admin/Member roles and Enterprise agent-level permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Admin Controls & Governance"
            }
          ],
          "note": "Genspark organizations provide role-based access and agent-level permissions."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "genspark_team_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark documents SAML 2.0 SSO with Entra ID, Google Workspace, Okta, and generic SAML providers.",
              "evidence_type": "technical_docs",
              "source_section": "SSO setup"
            }
          ],
          "note": "Genspark Team and Enterprise support SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "genspark_super_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Super Agent",
              "url": "https://www.genspark.ai/de/helpcenter",
              "note": "Genspark documents Super Agent as its autonomous assistant available in the Genspark workspace, using connected apps, files, accounts, and SecondBrain.",
              "evidence_type": "technical_docs",
              "source_section": "Super-Agent / Was ist der Genspark Super-Agent?"
            }
          ],
          "note": "Genspark Super Agent is delivered as a managed Genspark workspace service."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "genspark_enterprise_dedicated_vpc",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark documents an Enterprise dedicated VPC option for network isolation.",
              "evidence_type": "technical_docs",
              "source_section": "Enterprise additions"
            }
          ],
          "note": "Genspark Enterprise offers a dedicated VPC option."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "genspark_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark documents configurable Enterprise data residency in US, EU, or APAC.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise additions"
            }
          ],
          "note": "Genspark Enterprise supports configurable data residency."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "genspark_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Enterprise customers can configure data residency among US, EU, or APAC.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise additions"
            }
          ],
          "note": "Genspark Enterprise customers can select among documented regions."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256-GCM",
          "scope": "genspark_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark states data is encrypted at rest using AES-256-GCM.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "Genspark documents AES-256-GCM encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "genspark_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark states TLS 1.3 is preferred and TLS 1.2+ supported in transit.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "Genspark documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "genspark_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Genspark Help – Team & Enterprise Plans",
              "url": "https://www.genspark.ai/helpcenter/team-enterprise-plans",
              "note": "Genspark states Team and Enterprise plans are SOC 2 Type II certified.",
              "evidence_type": "security_trust",
              "source_section": "Compliance & Certifications"
            }
          ],
          "note": "Genspark documents SOC 2 Type II certification."
        }
      ]
    },
    {
      "agent_id": "AI-0076",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "crewai_amp_deployed_crews",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI Docs – CrewAI AMP",
              "url": "https://docs.crewai.com/enterprise/introduction",
              "note": "CrewAI AMP documents REST API access for deployed crews and generated API endpoints.",
              "evidence_type": "api_docs",
              "source_section": "API Access"
            }
          ],
          "note": "CrewAI AMP exposes deployed crews through REST API endpoints."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "crewai_amp_runtime_events",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI Docs – CrewAI AMP",
              "url": "https://docs.crewai.com/enterprise/introduction",
              "note": "CrewAI AMP documents Webhook Streaming for real-time events and updates to external systems.",
              "evidence_type": "api_docs",
              "source_section": "Webhook Streaming"
            }
          ],
          "note": "CrewAI AMP supports webhook streaming of runtime events and updates."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "crewai_amp_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI – Enterprise Agent Build & Runtime",
              "url": "https://crewai.com/",
              "note": "CrewAI describes immutable audit trails in the Control Plane alongside RBAC.",
              "evidence_type": "official_product_page",
              "source_section": "Govern"
            },
            {
              "title": "CrewAI – A Missing Layer in Agentic Systems?",
              "url": "https://crewai.com/blog/a-missing-layer-in-agentic-systems",
              "note": "CrewAI documents full audit trails for human-in-the-loop requests, responses, and decisions in AMP.",
              "evidence_type": "official_release",
              "source_section": "Enterprise AMP"
            }
          ],
          "note": "CrewAI AMP documents audit trails for governed agent execution."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "crewai_amp_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI – Pricing",
              "url": "https://crewai.com/pricing",
              "note": "CrewAI Enterprise lists RBAC as a governance capability.",
              "evidence_type": "official_product_page",
              "source_section": "Governance from the start"
            },
            {
              "title": "CrewAI – Enterprise Agent Build & Runtime",
              "url": "https://crewai.com/",
              "note": "CrewAI states its control plane provides RBAC and granular governance controls.",
              "evidence_type": "official_product_page",
              "source_section": "Govern"
            }
          ],
          "note": "CrewAI AMP provides role-based access control."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "crewai_amp",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI Docs – CrewAI AMP",
              "url": "https://docs.crewai.com/enterprise/introduction",
              "note": "CrewAI AMP documents deploying crews to managed infrastructure.",
              "evidence_type": "technical_docs",
              "source_section": "Crew Deployments"
            }
          ],
          "note": "CrewAI AMP provides managed deployment infrastructure."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "crewai_factory_customer_vpc",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI – CrewAI Factory and NVIDIA",
              "url": "https://crewai.com/blog/unlocking-agent-native-transformation-with-crewai-factory-and-nvidia",
              "note": "CrewAI documents deployment in customer AWS/Azure VPCs and on-premises environments.",
              "evidence_type": "official_release",
              "source_section": "Deploy anywhere"
            },
            {
              "title": "CrewAI – Pricing",
              "url": "https://crewai.com/pricing",
              "note": "CrewAI Enterprise lists dedicated VPC deployment on CrewAI or customer infrastructure.",
              "evidence_type": "official_product_page",
              "source_section": "Deployment"
            }
          ],
          "note": "CrewAI Enterprise supports deployment in customer-controlled VPC/private infrastructure."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "crewai_factory_customer_infrastructure",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI – CrewAI Factory and NVIDIA",
              "url": "https://crewai.com/blog/unlocking-agent-native-transformation-with-crewai-factory-and-nvidia",
              "note": "CrewAI documents Enterprise deployment on customer infrastructure, including data centers and customer-managed Kubernetes environments.",
              "evidence_type": "official_release",
              "source_section": "Deploy anywhere"
            }
          ],
          "note": "CrewAI Enterprise can run on customer-managed infrastructure."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "crewai_framework_deployed_in_amp",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI Docs – Using Annotations in crew.py",
              "url": "https://docs.crewai.com/learn/using-annotations",
              "note": "CrewAI documents MCP integration through mcp_server_params and get_mcp_tools(), which starts an MCP adapter and hydrates tools from configured MCP servers.",
              "evidence_type": "technical_docs",
              "source_section": "MCP integration"
            }
          ],
          "note": "CrewAI agents can consume tools from configured MCP servers."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "crewai_amp_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI – Pricing",
              "url": "https://crewai.com/pricing",
              "note": "CrewAI lists 'Export as MCP server' as a supported capability.",
              "evidence_type": "official_product_page",
              "source_section": "Build and integrate"
            }
          ],
          "note": "CrewAI workflows can be exported as MCP servers."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "crewai_factory_customer_infrastructure",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI – CrewAI Factory and NVIDIA",
              "url": "https://crewai.com/blog/unlocking-agent-native-transformation-with-crewai-factory-and-nvidia",
              "note": "CrewAI explicitly lists encrypted storage as a CrewAI Factory security capability.",
              "evidence_type": "official_release",
              "source_section": "CrewAI Factory"
            }
          ],
          "note": "CrewAI Factory documents encryption for stored data."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "crewai_factory_customer_infrastructure",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI – CrewAI Factory and NVIDIA",
              "url": "https://crewai.com/blog/unlocking-agent-native-transformation-with-crewai-factory-and-nvidia",
              "note": "CrewAI explicitly lists encrypted communication as a CrewAI Factory security capability.",
              "evidence_type": "official_release",
              "source_section": "CrewAI Factory"
            }
          ],
          "note": "CrewAI Factory documents encrypted communications."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "crewai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "CrewAI Trust Center",
              "url": "https://trust.crewai.com/",
              "note": "CrewAI states it maintains a SOC 2 Type 2 certified security program and publishes a SOC 2 Type 2 report in its Trust Center.",
              "evidence_type": "security_trust",
              "source_section": "Compliance"
            }
          ],
          "note": "CrewAI documents SOC 2 Type 2 certification."
        }
      ]
    },
    {
      "agent_id": "AI-0077",
      "claims": [
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "adk_on_agent_runtime_with_agent_identity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud IAM – Authenticate using an agent's own authority",
              "url": "https://docs.cloud.google.com/iam/docs/auth-agent-own-identity",
              "note": "Google documents granting IAM roles directly to an agent identity, including Vertex AI Agent Engine identities.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ADK agents deployed with Agent Identity use Google Cloud IAM roles and policies for resource access."
        },
        {
          "path": "governance.tracing",
          "value": true,
          "scope": "adk_on_agent_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Trace an agent",
              "url": "https://docs.cloud.google.com/vertex-ai/generative-ai/docs/agent-engine/manage/tracing",
              "note": "Google documents enabling OpenTelemetry traces and logs for AdkApp deployments on Agent Runtime.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ADK deployments on Agent Runtime support OpenTelemetry-based tracing."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "adk_agent_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Agents CLI – Deployment",
              "url": "https://google.github.io/agents-cli/guide/deployment/",
              "note": "Google documents Agent Runtime as a fully managed deployment target for ADK agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ADK agents can be deployed to Google Agent Runtime as a fully managed runtime."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "adk_on_vertex_ai_agent_engine",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Vertex AI release notes",
              "url": "https://docs.cloud.google.com/vertex-ai/docs/release-notes",
              "note": "Google documents private VPC deployment with Private Service Connect for Vertex AI Agent Engine.",
              "evidence_type": "official_release"
            },
            {
              "title": "Google Agents CLI – Deployment",
              "url": "https://google.github.io/agents-cli/guide/deployment/",
              "note": "Google documents managed Agent Runtime as a deployment target for ADK agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ADK agents deployed on Vertex AI Agent Engine can use private VPC connectivity."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "adk_local_or_customer_managed_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Agents CLI – CLI reference",
              "url": "https://google.github.io/agents-cli/cli/",
              "note": "Google documents local ADK agent execution via a local server and deployment targets including GKE in addition to managed Agent Runtime.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Google ADK – Agent Runtime Code Execution tool",
              "url": "https://google.github.io/adk-docs/tools/google-cloud/code-exec-agent-engine/",
              "note": "Google states an ADK agent can run locally or with other services and need not be deployed to Agent Runtime.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ADK supports local/customer-managed runtime execution in addition to managed Agent Runtime deployment."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "adk_on_gemini_enterprise_agent_platform_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Supported locations for agents in Agent Platform",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/agent-locations",
              "note": "Google documents that supported agent infrastructure locations provide data-at-rest residency for agent source code, deployment packages, sessions, memory and metadata.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "ADK agents deployed on Agent Platform can use regional agent infrastructure with documented data-at-rest residency."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "adk_on_gemini_enterprise_agent_platform_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Supported locations for agents in Agent Platform",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/agent-locations",
              "note": "Google lists selectable zones, regions and multi-regions for Agent Platform runtime and related agent infrastructure.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Customers select a supported Agent Platform location when deploying regional agent infrastructure."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "adk_agents_built_with_agents_cli",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Agents CLI – Use Cases",
              "url": "https://google.github.io/agents-cli/guide/use-cases/",
              "note": "Google states the ADK template exposes the A2A protocol out of the box so other agents can communicate with deployed ADK agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ADK agents created with the supported template can expose an A2A service endpoint."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "adk_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Agents CLI – Agent Starter Pack migration reference",
              "url": "https://google.github.io/agents-cli/reference/from-agent-starter-pack/",
              "note": "Google states that A2A is built into every ADK agent template in Agents CLI.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "A2A is a documented first-party interoperability mode for ADK agents."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "adk_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google MCP Security – Remote MCP Server with ADK",
              "url": "https://google.github.io/mcp-security/remote_server.html",
              "note": "Google documents configuring an ADK agent with McpToolset and a remote MCP server over Streamable HTTP.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ADK agents can consume MCP servers through the documented MCP toolset."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "adk_on_vertex_ai_agent_engine",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Vertex AI release notes",
              "url": "https://docs.cloud.google.com/vertex-ai/docs/release-notes",
              "note": "Google documents customer-managed encryption key support for Vertex AI Agent Engine data at rest.",
              "evidence_type": "official_release"
            },
            {
              "title": "Google Agents CLI – Deployment",
              "url": "https://google.github.io/agents-cli/guide/deployment/",
              "note": "Google documents deployment of ADK agents to managed Agent Runtime.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ADK agents deployed on Vertex AI Agent Engine can use CMEK for data-at-rest protection."
        }
      ]
    },
    {
      "agent_id": "AI-0078",
      "claims": [
        {
          "path": "api.auth.api_key",
          "value": false,
          "scope": "agent_endpoint_inbound",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Configure and share your Foundry agent",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/configure-agent",
              "note": "Microsoft explicitly states that API key authentication is not supported for the Foundry agent endpoint and directs callers to Entra ID/Azure RBAC.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "This negative value is explicit and scoped only to inbound authentication on the agent endpoint."
        },
        {
          "path": "api.auth.entra_id",
          "value": true,
          "scope": "agent_endpoint_inbound",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Configure and share your Foundry agent",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/configure-agent",
              "note": "Microsoft documents Microsoft Entra ID authorization for inbound Foundry agent endpoint access.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Microsoft Entra ID is a supported inbound authorization scheme."
        },
        {
          "path": "api.openai_responses",
          "value": true,
          "scope": "agent_endpoint",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Configure and share your Foundry agent",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/configure-agent",
              "note": "Microsoft documents the agent endpoint's OpenAI Responses protocol URL and enables Responses by default.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Foundry agents expose a Responses protocol endpoint."
        },
        {
          "path": "api.rest",
          "value": true,
          "scope": "agent_management",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Configure and share your Foundry agent",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/configure-agent",
              "note": "Microsoft documents configuring agent versions, protocols, authorization, and agent cards through the REST API.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Agent endpoint configuration is available through a REST API."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "foundry_project",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Enable incoming A2A on a Foundry agent",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/enable-agent-to-agent-endpoint",
              "note": "The A2A setup documents required Foundry RBAC roles.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Azure RBAC is part of Agent Service access control."
        },
        {
          "path": "hosting.byo_vnet",
          "value": true,
          "scope": "standard_networking",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service networking options",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/concepts/networking-options",
              "note": "Foundry supports bring-your-own virtual networks with delegated subnets.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "BYO VNet is documented."
        },
        {
          "path": "hosting.customer_managed_storage",
          "value": true,
          "scope": "standard_setup",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service networking options",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/concepts/networking-options",
              "note": "BYO data resources can include Azure Storage, Azure AI Search and Cosmos DB in the customer tenant.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Customer-managed data resources are supported."
        },
        {
          "path": "hosting.managed_vnet",
          "value": true,
          "scope": "standard_networking",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service networking options",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/concepts/networking-options",
              "note": "A Microsoft-managed virtual network option is documented.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Managed VNet isolation is supported."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "foundry_agent_service",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service overview",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/overview",
              "note": "Foundry Agent Service is fully managed and handles hosting, scaling and identity.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Managed hosting is a core service property."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "foundry_account_and_project",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service networking options",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/concepts/networking-options",
              "note": "Foundry supports private endpoints and network-isolated configurations.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Private networking is supported."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "agent_service_state",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service data, privacy and security",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/agents/data-privacy-security",
              "note": "Data stored at rest is kept in the geography of the Azure OpenAI resource.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Agent Service data residency follows the Azure resource geography."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "foundry_agent_service_resource_region",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service data, privacy, and security",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/agents/data-privacy-security",
              "note": "Agent Service stores state in the geography of the customer-created Azure OpenAI/Foundry resource.",
              "evidence_type": "security_trust"
            },
            {
              "title": "Microsoft Learn – Foundry Agent Service FAQ",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/faq",
              "note": "Microsoft states Agent Service endpoints are regional and data is stored in the same region as the endpoint.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "The customer selects the Azure region when creating the Foundry resource/endpoint, determining agent-data residency."
        },
        {
          "path": "protocols.a2a.client",
          "value": true,
          "scope": "foundry_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Connect to an A2A endpoint from Foundry Agent Service",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/tools/agent-to-agent",
              "note": "Foundry agents can connect to remote A2A endpoints using A2A 1.0.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Outbound A2A is documented."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "prompt_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Enable incoming A2A on a Foundry agent",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/enable-agent-to-agent-endpoint",
              "note": "Foundry prompt agents can expose an incoming A2A endpoint.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Incoming A2A is documented."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "agent_endpoint_preview",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Configure and share your Foundry agent",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/configure-agent",
              "note": "Microsoft lists an MCP (preview) protocol endpoint that a Foundry agent can expose.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Foundry agents can expose an MCP endpoint in preview."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "supported_non_preview_features",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service data, privacy and security",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/agents/data-privacy-security",
              "note": "Customer-managed keys are optional for supported Agent Service features.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "CMK support is documented with preview caveats."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "stored_agent_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Foundry Agent Service data, privacy and security",
              "url": "https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/agents/data-privacy-security",
              "note": "Microsoft documents AES-256 encryption at rest.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "AES-256 at-rest encryption is documented."
        }
      ]
    },
    {
      "agent_id": "AI-0079",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "agentcore_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – AgentCore Runtime service contract",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-service-contract.html",
              "note": "AWS lists HTTP REST endpoints as a supported AgentCore Runtime protocol surface.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "AgentCore Runtime supports direct HTTP/REST invocation."
        },
        {
          "path": "api.websocket",
          "value": true,
          "scope": "agentcore_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – AgentCore Runtime service contract",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-service-contract.html",
              "note": "AWS lists WebSocket endpoints for the HTTP and AG-UI protocol surfaces.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "WebSocket invocation is documented for supported runtime protocols."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "agentcore_runtime_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Security best practices for AgentCore Runtime",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-security-best-practices.html",
              "note": "AWS documents CloudTrail recording Runtime invoke and control-plane API calls with caller identity, timestamp, source IP, and response status.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "AWS CloudTrail provides audit records for AgentCore Runtime API activity."
        },
        {
          "path": "governance.logs.cloudwatch",
          "value": true,
          "scope": "agentcore_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – AgentCore observability",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability-configure.html",
              "note": "AgentCore Runtime creates a CloudWatch log group for service-provided logs.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "CloudWatch logging is documented."
        },
        {
          "path": "governance.logs.firehose_export",
          "value": true,
          "scope": "memory_and_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – AgentCore observability",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability-configure.html",
              "note": "Memory and gateway logs can be sent to Amazon Data Firehose.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Firehose log export is documented."
        },
        {
          "path": "governance.logs.s3_export",
          "value": true,
          "scope": "memory_and_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – AgentCore observability",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability-configure.html",
              "note": "Memory and gateway logs can be configured to Amazon S3.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "S3 log destinations are documented."
        },
        {
          "path": "governance.observability",
          "value": true,
          "scope": "agentcore_resources",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – AgentCore observability",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability-configure.html",
              "note": "AgentCore documents observability for runtime, memory, gateway, tools and identity resources.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Built-in observability is documented."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "agentcore_resources_via_aws_iam",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Identity and access management for AgentCore",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/security-iam.html",
              "note": "AWS documents IAM identities and policies as the mechanism for controlling authentication and authorization to AgentCore resources.",
              "evidence_type": "security_trust"
            },
            {
              "title": "AWS Docs – IAM permissions for AgentCore Runtime",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-permissions.html",
              "note": "AWS documents IAM user/role and execution-role permissions for AgentCore Runtime.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "AgentCore access is governed through AWS IAM roles and policies."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "agentcore_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Deploy MCP servers in AgentCore Runtime",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-mcp.html",
              "note": "AgentCore Runtime deploys MCP server workloads on AWS-managed AgentCore infrastructure.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Managed runtime hosting is documented."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "gateway_targets",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – AgentCore Gateway VPC egress",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-vpc-egress.html",
              "note": "Gateway can route privately to MCP servers inside a VPC using managed VPC Lattice endpoints.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Private VPC connectivity is documented."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "agentcore_runtime_instances",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Security model for Runtime Instances",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-instances-security.html",
              "note": "AWS states Runtime Instances run on EC2 instances in the customer's own AWS account and VPC.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "AgentCore Runtime Instances provide a customer-account/VPC deployment mode in addition to serverless managed Runtime."
        },
        {
          "path": "identity.agent_identity",
          "value": true,
          "confidence": "high",
          "scope": "agentcore_identity",
          "verified_at": "2026-10-03",
          "note": "AgentCore Identity is documented as an agent identity, access and authentication management service.",
          "evidence": [
            {
              "title": "AWS Docs – Amazon Bedrock AgentCore overview",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/",
              "evidence_type": "technical_docs",
              "source_section": "Core services"
            }
          ]
        },
        {
          "path": "memory.long_term",
          "value": true,
          "confidence": "high",
          "scope": "agentcore_memory_long_term",
          "verified_at": "2026-10-03",
          "note": "AgentCore long-term memory stores extracted insights across multiple sessions.",
          "evidence": [
            {
              "title": "AWS Docs – Add memory to your AgentCore agent",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory.html",
              "evidence_type": "technical_docs",
              "source_section": "Memory types"
            }
          ]
        },
        {
          "path": "memory.session_state",
          "value": true,
          "confidence": "high",
          "scope": "agentcore_memory_short_term",
          "verified_at": "2026-10-03",
          "note": "AgentCore short-term memory stores turn-by-turn interactions within a session.",
          "evidence": [
            {
              "title": "AWS Docs – Add memory to your AgentCore agent",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory.html",
              "evidence_type": "technical_docs",
              "source_section": "Memory types"
            }
          ]
        },
        {
          "path": "memory.shared_across_agents",
          "value": true,
          "confidence": "high",
          "scope": "agentcore_memory_shared_stores",
          "verified_at": "2026-10-03",
          "note": "AWS documents the ability to share AgentCore memory stores across agents.",
          "evidence": [
            {
              "title": "AWS Docs – Amazon Bedrock AgentCore overview",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/",
              "evidence_type": "technical_docs",
              "source_section": "Core services"
            }
          ]
        },
        {
          "path": "operations.max_agents_per_account",
          "value": 1000,
          "confidence": "high",
          "scope": "agentcore_runtime_account_region",
          "verified_at": "2026-10-03",
          "note": "AgentCore Runtime documents a default total limit of 1,000 agents per account.",
          "evidence": [
            {
              "title": "AWS Docs – Quotas for Amazon Bedrock AgentCore",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html",
              "evidence_type": "technical_docs",
              "source_section": "Runtime resource allocation limits"
            }
          ]
        },
        {
          "path": "operations.rate_limits_documented",
          "value": true,
          "confidence": "high",
          "scope": "agentcore_services",
          "verified_at": "2026-10-03",
          "note": "AWS publishes TPS/throughput limits for multiple AgentCore APIs and services.",
          "evidence": [
            {
              "title": "AWS Docs – Quotas for Amazon Bedrock AgentCore",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html",
              "evidence_type": "technical_docs",
              "source_section": "Throttling limits"
            }
          ]
        },
        {
          "path": "operations.service_quotas_documented",
          "value": true,
          "confidence": "high",
          "scope": "agentcore_services",
          "verified_at": "2026-10-03",
          "note": "AWS publishes service/resource quotas for AgentCore Runtime, Memory, Identity, Gateway and other AgentCore services.",
          "evidence": [
            {
              "title": "AWS Docs – Quotas for Amazon Bedrock AgentCore",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html",
              "evidence_type": "technical_docs",
              "source_section": "AgentCore service quotas"
            }
          ]
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "agentcore_runtime_instances",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Security model for Runtime Instances",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-instances-security.html",
              "note": "AWS explicitly states agents run in the Region the customer specifies and session data and EBS volumes remain in the customer's account.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Runtime Instances provide explicit regional data-residency control."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "agentcore_runtime_instances",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Security model for Runtime Instances",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-instances-security.html",
              "note": "AWS states agents run in the VPC, subnets, account, and Region specified by the customer.",
              "evidence_type": "security_trust"
            },
            {
              "title": "AWS Docs – Supported AWS Regions for AgentCore",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-regions.html",
              "note": "AWS lists the supported AgentCore regions customers can deploy into.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Customers select a supported AWS Region for AgentCore Runtime Instances."
        },
        {
          "path": "protocols.a2a.auth.iam",
          "value": true,
          "scope": "agentcore_runtime_a2a",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – A2A protocol contract",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-a2a-protocol-contract.html",
              "note": "AWS documents SigV4 authentication for A2A server access.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "A2A endpoints support AWS SigV4 authentication."
        },
        {
          "path": "protocols.a2a.auth.oauth",
          "value": true,
          "scope": "agentcore_runtime_a2a",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – A2A protocol contract",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-a2a-protocol-contract.html",
              "note": "AWS documents OAuth 2.0 Bearer token authentication for A2A server access.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "A2A endpoints support OAuth 2.0 bearer-token authentication."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "agentcore_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Deploy A2A servers in AgentCore Runtime",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-a2a.html",
              "note": "AWS documents deploying and running A2A servers in AgentCore Runtime.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "AgentCore Runtime can host A2A servers."
        },
        {
          "path": "protocols.mcp.auth.api_key",
          "value": true,
          "scope": "mcp_gateway_targets",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – MCP server targets in AgentCore Gateway",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-target-MCPservers.html",
              "note": "Gateway supports API key credential providers for MCP targets.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "API-key auth is documented."
