{"schemaVersion":"2026-