        },
        {
          "path": "protocols.mcp.auth.iam",
          "value": true,
          "scope": "mcp_gateway_targets",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – MCP server targets in AgentCore Gateway",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-target-MCPservers.html",
              "note": "Gateway supports IAM SigV4 outbound authorization for compatible MCP targets.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "IAM/SigV4 auth is documented."
        },
        {
          "path": "protocols.mcp.auth.oauth",
          "value": true,
          "scope": "runtime_and_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – AgentCore Runtime authentication and authorization",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-oauth.html",
              "note": "AgentCore Runtime supports OAuth/JWT inbound authorization and gateway-restricted invocation.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "OAuth/JWT authorization is documented."
        },
        {
          "path": "protocols.mcp.gateway",
          "value": true,
          "scope": "agentcore_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – MCP server targets in AgentCore Gateway",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-target-MCPservers.html",
              "note": "Gateway aggregates MCP targets into a unified virtual MCP server.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "AgentCore includes MCP gateway capability."
        },
        {
          "path": "protocols.mcp.remote",
          "value": true,
          "scope": "agentcore_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – MCP server targets in AgentCore Gateway",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-target-MCPservers.html",
              "note": "AgentCore Gateway connects to MCP server targets by URL.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Remote MCP server targets are supported."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "agentcore_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Deploy MCP servers in AgentCore Runtime",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-mcp.html",
              "note": "AgentCore Runtime can host streamable-HTTP MCP servers.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "MCP server hosting is supported."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "supported_agentcore_resources",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Data encryption in Amazon Bedrock AgentCore",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-encryption.html",
              "note": "AWS documents customer-managed KMS keys for supported AgentCore resources including Memories and Gateways.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Customer-managed KMS keys are supported for documented AgentCore resource types."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AWS KMS (AWS owned keys)",
          "scope": "agentcore_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Security best practices for AgentCore Runtime",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-security-best-practices.html",
              "note": "AWS states Runtime data at rest is encrypted by default with AWS-owned keys in AWS KMS.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Default Runtime at-rest encryption uses AWS-owned AWS KMS keys."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "agentcore_runtime",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Docs – Security best practices for AgentCore Runtime",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-security-best-practices.html",
              "note": "AWS states all client-to-Runtime and Runtime-to-dependency communication is protected with TLS 1.2 or higher.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "TLS 1.2 or higher is the documented minimum for Runtime communication."
        }
      ]
    },
    {
      "agent_id": "AI-0080",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "langsmith_enterprise",
          "evidence": [
            {
              "title": "LangChain Support – Enabling Audit Logs in Self-Hosted LangSmith",
              "url": "https://support.langchain.com/articles/5478528798-enabling-audit-logs-in-self-hosted-langsmith",
              "note": "LangChain documents GET /api/v1/audit-logs for programmatic audit-log access.",
              "evidence_type": "api_docs",
              "source_section": "Accessing Logs"
            }
          ],
          "note": "LangSmith exposes audit logs through API.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "langsmith_enterprise",
          "evidence": [
            {
              "title": "LangChain Support – Enabling Audit Logs in Self-Hosted LangSmith",
              "url": "https://support.langchain.com/articles/5478528798-enabling-audit-logs-in-self-hosted-langsmith",
              "note": "LangChain documents LangSmith audit logs covering 70+ administrative operations.",
              "evidence_type": "technical_docs",
              "source_section": "What Gets Logged"
            }
          ],
          "note": "LangSmith provides administrative audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "langsmith_enterprise",
          "evidence": [
            {
              "title": "LangChain Support – Enabling Audit Logs in Self-Hosted LangSmith",
              "url": "https://support.langchain.com/articles/5478528798-enabling-audit-logs-in-self-hosted-langsmith",
              "note": "LangChain documents OCSF 1.7 audit-log format and compatibility with SIEM tools such as Splunk and Datadog.",
              "evidence_type": "technical_docs",
              "source_section": "What Gets Logged"
            }
          ],
          "note": "LangSmith audit logs are SIEM-compatible.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "langsmith_enterprise",
          "evidence": [
            {
              "title": "LangSmith – LLMOps",
              "url": "https://info.langchain.com/Llm-ops",
              "note": "LangChain explicitly documents role-based access control with organization-level permissions and project isolation.",
              "evidence_type": "official_product_page",
              "source_section": "Security and compliance at scale"
            }
          ],
          "note": "LangSmith Enterprise supports RBAC.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "langsmith_deployment_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "LangChain – LangSmith Deployment",
              "url": "https://www.langchain.com/langsmith/deployment",
              "note": "LangChain explicitly describes LangSmith Deployment as the managed service for running agents at scale in production with one-click deployments and autoscaling.",
              "evidence_type": "official_product_page",
              "source_section": "FAQ / One-click deploy"
            }
          ],
          "note": "LangSmith Deployment provides a managed agent runtime."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "langsmith_byoc_self_hosted",
          "evidence": [
            {
              "title": "LangChain – LangSmith BYOC on AWS is generally available",
              "url": "https://www.langchain.com/blog/langsmith-byoc-is-now-generally-available-on-aws",
              "note": "LangChain documents LangSmith BYOC in customer AWS accounts, with EKS audit logs and VPC flow logs remaining in customer-controlled infrastructure.",
              "evidence_type": "official_release",
              "source_section": "BYOC architecture"
            }
          ],
          "note": "LangSmith supports customer-account/VPC deployment through BYOC/self-hosted models.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "langsmith_deployment_enterprise",
          "evidence": [
            {
              "title": "LangChain Enterprise Hub – Self-Hosted Onboarding Overview",
              "url": "https://enterprise-hub.langchain.com/onboarding/self-hosted-overview",
              "note": "LangChain documents LangSmith Self-Hosted running entirely in the customer's own infrastructure.",
              "evidence_type": "technical_docs",
              "source_section": "What is LangSmith Self-Hosted?"
            }
          ],
          "note": "LangSmith Deployment supports self-hosting.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "langsmith_saas_and_self_hosted",
          "evidence": [
            {
              "title": "LangChain Academy – Introduction to LangSmith",
              "url": "https://academy.langchain.com/courses/intro-to-langsmith",
              "note": "LangChain documents LangSmith hosted data in the U.S. or Netherlands and Enterprise self-hosted deployment where data remains in the customer environment.",
              "evidence_type": "technical_docs",
              "source_section": "LangSmith FAQs / Where is my data stored?"
            }
          ],
          "note": "LangSmith offers regional hosted instances and self-hosted residency options.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "langsmith_platform",
          "evidence": [
            {
              "title": "LangChain Support – Security & Compliance Information",
              "url": "https://support.langchain.com/articles/9852244333-how-to-access-langchain-security-compliance-information",
              "note": "LangChain states LangSmith product data is encrypted at rest.",
              "evidence_type": "security_trust",
              "source_section": "Product Security"
            }
          ],
          "note": "LangSmith documents encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "langsmith_platform",
          "evidence": [
            {
              "title": "LangChain Support – Security & Compliance Information",
              "url": "https://support.langchain.com/articles/9852244333-how-to-access-langchain-security-compliance-information",
              "note": "LangChain states LangSmith product data is encrypted in transit.",
              "evidence_type": "security_trust",
              "source_section": "Product Security"
            }
          ],
          "note": "LangSmith documents encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "langsmith_entire_offering",
          "evidence": [
            {
              "title": "LangChain Trust Center",
              "url": "https://trust.langchain.com/",
              "note": "LangChain states its 2026 SOC 2 Type II examination spans the entire LangSmith offering.",
              "evidence_type": "security_trust",
              "source_section": "Compliance / 2026 SOC 2 Type II Report"
            }
          ],
          "note": "LangSmith is covered by SOC 2 Type II.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0081",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "workato_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agent Studio API",
              "url": "https://docs.workato.com/workato-api/agent-studio.html",
              "note": "Workato documents REST endpoints to create, manage, start, and stop Agent Studio genies and related assets.",
              "evidence_type": "api_docs",
              "source_section": "Agent Studio APIs"
            }
          ],
          "note": "Workato exposes Agent Studio resources through documented REST APIs."
        },
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "workato_genie_conversation_history",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agentic",
              "url": "https://docs.workato.com/agentic/agentic.html",
              "note": "Workato documents API access for querying genie conversation history programmatically on eligible plans.",
              "evidence_type": "api_docs",
              "source_section": "Genie conversation observability"
            }
          ],
          "note": "Eligible Workato plans provide API access to query genie conversation history."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "workato_agent_studio_and_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agent Studio",
              "url": "https://docs.workato.com/agentic/agent-studio.html",
              "note": "Workato documents audit trails for all actions taken in Agent Studio.",
              "evidence_type": "technical_docs",
              "source_section": "Enterprise-grade security features"
            },
            {
              "title": "Workato Docs – Agentic",
              "url": "https://docs.workato.com/agentic/agentic.html",
              "note": "Workato documents full genie conversation history and per-skill job history for observability.",
              "evidence_type": "technical_docs",
              "source_section": "Genie conversation observability"
            }
          ],
          "note": "Workato Agentic provides audit trails and conversation/job history."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "workato_agentic_and_platform_logs",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agentic",
              "url": "https://docs.workato.com/agentic/agentic.html",
              "note": "Workato documents genie conversation log streaming to destinations including Splunk and Datadog.",
              "evidence_type": "technical_docs",
              "source_section": "Genie conversation observability"
            },
            {
              "title": "Workato Docs – MCP Gateway",
              "url": "https://docs.workato.com/en/mcp/mcp-gateway",
              "note": "Workato documents streaming MCP activity logs to any SIEM application.",
              "evidence_type": "security_trust",
              "source_section": "Observability / Server-level logs"
            }
          ],
          "note": "Workato Agentic logs can be streamed to external SIEM/observability destinations."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "workato_workspace_and_agentic_assets",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Security",
              "url": "https://docs.workato.com/security.html",
              "note": "Workato documents environment roles, project roles, and custom roles for granular access to platform assets.",
              "evidence_type": "security_trust",
              "source_section": "Controlling user access through RBAC"
            }
          ],
          "note": "Workato supports custom roles for granular platform and asset permissions."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "workato_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agent Studio",
              "url": "https://docs.workato.com/agentic/agent-studio.html",
              "note": "Workato documents RBAC for genies and knowledge bases, including collaborator privileges and access to test mode and conversation history.",
              "evidence_type": "technical_docs",
              "source_section": "Enterprise-grade security features"
            }
          ],
          "note": "Agent Studio has explicit role-based access control."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "workato_workspace_identity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Configure and use SCIM",
              "url": "https://docs.workato.com/en/scim-workato.html",
              "note": "Workato documents SCIM 2.0 provisioning, deprovisioning, and role/group synchronization.",
              "evidence_type": "technical_docs",
              "source_section": "Configure SCIM in Workato"
            }
          ],
          "note": "Workato supports SCIM 2.0 provisioning and deprovisioning."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "workato_identity_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Workato Identity SAML-based SSO",
              "url": "https://docs.workato.com/workato-identity/saml-sso",
              "note": "Workato documents SAML-based SSO for Workato Identity, which is used by Agent Studio and other agentic features.",
              "evidence_type": "technical_docs",
              "source_section": "SAML-based SSO"
            },
            {
              "title": "Workato Docs – Microsoft Entra ID SAML configuration",
              "url": "https://docs.workato.com/en/workato-identity/microsoft-entra-id-saml-configuration",
              "note": "Workato states Workato Identity is available for Agent Studio, Workato GO, MCP, and the API developer portal.",
              "evidence_type": "technical_docs",
              "source_section": "Prerequisites"
            }
          ],
          "note": "Agent Studio supports SAML SSO through Workato Identity."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "workato_agent_studio_genies",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agentic FAQ",
              "url": "https://docs.workato.com/en/agentic/faqs.html",
              "note": "Workato states that genies are AI agents hosted and managed by Workato.",
              "evidence_type": "technical_docs",
              "source_section": "When should I use Workato genies vs. external AI clients with MCP?"
            }
          ],
          "note": "Workato hosts and manages Agent Studio genies."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "workato_private_connectivity_and_vpw",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Private connectivity",
              "url": "https://docs.workato.com/en/security/data-protection/private-connectivity.html",
              "note": "Workato documents AWS PrivateLink, Azure Private Link, on-prem agent connectivity, and Virtual Private Workato for private network connectivity.",
              "evidence_type": "security_trust",
              "source_section": "Private connectivity"
            },
            {
              "title": "Workato Docs – Virtual Private Workato",
              "url": "https://docs.workato.com/en/cloud-hosting-editions/hosting-editions.html",
              "note": "Workato documents dedicated isolated VPW environments in AWS VPCs with VPC peering/transit connectivity to customer private networks.",
              "evidence_type": "security_trust",
              "source_section": "Virtual Private Workato"
            }
          ],
          "note": "Workato supports private connectivity and dedicated VPC deployment options."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "workato_agent_studio_genies",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agent Studio data",
              "url": "https://docs.workato.com/en/agentic/agent-studio/data.html",
              "note": "Workato documents Agent Studio/genie availability across US, EU, AU, SG, and JP data centers and regional model hosting for data-residency requirements.",
              "evidence_type": "security_trust",
              "source_section": "Data residency"
            }
          ],
          "note": "Agent Studio supports regional deployment/data-residency options."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "workato_workspace_region",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Data center overview",
              "url": "https://docs.workato.com/datacenter/datacenter-overview",
              "note": "Workato documents regional data centers and states each account is hosted in a single selected regional data center, with separate accounts used for multiple regions.",
              "evidence_type": "technical_docs",
              "source_section": "Workato across regions"
            },
            {
              "title": "Workato Docs – Agent Studio data",
              "url": "https://docs.workato.com/en/agentic/agent-studio/data.html",
              "note": "Workato lists the regional data centers in which genies are available.",
              "evidence_type": "security_trust",
              "source_section": "Data residency"
            }
          ],
          "note": "Customers choose the regional Workato data center in which their Agent Studio workspace operates."
        },
        {
          "path": "protocols.a2a.client",
          "value": true,
          "scope": "workato_agent_studio_genies",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agentic",
              "url": "https://docs.workato.com/agentic/agentic.html",
              "note": "Workato states genies can call any A2A Protocol-compliant agent and delegate tasks to external agents.",
              "evidence_type": "technical_docs",
              "source_section": "Workato Agent Registry"
            },
            {
              "title": "Workato Docs – A2A Protocol",
              "url": "https://docs.workato.com/en/connectors/a2a",
              "note": "Workato documents invoking compliant A2A agent servers synchronously or asynchronously over HTTP/JSON-RPC.",
              "evidence_type": "technical_docs",
              "source_section": "A2A Protocol"
            }
          ],
          "note": "Workato genies can act as A2A clients when delegating tasks to external agents."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "workato_agentic",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Agentic",
              "url": "https://docs.workato.com/agentic/agentic.html",
              "note": "Workato documents Agent Studio genies collaborating with external agents using the Agent-to-Agent (A2A) protocol.",
              "evidence_type": "technical_docs",
              "source_section": "Workato Agent Registry"
            }
          ],
          "note": "A2A is a documented interoperability protocol in Workato Agentic."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "workato_agent_studio_genies",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Genies as MCP clients",
              "url": "https://docs.workato.com/en/mcp/genies-as-mcp-clients.html",
              "note": "Workato documents Agent Studio genies consuming Workato-hosted and external MCP servers as tools.",
              "evidence_type": "technical_docs",
              "source_section": "Genies as MCP clients"
            }
          ],
          "note": "Workato genies can act as MCP clients."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "workato_agentic_and_enterprise_mcp",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – MCP servers",
              "url": "https://docs.workato.com/en/mcp/mcp-servers",
              "note": "Workato documents authenticated remote MCP servers that expose Workato endpoints and tools to AI agents and clients.",
              "evidence_type": "technical_docs",
              "source_section": "MCP servers"
            },
            {
              "title": "Workato Docs – Chat interface",
              "url": "https://docs.workato.com/agentic/agent-studio/chat-interface/chat-interface",
              "note": "Workato documents exposing a genie as an MCP server for external AI clients.",
              "evidence_type": "technical_docs",
              "source_section": "Using an external AI client?"
            }
          ],
          "note": "Workato can expose Workato capabilities and genies through MCP servers."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "workato_enterprise_key_management",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Encryption key management",
              "url": "https://docs.workato.com/security/data-protection/encryption-key-management/",
              "note": "Workato documents customer-managed Customer Main Keys where customers own and manage the key supplied to Workato.",
              "evidence_type": "security_trust",
              "source_section": "Top level"
            }
          ],
          "note": "Workato supports customer-managed/BYOK encryption keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "workato_platform_data_including_agentic_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Security",
              "url": "https://docs.workato.com/security.html",
              "note": "Workato documents AES-256 encryption for data at rest, including job history and audit logs.",
              "evidence_type": "security_trust",
              "source_section": "Data encryption"
            }
          ],
          "note": "Workato encrypts platform data at rest with AES-256."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "workato_platform_data_including_agentic_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Security",
              "url": "https://docs.workato.com/security.html",
              "note": "Workato states all platform data is encrypted in transit and documents TLS 1.2/1.3 for API Platform endpoints.",
              "evidence_type": "security_trust",
              "source_section": "TLS and HTTP standards / Data encryption"
            }
          ],
          "note": "Workato encrypts platform data in transit and supports TLS 1.2/1.3 for API endpoints."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "workato_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workato Docs – Virtual Private Workato",
              "url": "https://docs.workato.com/en/cloud-hosting-editions/hosting-editions.html",
              "note": "Workato lists SOC 2 Type II among supported compliance frameworks.",
              "evidence_type": "security_trust",
              "source_section": "VPW key features"
            }
          ],
          "note": "Workato documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0082",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "agentstudio_programmatic_management",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Agentstudio benefits and features",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Agentstudio",
              "note": "Agentstudio documents programmatic agent development/management through REST APIs.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "REST APIs are documented."
        },
        {
          "path": "governance.ai_control_tower",
          "value": true,
          "scope": "agentstudio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Agentstudio benefits and features",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Agentstudio",
              "note": "Agent Control Tower is the governance layer of Agentstudio.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Centralized agent governance is documented."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "agentstudio_agent_sessions",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Documentation – Agent management FAQ",
              "url": "https://help.boomi.com/docs/atomsphere/platform/atm-boomiai_faq_8a8705a8-4773-44bd-92ed-41105186781c/",
              "note": "Boomi documents audit trails for actions related to agent sessions, including access records.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agentstudio session actions are covered by documented audit trails."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "agentstudio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Accessing Agentstudio and setting up permissions",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Accessing_agentstudio",
              "note": "Boomi explicitly supports custom roles with granular Agent Garden privileges for building and managing agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Custom roles with granular Agentstudio privileges are supported."
        },
        {
          "path": "governance.observability",
          "value": true,
          "scope": "agentstudio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Agentstudio benefits and features",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Agentstudio",
              "note": "Agentstudio documents near-real-time metrics and agent-session tracing.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agent monitoring and tracing are documented."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "agentstudio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Agentstudio access and permissions",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Accessing_agentstudio",
              "note": "Agentstudio documents Administrator, Developer, User and custom privilege-based roles.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Role-based access patterns are documented."
        },
        {
          "path": "governance.session_logs.available",
          "value": true,
          "scope": "deployed_conversational_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Tracing sessions of Boomi Agent Garden agents",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Sessionlogs",
              "note": "Boomi documents session logs for deployed conversational Agent Garden agents, including all executed sessions.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Session logs are available for deployed conversational agents in Agent Garden."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "boomi_enterprise_platform_users_accessing_agentstudio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Documentation – Single sign-on with SAML authentication",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/c-atm-Single_sign-on_with_SAML_authentication_71c031d5-5912-4255-bb8e-61a129afabc1",
              "note": "Boomi documents SAML 2.0 single sign-on for the Boomi Enterprise Platform.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Boomi Documentation – Accessing Agentstudio and setting up permissions",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Accessing_agentstudio",
              "note": "Boomi documents Agentstudio as an application accessed through the Boomi Enterprise Platform and governed by Platform user management.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agentstudio users access the Boomi Enterprise Platform, which supports SAML 2.0 SSO where the Advanced User Security feature is enabled."
        },
        {
          "path": "governance.tracing",
          "value": true,
          "scope": "deployed_conversational_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Tracing sessions of Boomi Agent Garden agents",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Sessionlogs",
              "note": "Boomi states session logs provide production reasoning visibility and detailed session traces for troubleshooting and optimization.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Production session tracing is documented for deployed conversational agents."
        },
        {
          "path": "memory.session_state",
          "value": true,
          "confidence": "high",
          "scope": "conversational_agents_extended_thinking",
          "verified_at": "2026-10-03",
          "note": "With Extended Thinking enabled, conversational agents retain tool-response data for the rest of the session; structured mode and Agent Step are single-turn.",
          "evidence": [
            {
              "title": "Boomi Docs – Agentstudio token limits",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/ai-as_token_limits",
              "evidence_type": "technical_docs",
              "source_section": "Session memory"
            }
          ]
        },
        {
          "path": "operations.context_window_tokens",
          "value": 200000,
          "confidence": "high",
          "scope": "agent_interaction",
          "verified_at": "2026-10-03",
          "note": "Boomi documents a 200,000-input-token model context window for Agentstudio interactions.",
          "evidence": [
            {
              "title": "Boomi Docs – Agentstudio token limits",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/ai-as_token_limits",
              "evidence_type": "technical_docs",
              "source_section": "Token limitation details"
            }
          ]
        },
        {
          "path": "operations.max_output_tokens_per_turn",
          "value": 4096,
          "confidence": "high",
          "scope": "agent_interaction",
          "verified_at": "2026-10-03",
          "note": "Boomi documents a maximum of 4,096 output tokens for an agent response per turn.",
          "evidence": [
            {
              "title": "Boomi Docs – Agentstudio token limits",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/ai-as_token_limits",
              "evidence_type": "technical_docs",
              "source_section": "Token limitation details"
            }
          ]
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "boomi_ai_services",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Boomi – AI Security & Trust",
              "url": "https://boomi.com/de/ai-security-trust/",
              "note": "Boomi documents data residency for AI services and regional containment.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Boomi documents data-residency controls for its AI services."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "boomi_agent_garden_runtime_cloud",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Documentation – Deploying agents",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/ai-deploying_agents",
              "note": "Boomi documents deploying Agentstudio agents to runtime clouds in the US, UK, Japan, and Australia and states regional deployment keeps data within regional boundaries for compliance.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agentstudio users select supported regional runtime clouds when deploying agents."
        },
        {
          "path": "privacy.residency.region",
          "value": "North America",
          "scope": "boomi_agentstudio_and_agent_session_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Boomi – AI Security & Trust",
              "url": "https://boomi.com/de/ai-security-trust/",
              "note": "Boomi states Agentstudio agents and agent session data operate within North American data centers and are not replicated outside those boundaries.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Current Boomi documentation places Agentstudio and agent-session data in North American data centers."
        },
        {
          "path": "protocols.mcp.auth.basic",
          "value": true,
          "scope": "mcp_sources",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Creating and managing Agentstudio sources",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/ai_Creating_and_managing_sources",
              "note": "Boomi documents Basic authentication for MCP sources.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Basic auth is supported."
        },
        {
          "path": "protocols.mcp.auth.jwt",
          "value": true,
          "scope": "mcp_sources",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Creating and managing Agentstudio sources",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/ai_Creating_and_managing_sources",
              "note": "Boomi documents Platform JWT authentication for MCP sources.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Platform JWT auth is supported."
        },
        {
          "path": "protocols.mcp.auth.oauth",
          "value": true,
          "scope": "mcp_sources",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Creating and managing Agentstudio sources",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/ai_Creating_and_managing_sources",
              "note": "Boomi documents OAuth 2.0/2.1 for MCP source authentication.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "OAuth for MCP sources is documented."
        },
        {
          "path": "protocols.mcp.auth.token",
          "value": true,
          "scope": "mcp_sources",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Creating and managing Agentstudio sources",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/ai_Creating_and_managing_sources",
              "note": "Boomi documents Token authentication for MCP sources.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Token auth is supported."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "agent_designer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Using MCP with Agent Designer",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Using_MCP_with_Agent_Designer",
              "note": "Boomi Agent Designer connects to remote MCP servers and imports their tools.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agentstudio acts as an MCP client."
        },
        {
          "path": "protocols.mcp.registry",
          "value": true,
          "scope": "api_control_plane",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – MCP Server Catalog",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Using_the_MCP_registry",
              "note": "Boomi provides a centralized MCP Registry and governed Server Catalog.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "A managed MCP registry/catalog is documented."
        },
        {
          "path": "protocols.mcp.remote",
          "value": true,
          "scope": "agent_designer",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Docs – Using MCP with Agent Designer",
              "url": "https://help.boomi.com/docs/Atomsphere/Platform/Using_MCP_with_Agent_Designer",
              "note": "Agent Designer can connect to third-party remote MCP servers.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Remote MCP servers are supported."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "boomi_ai_including_agentstudio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Documentation – Agent management FAQ",
              "url": "https://help.boomi.com/docs/atomsphere/platform/atm-boomiai_faq_8a8705a8-4773-44bd-92ed-41105186781c/",
              "note": "Boomi explicitly states all Boomi AI data is encrypted at rest and that Agentstudio sensitive data also uses a customer account-specific encryption key.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Boomi documents at-rest encryption for all Boomi AI data, including Agentstudio."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "boomi_ai_including_agentstudio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Boomi Documentation – Agent management FAQ",
              "url": "https://help.boomi.com/docs/atomsphere/platform/atm-boomiai_faq_8a8705a8-4773-44bd-92ed-41105186781c/",
              "note": "Boomi explicitly states all Boomi AI data is encrypted in transit.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Boomi documents in-transit encryption for all Boomi AI data, including Agentstudio."
        }
      ]
    },
    {
      "agent_id": "AI-0083",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "kore_ai_artemis_and_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Kore.ai – Artemis Agent Platform launch",
              "url": "https://www.kore.ai/news/kore-ai-launches-artemis-the-new-generation-of-the-kore-ai-agent-platform-for-building-governing-and-optimizing-enterprise-ai",
              "note": "Kore.ai states immutable audit trails apply to every agent action.",
              "evidence_type": "official_release",
              "source_section": "Built for the Global 2000"
            }
          ],
          "note": "Kore.ai provides agent/platform audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "kore_ai_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Kore.ai – Agent Platform announcement",
              "url": "https://www.kore.ai/news/kore-ai-announces-agent-platform-for-building-deploying-and-orchestrating-agentic-applications",
              "note": "Kore.ai documents secure role-based access in the Agent Platform.",
              "evidence_type": "official_release",
              "source_section": "AI for Work / secure role-based access"
            }
          ],
          "note": "Kore.ai Agent Platform supports role-based access."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "kore_ai_artemis_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kore.ai – Artemis Agent Platform launch",
              "url": "https://www.kore.ai/news/kore-ai-launches-artemis-the-new-generation-of-the-kore-ai-agent-platform-for-building-governing-and-optimizing-enterprise-ai",
              "note": "Kore.ai documents the Artemis generation of Kore.ai Agent Platform launching initially on Microsoft Azure as the enterprise foundation for building and operating agents.",
              "evidence_type": "official_release",
              "source_section": "Kore.ai Agent Platform Artemis edition"
            }
          ],
          "note": "Kore.ai Agent Platform Artemis is delivered as a managed cloud platform, initially on Microsoft Azure."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "kore_ai_artemis_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kore.ai – Artemis Agent Platform launch",
              "url": "https://www.kore.ai/news/kore-ai-launches-artemis-the-new-generation-of-the-kore-ai-agent-platform-for-building-governing-and-optimizing-enterprise-ai",
              "note": "Kore.ai states customers can deploy in private cloud as well as public/sovereign/on-prem environments.",
              "evidence_type": "official_release",
              "source_section": "Built for the Global 2000"
            }
          ],
          "note": "Kore.ai Artemis supports private-cloud deployment."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "kore_ai_artemis_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kore.ai – Artemis Agent Platform launch",
              "url": "https://www.kore.ai/news/kore-ai-launches-artemis-the-new-generation-of-the-kore-ai-agent-platform-for-building-governing-and-optimizing-enterprise-ai",
              "note": "Kore.ai states customers can deploy Artemis on-premises.",
              "evidence_type": "official_release",
              "source_section": "Built for the Global 2000"
            }
          ],
          "note": "Kore.ai Artemis supports on-premises deployment."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "kore_ai_artemis_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kore.ai – Artemis Agent Platform launch",
              "url": "https://www.kore.ai/news/kore-ai-launches-artemis-the-new-generation-of-the-kore-ai-agent-platform-for-building-governing-and-optimizing-enterprise-ai",
              "note": "Kore.ai explicitly documents data residency by region and sovereign-region deployment.",
              "evidence_type": "official_release",
              "source_section": "Built for the Global 2000"
            }
          ],
          "note": "Kore.ai Artemis supports regional data residency."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "kore_ai_agent_platform_amp",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Kore.ai – Why enterprises need an Agent Management Platform",
              "url": "https://www.kore.ai/blog/why-enterprises-need-agent-management-platform",
              "note": "Kore.ai explicitly states agents communicate through A2A (Agent-to-Agent) protocols.",
              "evidence_type": "official_release",
              "source_section": "Agent Management Platform / interoperability"
            }
          ],
          "note": "Kore.ai explicitly documents A2A protocol support."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "kore_ai_agent_platform_agents",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Kore.ai – Introducing Agent Blueprint Language (ABL)",
              "url": "https://www.kore.ai/blog/introducing-agent-blueprint-language-abl",
              "note": "Kore.ai documents enterprise agents connecting to existing enterprise systems through MCP alongside HTTP, OpenAPI, A2A, Lambda, and webhooks.",
              "evidence_type": "official_release",
              "source_section": "Deployment options / enterprise-system connectivity"
            }
          ],
          "note": "Kore.ai Agent Platform supports agent connectivity to enterprise systems through MCP."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "kore_ai_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Kore.ai – How to ensure AI agents comply with industry regulations",
              "url": "https://www.kore.ai/blog/how-to-make-ai-agents-comply-with-industry-regulations",
              "note": "Kore.ai states enterprise data in its AI agent platform is protected with AES-256 encryption at rest backed by HSMs.",
              "evidence_type": "official_release",
              "source_section": "Security and compliance strengthen AI governance"
            }
          ],
          "note": "Kore.ai documents AES-256 encryption at rest for enterprise AI-agent data."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "kore_ai_artemis",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Kore.ai – Artemis Agent Platform launch",
              "url": "https://www.kore.ai/news/kore-ai-launches-artemis-the-new-generation-of-the-kore-ai-agent-platform-for-building-governing-and-optimizing-enterprise-ai",
              "note": "Kore.ai states Artemis meets SOC 2 Type II requirements.",
              "evidence_type": "security_trust",
              "source_section": "Built for the Global 2000"
            }
          ],
          "note": "Kore.ai documents SOC 2 Type II compliance for Artemis."
        }
      ]
    },
    {
      "agent_id": "AI-0084",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "tray_platform_including_merlin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – Logs and Debugging",
              "url": "https://tray.ai/documentation/platform/artificial-intelligence/agent-builder/logs-and-debugging",
              "note": "Tray documents detailed logs for each agent request and execution.",
              "evidence_type": "technical_docs",
              "source_section": "Logs and Debugging"
            },
            {
              "title": "Tray Docs – Security Policies",
              "url": "https://tray.ai/documentation/platform/enterprise-core/security-compliance/security-policies",
              "note": "Tray documents comprehensive audit logs across its application and infrastructure.",
              "evidence_type": "security_trust",
              "source_section": "Security Policies"
            }
          ],
          "note": "Tray provides agent execution logs and platform audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 30,
          "scope": "tray_default_workflow_logs_used_by_merlin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – Security Statement",
              "url": "https://tray.ai/documentation/platform/enterprise-core/security-compliance/security-statement",
              "note": "Tray states customers can reduce workflow-log retention from 30 days to 24 hours; Merlin Agent Builder stores conversation inputs and outputs in workflow logs.",
              "evidence_type": "security_trust",
              "source_section": "Additional Safeguards"
            },
            {
              "title": "Tray Docs – How does Merlin AI use my data?",
              "url": "https://tray.ai/documentation/platform/enterprise-core/security-compliance/how-does-merlin-ai-use-my-data",
              "note": "Merlin Agent Builder conversation inputs and outputs follow the existing workflow-log retention period.",
              "evidence_type": "technical_docs",
              "source_section": "Merlin Agent Builder"
            }
          ],
          "note": "The documented default workflow-log retention used by Merlin Agent Builder is 30 days."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "tray_platform_logs",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – Log Streaming",
              "url": "https://tray.ai/documentation/platform/enterprise-core/logs-debugging/log-streaming",
              "note": "Tray documents streaming execution, step, and audit logs to external systems such as Datadog, Sentry, New Relic, or Kibana.",
              "evidence_type": "technical_docs",
              "source_section": "Log Streaming / Audit event type"
            }
          ],
          "note": "Tray can stream audit and execution logs to external observability/SIEM systems."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "tray_platform_including_merlin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – User management and RBAC",
              "url": "https://tray.ai/documentation/platform/enterprise-core/organisation-management/users/roles",
              "note": "Tray documents Owner, Admin, Contributor, and Viewer roles with an RBAC permission matrix.",
              "evidence_type": "technical_docs",
              "source_section": "Role-Based Access Control (RBAC)"
            },
            {
              "title": "Tray Docs – Merlin Agent Builder Getting Started",
              "url": "https://tray.ai/documentation/platform/artificial-intelligence/agent-builder/getting-started",
              "note": "Tray requires workspace/project permissions to access Merlin Agent Builder.",
              "evidence_type": "technical_docs",
              "source_section": "Prerequisites"
            }
          ],
          "note": "Merlin Agent Builder access operates within Tray's RBAC model."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "tray_enterprise_including_merlin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – Profile & Login",
              "url": "https://tray.ai/documentation/platform/enterprise-core/organisation-management/users/profile-login",
              "note": "Tray documents SSO with any SAML 2.0-compatible identity provider for Enterprise organizations.",
              "evidence_type": "technical_docs",
              "source_section": "Single Sign-On"
            }
          ],
          "note": "Tray Enterprise supports SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "tray_merlin_agent_builder",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – How does Merlin AI use my data?",
              "url": "https://tray.ai/documentation/platform/enterprise-core/security-compliance/how-does-merlin-ai-use-my-data",
              "note": "Tray explicitly states Merlin Agent Builder runs within Tray's cloud infrastructure.",
              "evidence_type": "technical_docs",
              "source_section": "Merlin Agent Builder"
            }
          ],
          "note": "Merlin Agent Builder runs on Tray-managed cloud infrastructure."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "tray_merlin_agent_builder",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – Regional Hosting",
              "url": "https://tray.ai/documentation/platform/enterprise-core/organisation-management/regional-hosting",
              "note": "Tray documents US, EU, and APAC data regions for Tray instances.",
              "evidence_type": "technical_docs",
              "source_section": "Regional Hosting"
            },
            {
              "title": "Tray Docs – How does Merlin AI use my data?",
              "url": "https://tray.ai/documentation/platform/enterprise-core/security-compliance/how-does-merlin-ai-use-my-data",
              "note": "Tray documents Merlin Agent Builder processing in region-aware Tray infrastructure and regional Bedrock inference boundaries.",
              "evidence_type": "technical_docs",
              "source_section": "Cross-Region AI Processing"
            }
          ],
          "note": "Merlin Agent Builder is available on Tray's region-aware hosting platform."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "tray_organization_instance",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – Regional Hosting",
              "url": "https://tray.ai/documentation/platform/enterprise-core/organisation-management/regional-hosting",
              "note": "Tray states a Tray instance can be hosted in one of US, EU, or APAC data regions, with Enterprise access to all regions.",
              "evidence_type": "technical_docs",
              "source_section": "Regional Hosting"
            }
          ],
          "note": "Customers can select among supported Tray data regions for their organization instance."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "tray_platform_including_merlin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – Security Policies",
              "url": "https://tray.ai/documentation/platform/enterprise-core/security-compliance/security-policies",
              "note": "Tray states all stored data is encrypted at rest, with additional encryption for sensitive workflow authentications.",
              "evidence_type": "security_trust",
              "source_section": "Security Measures"
            }
          ],
          "note": "Tray documents encryption at rest for stored platform data."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "tray_platform_including_merlin",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray Docs – Security Policies",
              "url": "https://tray.ai/documentation/platform/enterprise-core/security-compliance/security-policies",
              "note": "Tray states all data sent to Tray is encrypted and endpoints are TLS/SSL-only.",
              "evidence_type": "security_trust",
              "source_section": "Security Measures"
            }
          ],
          "note": "Tray documents encrypted TLS/SSL transport for data sent to the platform."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "tray_platform_including_merlin_agent_builder",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Tray.ai Trust Center",
              "url": "https://trust.tray.ai/",
              "note": "Tray's Trust Center lists SOC 2 Type II for the Tray platform; Merlin Agent Builder is documented as native functionality on Tray.",
              "evidence_type": "security_trust",
              "source_section": "Compliance / SOC 2 Type II"
            }
          ],
          "note": "Merlin Agent Builder runs on the Tray platform covered by Tray's SOC 2 Type II compliance posture."
        }
      ]
    },
    {
      "agent_id": "AI-0085",
      "claims": [
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "strands_agents_sdk",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "AWS Prescriptive Guidance – Strands Agents",
              "url": "https://docs.aws.amazon.com/prescriptive-guidance/latest/agentic-ai-frameworks/strands-agents.html",
              "note": "AWS documents Strands Agents as an open-source SDK with a DIY deployment model for building autonomous agents across AWS and third-party components.",
              "evidence_type": "technical_docs",
              "source_section": "Strands Agents / Comparing agentic AI frameworks"
            }
          ],
          "note": "Strands Agents is an open-source SDK intended to run in developer/customer-managed environments."
        },
        {
          "path": "protocols.a2a.client",
          "value": true,
          "scope": "strands_agents_sdk",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Strands Agents – Agent-to-Agent (A2A) Protocol",
              "url": "https://strandsagents.com/docs/user-guide/sdk/multi-agent/agent-to-agent/",
              "note": "Strands documents consuming remote A2A agents through the A2AAgent client class.",
              "evidence_type": "technical_docs",
              "source_section": "Consuming Remote Agents"
            }
          ],
          "note": "Strands Agents can act as an A2A client."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "strands_agents_sdk",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Strands Agents – Agent-to-Agent (A2A) Protocol",
              "url": "https://strandsagents.com/docs/user-guide/sdk/multi-agent/agent-to-agent/",
              "note": "Strands documents serving Strands agents over A2A using A2AServer/A2AExpressServer.",
              "evidence_type": "technical_docs",
              "source_section": "Serving an Agent over A2A"
            }
          ],
          "note": "Strands Agents can act as an A2A server."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "strands_agents_sdk",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Strands Agents – Agent-to-Agent (A2A) Protocol",
              "url": "https://strandsagents.com/docs/user-guide/sdk/multi-agent/agent-to-agent/",
              "note": "Strands explicitly documents native A2A support on both consuming and serving sides.",
              "evidence_type": "technical_docs",
              "source_section": "Agent-to-Agent (A2A) Protocol"
            }
          ],
          "note": "Strands Agents natively supports A2A."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "strands_agents_sdk",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Strands Agents – Connect your agent to MCP tools",
              "url": "https://strandsagents.com/docs/user-guide/sdk/tools/mcp-tools/",
              "note": "Strands documents MCPClient loading tools from external MCP servers and handing them to the agent.",
              "evidence_type": "technical_docs",
              "source_section": "Quick Start"
            }
          ],
          "note": "Strands Agents can act as MCP clients."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "strands_shell",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Strands Agents – Run the MCP server",
              "url": "https://strandsagents.com/docs/user-guide/shell/mcp-server/",
              "note": "Strands documents a built-in MCP server exposing a sandboxed shell over JSON-RPC on stdio.",
              "evidence_type": "technical_docs",
              "source_section": "Run the MCP server"
            }
          ],
          "note": "Strands includes an MCP server mode."
        }
      ]
    },
    {
      "agent_id": "AI-0086",
      "claims": [
        {
          "path": "api.openai_compatible",
          "value": true,
          "scope": "self_hosted_and_managed",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Hosting Agent Framework applications",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/",
              "note": "The hosting documentation describes OpenAI-compatible Responses and Chat Completions endpoints.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "OpenAI-compatible serving endpoints are documented."
        },
        {
          "path": "api.rest",
          "value": true,
          "scope": "agent_framework_openai_compatible_http_endpoints",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – OpenAI-Compatible Endpoints",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/self-hosting/openai-endpoints",
              "note": "Microsoft documents exposing Agent Framework agents through OpenAI-compatible HTTP Chat Completions and Responses endpoints, including POST examples and custom API paths.",
              "evidence_type": "api_docs",
              "source_section": "Hosting Agents as OpenAI Endpoints"
            }
          ],
          "note": "Agent Framework can expose agents through documented HTTP/REST-style API endpoints."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "agent_framework_durable_extension_event_driven_hosts",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Durable Extension",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/azure-functions",
              "note": "Microsoft lists webhooks alongside triggers, queues, timers, and application events as supported event-driven orchestration inputs for durable Agent Framework agents.",
              "evidence_type": "technical_docs",
              "source_section": "When to use durable agents"
            }
          ],
          "note": "The Durable Extension supports webhook-driven Agent Framework orchestration."
        },
        {
          "path": "hosting.managed_provider",
          "value": "Microsoft Foundry",
          "scope": "framework",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Hosting Agent Framework applications",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/",
              "note": "Foundry Hosted Agents are the documented managed hosting option.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Microsoft Foundry is a documented managed host."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "framework",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Hosting Agent Framework applications",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/",
              "note": "Microsoft documents Foundry Hosted Agents as a managed hosting path.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Managed hosting through Microsoft Foundry is documented."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "agent_framework_on_azure_functions_supported_host",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Durable Extension",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/azure-functions",
              "note": "Microsoft documents Azure Functions as a supported hosting model for Agent Framework durable agents.",
              "evidence_type": "technical_docs",
              "source_section": "Azure Functions hosting"
            },
            {
              "title": "Microsoft Learn – Azure Functions networking options",
              "url": "https://learn.microsoft.com/en-us/azure/azure-functions/functions-networking-options",
              "note": "Microsoft documents Azure Functions hosting plans with private endpoints, inbound access restrictions, and outbound virtual-network connectivity.",
              "evidence_type": "technical_docs",
              "source_section": "Compare hosting options"
            }
          ],
          "note": "Agent Framework deployments on the supported Azure Functions host can be placed behind private endpoints and VNet integration."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "framework",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Hosting Agent Framework applications",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/",
              "note": "Microsoft documents self-hosting Agent Framework applications.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Self-hosting is supported."
        },
        {
          "path": "protocols.a2a.client",
          "value": true,
          "scope": "microsoft_agent_framework_remote_a2a_agent_service",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – A2A agent service",
              "url": "https://learn.microsoft.com/en-us/agent-framework/agents/providers/agent-to-agent",
              "note": "Microsoft documents A2AAgent as a client wrapper that connects Agent Framework applications to remote A2A-compliant agent endpoints.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Microsoft Agent Framework can invoke remote agents through the A2A protocol."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "microsoft_agent_framework_a2a_hosting",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – A2A Hosting",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/agent-to-agent",
              "note": "Microsoft documents hosting packages that expose Agent Framework agents through the A2A protocol for discovery and communication by A2A clients.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Microsoft Agent Framework agents can be exposed as A2A servers."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "framework",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Hosting Agent Framework applications",
              "url": "https://learn.microsoft.com/en-us/agent-framework/hosting/",
              "note": "Microsoft documents A2A hosting and remote A2A agent services.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "A2A integration/hosting is documented."
        },
        {
          "path": "protocols.mcp.auth.api_key",
          "value": true,
          "scope": "framework",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft GitHub – Agent Framework MCP examples",
              "url": "https://github.com/microsoft/agent-framework/blob/main/python/samples/02-agents/mcp/README.md",
              "note": "The official MCP examples include API-key authentication for MCP connections.",
              "evidence_type": "official_github"
            }
          ],
          "note": "API-key authentication for MCP connections is documented."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "framework",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Using MCP tools with Agents",
              "url": "https://learn.microsoft.com/en-us/agent-framework/user-guide/model-context-protocol/using-mcp-tools",
              "note": "Microsoft documents connecting Agent Framework agents to MCP servers and using their tools.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agent Framework includes MCP client integration."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "framework",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft GitHub – Agent Framework MCP examples",
              "url": "https://github.com/microsoft/agent-framework/blob/main/python/samples/02-agents/mcp/README.md",
              "note": "The official MCP examples include exposing an Agent Framework agent as an MCP server.",
              "evidence_type": "official_github"
            }
          ],
          "note": "Agents can be exposed as MCP servers."
        }
      ]
    },
    {
      "agent_id": "AI-0087",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Admin Audit Logs API",
              "url": "https://docs.mistral.ai/api/endpoint/beta/admin/audit-logs",
              "note": "Mistral documents GET /v1/admin/audit-logs for programmatic organization audit-log access.",
              "evidence_type": "api_docs",
              "source_section": "Get Audit Logs"
            }
          ],
          "note": "Mistral Enterprise exposes audit logs through Admin API.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Audit logs",
              "url": "https://docs.mistral.ai/admin/monitor-comply/audit-logs/overview",
              "note": "Mistral documents Enterprise audit logs across Studio and Vibe, including user, API-key, security, and Vibe interaction events.",
              "evidence_type": "technical_docs",
              "source_section": "Audit logs / What gets logged"
            }
          ],
          "note": "Mistral Enterprise provides audit logs covering Vibe.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Admin",
              "url": "https://docs.mistral.ai/admin",
              "note": "Mistral documents role-based access control for organization members, groups, roles, and permissions across workspaces including Vibe.",
              "evidence_type": "technical_docs",
              "source_section": "Identity and access (RBAC)"
            }
          ],
          "note": "Mistral Enterprise supports RBAC.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Admin SCIM API",
              "url": "https://docs.mistral.ai/api/endpoint/beta/admin/scim",
              "note": "Mistral documents SCIM user-provisioning mode and SCIM synchronization endpoints requiring SAML authentication.",
              "evidence_type": "api_docs",
              "source_section": "Beta Admin Scim Endpoints"
            }
          ],
          "note": "Mistral Enterprise supports SCIM provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "mistral_enterprise_vibe",
          "evidence": [
            {
              "title": "Mistral Docs – Create your organization",
              "url": "https://docs.mistral.ai/getting-started/quickstarts/admin/create-organization",
              "note": "Mistral documents SAML-based SSO for Enterprise organization authentication across Studio and Vibe.",
              "evidence_type": "technical_docs",
              "source_section": "Security and monitoring"
            }
          ],
          "note": "Mistral Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "mistral_vibe_work",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Mistral Docs – Release notes",
              "url": "https://docs.mistral.ai/resources/release-notes",
              "note": "Mistral marks Vibe Work General Availability as Mistral-Hosted.",
              "evidence_type": "official_release",
              "source_section": "A simpler Vibe experience / Hosting"
            }
          ],
          "note": "Vibe Work is explicitly documented as Mistral-hosted."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "mistral_vibe_enterprise",
          "evidence": [
            {
              "title": "Mistral – Vibe",
              "url": "https://mistral.ai/products/vibe/",
              "note": "Mistral states Enterprise customers can deploy Vibe on-premises or in a private cloud.",
              "evidence_type": "official_product_page",
              "source_section": "Can I deploy Vibe on my own infrastructure?"
            }
          ],
          "note": "Mistral Vibe supports on-premises/private-cloud deployment.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "mistral_vibe_enterprise",
          "evidence": [
            {
              "title": "Mistral – Vibe",
              "url": "https://mistral.ai/products/vibe/",
              "note": "Mistral states Enterprise Vibe supports full data residency across on-premises, private cloud, or Mistral Cloud deployments.",
              "evidence_type": "official_product_page",
              "source_section": "Intelligence you own / FAQ"
            }
          ],
          "note": "Mistral Vibe Enterprise supports data-residency controls.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "mistral_vibe_enterprise",
          "evidence": [
            {
              "title": "Mistral – Regional inference",
              "url": "https://mistral.ai/news/regional-inference-open-models-new-compute/",
              "note": "Mistral documents regional endpoints allowing customers to choose EU or US inference regions for regional control and data-residency requirements.",
              "evidence_type": "official_release",
              "source_section": "Regional control, production-grade reliability"
            }
          ],
          "note": "Mistral customers can choose supported regional inference locations.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "mistral_platform_including_vibe",
          "evidence": [
            {
              "title": "Mistral Help – SOC 2 and ISO certifications",
              "url": "https://help.mistral.ai/en/articles/347638-do-you-have-soc-2-or-iso-27001-certification",
              "note": "Mistral states it complies with SOC 2 Type II and ISO 27001/27701 frameworks.",
              "evidence_type": "security_trust",
              "source_section": "Answer"
            }
          ],
          "note": "Mistral documents SOC 2 Type II compliance.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0088",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "grok_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI API – Enterprise controls",
              "url": "https://x.ai/api",
              "note": "SpaceXAI documents audit logging for enterprise Grok teams.",
              "evidence_type": "api_docs",
              "source_section": "SSO and audit logging"
            }
          ],
          "note": "Grok Enterprise provides audit logging."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "grok_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI for Business",
              "url": "https://x.ai/grok/business",
              "note": "SpaceXAI explicitly lists Custom Role Based Access Control for Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise / Security & compliance"
            }
          ],
          "note": "Grok Enterprise supports custom RBAC roles."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "grok_business_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI for Business",
              "url": "https://x.ai/grok/business",
              "note": "SpaceXAI lists role-based access control for Business/Enterprise.",
              "evidence_type": "official_product_page",
              "source_section": "Security & compliance"
            }
          ],
          "note": "Grok Business/Enterprise supports RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "grok_for_business",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "xAI – Grok for Business",
              "url": "https://x.ai/grok/business",
              "note": "xAI explicitly lists SCIM among Grok for Business enterprise controls.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise-grade AI"
            }
          ],
          "note": "Grok for Business supports SCIM."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "grok_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI API – Enterprise controls",
              "url": "https://x.ai/api",
              "note": "SpaceXAI explicitly documents SAML SSO for enterprise teams.",
              "evidence_type": "api_docs",
              "source_section": "Enterprise API controls / SSO and audit logging"
            }
          ],
          "note": "Grok Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "grok_bot",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "xAI – Introducing Grok Bot",
              "url": "https://x.ai/news/introducing-grok-bot",
              "note": "xAI documents Grok Bot as a subscription service of always-on agents with their own computer, available to eligible SuperGrok and Cursor subscribers.",
              "evidence_type": "official_release",
              "source_section": "Introducing Grok Bot"
            }
          ],
          "note": "Grok Bot is delivered as an xAI-managed persistent-agent service."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "grok_for_business_enterprise_vault",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "xAI – Grok for Business",
              "url": "https://x.ai/grok/business",
              "note": "xAI states Enterprise Vault data is encrypted with customer-controlled keys.",
              "evidence_type": "security_trust",
              "source_section": "Secure, Enterprise Vault"
            }
          ],
          "note": "Grok for Business documents customer-controlled encryption keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "grok_enterprise_vault",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI – Grok Business and Enterprise",
              "url": "https://x.ai/news/grok-business",
              "note": "SpaceXAI states Enterprise Vault data is encrypted at rest under customer-controlled keys.",
              "evidence_type": "official_release",
              "source_section": "Ultimate privacy with Enterprise Vault"
            }
          ],
          "note": "Grok Enterprise Vault documents encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "grok_enterprise_vault",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "SpaceXAI – Grok Business and Enterprise",
              "url": "https://x.ai/news/grok-business",
              "note": "SpaceXAI states Enterprise Vault data is encrypted in transit.",
              "evidence_type": "official_release",
              "source_section": "Ultimate privacy with Enterprise Vault"
            }
          ],
          "note": "Grok Enterprise Vault documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "grok_for_business",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "xAI – Grok for Business",
              "url": "https://x.ai/grok/business",
              "note": "xAI explicitly lists SOC 2 Type II for Grok for Business.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise-grade security"
            }
          ],
          "note": "Grok for Business documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0089",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "box_platform_and_box_ai",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box – Box AI privacy and GDPR",
              "url": "https://www.box.com/de-de/resources/box-ai-privacy-gdpr",
              "note": "Box documents full audit logs for data access and AI actions.",
              "evidence_type": "security_trust",
              "source_section": "Auditability"
            },
            {
              "title": "Box – Introducing the new Box Agent",
              "url": "https://blog.box.com/box-agent-launch",
              "note": "Box states Box Agent inherits Box governance, auditability, and retention controls.",
              "evidence_type": "official_release",
              "source_section": "Enterprise-grade security and governance"
            }
          ],
          "note": "Box provides audit trails covering Box AI/Agent activity."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "box_platform_including_box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box – Security & Compliance",
              "url": "https://www.box.com/de-de/security-compliance",
              "note": "Box documents integrations with CASB and SIEM tools alongside centralized audit logs.",
              "evidence_type": "security_trust",
              "source_section": "Monitoring and governance"
            }
          ],
          "note": "Box audit/security activity can be integrated with SIEM tooling."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "box_platform_including_box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box – Security & Compliance",
              "url": "https://www.box.com/de-de/security-compliance",
              "note": "Box documents seven user roles and granular permission controls across the platform.",
              "evidence_type": "security_trust",
              "source_section": "Access controls"
            }
          ],
          "note": "Box uses role-based access controls and granular permissions."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "box_business_enterprise_including_box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box Support – Setting Up Single Sign-On (SSO) for Your Organization",
              "url": "https://support.box.com/hc/en-us/articles/360043696514-Setting-Up-Single-Sign-On-SSO-for-Your-Organization",
              "note": "Box documents SAML 2.0 SSO for Business and Enterprise organizations.",
              "evidence_type": "technical_docs",
              "source_section": "Single Sign-On"
            }
          ],
          "note": "Box organizations using Box Agent can use SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box – Introducing the new Box Agent",
              "url": "https://blog.box.com/box-agent-launch",
              "note": "Box documents Box Agent as a secure content-centric AI agent built directly into Box and accessed through the hosted Box AI Home experience.",
              "evidence_type": "official_release",
              "source_section": "What is Box Agent? / How do I get started"
            }
          ],
          "note": "Box Agent is delivered as a managed capability inside Box."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "box_platform_including_box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box – Box AI privacy and GDPR",
              "url": "https://www.box.com/de-de/resources/box-ai-privacy-gdpr",
              "note": "Box documents regional storage options for Box and Box AI, including EU data storage.",
              "evidence_type": "security_trust",
              "source_section": "Data residency / GDPR"
            }
          ],
          "note": "Box offers regional data-residency options for Box AI content."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "box_platform_including_box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box – Box AI privacy and GDPR",
              "url": "https://www.box.com/de-de/resources/box-ai-privacy-gdpr",
              "note": "Box documents enterprise configuration of server/data-storage location, including EU options.",
              "evidence_type": "security_trust",
              "source_section": "Data residency / enterprise configuration"
            }
          ],
          "note": "Eligible Box customers can select supported data-storage regions."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "box_enterprise_keysafe",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box – Security & Compliance",
              "url": "https://www.box.com/de-de/security-compliance",
              "note": "Box documents KeySafe for customer control of encryption keys.",
              "evidence_type": "security_trust",
              "source_section": "Encryption / KeySafe"
            }
          ],
          "note": "Box supports customer-managed encryption keys through Box KeySafe."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "box_platform_including_box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box Support – Data Encryption at Box",
              "url": "https://support.box.com/hc/en-us/articles/360044194533-Data-Encryption-at-Box",
              "note": "Box documents AES-256 encryption for content at rest.",
              "evidence_type": "security_trust",
              "source_section": "Encryption at rest"
            }
          ],
          "note": "Box documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "box_platform_including_box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box Support – Data Encryption at Box",
              "url": "https://support.box.com/hc/en-us/articles/360044194533-Data-Encryption-at-Box",
              "note": "Box documents TLS 1.2 or higher for data in transit.",
              "evidence_type": "security_trust",
              "source_section": "Encryption in transit"
            }
          ],
          "note": "Box documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "box_platform_including_box_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Box – Box AI privacy and GDPR",
              "url": "https://www.box.com/de-de/resources/box-ai-privacy-gdpr",
              "note": "Box lists SOC 2 Type II among the platform certifications applicable to Box AI.",
              "evidence_type": "security_trust",
              "source_section": "Security and compliance"
            }
          ],
          "note": "Box documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0090",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "slack_enterprise",
          "evidence": [
            {
              "title": "Slack Developer Docs – Using the Audit Logs API",
              "url": "https://docs.slack.dev/admins/audit-logs-api/",
              "note": "Slack documents programmatic monitoring of Enterprise audit events and explicitly describes feeding Slack access data into SIEM and other auditing tools.",
              "evidence_type": "api_docs",
              "source_section": "What the Audit Logs API can do"
            }
          ],
          "note": "Slack Enterprise provides a documented RESTful Audit Logs API for programmatic monitoring.",
          "confidence": "high",
          "verified_at": "2026-10-02"
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "slack_enterprise",
          "evidence": [
            {
              "title": "Slack Developer Docs – Using the Audit Logs API",
              "url": "https://docs.slack.dev/admins/audit-logs-api/",
              "note": "Slack documents programmatic monitoring of Enterprise audit events and explicitly describes feeding Slack access data into SIEM and other auditing tools.",
              "evidence_type": "api_docs",
              "source_section": "What the Audit Logs API can do"
            }
          ],
          "note": "Slack Enterprise exposes organization-wide audit events through its documented Audit Logs API.",
          "confidence": "high",
          "verified_at": "2026-10-02"
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "slack_enterprise",
          "evidence": [
            {
              "title": "Slack Developer Docs – Using the Audit Logs API",
              "url": "https://docs.slack.dev/admins/audit-logs-api/",
              "note": "Slack documents programmatic monitoring of Enterprise audit events and explicitly describes feeding Slack access data into SIEM and other auditing tools.",
              "evidence_type": "api_docs",
              "source_section": "What the Audit Logs API can do"
            }
          ],
          "note": "Slack explicitly documents feeding Audit Logs API data into SIEM and other auditing tools.",
          "confidence": "high",
          "verified_at": "2026-10-02"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "slack_business_enterprise",
          "evidence": [
            {
              "title": "Slack Developer Docs – Using the SCIM API",
              "url": "https://docs.slack.dev/admins/scim-api/",
              "note": "Slack documents SCIM 1.1 and 2.0 for provisioning and managing users and groups on Business+ and Enterprise plans.",
              "evidence_type": "api_docs",
              "source_section": "Using the Slack SCIM API"
            }
          ],
          "note": "Slack supports SCIM provisioning and management through its documented SCIM API.",
          "confidence": "high",
          "verified_at": "2026-10-02"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "slack_business_enterprise",
          "evidence": [
            {
              "title": "Slack – Enterprise",
              "url": "https://slack.com/enterprise",
              "note": "Slack explicitly lists SAML-based single sign-on for Business+ and multiple SAML configurations for Enterprise plans.",
              "evidence_type": "official_product_page",
              "source_section": "Business+ / Enterprise+ features"
            }
          ],
          "note": "Slack supports SAML-based SSO on eligible business and enterprise plans.",
          "confidence": "high",
          "verified_at": "2026-10-02"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "slackbot_ai_teammate",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Slack – Enterprise",
              "url": "https://slack.com/enterprise",
              "note": "Slack lists Slackbot as a personal AI agent available directly in Slack on eligible plans.",
              "evidence_type": "official_product_page",
              "source_section": "Business+ / Slackbot (personal AI agent)"
            }
          ],
          "note": "Slackbot is delivered as a native managed capability inside Slack."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "slack_business_enterprise_platform_data",
          "evidence": [
            {
              "title": "Slack – Security",
              "url": "https://slack.com/trust/security",
              "note": "Slack documents data residency as a security capability that lets organizations choose the country or region where encrypted data at rest is stored.",
              "evidence_type": "security_trust",
              "source_section": "Data residency"
            }
          ],
          "note": "Eligible Slack organizations can use regional data-residency controls.",
          "confidence": "high",
          "verified_at": "2026-10-02"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "slack_business_enterprise",
          "evidence": [
            {
              "title": "Slack – Security",
              "url": "https://slack.com/trust/security",
              "note": "Slack states data residency lets organizations choose the country or region where encrypted data at rest is stored.",
              "evidence_type": "security_trust",
              "source_section": "Data residency"
            }
          ],
          "note": "Eligible Slack customers can select a supported country or region for covered data at rest.",
          "confidence": "high",
          "verified_at": "2026-10-02"
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "slack_enterprise_key_management",
          "evidence": [
            {
              "title": "Slack – Enterprise Key Management",
              "url": "https://slack.com/enterprise-key-management",
              "note": "Slack documents using customer-owned keys stored in AWS KMS to encrypt Slack messages and files, with granular key-access revocation.",
              "evidence_type": "security_trust",
              "source_section": "Bring your own keys"
            }
          ],
          "note": "Slack Enterprise supports customer-controlled encryption keys through Slack EKM.",
          "confidence": "high",
          "verified_at": "2026-10-02"
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "slack_customer_data",
          "evidence": [
            {
              "title": "Slack – Security",
              "url": "https://slack.com/trust/security",
              "note": "Slack states customer data is encrypted at rest by default.",
              "evidence_type": "security_trust",
              "source_section": "Data protection"
            }
          ],
          "note": "Slack documents encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2",
          "scope": "slack_customer_data",
          "evidence": [
            {
              "title": "Slack – Data Request Overview",
              "url": "https://slack.com/trust/data-requests",
              "note": "Slack states it uses TLS 1.2 over HTTPS for secure data transport.",
              "evidence_type": "security_trust",
              "source_section": "How does Slack protect data in motion and data at rest?"
            }
          ],
          "note": "Slack documents TLS 1.2 for data in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "slack_platform",
          "evidence": [
            {
              "title": "Slack – Security",
              "url": "https://slack.com/trust/security",
              "note": "Slack lists SOC 2 Type II among its compliance certifications.",
              "evidence_type": "security_trust",
              "source_section": "Compliance certifications and attestations"
            }
          ],
          "note": "Slack documents SOC 2 Type II compliance.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0091",
      "claims": [
        {
          "path": "api.auth.oauth",
          "value": true,
          "scope": "agent_authentication",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – Agent Security setup considerations",
              "url": "https://stage.doc.workday.com/admin-guide/en-us/workday-ai/agents/agent-system-of-record/agent-security-and-compliance/setup-considerations--agent-security.html",
              "note": "Workday documents OAuth 2.0 token exchange for agent authentication in delegate mode.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "OAuth 2.0 is documented in the Workday agent authentication flow."
        },
        {
          "path": "api.rest",
          "value": true,
          "scope": "agent_tool_access_and_external_agent_definition",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – Agent Security setup considerations",
              "url": "https://stage.doc.workday.com/admin-guide/en-us/workday-ai/agents/agent-system-of-record/agent-security-and-compliance/setup-considerations--agent-security.html",
              "note": "Workday states agent access to Workday data is carried out through REST API endpoints secured by domain or business-process policies.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Workday agents use secured REST API endpoints for data/tool access."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "agent_system_of_record",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – About Workday Agents",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/setup-considerations--agent-system-of-record.html?toc=0",
              "note": "Workday describes ASOR as a control center for governance, security and auditing and recommends reviewing the audit log for agent actions.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agent actions and security activity have documented audit-trail support in ASOR."
        },
        {
          "path": "governance.observability",
          "value": true,
          "scope": "agent_system_of_record",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – About Workday Agents",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/setup-considerations--agent-system-of-record.html?toc=0",
              "note": "Workday documents monitoring, agent analytics, usage and performance reporting in ASOR.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ASOR exposes agent monitoring and analytics."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "agent_system_of_record",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – Set Up Agent System of Record",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/set-up-agent-system-of-record.html",
              "note": "Workday documents domain security policies, security groups, and View/Modify permissions for ASOR administration.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ASOR administration is governed by Workday security groups and domain permissions."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "workday_agent_system_of_record",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – About Workday Agents",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/setup-considerations--agent-system-of-record.html?toc=0",
              "note": "Workday documents ASOR as a centralized Workday framework/control center for registering, configuring, monitoring, securing and auditing agents in Workday tenants.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ASOR is delivered and operated as part of the Workday platform."
        },
        {
          "path": "identity.agent_identity",
          "value": true,
          "scope": "workday_agent_security",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – Agent Security",
              "url": "https://stage.doc.workday.com/admin-guide/en-us/workday-ai/agents/agent-system-of-record/agent-security-and-compliance/concept--agent-security.html",
              "note": "Workday documents unique agent identities through Agent System User (ASU) accounts.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Workday Agent Security assigns agents distinct managed identities."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "workday_cloud_tenant_hosting_asor",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday – Better Together: Workday and AWS",
              "url": "https://www.workday.com/content/dam/web/en-us/documents/solution-brief/workday-aws-cloud-solution-brief.pdf",
              "note": "Workday documents regional deployment flexibility specifically to address data-residency requirements.",
              "evidence_type": "security_trust",
              "source_section": "Why run Workday on AWS?"
            },
            {
              "title": "Workday Admin Guide – Set Up Agent System of Record",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/set-up-agent-system-of-record.html",
              "note": "Workday documents ASOR as a tenant-level functional area configured in each Workday tenant.",
              "evidence_type": "technical_docs",
              "source_section": "Set Up Agent System of Record"
            }
          ],
          "note": "ASOR resides in the Workday tenant and can benefit from Workday regional hosting options designed for data residency."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "workday_cloud_tenant_hosting_asor",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday – Better Together: Workday and AWS",
              "url": "https://www.workday.com/content/dam/web/en-us/documents/solution-brief/workday-aws-cloud-solution-brief.pdf",
              "note": "Workday states customers have flexibility to choose a deployment region to meet data-residency requirements.",
              "evidence_type": "security_trust",
              "source_section": "Workday and AWS"
            },
            {
              "title": "Workday Admin Guide – Set Up Agent System of Record",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/set-up-agent-system-of-record.html",
              "note": "Workday documents ASOR as tenant-local configuration and states it must be configured separately in each tenant.",
              "evidence_type": "technical_docs",
              "source_section": "Set Up Agent System of Record"
            }
          ],
          "note": "Workday customers can choose supported regional deployment for the tenant in which ASOR is configured."
        },
        {
          "path": "protocols.a2a.server",
          "value": true,
          "scope": "workday_agents_managed_in_asor_exposed_via_agent_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – Connect External Agents to Workday Using A2A",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/external-agents/connect-external-agent-to-workday-using-a2a.html?toc=0.8.2",
              "note": "Workday documents external A2A clients retrieving the Workday agent card and invoking Self-Service Agent through regional Agent Gateway A2A endpoints.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Workday agents registered/managed through ASOR can be exposed to external A2A clients via Agent Gateway."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "asor_registered_agents_and_workday_agent_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – Connect External Agents to Workday Using A2A",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/external-agents/connect-external-agent-to-workday-using-a2a.html?toc=0.8.2",
              "note": "Workday documents registering third-party agents in ASOR and enabling them to discover and call Workday Self-Service Agent through the industry A2A protocol.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "ASOR and Agent Gateway support A2A-based interoperability between registered external agents and Workday agents."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "HTTPS/TLS",
          "scope": "asor_and_agent_gateway_api_traffic",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday Admin Guide – Authenticate Agents to Agent Gateway",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/onboard-partner-agent-to-agent-gateway.html",
              "note": "Workday documents HTTPS authorization and OAuth token endpoints for Agent Gateway and routes requests to the tenant's Workday data center.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "ASOR/Agent Gateway authentication and agent API traffic use HTTPS endpoints."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "workday_enterprise_products_including_asor",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Workday – Compliance and Third-Party Assessments",
              "url": "https://www.workday.com/en-us/why-workday/trust/compliance.html",
              "note": "Workday documents an annual SOC 2 Type II report applying to Workday Enterprise Products and assessing controls for systems containing customer data.",
              "evidence_type": "security_trust",
              "source_section": "SOC 2"
            },
            {
              "title": "Workday Admin Guide – About Workday Agents",
              "url": "https://doc.workday.com/admin-guide/en-us/workday-ai/agents/setup-considerations--agent-system-of-record.html?toc=0",
              "note": "Workday documents ASOR as a centralized framework delivered within Workday tenants for governance, security, auditing, and agent management.",
              "evidence_type": "technical_docs",
              "source_section": "Workday Agent System of Record (ASOR)"
            }
          ],
          "note": "ASOR is part of the Workday enterprise tenant environment covered by Workday's Enterprise Products SOC 2 Type II program."
        }
      ]
    },
    {
      "agent_id": "AI-0092",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "gemini_enterprise_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Agent Platform audit logging information",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/machine-learning/general/audit-logging",
              "note": "Google documents Admin Activity, System Event, and optional Data Access Cloud Audit Logs for Agent Platform.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Agent Platform produces Google Cloud Audit Logs."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "gemini_enterprise_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Agent Platform access control",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/access-control",
              "note": "Google explicitly documents using custom IAM roles for user-defined permission sets on Agent Platform operations.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Custom IAM roles can grant fine-grained Agent Platform permissions."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "gemini_enterprise_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Agent Platform access control",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/access-control",
              "note": "Google documents IAM roles and permissions governing principals' access to Agent Platform resources.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Agent Platform access is governed through Google Cloud IAM roles."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "gemini_enterprise_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Agent Platform data residency",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/data-residency",
              "note": "Google documents that data stored at rest remains in the customer-selected Agent Platform location and describes regional processing controls.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Agent Platform provides documented data-residency controls."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "gemini_enterprise_agent_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Agent Platform data residency",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/data-residency",
              "note": "Google states customers choose the location in which Agent Platform data is stored at rest and can use jurisdictional or locational endpoints for processing.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Customers select supported Agent Platform locations/endpoints for residency."
        },
        {
          "path": "protocols.a2a.client",
          "value": true,
          "scope": "gemini_enterprise_invoking_registered_a2a_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Register and manage A2A agents",
              "url": "https://docs.cloud.google.com/gemini/enterprise/docs/register-and-manage-an-a2a-agent",
              "note": "Google documents Gemini Enterprise invoking registered A2A agents with service IAM and optional end-user OAuth credentials.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Gemini Enterprise acts as an A2A client when invoking registered agents."
        },
        {
          "path": "protocols.a2a.supported",
          "value": true,
          "scope": "gemini_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Register and manage A2A agents",
              "url": "https://docs.cloud.google.com/gemini/enterprise/docs/register-and-manage-an-a2a-agent",
              "note": "Google documents registering A2A agents hosted on any platform so Gemini Enterprise users can invoke them.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Gemini Enterprise supports A2A agents."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "gemini_enterprise_apps_via_agent_gateway",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Import MCP servers from Agent Registry",
              "url": "https://docs.cloud.google.com/gemini/enterprise/docs/connectors/custom-mcp-server/import-govern-mcp-server-agent-registry",
              "note": "Google documents importing governed MCP servers into Gemini Enterprise apps through Agent Registry and Agent Gateway.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Gemini Enterprise apps can consume governed MCP servers."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "supported_gemini_enterprise_agent_platform_resources",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Customer-managed encryption keys for Agent Platform",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/machine-learning/general/cmek",
              "note": "Google documents Cloud KMS customer-managed encryption keys for CMEK-integrated Agent Platform resources.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Supported Agent Platform resources can use customer-managed encryption keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "Google default encryption",
          "scope": "gemini_enterprise_agent_platform_customer_content",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Google Cloud – Customer-managed encryption keys for Agent Platform",
              "url": "https://docs.cloud.google.com/gemini-enterprise-agent-platform/machine-learning/general/cmek",
              "note": "Google states Agent Platform encrypts customer content at rest by default using Google-managed encryption.",
              "evidence_type": "security_trust"
            }
          ],
          "note": "Agent Platform customer content is encrypted at rest by default."
        }
      ]
    },
    {
      "agent_id": "AI-0093",
      "claims": [
        {
          "path": "governance.audit_logs.api",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Audit Query API",
              "url": "https://experienceleague.adobe.com/en/docs/experience-platform/landing/governance-privacy-security/audit-logs/audit-api/overview",
              "note": "Adobe documents the Audit Query API for programmatically retrieving and monitoring audit event data.",
              "evidence_type": "api_docs",
              "source_section": "Audit Query API guide"
            }
          ],
          "note": "Experience Platform audit logs are available through API.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Audit logs",
              "url": "https://experienceleague.adobe.com/en/docs/experience-platform/landing/governance-privacy-security/audit-logs/overview",
              "note": "Adobe documents audit logs for user activity across Experience Platform services and capabilities.",
              "evidence_type": "technical_docs",
              "source_section": "Audit logs"
            }
          ],
          "note": "Experience Platform provides audit logs.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "adobe_experience_platform_audit_logs",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Audit logs",
              "url": "https://experienceleague.adobe.com/en/docs/experience-platform/landing/governance-privacy-security/audit-logs/overview",
              "note": "Adobe states audit logs are retained for 365 days.",
              "evidence_type": "technical_docs",
              "source_section": "Managing audit logs in the UI"
            }
          ],
          "note": "Experience Platform retains audit logs for 365 days.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Manage roles",
              "url": "https://experienceleague.adobe.com/en/docs/experience-platform/access-control/abac/permissions-ui/roles",
              "note": "Adobe documents creating new custom roles and assigning resources and permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Create a new role"
            }
          ],
          "note": "Experience Platform supports custom roles.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Access control overview",
              "url": "https://experienceleague.adobe.com/en/docs/experience-platform/access-control/home",
              "note": "Adobe documents role-based access control through roles, permissions, policies, and sandbox assignments.",
              "evidence_type": "technical_docs",
              "source_section": "Roles / Access control hierarchy"
            }
          ],
          "note": "Experience Platform provides RBAC for capabilities including Agent Orchestrator.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Adobe Experience League – Agent Orchestrator",
              "url": "https://experienceleague.adobe.com/en/docs/cx-enterprise-ai/experience-cloud-ai/agents/agent-orchestrator",
              "note": "Adobe documents Agent Orchestrator as the agentic layer in Adobe Experience Platform, invoked through Experience Cloud conversational interfaces to orchestrate specialized agents.",
              "evidence_type": "technical_docs",
              "source_section": "Adobe Experience Platform Agent Orchestrator"
            }
          ],
          "note": "Adobe Agent Orchestrator is delivered inside the managed Adobe Experience Platform."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Customer Journey Analytics data centers",
              "url": "https://experienceleague.adobe.com/en/docs/analytics-platform/using/technotes/data-centers",
              "note": "Adobe documents Experience Platform data hosting across North America, Europe, and APAC regions.",
              "evidence_type": "technical_docs",
              "source_section": "Hosting locations"
            }
          ],
          "note": "Agent Orchestrator runs on Experience Platform, which supports regional data hosting.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Customer Journey Analytics data centers",
              "url": "https://experienceleague.adobe.com/en/docs/analytics-platform/using/technotes/data-centers",
              "note": "Adobe states customers designate the region where their Adobe Experience Platform data will reside at provisioning.",
              "evidence_type": "technical_docs",
              "source_section": "Hosting locations"
            }
          ],
          "note": "Customers can designate the region for Experience Platform data.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Customer Managed Keys",
              "url": "https://experienceleague.adobe.com/en/docs/experience-platform/landing/governance-privacy-security/customer-managed-keys/overview",
              "note": "Adobe documents customer-managed encryption keys for Experience Platform on Azure and AWS.",
              "evidence_type": "security_trust",
              "source_section": "Customer Managed Keys"
            }
          ],
          "note": "Experience Platform supports customer-managed keys.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Data encryption",
              "url": "https://experienceleague.adobe.com/en/docs/experience-platform/landing/governance-privacy-security/encryption",
              "note": "Adobe states all data used by Experience Platform is encrypted at rest.",
              "evidence_type": "security_trust",
              "source_section": "Data at rest"
            }
          ],
          "note": "Experience Platform encrypts data at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2",
          "scope": "adobe_experience_platform_agent_orchestrator",
          "evidence": [
            {
              "title": "Adobe Experience Platform – Data encryption",
              "url": "https://experienceleague.adobe.com/en/docs/experience-platform/landing/governance-privacy-security/encryption",
              "note": "Adobe states all data in transit between Experience Platform and external components uses HTTPS TLS v1.2.",
              "evidence_type": "security_trust",
              "source_section": "Data in transit"
            }
          ],
          "note": "Experience Platform documents TLS 1.2 encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0094",
      "claims": [
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "moveworks_agent_studio_system_triggers",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – Agent Studio Overview",
              "url": "https://help.moveworks.com/agent-studio/overview",
              "note": "Moveworks lists System Triggers with Webhooks and scheduled triggers among Agent Studio building blocks.",
              "evidence_type": "technical_docs",
              "source_section": "Building Blocks Reference / Triggers"
            }
          ],
          "note": "Moveworks Agent Studio supports webhook-based system triggers."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "moveworks_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – Release Notes 2024",
              "url": "https://help.moveworks.com/ai-assistant/getting-started/roadmap-release-notes/release-notes-2024",
              "note": "Moveworks documents Agent Studio audit logs for developer activity and connections to business systems.",
              "evidence_type": "official_release",
              "source_section": "Audit how developers are using Agent Studio"
            }
          ],
          "note": "Agent Studio provides audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 60,
          "scope": "moveworks_configuration_and_permissions_logs",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – Configuration Change Logs",
              "url": "https://help.moveworks.com/service-management/administration/configuration-change-logs",
              "note": "Moveworks documents 60-day retention for configuration change audit logs.",
              "evidence_type": "technical_docs",
              "source_section": "Retention"
            },
            {
              "title": "Moveworks – Permissions Logs",
              "url": "https://help.moveworks.com/service-management/administration/permissions-logs",
              "note": "Moveworks documents 60-day retention for permissions audit logs.",
              "evidence_type": "technical_docs",
              "source_section": "Retention"
            }
          ],
          "note": "Moveworks documents 60-day retention for key administrative audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "moveworks_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Moveworks – Agent Studio Roles and Permissions",
              "url": "https://help.moveworks.com/agent-studio/access-control/roles-and-permissions",
              "note": "Moveworks documents four Agent Studio asset roles—Manager, Developer, Operator, and Viewer—with explicit editing and runtime permission mappings.",
              "evidence_type": "technical_docs",
              "source_section": "The Four Roles / Permission Matrix"
            }
          ],
          "note": "Agent Studio uses explicit role-based access controls for assets and runtime permissions."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "moveworks_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – MyMoveworks SSO",
              "url": "https://help.moveworks.com/service-management/administration/sso",
              "note": "Moveworks documents OpenID Connect as a supported SSO protocol for MyMoveworks applications, including Agent Studio.",
              "evidence_type": "technical_docs",
              "source_section": "MyMoveworks SSO"
            }
          ],
          "note": "Moveworks Studio supports OIDC SSO."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "moveworks_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – Okta Installation Guide (SAML)",
              "url": "https://help.moveworks.com/service-management/administration/sso/configure-okta-sso-app/okta-sso-configuration-guide-saml",
              "note": "Moveworks explicitly documents a SAML configuration whose Moveworks Product is 'studio'.",
              "evidence_type": "technical_docs",
              "source_section": "Add SAML Configuration in MyMoveworks"
            }
          ],
          "note": "Moveworks Studio supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "moveworks_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – Agent Studio Overview",
              "url": "https://help.moveworks.com/agent-studio/overview",
              "note": "Moveworks documents Agent Studio as an application within the Moveworks platform used to build, test, and publish plugins and agents.",
              "evidence_type": "technical_docs",
              "source_section": "Agent Studio Overview"
            },
            {
              "title": "Moveworks – On-Prem Agent",
              "url": "https://help.moveworks.com/agent-studio/core-platform/moveworks-agent",
              "note": "Moveworks distinguishes the hosted Moveworks Platform from the optional on-premises connector agent installed behind a customer firewall.",
              "evidence_type": "technical_docs",
              "source_section": "Overview"
            }
          ],
          "note": "Agent Studio is delivered as part of the managed Moveworks Platform."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "moveworks_platform_including_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – FAQ",
              "url": "https://www.moveworks.com/us/en/faq",
              "note": "Moveworks states customer data is encrypted at rest.",
              "evidence_type": "security_trust",
              "source_section": "Security and compliance"
            }
          ],
          "note": "Moveworks documents encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "moveworks_platform_including_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – FAQ",
              "url": "https://www.moveworks.com/us/en/faq",
              "note": "Moveworks states customer data is encrypted in transit.",
              "evidence_type": "security_trust",
              "source_section": "Security and compliance"
            }
          ],
          "note": "Moveworks documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "moveworks_platform_including_agent_studio",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Moveworks – FAQ",
              "url": "https://www.moveworks.com/us/en/faq",
              "note": "Moveworks lists SOC 2 Type 2 among its platform certifications.",
              "evidence_type": "security_trust",
              "source_section": "Security and compliance"
            }
          ],
          "note": "Moveworks documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0095",
      "claims": [
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "monday_ai_agents_custom_agent_callbacks",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "monday Developer – Agents API",
              "url": "https://developer.monday.com/api-reference/reference/agents",
              "note": "monday.com documents custom agent callback URLs that receive HTTP POST trigger payloads and signed webhook events.",
              "evidence_type": "api_docs",
              "source_section": "Connect external agents / Receive a trigger"
            }
          ],
          "note": "monday.com Agents support signed webhook/callback event delivery."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "monday_enterprise",
          "evidence": [
            {
              "title": "monday.com Support – Account permissions",
              "url": "https://support.monday.com/hc/en-us/articles/360003457320-Account-permissions",
              "note": "monday.com documents Enterprise custom roles with specific account permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Create custom roles"
            }
          ],
          "note": "monday.com Enterprise supports custom roles.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "monday_enterprise_ai_agents",
          "evidence": [
            {
              "title": "monday.com Support – AI Permissions and Governance",
              "url": "https://support.monday.com/hc/en-us/articles/30934592475410-AI-Permissions-and-Governance",
              "note": "monday.com documents role-based permissions for AI agent types, allowing access by selected account roles and individual agents.",
              "evidence_type": "technical_docs",
              "source_section": "AI permissions"
            }
          ],
          "note": "monday.com Enterprise provides role-based access controls for AI agents.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "monday_enterprise",
          "evidence": [
            {
              "title": "monday.com Support – SAML Single Sign-on",
              "url": "https://support.monday.com/hc/en-us/articles/360000460605-SAML-Single-Sign-on",
              "note": "monday.com documents SCIM provisioning for Enterprise accounts.",
              "evidence_type": "technical_docs",
              "source_section": "Provisioning"
            }
          ],
          "note": "monday.com Enterprise supports SCIM provisioning.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "monday_enterprise",
          "evidence": [
            {
              "title": "monday.com Support – SAML Single Sign-on",
              "url": "https://support.monday.com/hc/en-us/articles/360000460605-SAML-Single-Sign-on",
              "note": "monday.com documents SAML 2.0 SSO for Enterprise.",
              "evidence_type": "technical_docs",
              "source_section": "SAML Single Sign-on"
            }
          ],
          "note": "monday.com Enterprise supports SAML SSO.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "monday_ai_agents",
          "evidence": [
            {
              "title": "monday.com Trust Center – Data Security",
              "url": "https://monday.com/trustcenter/datasecure",
              "note": "monday.com states it is a cloud-based solution with no on-premise infrastructure.",
              "evidence_type": "security_trust",
              "source_section": "Physical Security"
            }
          ],
          "note": "monday AI Agents run on monday.com's managed cloud platform.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "monday_enterprise",
          "evidence": [
            {
              "title": "monday.com – Security and Privacy FAQs",
              "url": "https://monday.com/trustcenter/faqs",
              "note": "monday.com documents an EU data-center option for Enterprise customers.",
              "evidence_type": "security_trust",
              "source_section": "Where are monday.com’s data centers located?"
            }
          ],
          "note": "monday.com Enterprise provides a regional data-hosting option.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "monday_enterprise",
          "evidence": [
            {
              "title": "monday.com – Security and Privacy FAQs",
              "url": "https://monday.com/trustcenter/faqs",
              "note": "monday.com states Enterprise customers can choose to host data in its EU data center in Frankfurt.",
              "evidence_type": "security_trust",
              "source_section": "Where are monday.com’s data centers located?"
            }
          ],
          "note": "Enterprise customers can choose EU data hosting.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "monday_platform",
          "evidence": [
            {
              "title": "monday.com Trust Center – Data Security",
              "url": "https://monday.com/trustcenter/datasecure",
              "note": "monday.com states user data at rest is encrypted with AES-256 or better.",
              "evidence_type": "security_trust",
              "source_section": "Data Encryption"
            }
          ],
          "note": "monday.com documents AES-256-or-better encryption at rest.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "monday_platform",
          "evidence": [
            {
              "title": "monday.com Trust Center – Data Security",
              "url": "https://monday.com/trustcenter/datasecure",
              "note": "monday.com states traffic uses TLS 1.3 with TLS 1.2 minimum.",
              "evidence_type": "security_trust",
              "source_section": "Data Encryption"
            }
          ],
          "note": "monday.com documents TLS 1.2+ encryption in transit.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "monday_platform",
          "evidence": [
            {
              "title": "monday.com – SOC 2 Report",
              "url": "https://monday.com/terms/soc2",
              "note": "monday.com states it undergoes an annual SOC 2 Type II audit.",
              "evidence_type": "security_trust",
              "source_section": "Service Organization Control (SOC) 2 Report"
            }
          ],
          "note": "monday.com documents SOC 2 Type II compliance.",
          "confidence": "high",
          "verified_at": "2026-10-01"
        }
      ]
    },
    {
      "agent_id": "AI-0096",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "zoom_account_including_zoommate",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zoom Support – Admin Activity Logs",
              "url": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0067251",
              "note": "Zoom documents review and export of an audit log containing admin actions.",
              "evidence_type": "technical_docs",
              "source_section": "Admin Activity Logs"
            }
          ],
          "note": "Zoom provides account administrative audit logs."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "zoom_account_including_zoommate",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Zoom Support – Using role management",
              "url": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0064983",
              "note": "Zoom documents adding custom user roles, assigning members, and configuring role permissions and scope through role management.",
              "evidence_type": "technical_docs",
              "source_section": "How to add additional user roles / How to change permissions for a role"
            }
          ],
          "note": "Zoom supports administrator-defined custom roles with configurable permissions."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "zoom_account_including_zoommate",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zoom Support – Admin Activity Logs",
              "url": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0067251",
              "note": "Zoom documents account owners, admins, and customized roles with controlled access to account administration.",
              "evidence_type": "technical_docs",
              "source_section": "Admin activity logs / permissions"
            }
          ],
          "note": "Zoom provides role-based administrative access."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "zoom_account_including_zoommate",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Zoom Support – Configuring Zoom SSO with Microsoft Entra",
              "url": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0064121",
              "note": "Zoom documents SCIM auto-provisioning for Zoom users through Microsoft Entra.",
              "evidence_type": "technical_docs",
              "source_section": "How to set up Auto Provisioning (SCIM)"
            }
          ],
          "note": "Zoom supports SCIM provisioning."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "zoom_account_including_zoommate",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Zoom Support – Quick start guide for single sign-on (SSO)",
              "url": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0060673",
              "note": "Zoom states its SSO is based on SAML 2.0 and documents setup for Business, Education, and Enterprise accounts.",
              "evidence_type": "technical_docs",
              "source_section": "Quick start guide for single sign-on (SSO)"
            }
          ],
          "note": "Zoom supports SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "zoommate",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Zoom – ZoomMate launch",
              "url": "https://news.zoom.com/zoom-launches-zoommate/",
              "note": "Zoom documents ZoomMate as a generally available paid Zoom work surface integrating agentic search, execution, custom agents, and content creation.",
              "evidence_type": "official_release",
              "source_section": "Zoom launches ZoomMate / Availability"
            }
          ],
          "note": "ZoomMate is delivered as a managed Zoom service."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "zoom_advanced_cmk",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Zoom Support – Advanced CMK Chat Encryption",
              "url": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0082248",
              "note": "Zoom documents customer-managed-key (CMK) options for advanced and client-side chat encryption.",
              "evidence_type": "security_trust",
              "source_section": "Advanced CMK Chat Encryption"
            }
          ],
          "note": "Zoom supports customer-managed encryption keys for supported services."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "zoom_cloud_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Zoom Support – Advanced chat encryption",
              "url": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065662",
              "note": "Zoom states Chat messages stored in Zoom Cloud are encrypted at rest by default.",
              "evidence_type": "security_trust",
              "source_section": "Differences when advanced chat encryption is enabled and disabled"
            }
          ],
          "note": "Zoom documents encryption at rest for cloud-stored chat data."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "zoom_cloud_communications",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Zoom Support – Advanced chat encryption",
              "url": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065662",
              "note": "Zoom states Chat messages are encrypted with TLS in transit between users and Zoom Cloud.",
              "evidence_type": "security_trust",
              "source_section": "Differences when advanced chat encryption is enabled and disabled"
            }
          ],
          "note": "Zoom documents TLS encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "zoom_communications_platform_including_ai_services",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Zoom – SOC 2 + HITRUST",
              "url": "https://www.zoom.com/de/trust/legal-compliance/soc2-hitrust/",
              "note": "Zoom documents a SOC 2 Type 2 + HITRUST attestation for the Zoom Communications Platform and its AI-related services.",
              "evidence_type": "security_trust",
              "source_section": "SOC 2 + HITRUST report"
            }
          ],
          "note": "Zoom documents SOC 2 Type 2 coverage for its communications platform."
        }
      ]
    },
    {
      "agent_id": "AI-0097",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "dropbox_dash_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dropbox Dash – Security",
              "url": "https://dash.dropbox.com/security",
              "note": "Dropbox documents audit and activity logging for Dash enterprise administration.",
              "evidence_type": "security_trust",
              "source_section": "Admin controls / audit logging"
            }
          ],
          "note": "Dropbox Dash provides audit/activity logs."
        },
        {
          "path": "governance.audit_logs.siem_export",
          "value": true,
          "scope": "dropbox_dash_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dropbox Dash – Security",
              "url": "https://dash.dropbox.com/security",
              "note": "Dropbox documents export/integration of Dash audit activity with enterprise security and SIEM workflows.",
              "evidence_type": "security_trust",
              "source_section": "Audit and security integrations"
            }
          ],
          "note": "Dash activity can be exported/integrated with SIEM tooling."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "dropbox_dash_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Dropbox Dash Security Whitepaper",
              "url": "https://aem.dropbox.com/cms/content/dam/dropbox/warp/en-us/dash/Dash-Security-Architecture-Overview_Whitepaper.pdf",
              "note": "Dropbox documents role-based access controls for administrative/manual review and access enforcement in Dash.",
              "evidence_type": "security_trust",
              "source_section": "Access controls"
            }
          ],
          "note": "Dropbox Dash uses role-based access controls."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "dropbox_dash_via_core_dropbox_identity",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Dropbox Dash Security Whitepaper",
              "url": "https://aem.dropbox.com/cms/content/dam/dropbox/warp/en-us/dash/Dash-Security-Architecture-Overview_Whitepaper.pdf",
              "note": "Dropbox documents Dash using the core Dropbox Identity platform for authentication and account identity.",
              "evidence_type": "security_trust",
              "source_section": "Identity and authentication"
            },
            {
              "title": "Dropbox Security Whitepaper",
              "url": "https://aem.dropbox.com/cms/content/dam/dropbox/www/en-us/business/solutions/solutions/dfb_security_whitepaper.pdf",
              "note": "Dropbox documents SCIM integration for provisioning and managing users and groups in Dropbox team accounts.",
              "evidence_type": "security_trust",
              "source_section": "System for Cross-domain Identity Management (SCIM)"
            }
          ],
          "note": "Dash uses core Dropbox Identity, whose team identity layer supports SCIM provisioning."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "dropbox_dash_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Dropbox Dash Security Whitepaper",
              "url": "https://aem.dropbox.com/cms/content/dam/dropbox/warp/en-us/dash/Dash-Security-Architecture-Overview_Whitepaper.pdf",
              "note": "Dropbox documents Dash using core Dropbox Identity and external SAML 2.0 identity providers.",
              "evidence_type": "security_trust",
              "source_section": "Identity and authentication"
            }
          ],
          "note": "Dropbox Dash supports SAML 2.0 SSO through Dropbox Identity."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "dropbox_dash",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dropbox – Dash AI information",
              "url": "https://dash.dropbox.com/ai-info-page",
              "note": "Dropbox documents Dash as Dropbox's AI-powered universal search and knowledge workspace that acts as an AI teammate across team content and workflows.",
              "evidence_type": "official_product_page",
              "source_section": "Basic information"
            }
          ],
          "note": "Dropbox Dash is delivered as a managed Dropbox workspace service."
        },
        {
          "path": "privacy.residency.available",
          "value": false,
          "scope": "dropbox_dash_storage",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Dropbox Dash Security Whitepaper",
              "url": "https://aem.dropbox.com/cms/content/dam/dropbox/warp/en-us/dash/Dash-Security-Architecture-Overview_Whitepaper.pdf",
              "note": "Dropbox explicitly states Dash is a multi-tenant SaaS service and currently does not offer data storage outside the United States.",
              "evidence_type": "security_trust",
              "source_section": "Data residency / architecture"
            }
          ],
          "note": "Official Dash security documentation explicitly states that storage outside the US is not currently offered."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "dropbox_dash",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Dropbox Dash Security Whitepaper",
              "url": "https://aem.dropbox.com/cms/content/dam/dropbox/warp/en-us/dash/Dash-Security-Architecture-Overview_Whitepaper.pdf",
              "note": "Dropbox states Dash encrypts all data at rest, verified as part of its SOC 2 Type 2 audit.",
              "evidence_type": "security_trust",
              "source_section": "Encryption"
            }
          ],
          "note": "Dropbox Dash encrypts data at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "dropbox_dash",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Dropbox Dash Security Whitepaper",
              "url": "https://aem.dropbox.com/cms/content/dam/dropbox/warp/en-us/dash/Dash-Security-Architecture-Overview_Whitepaper.pdf",
              "note": "Dropbox states Dash encrypts all data in transit; public endpoints use HTTPS and internal service traffic uses encrypted transport.",
              "evidence_type": "security_trust",
              "source_section": "Encryption"
            }
          ],
          "note": "Dropbox Dash encrypts data in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "dropbox_dash",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Dropbox Dash – Security",
              "url": "https://dash.dropbox.com/security",
              "note": "Dropbox documents SOC 2 Type II compliance for Dash.",
              "evidence_type": "security_trust",
              "source_section": "Compliance"
            }
          ],
          "note": "Dropbox Dash is covered by SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0098",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "snowflake_account_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – ACCESS_HISTORY view",
              "url": "https://docs.snowflake.com/en/sql-reference/account-usage/access_history",
              "note": "Snowflake documents account-level access history for auditing data access and object usage.",
              "evidence_type": "technical_docs",
              "source_section": "ACCESS_HISTORY"
            }
          ],
          "note": "Snowflake provides account access/audit history."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "snowflake_access_history",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – ACCESS_HISTORY view",
              "url": "https://docs.snowflake.com/en/sql-reference/account-usage/access_history",
              "note": "Snowflake states the Account Usage ACCESS_HISTORY view retains records for 365 days.",
              "evidence_type": "technical_docs",
              "source_section": "Retention"
            }
          ],
          "note": "Snowflake ACCESS_HISTORY retains records for 365 days."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "snowflake_account_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Access control",
              "url": "https://docs.snowflake.com/en/user-guide/security-access-control-overview",
              "note": "Snowflake documents account administrators creating custom roles and role hierarchies.",
              "evidence_type": "technical_docs",
              "source_section": "Custom roles"
            }
          ],
          "note": "Snowflake supports custom roles."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "snowflake_account_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Access control",
              "url": "https://docs.snowflake.com/en/user-guide/security-access-control-overview",
              "note": "Snowflake documents role-based access control as a core access model.",
              "evidence_type": "technical_docs",
              "source_section": "Role-based access control"
            }
          ],
          "note": "Snowflake uses RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "snowflake_account_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – SCIM",
              "url": "https://docs.snowflake.com/en/user-guide/scim",
              "note": "Snowflake documents SCIM-based user and group provisioning.",
              "evidence_type": "technical_docs",
              "source_section": "SCIM"
            }
          ],
          "note": "Snowflake supports SCIM provisioning."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "snowflake_account_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Federated authentication and SSO",
              "url": "https://docs.snowflake.com/en/user-guide/admin-security-fed-auth",
              "note": "Snowflake documents OpenID Connect support for federated authentication.",
              "evidence_type": "technical_docs",
              "source_section": "OpenID Connect"
            }
          ],
          "note": "Snowflake supports OIDC federation."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "snowflake_account_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Federated authentication and SSO",
              "url": "https://docs.snowflake.com/en/user-guide/admin-security-fed-auth",
              "note": "Snowflake documents SAML 2.0 federated authentication and SSO.",
              "evidence_type": "technical_docs",
              "source_section": "SAML 2.0"
            }
          ],
          "note": "Snowflake supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "snowflake_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake – CoWork",
              "url": "https://www.snowflake.com/de/product/snowflake-cowork/",
              "note": "Snowflake documents CoWork as a Snowflake AI Data Cloud product accessed through Snowflake's hosted service and ai.snowflake.com.",
              "evidence_type": "official_product_page",
              "source_section": "Snowflake CoWork für Ihr Unternehmen"
            }
          ],
          "note": "Snowflake CoWork is delivered as a managed Snowflake cloud service."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "snowflake_cowork_on_snowflake",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Supported cloud regions",
              "url": "https://docs.snowflake.com/en/user-guide/intro-regions",
              "note": "Snowflake documents supported cloud regions and region-specific accounts for customer data and workloads.",
              "evidence_type": "technical_docs",
              "source_section": "Regions"
            }
          ],
          "note": "Snowflake supports region-based deployment/data residency."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "snowflake_account_hosting",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Supported cloud regions",
              "url": "https://docs.snowflake.com/en/user-guide/intro-regions",
              "note": "Snowflake documents customer account creation in selected supported cloud regions.",
              "evidence_type": "technical_docs",
              "source_section": "Choosing a region"
            }
          ],
          "note": "Customers select a supported Snowflake region for account deployment."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "snowflake_trihybrid_security",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Tri-Secret Secure",
              "url": "https://docs.snowflake.com/en/user-guide/security-encryption-manage",
              "note": "Snowflake documents customer-managed keys combined with Snowflake-managed keys through Tri-Secret Secure.",
              "evidence_type": "security_trust",
              "source_section": "Customer-managed keys / Tri-Secret Secure"
            }
          ],
          "note": "Snowflake supports customer-managed encryption keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "snowflake_platform_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – End-to-end encryption",
              "url": "https://docs.snowflake.com/en/user-guide/security-encryption",
              "note": "Snowflake documents encryption of data at rest as part of end-to-end encryption.",
              "evidence_type": "security_trust",
              "source_section": "Encryption at rest"
            }
          ],
          "note": "Snowflake encrypts data at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "snowflake_platform_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – End-to-end encryption",
              "url": "https://docs.snowflake.com/en/user-guide/security-encryption",
              "note": "Snowflake documents encryption of data in transit as part of end-to-end encryption.",
              "evidence_type": "security_trust",
              "source_section": "Encryption in transit"
            }
          ],
          "note": "Snowflake encrypts data in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "snowflake_platform_including_cowork",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake – Compliance",
              "url": "https://www.snowflake.com/en/legal/compliance/",
              "note": "Snowflake documents SOC 2 Type II compliance for its service.",
              "evidence_type": "security_trust",
              "source_section": "SOC 2"
            }
          ],
          "note": "Snowflake documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0099",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "cognigy_ai_platform_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy – Cognigy.AI Platform",
              "url": "https://www.cognigy.com/platform/cognigy-ai",
              "note": "Cognigy documents an open API and API-driven extensibility for the platform that hosts AI Agents.",
              "evidence_type": "api_docs",
              "source_section": "Enterprise platform / Open API"
            }
          ],
          "note": "Cognigy exposes platform functionality through documented APIs."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "cognigy_ai_platform_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy – AI Ops and Orchestration",
              "url": "https://www.cognigy.com/platform/ai-ops-and-orchestration",
              "note": "Cognigy documents detailed audit logs for governed AI operations.",
              "evidence_type": "security_trust",
              "source_section": "Governance and security"
            }
          ],
          "note": "Cognigy provides detailed audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "cognigy_ai_platform_and_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy – AI Ops and Orchestration",
              "url": "https://www.cognigy.com/platform/ai-ops-and-orchestration",
              "note": "Cognigy documents RBAC and granular governance controls for AI operations.",
              "evidence_type": "security_trust",
              "source_section": "Governance and security"
            }
          ],
          "note": "Cognigy provides role-based access control."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "cognigy_ai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy Release Notes – OIDC",
              "url": "https://docs.cognigy.com/release-notes/earlier-versions/cognigy-ai-pre-4.30",
              "note": "Cognigy documents OpenID Connect support for Cognigy.AI authentication.",
              "evidence_type": "technical_docs",
              "source_section": "OIDC / authentication"
            }
          ],
          "note": "Cognigy.AI supports OIDC."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "cognigy_ai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy Release Notes – SAML 2.0 SSO",
              "url": "https://docs.cognigy.com/release-notes/earlier-versions/cognigy-ai-pre-4.30",
              "note": "Cognigy documents SAML 2.0 single sign-on support in Cognigy.AI.",
              "evidence_type": "technical_docs",
              "source_section": "SAML 2.0 SSO"
            }
          ],
          "note": "Cognigy.AI supports SAML 2.0 SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "cognigy_ai_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy Docs – Deploying your AI Agents",
              "url": "https://docs.cognigy.com/ai/agents/deploy/deploying-your-ai-agents",
              "note": "Cognigy documents deploying AI Agents through Cognigy.AI endpoints to Webchat, WhatsApp, Voice Gateway, Amazon, Twilio, and other channels.",
              "evidence_type": "technical_docs",
              "source_section": "Deploying your AI Agents"
            }
          ],
          "note": "NiCE Cognigy AI Agents are deployed and operated through the managed Cognigy.AI platform."
        },
        {
          "path": "hosting.self_hosted",
          "value": true,
          "scope": "cognigy_ai_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy – DATEV deploys privacy-compliant voice bots",
              "url": "https://www.cognigy.com/de/news/datev-cognigy.ai-datenschutzkonforme-voice-bots",
              "note": "Cognigy states Cognigy.AI can be operated in European data centers or fully on-premises.",
              "evidence_type": "official_release",
              "source_section": "Deployment"
            }
          ],
          "note": "Cognigy supports fully on-premises deployment."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "cognigy_ai_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy – Cognigy.AI Platform",
              "url": "https://www.cognigy.com/platform/cognigy-ai",
              "note": "Cognigy documents database encryption for enterprise deployments.",
              "evidence_type": "security_trust",
              "source_section": "Enterprise security"
            }
          ],
          "note": "Cognigy documents encryption of stored platform data."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "cognigy_ai_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy – AI Ops and Orchestration",
              "url": "https://www.cognigy.com/platform/ai-ops-and-orchestration",
              "note": "Cognigy documents encryption in transit as an enterprise security control.",
              "evidence_type": "security_trust",
              "source_section": "Security"
            }
          ],
          "note": "Cognigy documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "cognigy_ai_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Cognigy – SOC 2 attestation",
              "url": "https://www.cognigy.com/news/conversational-ai-platform-cognigy-receives-soc-2-type-i-attestation",
              "note": "Cognigy states its platform completed a SOC 2 Type II examination and maintains the corresponding assurance program.",
              "evidence_type": "security_trust",
              "source_section": "SOC 2"
            }
          ],
          "note": "Cognigy documents SOC 2 Type II assurance."
        }
      ]
    },
    {
      "agent_id": "AI-0100",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "decagon_platform_ai_concierge",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Decagon – Security",
              "url": "https://decagon.ai/security",
              "note": "Decagon documents comprehensive tamper-protected audit logs capturing key platform events.",
              "evidence_type": "security_trust",
              "source_section": "Ensure safe, transparent, and accountable AI performance"
            }
          ],
          "note": "Decagon provides tamper-protected audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "decagon_platform_ai_concierge",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Decagon – Security",
              "url": "https://decagon.ai/security",
              "note": "Decagon explicitly documents role-based access control for platform access.",
              "evidence_type": "security_trust",
              "source_section": "Authenticate users with precision and confidence"
            }
          ],
          "note": "Decagon provides RBAC."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "decagon_ai_concierge",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Decagon – Official Site",
              "url": "https://decagon.ai/",
              "note": "Decagon documents AI Concierge as its enterprise customer-experience product spanning chat, voice, and email, offered through Decagon's product platform and integrations.",
              "evidence_type": "official_product_page",
              "source_section": "The AI concierge for every customer / Product"
            }
          ],
          "note": "Decagon AI Concierge is delivered as a managed Decagon service."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "decagon_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Decagon – Security",
              "url": "https://decagon.ai/security",
              "note": "Decagon states storage and backups are encrypted with AES-256.",
              "evidence_type": "security_trust",
              "source_section": "Protect your data"
            }
          ],
          "note": "Decagon documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "decagon_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Decagon – Security",
              "url": "https://decagon.ai/security",
              "note": "Decagon states all network transmission uses TLS 1.2 or higher.",
              "evidence_type": "security_trust",
              "source_section": "Protect your data"
            }
          ],
          "note": "Decagon documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "decagon_platform_ai_concierge",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Decagon Trust Center",
              "url": "https://trust.decagon.ai/",
              "note": "Decagon's Trust Center lists SOC 2 Type II and current SOC 2 Type II reports.",
              "evidence_type": "security_trust",
              "source_section": "Compliance"
            }
          ],
          "note": "Decagon documents SOC 2 Type II compliance."
        }
      ]
    },
    {
      "agent_id": "AI-0101",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "11x_alice_shared_api",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "11x Docs – Webhooks and REST API",
              "url": "https://docs.11x.ai/integrations/webhooks",
              "note": "11x documents one bi-directional API across Alice and Julian for pushing data, pulling outcomes, and triggering motions; the page is explicitly titled Webhooks and REST API.",
              "evidence_type": "api_docs",
              "source_section": "Webhooks and API"
            }
          ],
          "note": "Alice uses the shared 11x REST API."
        },
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "11x_alice",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "11x Docs – Webhooks and API",
              "url": "https://docs.11x.ai/integrations/webhooks",
              "note": "11x states one API spans Alice and Julian and supports subscriptions to real-time events via webhooks/callbacks.",
              "evidence_type": "api_docs",
              "source_section": "Webhooks and API"
            }
          ],
          "note": "Alice supports webhook event subscriptions through the shared 11x integration API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "11x_alice",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "11x – Audit and Oversight",
              "url": "https://docs.11x.ai/security/audit-and-oversight",
              "note": "11x documents audit trails across recordings/transcripts, quality assessments, knowledge-base version history, approval trails, and CRM write-back.",
              "evidence_type": "security_trust",
              "source_section": "The five audit surfaces"
            }
          ],
          "note": "11x provides multiple audit surfaces for Alice activity and outcomes."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "11x_alice_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "11x Security and Data Handling",
              "url": "https://docs.11x.ai/security/overview",
              "note": "11x documents platform hosting in AWS high-security facilities and dynamically scaled containerized deployments.",
              "evidence_type": "security_trust",
              "source_section": "Platform controls"
            }
          ],
          "note": "Alice runs on the managed 11x AWS-hosted platform."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "11x_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "11x Security and Data Handling",
              "url": "https://docs.11x.ai/security/overview",
              "note": "11x states data at rest is encrypted with AES-256 in AWS RDS.",
              "evidence_type": "security_trust",
              "source_section": "Platform controls"
            }
          ],
          "note": "11x documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS",
          "scope": "11x_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "11x Security and Data Handling",
              "url": "https://docs.11x.ai/security/overview",
              "note": "11x states data in transit is protected with TLS.",
              "evidence_type": "security_trust",
              "source_section": "Platform controls"
            }
          ],
          "note": "11x documents TLS encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "11x_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "11x Security and Compliance",
              "url": "https://docs.11x.ai/help-center/overview/security-and-compliance",
              "note": "11x states it holds SOC 2 Type II certification, audited annually.",
              "evidence_type": "security_trust",
              "source_section": "Certifications"
            }
          ],
          "note": "11x documents SOC 2 Type II certification."
        }
      ]
    },
    {
      "agent_id": "AI-0102",
      "claims": [
        {
          "path": "api.webhooks",
          "value": true,
          "scope": "artisan_ava_custom_webhooks",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Artisan – Pricing",
              "url": "https://www.artisan.co/pricing",
              "note": "Artisan documents custom webhooks for Ava/Artisan integrations as part of its outbound platform.",
              "evidence_type": "official_product_page",
              "source_section": "FAQ / Which tools does Ava integrate with?"
            }
          ],
          "note": "Artisan supports custom webhook integrations for Ava."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "artisan_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Artisan – Pricing",
              "url": "https://www.artisan.co/pricing",
              "note": "Artisan Enterprise explicitly lists audit logs.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security"
            }
          ],
          "note": "Artisan Enterprise provides audit logs."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "artisan_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Artisan – The best enterprise sales dialers in 2026",
              "url": "https://www.artisan.co/blog/the-best-enterprise-sales-dialers-compliance-admin-controls-and-scale",
              "note": "Artisan explicitly documents role-based access with built-in and custom roles as part of its enterprise admin controls.",
              "evidence_type": "official_release",
              "source_section": "Which AI dialer offers enterprise admin controls, analytics, and SSO?"
            }
          ],
          "note": "Artisan Enterprise supports built-in and custom roles."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "artisan_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Artisan – Ava 2.0",
              "url": "https://www.artisan.co/blog/artisan-launches-ava-2-0-first-autonomous-ai-bdr",
              "note": "Artisan states Ava Enterprise includes role-based access control plus team/workspace permissions.",
              "evidence_type": "official_release",
              "source_section": "Built for enterprise scale"
            }
          ],
          "note": "Artisan Enterprise provides RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "artisan_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Artisan – Official Site",
              "url": "https://www.artisan.co/",
              "note": "Artisan explicitly lists SAML & SCIM among enterprise-grade security controls.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise-grade security built in"
            }
          ],
          "note": "Artisan Enterprise supports SCIM."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "artisan_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Artisan – Pricing",
              "url": "https://www.artisan.co/pricing",
              "note": "Artisan Enterprise explicitly lists SSO / SAML.",
              "evidence_type": "official_product_page",
              "source_section": "Enterprise security"
            }
          ],
          "note": "Artisan Enterprise supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "artisan_ava",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Artisan – Ava 2.0",
              "url": "https://www.artisan.co/blog/artisan-launches-ava-2-0-first-autonomous-ai-bdr",
              "note": "Artisan documents Ava as its autonomous AI BDR delivered through the Artisan platform for enterprise sales teams.",
              "evidence_type": "official_release",
              "source_section": "Ava 2.0"
            }
          ],
          "note": "Ava is delivered as a managed Artisan service."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "artisan_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Artisan – Data Processing Agreement",
              "url": "https://www.artisan.co/dpa",
              "note": "Artisan states stored data is encrypted at rest.",
              "evidence_type": "security_trust",
              "source_section": "Technical and Organizational Measures / Transmission Control"
            }
          ],
          "note": "Artisan documents encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "artisan_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Artisan – Data Processing Agreement",
              "url": "https://www.artisan.co/dpa",
              "note": "Artisan requires HTTPS/TLS encryption on login interfaces and customer sites.",
              "evidence_type": "security_trust",
              "source_section": "Technical and Organizational Measures / Transmission Control"
            }
          ],
          "note": "Artisan documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "artisan_ava_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Artisan – Ava 2.0",
              "url": "https://www.artisan.co/blog/artisan-launches-ava-2-0-first-autonomous-ai-bdr",
              "note": "Artisan explicitly states it is SOC 2 Type II audited in the enterprise security section for Ava 2.0.",
              "evidence_type": "official_release",
              "source_section": "Built for enterprise scale"
            }
          ],
          "note": "Artisan documents SOC 2 Type II audit coverage for the platform delivering Ava."
        }
      ]
    },
    {
      "agent_id": "AI-0103",
      "claims": [
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "qualified_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Qualified – Trust",
              "url": "https://www.qualified.com/trust",
              "note": "Qualified explicitly documents SAML 2.0-based SSO for Enterprise customers.",
              "evidence_type": "security_trust",
              "source_section": "Application Security / Single Sign-On"
            }
          ],
          "note": "Qualified Enterprise supports SAML 2.0 SSO."
        },
        {
          "path": "memory.persistent",
          "value": true,
          "confidence": "high",
          "scope": "piper_returning_visitor_conversations",
          "verified_at": "2026-10-03",
          "note": "Qualified documents continuity for returning cookied visitors using information from recent previous conversation history, approximately the last 30 days.",
          "evidence": [
            {
              "title": "Qualified University – Understanding how Piper handles PII",
              "url": "https://university.qualified.com/about-the-agentic-marketing-platform-85/understanding-how-piper-the-ai-sdr-agent-handles-pii-252",
              "evidence_type": "technical_docs",
              "source_section": "Continuity with returning visitors"
            }
          ]
        },
        {
          "path": "memory.session_state",
          "value": true,
          "confidence": "high",
          "scope": "piper_website_conversations",
          "verified_at": "2026-10-03",
          "note": "Qualified documents that Piper can remember a visitor's name from the current conversation history to maintain dialogue continuity.",
          "evidence": [
            {
              "title": "Qualified University – Understanding how Piper handles PII",
              "url": "https://university.qualified.com/about-the-agentic-marketing-platform-85/understanding-how-piper-the-ai-sdr-agent-handles-pii-252",
              "evidence_type": "technical_docs",
              "source_section": "Default information access and how the AI agent learns names"
            }
          ]
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "qualified_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Qualified – Trust",
              "url": "https://www.qualified.com/trust",
              "note": "Qualified states all stored customer data is securely encrypted.",
              "evidence_type": "security_trust",
              "source_section": "Data Storage"
            }
          ],
          "note": "Qualified documents encryption for stored customer data."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "qualified_platform_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Qualified – Trust",
              "url": "https://www.qualified.com/trust",
              "note": "Qualified documents encryption for customer data in motion over public networks.",
              "evidence_type": "security_trust",
              "source_section": "Encryption In Transit"
            }
          ],
          "note": "Qualified documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "qualified_platform_including_piper",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Qualified – Trust",
              "url": "https://www.qualified.com/trust",
              "note": "Qualified states it undergoes a SOC 2 Type II audit annually; the same Qualified platform page identifies Piper as its AI SDR agent.",
              "evidence_type": "security_trust",
              "source_section": "Compliance and Certification / SOC-2 Type II Report"
            }
          ],
          "note": "Piper runs on the Qualified platform covered by Qualified's annual SOC 2 Type II audit."
        }
      ]
    },
    {
      "agent_id": "AI-0104",
      "claims": [
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "claygent_builder",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Clay Docs – Claygent Builder",
              "url": "https://university.clay.com/docs/claygent-builder",
              "note": "Clay documents Claygent Builder as the centralized workspace hub for building, testing, deploying, versioning, and managing Clay AI agents across workflows.",
              "evidence_type": "technical_docs",
              "source_section": "Claygent Builder / Centralized management"
            }
          ],
          "note": "Claygent is delivered and centrally managed within Clay's hosted workspace."
        }
      ]
    },
    {
      "agent_id": "AI-0105",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "cortex_agents_agent_run",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Cortex Agents access control and authentication",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-setup",
              "note": "Snowflake documents the Cortex Agents agent:run API and the roles/privileges required to call it.",
              "evidence_type": "api_docs"
            }
          ],
          "note": "Cortex Agents expose a documented agent:run API."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "cortex_agent_activity",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Agent identity",
              "url": "https://docs.snowflake.com/en/user-guide/agent-identity",
              "note": "Snowflake carries agent identity into QUERY_HISTORY and ACCESS_HISTORY so Cortex Agent activity and accessed objects can be audited.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Cortex Agent activity is represented in Snowflake audit/history views."
        },
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Cortex Agents access control and authentication",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-setup",
              "note": "Snowflake documents granting the CORTEX_AGENT_USER database role to a custom role for selected users.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Custom Snowflake roles can be used to scope Cortex Agent access."
        },
        {
          "path": "governance.monitoring_access_control",
          "value": true,
          "scope": "cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Monitor Cortex Agent requests",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-monitor",
              "note": "Viewing Cortex Agent logs requires OWNERSHIP or MONITOR on the AGENT plus the CORTEX_USER database role.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Monitoring access is explicitly privilege-gated."
        },
        {
          "path": "governance.observability",
          "value": true,
          "scope": "cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Monitor Cortex Agent requests",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-monitor",
              "note": "Snowflake documents live conversation history, execution traces, planning, tool calls, responses, and feedback for Cortex Agents.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Cortex Agent observability includes production conversations and execution telemetry."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Cortex Agents access control and authentication",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-setup",
              "note": "Snowflake explicitly states access to Cortex Agents is governed by Snowflake role-based access control.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Cortex Agent access uses Snowflake RBAC."
        },
        {
          "path": "governance.scim",
          "value": true,
          "scope": "snowflake_account_users_and_roles_for_cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – SCIM support",
              "url": "https://docs.snowflake.com/en/user-guide/scim-intro",
              "note": "Snowflake supports SCIM 2.0 provisioning of users and groups/roles from identity providers.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Snowflake Docs – Cortex Agents access control and authentication",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-setup",
              "note": "Cortex Agents access is granted through Snowflake roles and user identities.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Users and roles that govern Cortex Agent access can be provisioned through Snowflake SCIM."
        },
        {
          "path": "governance.sso.oidc",
          "value": true,
          "scope": "snowflake_account_access_to_cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Federated authentication and SSO",
              "url": "https://docs.snowflake.com/en/user-guide/admin-security-fed-auth-overview",
              "note": "Snowflake documents OIDC federated authentication with managed or custom identity providers.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Snowflake Docs – Cortex Agents access control and authentication",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-setup",
              "note": "Cortex Agents permissions are resolved from the authenticated Snowflake user and default role.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Cortex Agent users can authenticate through Snowflake's OIDC federation controls."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "snowflake_account_access_to_cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Federated authentication and SSO",
              "url": "https://docs.snowflake.com/en/user-guide/admin-security-fed-auth-overview",
              "note": "Snowflake documents SAML 2.0 federated authentication for account users; Cortex Agents execute under the querying user's Snowflake role.",
              "evidence_type": "technical_docs"
            },
            {
              "title": "Snowflake Docs – Cortex Agents access control and authentication",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-setup",
              "note": "Cortex Agents uses the querying user's Snowflake identity and default role for permissions.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Cortex Agent users can authenticate through Snowflake's SAML SSO controls."
        },
        {
          "path": "governance.tracing",
          "value": true,
          "scope": "cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Monitor Cortex Agent requests",
              "url": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-monitor",
              "note": "Snowflake stores OpenTelemetry-style traces and spans for Cortex Agent turns in AI_OBSERVABILITY_EVENTS.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Cortex Agent runs produce OpenTelemetry-style trace data."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "cortex_agents_account_data_and_inference_controls",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Snowflake Docs – Supported cloud regions",
              "url": "https://docs.snowflake.com/en/user-guide/intro-regions",
              "note": "Snowflake documents account deployment across supported cloud regions and geographic storage of account data.",
              "evidence_type": "technical_docs",
              "source_section": "Supported cloud regions"
            },
            {
              "title": "Snowflake Docs – Account parameters",
              "url": "https://docs.snowflake.com/en/sql-reference/parameters",
              "note": "Snowflake documents the account-level CORTEX_ENABLED_CROSS_REGION parameter and states that DISABLED prevents cross-region inference processing.",
              "evidence_type": "technical_docs",
              "source_section": "CORTEX_ENABLED_CROSS_REGION"
            }
          ],
          "note": "Snowflake accounts have regional deployment controls, and Cortex cross-region inference can be disabled at the account level."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "snowflake_account_hosting_cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Snowflake Docs – Supported cloud regions",
              "url": "https://docs.snowflake.com/en/user-guide/intro-regions",
              "note": "Snowflake documents supported cloud regions and states organizations choose the region in which an account is located.",
              "evidence_type": "technical_docs",
              "source_section": "Supported cloud regions"
            }
          ],
          "note": "Organizations choose the supported Snowflake account region that hosts Cortex Agents and account data."
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "cortex_agents",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Snowflake Docs – Use app-created Cortex Agents and MCP servers",
              "url": "https://docs.snowflake.com/en/developer-guide/native-apps/ui-consumer-agents-mcp",
              "note": "Snowflake documents connecting multiple MCP servers to a Cortex Agent and monitoring resulting tool activity.",
              "evidence_type": "technical_docs"
            }
          ],
          "note": "Cortex Agents can consume MCP servers as agent tools."
        }
      ]
    },
    {
      "agent_id": "AI-0106",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "fabric_data_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Auditing data agent interactions in Microsoft Purview",
              "url": "https://learn.microsoft.com/en-us/fabric/data-science/data-agent-purview-governance",
              "note": "Microsoft documents a Copilot Interaction audit record for each Data Agent request and response, stored in the Microsoft 365 unified audit log.",
              "evidence_type": "technical_docs",
              "source_section": "Viewing Data Agent Audit Logs"
            }
          ],
          "note": "Fabric Data Agent interactions are auditable through Microsoft Purview/Microsoft 365 audit logs."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "fabric_data_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Create a Fabric data agent",
              "url": "https://learn.microsoft.com/en-us/fabric/data-science/how-to-create-data-agent",
              "note": "Microsoft states Data Agent data access runs under the user's Entra identity and Fabric workspace/data permissions.",
              "evidence_type": "technical_docs",
              "source_section": "Authentication and tokens"
            }
          ],
          "note": "Fabric Data Agent honors Fabric workspace/data role permissions."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "fabric_data_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Create a Fabric data agent",
              "url": "https://learn.microsoft.com/en-us/fabric/data-science/how-to-create-data-agent",
              "note": "Microsoft documents Fabric Data Agent as a managed Fabric experience using Microsoft-managed Azure OpenAI services and Fabric workspaces.",
              "evidence_type": "technical_docs",
              "source_section": "Authentication and tokens"
            }
          ],
          "note": "Fabric Data Agent runs as a managed Microsoft Fabric service."
        },
        {
          "path": "hosting.private_network",
          "value": true,
          "scope": "fabric_workspace_data_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Data security overview",
              "url": "https://learn.microsoft.com/en-us/fabric/onelake/security/fabric-onelake-security",
              "note": "Fabric documents private links and restricted network access for OneLake/Fabric workspaces used by Fabric workloads.",
              "evidence_type": "security_trust",
              "source_section": "Secure OneLake access by using private links"
            }
          ],
          "note": "Fabric supports private-link network access for workspaces hosting data-agent data."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "microsoft_fabric_workspace_data_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Fabric security fundamentals",
              "url": "https://learn.microsoft.com/en-us/fabric/security/security-fundamentals",
              "note": "Microsoft documents geographic data residency controls for Fabric workloads and customer data.",
              "evidence_type": "security_trust",
              "source_section": "Data residency and geography"
            }
          ],
          "note": "Microsoft Fabric supports geographic data residency for workspaces and workloads including Data Agent data."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "microsoft_fabric_workspace_data_agent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Fabric security fundamentals",
              "url": "https://learn.microsoft.com/en-us/fabric/security/security-fundamentals",
              "note": "Microsoft documents capacity/workspace placement and Multi-Geo options that let organizations place Fabric content in supported geographic regions.",
              "evidence_type": "security_trust",
              "source_section": "Data residency and Multi-Geo"
            }
          ],
          "note": "Eligible Fabric organizations can place workspace content in supported geographic regions."
        },
        {
          "path": "protocols.mcp.server",
          "value": true,
          "scope": "microsoft_fabric_data_agent_published",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "MicrosoftDocs – Data agent as Model Context Protocol server",
              "url": "https://github.com/MicrosoftDocs/fabric-docs/blob/main/docs/data-science/data-agent-mcp-server.md",
              "note": "Microsoft documents a published Fabric data agent acting as an MCP server with an MCP endpoint that exposes enterprise data and queries to MCP clients.",
              "evidence_type": "official_github",
              "source_section": "Data agent as Model Context Protocol server"
            }
          ],
          "note": "Published Microsoft Fabric Data Agents can expose an MCP server endpoint."
        },
        {
          "path": "security.customer_managed_key",
          "value": true,
          "scope": "fabric_workspace_data_agent_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Customer-managed keys for Fabric workspaces",
              "url": "https://learn.microsoft.com/en-us/fabric/security/workspace-customer-managed-keys",
              "note": "Microsoft documents workspace-level customer-managed keys controlling encryption of Fabric customer content.",
              "evidence_type": "security_trust",
              "source_section": "How customer-managed keys work"
            }
          ],
          "note": "Fabric supports workspace-level customer-managed encryption keys."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "fabric_workspace_data_agent_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Data security overview",
              "url": "https://learn.microsoft.com/en-us/fabric/onelake/security/fabric-onelake-security",
              "note": "Microsoft states OneLake/Fabric data is encrypted at rest by default.",
              "evidence_type": "security_trust",
              "source_section": "Encrypt data at rest"
            }
          ],
          "note": "Fabric encrypts workspace data at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "fabric_workspace_data_agent_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Microsoft Learn – Data security overview",
              "url": "https://learn.microsoft.com/en-us/fabric/onelake/security/fabric-onelake-security",
              "note": "Microsoft documents at least TLS 1.2 for data in transit across public internet endpoints.",
              "evidence_type": "security_trust",
              "source_section": "Encrypt data in transit by using TLS"
            }
          ],
          "note": "Fabric documents TLS 1.2+ encryption in transit."
        }
      ]
    },
    {
      "agent_id": "AI-0107",
      "claims": [
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "lexis_plus_with_protege",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Lexis+ with Protégé",
              "url": "https://www.lexisnexis.com/en-us/products/lexis-plus-protege.page",
              "note": "LexisNexis documents Protégé as a cloud-based Lexis+ legal AI service operated on enterprise-grade cloud providers.",
              "evidence_type": "official_product_page",
              "source_section": "Data Security, Privacy, and Governance"
            }
          ],
          "note": "Lexis+ with Protégé is delivered as a managed LexisNexis cloud service."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "lexis_plus_with_protege_france_mistral",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "LexisNexis – Mistral integration in Lexis+ with Protégé in France",
              "url": "https://www.lexisnexis.com/community/pressroom/b/news/posts/lexisnexis-announces-the-integration-of-mistral-in-lexis-with-protege-in-france",
              "note": "LexisNexis documents the France Mistral integration as operating in an encrypted framework hosted within the European Union.",
              "evidence_type": "official_release",
              "source_section": "EU hosting"
            }
          ],
          "note": "A documented EU-hosted Protégé deployment is available in the France/Mistral offering."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "lexis_plus_with_protege",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "LexisNexis – Protégé comparison/security guide",
              "url": "https://www.lexisnexis.com/supportandtraining/cfs-file/__key/telligent-evolution-components-attachments/01-88-00-00-00-00-13-49/protege_2D00_comparison_2D00_chatgpt.PDF",
              "note": "LexisNexis states Lexis+ AI/Protégé uses AES-256 encryption.",
              "evidence_type": "security_trust",
              "source_section": "Security Certifications"
            }
          ],
          "note": "LexisNexis documents AES-256 encryption for Lexis+ AI/Protégé."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2",
          "scope": "lexis_plus_with_protege",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "LexisNexis – Protégé comparison/security guide",
              "url": "https://www.lexisnexis.com/supportandtraining/cfs-file/__key/telligent-evolution-components-attachments/01-88-00-00-00-00-13-49/protege_2D00_comparison_2D00_chatgpt.PDF",
              "note": "LexisNexis states Lexis+ AI/Protégé uses TLS 1.2 encryption.",
              "evidence_type": "security_trust",
              "source_section": "Security Certifications"
            }
          ],
          "note": "LexisNexis documents TLS 1.2 encryption for Lexis+ AI/Protégé."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "lexis_plus_with_protege",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "LexisNexis – Protégé General AI privacy and security",
              "url": "https://www.lexisnexis.com/blogs/amppage/136/inside-the-innovation-how-protege-general-ai-was-built-to-balance-power-privacy-and-choice",
              "note": "LexisNexis states Protégé General AI adheres to SOC 2 Type II compliance standards.",
              "evidence_type": "security_trust",
              "source_section": "The Privacy Core: Building Trust into Every Layer"
            }
          ],
          "note": "LexisNexis documents SOC 2 Type II compliance for Protégé."
        }
      ]
    },
    {
      "agent_id": "AI-0108",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "vlex_vincent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "vLex – Core Security Measures",
              "url": "https://support.vlex.com/vincent-by-vlex/vincent/security-privacy-and-compliance/reviewing-our-core-security-measures",
              "note": "vLex documents detailed third-party-managed audit logs of all access to data.",
              "evidence_type": "security_trust",
              "source_section": "Operational Security"
            }
          ],
          "note": "Vincent provides detailed audit logs."
        },
        {
          "path": "governance.audit_logs.retention_days",
          "value": 365,
          "scope": "vlex_vincent_conversation_logs_and_files_default",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "vLex – Core Security Measures",
              "url": "https://support.vlex.com/vincent-by-vlex/vincent/security-privacy-and-compliance/reviewing-our-core-security-measures",
              "note": "vLex states customer-configurable retention for conversation logs and files defaults to one year.",
              "evidence_type": "security_trust",
              "source_section": "Customizable Data Retention"
            }
          ],
          "note": "Vincent's documented default retention for conversation logs and files is one year (365 days)."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "vlex_vincent",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "vLex – Core Security Measures",
              "url": "https://support.vlex.com/vincent-by-vlex/vincent/security-privacy-and-compliance/reviewing-our-core-security-measures",
              "note": "vLex explicitly documents role-based access control protecting systems and data.",
              "evidence_type": "security_trust",
              "source_section": "Operational Security"
            }
          ],
          "note": "Vincent uses role-based access control."
        },
        {
          "path": "governance.sso.saml",
          "value": true,
          "scope": "vlex_platform_including_vincent",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "vLex – Integrations",
              "url": "https://support.vlex.com/support-1/integrations",
              "note": "vLex explicitly lists SAML among supported SSO options for enterprise identity services.",
              "evidence_type": "technical_docs",
              "source_section": "SSO Options"
            }
          ],
          "note": "vLex supports SAML SSO."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "vlex_vincent_platform",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "vLex – Technical & Infrastructure Security",
              "url": "https://support.vlex.com/vincent-by-vlex/vincent/security-privacy-and-compliance/reviewing-our-technical-and-infrastructure-security",
              "note": "vLex states its platform is hosted on Amazon Web Services and describes responsibility for securing the application and customer data in that cloud environment.",
              "evidence_type": "security_trust",
              "source_section": "Cloud Architecture"
            }
          ],
          "note": "Vincent is delivered on vLex's managed AWS-hosted platform."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "vlex_vincent_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "vLex – Core Security Measures",
              "url": "https://support.vlex.com/vincent-by-vlex/vincent/security-privacy-and-compliance/reviewing-our-core-security-measures",
              "note": "vLex documents configurable Vincent data residency in US, AU, or EU regions.",
              "evidence_type": "security_trust",
              "source_section": "Data Protection & Encryption"
            }
          ],
          "note": "Vincent supports regional data residency."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "vlex_vincent_enterprise",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "vLex – Core Security Measures",
              "url": "https://support.vlex.com/vincent-by-vlex/vincent/security-privacy-and-compliance/reviewing-our-core-security-measures",
              "note": "vLex states customers can configure their account so data and encryption keys are hosted in a selected US, AU, or EU region.",
              "evidence_type": "security_trust",
              "source_section": "You Control Your Data's Location"
            }
          ],
          "note": "Vincent customers can select a supported data region."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "vlex_vincent_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "vLex – Core Security Measures",
              "url": "https://support.vlex.com/vincent-by-vlex/vincent/security-privacy-and-compliance/reviewing-our-core-security-measures",
              "note": "vLex states Vincent customer data is continuously encrypted at rest using a FIPS 140-2 compliant cryptographic suite.",
              "evidence_type": "security_trust",
              "source_section": "Data Protection & Encryption"
            }
          ],
          "note": "Vincent encrypts customer data at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "vlex_vincent_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "vLex – Core Security Measures",
              "url": "https://support.vlex.com/vincent-by-vlex/vincent/security-privacy-and-compliance/reviewing-our-core-security-measures",
              "note": "vLex states Vincent customer data is continuously encrypted in transit using a FIPS 140-2 compliant cryptographic suite.",
              "evidence_type": "security_trust",
              "source_section": "Data Protection & Encryption"
            }
          ],
          "note": "Vincent encrypts customer data in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "vincent_ai",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "vLex – Ethical AI for Lawyers",
              "url": "https://vlex.com/news/Ethical-AI-for-Lawyers",
              "note": "vLex states Vincent is backed by SOC 2 Type II certification.",
              "evidence_type": "security_trust",
              "source_section": "Security: The Foundation of Ethical AI Use"
            }
          ],
          "note": "Vincent AI is documented as SOC 2 Type II certified."
        }
      ]
    },
    {
      "agent_id": "AI-0109",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "luminance_platform_including_lumi",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Luminance – Security",
              "url": "https://www.luminance.com/security",
              "note": "Luminance explicitly lists audit logging among configurable enterprise access/security controls.",
              "evidence_type": "security_trust",
              "source_section": "Granular access, controlled by you"
            }
          ],
          "note": "Luminance provides audit logging."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "luminance_platform_including_lumi",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Luminance – Security",
              "url": "https://www.luminance.com/security",
              "note": "Luminance documents configurable role-based access and granular controls for customer access.",
              "evidence_type": "security_trust",
              "source_section": "Granular access, controlled by you"
            }
          ],
          "note": "Luminance provides role-based access control."
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "luminance_agent_lumi",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Luminance – Legal",
              "url": "https://www.luminance.com/solutions/legal/",
              "note": "Luminance documents Lumi as an integrated Legal-Grade AI capability within the Luminance Contract Intelligence platform for contract review, drafting, search, and enterprise legal workflows.",
              "evidence_type": "official_product_page",
              "source_section": "Luminance for Legal / With Luminance"
            }
          ],
          "note": "Lumi is delivered as a managed capability within Luminance's enterprise legal platform."
        },
        {
          "path": "privacy.residency.available",
          "value": true,
          "scope": "luminance_hosted_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Luminance – Master Hosted Terms",
              "url": "https://www.luminance.com/legal/terms-conditions",
              "note": "Luminance documents hosting Customer Data in selected AWS data centres with residency fixed to that regional data centre and backup region.",
              "evidence_type": "security_trust",
              "source_section": "Hosting Location / Security"
            }
          ],
          "note": "Luminance supports regional data residency."
        },
        {
          "path": "privacy.residency.customer_region_selectable",
          "value": true,
          "scope": "luminance_hosted_customer_data",
          "confidence": "high",
          "verified_at": "2026-10-02",
          "evidence": [
            {
              "title": "Luminance – Master Hosted Terms",
              "url": "https://www.luminance.com/legal/terms-conditions",
              "note": "Luminance states customers can choose which AWS data centre, subject to availability, hosts Customer Data.",
              "evidence_type": "security_trust",
              "source_section": "Hosting Location"
            }
          ],
          "note": "Luminance customers can choose a supported AWS hosting region."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "AES-256",
          "scope": "luminance_platform_including_lumi",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Luminance – Security",
              "url": "https://www.luminance.com/security",
              "note": "Luminance states AWS-hosted data at rest is encrypted using AES-256 with AWS KMS.",
              "evidence_type": "security_trust",
              "source_section": "Encrypted at every stage"
            }
          ],
          "note": "Luminance documents AES-256 encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "TLS 1.2+",
          "scope": "luminance_platform_including_lumi",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Luminance – Security",
              "url": "https://www.luminance.com/security",
              "note": "Luminance states data in transit uses TLS 1.2 or higher.",
              "evidence_type": "security_trust",
              "source_section": "Encrypted at every stage"
            }
          ],
          "note": "Luminance documents TLS 1.2+ encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "luminance_platform_including_lumi",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Luminance – Security",
              "url": "https://www.luminance.com/security",
              "note": "Luminance states it undergoes regular SOC 2 Type II examinations.",
              "evidence_type": "security_trust",
              "source_section": "Independently assessed security"
            }
          ],
          "note": "Luminance documents SOC 2 Type II assurance."
        }
      ]
    },
    {
      "agent_id": "AI-0110",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "rogo_platform_ai_analyst",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Rogo Trust Center",
              "url": "https://trust.rogo.ai/",
              "note": "Rogo's Trust Center lists Audit Logging as a Product Security control.",
              "evidence_type": "security_trust",
              "source_section": "Product Security"
            }
          ],
          "note": "Rogo documents audit logging as a product security control."
        },
        {
          "path": "security.encryption.at_rest",
          "value": true,
          "scope": "rogo_platform_ai_analyst",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Rogo Trust Center",
              "url": "https://trust.rogo.ai/",
              "note": "Rogo's Trust Center lists Encryption-at-rest under Data Security controls.",
              "evidence_type": "security_trust",
              "source_section": "Data Security"
            }
          ],
          "note": "Rogo documents encryption at rest."
        },
        {
          "path": "security.encryption.in_transit",
          "value": true,
          "scope": "rogo_platform_ai_analyst",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Rogo Trust Center",
              "url": "https://trust.rogo.ai/",
              "note": "Rogo's Trust Center lists Encryption-in-transit under Data Security controls.",
              "evidence_type": "security_trust",
              "source_section": "Data Security"
            }
          ],
          "note": "Rogo documents encryption in transit."
        },
        {
          "path": "security.soc2_type2",
          "value": true,
          "scope": "rogo_platform_ai_analyst",
          "confidence": "high",
          "verified_at": "2026-10-01",
          "evidence": [
            {
              "title": "Rogo Trust Center",
              "url": "https://trust.rogo.ai/",
              "note": "Rogo's Trust Center lists SOC 2 Type 2 among its compliance certifications and product-security controls.",
              "evidence_type": "security_trust",
              "source_section": "Compliance"
            }
          ],
          "note": "Rogo documents SOC 2 Type 2 compliance for the platform providing its AI Analyst."
        }
      ]
    },
    {
      "agent_id": "AI-0111",
      "claims": [
        {
          "path": "governance.custom_roles",
          "value": true,
          "scope": "chatgpt_enterprise_dots_access",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "OpenAI Help – Manage dots in ChatGPT workspaces",
              "url": "https://help.openai.com/en/articles/20001554-manage-dots-in-chatgpt-workspaces",
              "note": "OpenAI documents enabling dots through workspace permissions and custom roles for selected members or groups.",
              "evidence_type": "technical_docs",
              "source_section": "Access and permissions / How do I enable dots for members?"
            }
          ],
          "note": "Enterprise dots access can be assigned through custom roles."
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "scope": "chatgpt_dots_actions",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "OpenAI Help – Getting started with your dot",
              "url": "https://help.openai.com/en/articles/20001530-getting-started-with-your-dot",
              "note": "OpenAI documents action behaviors that can require approval, pre-approval, autonomous action, or handoff to the user.",
              "evidence_type": "technical_docs",
              "source_section": "Controls and approvals / How do I manage confirmations and custom rules?"
            }
          ],
          "note": "Dots support explicit action rules with approval and handoff behaviors."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "chatgpt_enterprise_dots_access",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "OpenAI Help – Manage dots in ChatGPT workspaces",
              "url": "https://help.openai.com/en/articles/20001554-manage-dots-in-chatgpt-workspaces",
              "note": "Dots access is controlled through Permissions & roles, including workspace defaults, custom roles, members and groups.",
              "evidence_type": "technical_docs",
              "source_section": "Access and permissions / Managing access"
            }
          ],
          "note": "OpenAI documents role- and group-based permission assignment for dots in Enterprise."
        },
        {
          "path": "identity.agent_identity",
          "value": true,
          "scope": "chatgpt_dots_supported_messaging_channels",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "OpenAI Help – Manage dots in ChatGPT workspaces",
              "url": "https://help.openai.com/en/articles/20001554-manage-dots-in-chatgpt-workspaces",
              "note": "OpenAI documents that a dot can join supported Slack or Microsoft Teams workspaces and post with its own identity, where available.",
              "evidence_type": "technical_docs",
              "source_section": "Access and permissions / What do the dots permissions control?"
            }
          ],
          "note": "Dots can have their own identity in supported messaging channels."
        },
        {
          "path": "privacy.training.customer_data",
          "value": false,
          "scope": "chatgpt_business_enterprise_edu_dots",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "OpenAI Help – Dots privacy, security, and safety FAQs",
              "url": "https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs",
              "note": "OpenAI states that data from ChatGPT Business, Enterprise and Edu workspaces is not used to train models by default, including dots activity under those workspaces.",
              "evidence_type": "security_trust",
              "source_section": "Data use, memory, and privacy / Does OpenAI use information from my dot to improve its models?"
            }
          ],
          "note": "For Business, Enterprise and Edu workspaces, dot data is documented as not used for model training by default."
        },
        {
          "path": "security.encryption.at_rest",
          "value": "encrypted",
          "scope": "chatgpt_dots_content",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "OpenAI Help – Dots privacy, security, and safety FAQs",
              "url": "https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs",
              "note": "OpenAI states that dot content is encrypted while stored.",
              "evidence_type": "security_trust",
              "source_section": "Data use, memory, and privacy / What information does my dot retain, and how is it protected?"
            }
          ],
          "note": "OpenAI documents encryption of dot content while stored; no algorithm is asserted here."
        },
        {
          "path": "security.encryption.in_transit",
          "value": "encrypted",
          "scope": "chatgpt_dots_content",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "OpenAI Help – Dots privacy, security, and safety FAQs",
              "url": "https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs",
              "note": "OpenAI states that dot content is encrypted while traveling between the user, OpenAI and service providers.",
              "evidence_type": "security_trust",
              "source_section": "Data use, memory, and privacy / What information does my dot retain, and how is it protected?"
            }
          ],
          "note": "OpenAI documents encryption of dot content in transit; no protocol version is asserted here."
        }
      ]
    },
    {
      "agent_id": "AI-0112",
      "claims": [
        {
          "path": "governance.human_oversight",
          "value": true,
          "confidence": "high",
          "scope": "hiring_decisions",
          "verified_at": "2026-10-03",
          "note": "LinkedIn states recruiters must review and verify AI-generated information before hiring decisions and retain full control over how to proceed with each candidate.",
          "evidence": [
            {
              "title": "LinkedIn Recruiter Help – How LinkedIn uses AI Agents",
              "url": "https://www.linkedin.com/help/recruiter/answer/a7454104",
              "evidence_type": "technical_docs",
              "source_section": "Human review of AI outputs"
            }
          ]
        },
        {
          "path": "governance.permission_controls",
          "value": true,
          "confidence": "high",
          "scope": "hiring_assistant_project_access",
          "verified_at": "2026-10-03",
          "note": "Hiring Assistant requires an assigned Hiring Assistant Permission and project-level access controls determine which capabilities collaborators can use.",
          "evidence": [
            {
              "title": "LinkedIn Recruiter Help – Hiring Assistant project permissions and visibility",
              "url": "https://www.linkedin.com/help/recruiter/answer/a9814001",
              "evidence_type": "technical_docs",
              "source_section": "Project permissions and visibility"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0113",
      "claims": [
        {
          "path": "governance.human_oversight",
          "value": true,
          "confidence": "high",
          "scope": "candidate_advancement",
          "verified_at": "2026-10-03",
          "note": "Workday's documented recruiting scenario keeps the hiring manager reviewing surfaced candidates and deciding who advances.",
          "evidence": [
            {
              "title": "Workday – Talent Acquisition AI Agent",
              "url": "https://www.workday.com/en-us/artificial-intelligence/ai-agents/talent-acquisition.html",
              "evidence_type": "official_product_page",
              "source_section": "Talent Acquisition Agent use cases"
            }
          ]
        },
        {
          "path": "governance.permission_controls",
          "value": true,
          "confidence": "high",
          "scope": "workday_talent_acquisition_agent",
          "verified_at": "2026-10-03",
          "note": "Workday states agent actions are grounded in Workday data, permissions and governance and operate within recruiter-set guardrails.",
          "evidence": [
            {
              "title": "Workday – Talent Acquisition AI Agent",
              "url": "https://www.workday.com/en-us/artificial-intelligence/ai-agents/talent-acquisition.html",
              "evidence_type": "official_product_page",
              "source_section": "Permissions and governance"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0114",
      "claims": [
        {
          "path": "governance.human_oversight",
          "value": true,
          "confidence": "high",
          "scope": "paradox_olivia_recruiting_decisions",
          "verified_at": "2026-10-03",
          "note": "Paradox explicitly frames Olivia as automating administrative recruiting work while critical and final hiring decisions remain human responsibilities.",
          "evidence": [
            {
              "title": "Paradox – Everything a talent leader needs to know about AI in recruiting",
              "url": "https://www.paradox.ai/blog/everything-a-talent-leader-needs-to-know-about-ai-in-recruiting",
              "evidence_type": "official_product_page",
              "source_section": "Human-first approach and hiring decisions"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0115",
      "claims": [
        {
          "path": "governance.human_oversight",
          "value": true,
          "confidence": "high",
          "scope": "quickbooks_accounting_agent_review",
          "verified_at": "2026-10-03",
          "note": "QuickBooks states work performed by its AI agents is added to the business feed for review and approval, keeping the user in control; the Accounting Agent also flags items needing approval or attention.",
          "evidence": [
            {
              "title": "QuickBooks – AI Accounting Agent",
              "url": "https://quickbooks.intuit.com/my/ai-agents/accounting/",
              "evidence_type": "official_product_page",
              "source_section": "AI agents FAQ and Accounting Agent"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0116",
      "claims": [
        {
          "path": "governance.human_oversight",
          "value": true,
          "confidence": "high",
          "scope": "quickbooks_finance_agent_decision_support",
          "verified_at": "2026-10-03",
          "note": "Finance AI provides editable summaries and KPI-level recommendations to financial decision-makers; the documented role is decision support rather than autonomous final financial decision-making.",
          "evidence": [
            {
              "title": "QuickBooks – AI Finance Agent",
              "url": "https://quickbooks.intuit.com/finance-agent/",
              "evidence_type": "official_product_page",
              "source_section": "Finance AI capabilities"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0117",
      "claims": [
        {
          "path": "governance.action_permissions",
          "value": true,
          "confidence": "high",
          "scope": "accounting_agent_actions",
          "verified_at": "2026-10-03",
          "note": "Ramp states the customer determines which Accounting Agent actions are allowed: code, review, sync, or all of the above.",
          "evidence": [
            {
              "title": "Ramp – Accounting Agent launch",
              "url": "https://ramp.com/blog/accounting-agent-launch",
              "evidence_type": "official_release",
              "source_section": "How it works"
            }
          ]
        },
        {
          "path": "governance.audit_logs.action_level",
          "value": true,
          "confidence": "high",
          "scope": "routine_spend_sync",
          "verified_at": "2026-10-03",
          "note": "Ramp documents that automatically synced routine spend is posted with a full audit trail.",
          "evidence": [
            {
              "title": "Ramp – Accounting Agent launch",
              "url": "https://ramp.com/blog/accounting-agent-launch",
              "evidence_type": "official_release",
              "source_section": "From swipe to sync"
            }
          ]
        },
        {
          "path": "governance.human_oversight",
          "value": true,
          "confidence": "high",
          "scope": "judgment_required_transactions",
          "verified_at": "2026-10-03",
          "note": "Ramp surfaces transactions needing judgment for user review while routine work can move automatically.",
          "evidence": [
            {
              "title": "Ramp – Accounting Agent launch",
              "url": "https://ramp.com/blog/accounting-agent-launch",
              "evidence_type": "official_release",
              "source_section": "How it works"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0118",
      "claims": [
        {
          "path": "governance.human_approval",
          "value": true,
          "confidence": "high",
          "scope": "ramp_procurement_signoff",
          "verified_at": "2026-10-03",
          "note": "Ramp states purchasing agents move procurement forward while spend cannot slip through without sign-off; vendor selection remains a user decision.",
          "evidence": [
            {
              "title": "Ramp – Q2 2026 Product Release",
              "url": "https://ramp.com/new-on-ramp-q2-2026",
              "evidence_type": "official_release",
              "source_section": "Purchasing Agents"
            }
          ]
        },
        {
          "path": "orchestration.parallel_agents",
          "value": true,
          "scope": "ramp_procurement_ai_agents_2026",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "Ramp – New on Ramp: May Edition",
              "url": "https://ramp.com/blog/new-on-ramp-may-edition-26",
              "note": "Ramp states that security, legal, and vendor evaluations can run automatically in parallel.",
              "evidence_type": "official_release",
              "source_section": "Automate sourcing, intake, compliance reviews, and renewals"
            }
          ],
          "note": "Ramp documents parallel agent-supported procurement evaluations."
        }
      ]
    },
    {
      "agent_id": "AI-0119",
      "claims": [
        {
          "path": "governance.human_approval",
          "value": true,
          "confidence": "high",
          "scope": "qa_wolf_ai_test_maintenance",
          "verified_at": "2026-10-03",
          "note": "QA Wolf states human approval is required every time its AI modifies code to fix a test.",
          "evidence": [
            {
              "title": "QA Wolf – AI-native and human expertise for test accuracy",
              "url": "https://www.qawolf.com/blog/how-we-use-ai-native-and-human-expertise-in-4-stages-for-unmatched-test-accuracy",
              "evidence_type": "official_product_page",
              "source_section": "Find and fix issues faster with AI-powered diagnosis"
            }
          ]
        },
        {
          "path": "governance.human_oversight",
          "value": true,
          "confidence": "high",
          "scope": "qa_wolf_ai_testing_service",
          "verified_at": "2026-10-03",
          "note": "QA Wolf documents human review of AI-generated test code and human verification of failures and bug reports before they are delivered to customers.",
          "evidence": [
            {
              "title": "QA Wolf – AI-native and human expertise for test accuracy",
              "url": "https://www.qawolf.com/blog/how-we-use-ai-native-and-human-expertise-in-4-stages-for-unmatched-test-accuracy",
              "evidence_type": "official_product_page",
              "source_section": "Human oversight of AI-generated code and bug reports"
            }
          ]
        },
        {
          "path": "hosting.cloud",
          "value": true,
          "scope": "qa_wolf_cloud_testing_platform",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "QA Wolf – Agentic Cloud Testing Platform",
              "url": "https://www.qawolf.com/education/cloud-testing-platform",
              "note": "QA Wolf describes the product as an AI-native cloud testing platform.",
              "evidence_type": "official_product_page",
              "source_section": "Cloud testing platform"
            }
          ],
          "note": "QA Wolf is documented as a cloud testing platform."
        },
        {
          "path": "orchestration.multi_agent",
          "value": true,
          "scope": "qa_wolf_agentic_qa_platform",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "QA Wolf – AI Based Testing Tool",
              "url": "https://www.qawolf.com/education/ai-based-testing-tool",
              "note": "QA Wolf describes one platform powered by 100+ specialized AI-driven testing agents.",
              "evidence_type": "official_product_page",
              "source_section": "AI Based Testing"
            }
          ],
          "note": "QA Wolf explicitly documents a multi-agent testing architecture."
        },
        {
          "path": "orchestration.parallel_agents",
          "value": true,
          "scope": "qa_wolf_test_execution",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "QA Wolf – AI Based Testing Tool",
              "url": "https://www.qawolf.com/education/ai-based-testing-tool",
              "note": "QA Wolf documents 100% parallel test execution in its agentic testing platform.",
              "evidence_type": "official_product_page",
              "source_section": "Run infrastructure"
            }
          ],
          "note": "QA Wolf documents parallel execution for its agentic QA platform."
        }
      ]
    },
    {
      "agent_id": "AI-0120",
      "claims": [
        {
          "path": "governance.approval.pre_action",
          "value": true,
          "confidence": "high",
          "scope": "kaneai_test_plan_execution",
          "verified_at": "2026-10-03",
          "note": "KaneAI documents that a drafted test plan is executed only after the user reviews and approves it.",
          "evidence": [
            {
              "title": "TestMu AI – KaneAI",
              "url": "https://www.testmuai.com/kane-ai/",
              "evidence_type": "official_product_page",
              "source_section": "No Agent Runs Blind"
            }
          ]
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "confidence": "high",
          "scope": "kaneai_test_plan_execution",
          "verified_at": "2026-10-03",
          "note": "KaneAI requires users to review, edit and approve drafted test plans before execution in its documented human-in-the-loop flow.",
          "evidence": [
            {
              "title": "TestMu AI – KaneAI",
              "url": "https://www.testmuai.com/kane-ai/",
              "evidence_type": "official_product_page",
              "source_section": "Human in the loop"
            }
          ]
        },
        {
          "path": "governance.rollback",
          "value": true,
          "confidence": "high",
          "scope": "kaneai_test_versioning",
          "verified_at": "2026-10-03",
          "note": "KaneAI documents built-in versioning for every test change with the ability to compare versions and roll back.",
          "evidence": [
            {
              "title": "TestMu AI – KaneAI",
              "url": "https://www.testmuai.com/kane-ai/",
              "evidence_type": "official_product_page",
              "source_section": "Built-in versioning"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0121",
      "claims": [
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "security_copilot_custom_agent_lifecycle",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "Microsoft Learn – Security Copilot agent development overview",
              "url": "https://learn.microsoft.com/en-us/copilot/security/developer/custom-agent-overview",
              "note": "Microsoft explicitly documents RBAC for Security Copilot agent lifecycle operations.",
              "evidence_type": "technical_docs",
              "source_section": "Role-Based Access Control in Security Copilot"
            }
          ],
          "note": "Security Copilot uses RBAC for agent development and publishing operations."
        },
        {
          "path": "identity.agent_identity.provider",
          "value": "Microsoft Entra Agent ID",
          "scope": "microsoft_built_security_copilot_agents",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "Microsoft Learn – Security Copilot agents overview",
              "url": "https://learn.microsoft.com/en-us/copilot/security/agents-overview",
              "note": "For Microsoft-built agents, the setup can create a dedicated identity using Microsoft Entra Agent ID.",
              "evidence_type": "technical_docs",
              "source_section": "Agent terminology / Identity"
            }
          ],
          "note": "Dedicated Microsoft-built agent identities use Microsoft Entra Agent ID."
        },
        {
          "path": "identity.agent_identity",
          "value": true,
          "scope": "microsoft_security_copilot_agents",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "Microsoft Learn – Security Copilot agents overview",
              "url": "https://learn.microsoft.com/en-us/copilot/security/agents-overview",
              "note": "Microsoft documents that an agent needs an identity to authenticate and securely access resources.",
              "evidence_type": "technical_docs",
              "source_section": "Agent terminology / Identity"
            }
          ],
          "note": "Security Copilot agents have documented agent identity semantics."
        }
      ]
    },
    {
      "agent_id": "AI-0122",
      "claims": [
        {
          "path": "deployment.low_code",
          "value": true,
          "scope": "charlotte_ai_agentworks",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "CrowdStrike – Charlotte AI AgentWorks",
              "url": "https://www.crowdstrike.com/en-us/platform/charlotte-ai/charlotte-ai-agentworks/",
              "note": "CrowdStrike states teams can build agents without writing code and define goals, data, and behavior in natural language.",
              "evidence_type": "official_product_page",
              "source_section": "Build the agents you need"
            }
          ],
          "note": "AgentWorks explicitly supports no-code agent creation."
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "scope": "charlotte_ai_agentworks_agentic_soar",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "CrowdStrike – Charlotte AI AgentWorks",
              "url": "https://www.crowdstrike.com/en-us/platform/charlotte-ai/charlotte-ai-agentworks/",
              "note": "CrowdStrike documents configurable checkpoints for approvals in multi-agent workflows.",
              "evidence_type": "official_product_page",
              "source_section": "Build the agents you need"
            }
          ],
          "note": "Human approval checkpoints are explicitly configurable."
        },
        {
          "path": "governance.rbac",
          "value": true,
          "scope": "charlotte_ai_agentworks",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "CrowdStrike – Mission-Ready Agentic Workforce",
              "url": "https://www.crowdstrike.com/en-us/platform/charlotte-ai/agentic-security-workforce/",
              "note": "CrowdStrike documents role-based access controls and audit-ready logs for agents.",
              "evidence_type": "security_trust",
              "source_section": "Keep analysts in control"
            }
          ],
          "note": "CrowdStrike documents RBAC for its agentic security workforce."
        },
        {
          "path": "orchestration.handoffs",
          "value": true,
          "scope": "charlotte_agentic_soar",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "CrowdStrike – Charlotte Agentic SOAR",
              "url": "https://www.crowdstrike.com/en-us/platform/charlotte-ai/agentic-soar/",
              "note": "CrowdStrike explicitly describes defining handoffs so context carries from one agent to the next.",
              "evidence_type": "official_product_page",
              "source_section": "Coordinate agents across every security workflow"
            }
          ],
          "note": "Agent-to-agent handoffs are explicitly documented."
        },
        {
          "path": "orchestration.multi_agent",
          "value": true,
          "scope": "charlotte_agentic_soar",
          "confidence": "high",
          "verified_at": "2026-10-03",
          "evidence": [
            {
              "title": "CrowdStrike – Charlotte Agentic SOAR",
              "url": "https://www.crowdstrike.com/en-us/platform/charlotte-ai/agentic-soar/",
              "note": "CrowdStrike documents coordinating native, custom, and third-party agents as one workflow and team.",
              "evidence_type": "official_product_page",
              "source_section": "Coordinate agents across every security workflow"
            }
          ],
          "note": "CrowdStrike documents multi-agent orchestration in Charlotte Agentic SOAR."
        }
      ]
    },
    {
      "agent_id": "AI-0123",
      "claims": [
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "confidence": "high",
          "scope": "api_key_management_events",
          "verified_at": "2026-10-03",
          "note": "Cortex AgentiX provides Management Audit Logs for administrative and operational activities; the audit records are documented as immutable and view-only.",
          "evidence": [
            {
              "title": "Palo Alto Networks – Cortex AgentiX auditing permissions",
              "url": "https://docs-cortex.paloaltonetworks.com/r/Cortex-AgentiX/Cortex-AgentiX-Documentation/Auditing-permissions?contentId=7Evegg~PugE2k5~WfkTFtw",
              "evidence_type": "technical_docs",
              "source_section": "Auditing permissions"
            }
          ]
        },
        {
          "path": "governance.permission_controls",
          "value": true,
          "confidence": "high",
          "scope": "public_api_and_compute_usage",
          "verified_at": "2026-10-03",
          "note": "Cortex AgentiX documents RBAC and granular role permissions that constrain component access and underlying dataset visibility.",
          "evidence": [
            {
              "title": "Palo Alto Networks – Cortex AgentiX role permissions",
              "url": "https://docs-cortex.paloaltonetworks.com/r/Cortex-AgentiX/Cortex-AgentiX-Documentation/Role-permissions-by-component",
              "evidence_type": "technical_docs",
              "source_section": "Role permissions by component"
            }
          ]
        },
        {
          "path": "governance.rbac",
          "value": true,
          "confidence": "high",
          "scope": "cortex_agentix_access_management",
          "verified_at": "2026-10-03",
          "note": "Cortex AgentiX explicitly documents role-based access control with predefined and custom roles governing permissions and dataset visibility.",
          "evidence": [
            {
              "title": "Palo Alto Networks – Cortex AgentiX role permissions",
              "url": "https://docs-cortex.paloaltonetworks.com/r/Cortex-AgentiX/Cortex-AgentiX-Documentation/Role-permissions-by-component",
              "evidence_type": "technical_docs",
              "source_section": "Role-Based Access Control (RBAC)"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0124",
      "claims": [
        {
          "path": "governance.rbac",
          "value": true,
          "confidence": "high",
          "scope": "team_access",
          "verified_at": "2026-10-03",
          "note": "Ada Team access supports assigning permissions based on roles.",
          "evidence": [
            {
              "title": "Ada Docs – Key concepts",
              "url": "https://docs.ada.cx/docs/welcome/key-concepts",
              "evidence_type": "technical_docs",
              "source_section": "Team access"
            }
          ]
        },
        {
          "path": "governance.rollback",
          "value": true,
          "confidence": "high",
          "scope": "agent_configuration_snapshot",
          "verified_at": "2026-10-03",
          "note": "Ada's Snapshot API can save a restore point before a large change and import the archived configuration back into an Agent.",
          "evidence": [
            {
              "title": "Ada Docs – Key concepts",
              "url": "https://docs.ada.cx/docs/welcome/key-concepts",
              "evidence_type": "technical_docs",
              "source_section": "Snapshot API"
            }
          ]
        },
        {
          "path": "memory.persistent",
          "value": true,
          "confidence": "high",
          "scope": "chat_customer_persistence",
          "verified_at": "2026-10-03",
          "note": "Ada Customer Persistence can retain an end user's conversation history and variables across browser sessions.",
          "evidence": [
            {
              "title": "Ada Docs – Data controls",
              "url": "https://docs.ada.cx/docs/channels/chat/chat-configuration/data-controls",
              "evidence_type": "technical_docs",
              "source_section": "Persistence settings"
            }
          ]
        },
        {
          "path": "orchestration.handoffs",
          "value": true,
          "confidence": "high",
          "scope": "customer_support_handoff",
          "verified_at": "2026-10-03",
          "note": "Ada documents handoffs that escalate a conversation from the AI Agent to a human agent based on configured rules and triggers.",
          "evidence": [
            {
              "title": "Ada Docs – Key concepts",
              "url": "https://docs.ada.cx/docs/welcome/key-concepts",
              "evidence_type": "technical_docs",
              "source_section": "Handoffs"
            }
          ]
        },
        {
          "path": "tools.external_rest",
          "value": true,
          "confidence": "high",
          "scope": "actions",
          "verified_at": "2026-10-03",
          "note": "Ada Actions interact with external systems through API calls to retrieve or process information.",
          "evidence": [
            {
              "title": "Ada Docs – Key concepts",
              "url": "https://docs.ada.cx/docs/welcome/key-concepts",
              "evidence_type": "technical_docs",
              "source_section": "Actions"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0125",
      "claims": [
        {
          "path": "governance.human_oversight",
          "value": true,
          "scope": "workspace_agents_admin_controls",
          "confidence": "high",
          "verified_at": "2026-10-05",
          "evidence": [
            {
              "title": "OpenAI – Introducing workspace agents in ChatGPT",
              "url": "https://openai.com/index/introducing-workspace-agents-in-chatgpt/",
              "note": "OpenAI describes organization-defined permissions and controls for workspace agents.",
              "evidence_type": "product_docs",
              "source_section": "Workspace agents"
            }
          ]
        },
        {
          "path": "memory.persistent",
          "value": true,
          "scope": "workspace_agent_cloud_workspace",
          "confidence": "high",
          "verified_at": "2026-10-05",
          "evidence": [
            {
              "title": "OpenAI – Introducing workspace agents in ChatGPT",
              "url": "https://openai.com/index/introducing-workspace-agents-in-chatgpt/",
              "note": "OpenAI states agents have a cloud workspace for files, code, tools and memories.",
              "evidence_type": "product_docs",
              "source_section": "Workspace agents"
            }
          ]
        },
        {
          "path": "tools.external_rest",
          "value": true,
          "scope": "workspace_agents_connected_apps",
          "confidence": "medium",
          "verified_at": "2026-10-05",
          "evidence": [
            {
              "title": "OpenAI Developers – Workspace Agents",
              "url": "https://developers.openai.com/workspace-agents",
              "note": "OpenAI documents triggering published workspace agents from external systems.",
              "evidence_type": "api_docs",
              "source_section": "Workspace Agents"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0126",
      "claims": [
        {
          "path": "api.rest",
          "value": true,
          "scope": "openai_agents_api_public_beta",
          "confidence": "high",
          "verified_at": "2026-10-05",
          "evidence": [
            {
              "title": "OpenAI Developers – Agents API",
              "url": "https://developers.openai.com/api/docs/guides/agents-api/overview",
              "note": "OpenAI documents a managed API for durable cloud agents.",
              "evidence_type": "api_docs",
              "source_section": "Agents API"
            }
          ]
        },
        {
          "path": "protocols.mcp.client",
          "value": true,
          "scope": "agents_api_tooling",
          "confidence": "high",
          "verified_at": "2026-10-05",
          "evidence": [
            {
              "title": "OpenAI Developers – Agents API",
              "url": "https://developers.openai.com/api/docs/guides/agents-api/overview",
              "note": "OpenAI documents agents connecting to MCP servers.",
              "evidence_type": "api_docs",
              "source_section": "Agents API"
            }
          ]
        },
        {
          "path": "hosting.managed",
          "value": true,
          "scope": "openai_managed_agent_harness",
          "confidence": "high",
          "verified_at": "2026-10-05",
          "evidence": [
            {
              "title": "OpenAI – Introducing the Agents API",
              "url": "https://openai.com/index/introducing-the-agents-api/",
              "note": "OpenAI describes the Codex harness and infrastructure as fully managed.",
              "evidence_type": "product_docs",
              "source_section": "Agents API"
            }
          ]
        }
      ]
    },
    {
      "agent_id": "AI-0127",
      "claims": [
        {
          "path": "memory.persistent",
          "value": true,
          "scope": "gemini_agent_cloud_persistent_tasks",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud — Introducing the Gemini agent",
              "url": "https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026",
              "note": "Persistent execution and memory are explicitly described.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Persistent execution and memory are explicitly described."
        },
        {
          "path": "orchestration.multi_agent",
          "value": true,
          "scope": "gemini_agent_dynamic_subagents",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud — Introducing the Gemini agent",
              "url": "https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026",
              "note": "Google explicitly describes dynamic subagents.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Google explicitly describes dynamic subagents."
        },
        {
          "path": "identity.agent_identity",
          "value": true,
          "scope": "gemini_coworker_agents",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud — Introducing the Gemini agent",
              "url": "https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026",
              "note": "Dedicated coworker agent identity is described for the announced product layer.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Dedicated coworker agent identity is described for the announced product layer."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "gemini_enterprise_agent_audit",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud — Introducing the Gemini agent",
              "url": "https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026",
              "note": "Per-agent actions are described as logged and attributable.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Per-agent actions are described as logged and attributable."
        },
        {
          "path": "orchestration.model_routing",
          "value": true,
          "scope": "gemini_agent_enterprise_multi_model",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud: Gemini at Work 2026",
              "url": "https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026",
              "evidence_type": "official_product_announcement",
              "source_section": "Model choice flexibility",
              "note": "Google describes task-dependent model selection, including Anthropic Claude models."
            }
          ],
          "note": "Google describes task-dependent model selection, including Anthropic Claude models."
        },
        {
          "path": "integrations.workspace.inline",
          "value": true,
          "scope": "gemini_agent_google_workspace_announced",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud: Gemini at Work 2026",
              "url": "https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026",
              "evidence_type": "official_product_announcement",
              "source_section": "Gemini in Google Workspace",
              "note": "Google names Gmail, Drive, Docs, Slides, Sheets, Chat and Calendar surfaces."
            }
          ],
          "note": "Google names Gmail, Drive, Docs, Slides, Sheets, Chat and Calendar surfaces."
        },
        {
          "path": "security.network_policy.agent_gateway",
          "value": true,
          "scope": "gemini_enterprise_agent_gateway_announced",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud: Gemini at Work 2026",
              "url": "https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026",
              "evidence_type": "official_product_announcement",
              "source_section": "Securing and governing agents",
              "note": "Google describes policy enforcement via Agent Gateway for enterprise agents."
            }
          ],
          "note": "Google describes policy enforcement via Agent Gateway for enterprise agents."
        }
      ]
    },
    {
      "agent_id": "AI-0128",
      "claims": [
        {
          "path": "hosting.cloud",
          "value": true,
          "scope": "muse_secure_vm",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Meta — Introducing Muse",
              "url": "https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/",
              "note": "Meta documents an isolated cloud virtual machine.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Meta documents an isolated cloud virtual machine."
        },
        {
          "path": "governance.human_approval",
          "value": true,
          "scope": "muse_sensitive_actions",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Meta — Introducing Muse",
              "url": "https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/",
              "note": "Meta says approval is required before selected sensitive actions.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Meta says approval is required before selected sensitive actions."
        },
        {
          "path": "governance.audit_logs.available",
          "value": true,
          "scope": "muse_action_audit_trail",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Meta — Introducing Muse",
              "url": "https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/",
              "note": "Meta describes a full user-visible action audit trail.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Meta describes a full user-visible action audit trail."
        },
        {
          "path": "security.sentinel_network_review",
          "value": true,
          "scope": "muse_secure_vm_sentinel",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Meta: Introducing Muse",
              "url": "https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/",
              "evidence_type": "official_product_announcement",
              "source_section": "Built to be Private, Safe, and Secure",
              "note": "Meta describes a separate Sentinel approval layer for outbound traffic."
            }
          ],
          "note": "Meta describes a separate Sentinel approval layer for outbound traffic."
        },
        {
          "path": "access.us_canada",
          "value": true,
          "scope": "muse_personal_agent_sep2026_north_america",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Meta: Muse for Small Business",
              "url": "https://about.fb.com/news/2026/09/introducing-muse-small-business/",
              "evidence_type": "official_product_announcement",
              "source_section": "Muse for Small Business",
              "note": "Meta states Muse is available in the US and Canada."
            }
          ],
          "note": "Meta states Muse is available in the US and Canada."
        },
        {
          "path": "security.credentials_separate_storage",
          "value": true,
          "scope": "muse_secure_vm_credentials",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Meta: Introducing Muse",
              "url": "https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/",
              "evidence_type": "official_product_announcement",
              "source_section": "Built to be Private, Safe, and Secure",
              "note": "Meta says agent cannot see stored passwords or payment details."
            }
          ],
          "note": "Meta says agent cannot see stored passwords or payment details."
        },
        {
          "path": "security.audit_trail_user_visible",
          "value": true,
          "scope": "muse_personal_action_history",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Meta: Introducing Muse",
              "url": "https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/",
              "evidence_type": "official_product_announcement",
              "source_section": "Built to be Private, Safe, and Secure",
              "note": "Meta documents user-visible action/audit trail."
            }
          ],
          "note": "Meta documents user-visible action/audit trail."
        }
      ]
    },
    {
      "agent_id": "AI-0129",
      "claims": [
        {
          "path": "orchestration.multi_agent",
          "value": true,
          "scope": "antigravity_2_desktop_orchestration",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google I/O — Antigravity 2.0",
              "url": "https://blog.google/intl/de-de/produkte/suchen-entdecken/google-io-2026-developer-highlights/",
              "note": "Google describes coordinating several agents.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Google describes coordinating several agents."
        },
        {
          "path": "orchestration.parallel_agents",
          "value": true,
          "scope": "antigravity_2_parallel_workflows",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google I/O — Antigravity 2.0",
              "url": "https://blog.google/intl/de-de/produkte/suchen-entdecken/google-io-2026-developer-highlights/",
              "note": "Google describes multiple agents working in parallel.",
              "evidence_type": "official_product_announcement",
              "source_section": "Product capabilities"
            }
          ],
          "note": "Google describes multiple agents working in parallel."
        },
        {
          "path": "orchestration.git_worktrees",
          "value": true,
          "scope": "antigravity_2_desktop_worktree_mode",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Antigravity: getting started",
              "url": "https://www.antigravity.google/docs",
              "evidence_type": "official_product_announcement",
              "source_section": "Starting an Agent",
              "note": "Google documents New Worktree Mode in the desktop interface."
            }
          ],
          "note": "Google documents New Worktree Mode in the desktop interface."
        },
        {
          "path": "security.project_permissions",
          "value": true,
          "scope": "antigravity_2_project_scoped_permissions",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Antigravity: feature documentation",
              "url": "https://www.antigravity.google/docs/features",
              "evidence_type": "official_product_announcement",
              "source_section": "Projects",
              "note": "Google documents project-scoped permissions and settings."
            }
          ],
          "note": "Google documents project-scoped permissions and settings."
        },
        {
          "path": "availability.desktop_operating_systems",
          "value": [
            "macOS",
            "Windows",
            "Linux"
          ],
          "scope": "antigravity_2_desktop_downloads",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Antigravity: getting started",
              "url": "https://www.antigravity.google/docs",
              "evidence_type": "official_product_announcement",
              "source_section": "Download",
              "note": "Google documents availability for three desktop operating systems."
            }
          ],
          "note": "Google documents availability for three desktop operating systems."
        }
      ]
    },
    {
      "agent_id": "AI-0130",
      "claims": [
        {
          "path": "capabilities.algorithm_optimization",
          "value": true,
          "scope": "alphaevolve_cloud_ga",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud: AlphaEvolve generally available",
              "url": "https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/alphaevolve-on-cloud/",
              "evidence_type": "official_product_announcement",
              "source_section": "Availability",
              "note": "Google Cloud describes optimization from baseline algorithm and goals."
            }
          ],
          "note": "Google Cloud describes optimization from baseline algorithm and goals."
        },
        {
          "path": "availability.general_availability",
          "value": true,
          "scope": "google_cloud_alphaevolve_gemini_enterprise_agent_platform_2026_07",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google Cloud: AlphaEvolve generally available",
              "url": "https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/alphaevolve-on-cloud/",
              "evidence_type": "official_product_announcement",
              "source_section": "General availability",
              "note": "Google Cloud states GA for Google Cloud customers on Agent Platform in July 2026."
            }
          ],
          "note": "Google Cloud states GA for Google Cloud customers on Agent Platform in July 2026."
        },
        {
          "path": "capabilities.automated_evaluator",
          "value": true,
          "scope": "alphaevolve_evolutionary_research_architecture",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google DeepMind: AlphaEvolve architecture",
              "url": "https://deepmind.google/blog/alphaevolve-a-gemini-powered-coding-agent-for-designing-advanced-algorithms/",
              "evidence_type": "official_product_announcement",
              "source_section": "Designing better algorithms with large language models",
              "note": "DeepMind documents objective, automated evaluators scoring proposed programs."
            }
          ],
          "note": "DeepMind documents objective, automated evaluators scoring proposed programs."
        },
        {
          "path": "orchestration.evolutionary_search",
          "value": true,
          "scope": "alphaevolve_evolutionary_research_architecture",
          "confidence": "high",
          "verified_at": "2026-10-08",
          "evidence": [
            {
              "title": "Google DeepMind: AlphaEvolve architecture",
              "url": "https://deepmind.google/blog/alphaevolve-a-gemini-powered-coding-agent-for-designing-advanced-algorithms/",
              "evidence_type": "official_product_announcement",
              "source_section": "Designing better algorithms with large language models",
              "note": "DeepMind describes program archive and evolutionary selection."
            }
          ],
          "note": "DeepMind describes program archive and evolutionary selection."
        }
      ]
    }
  ]
}
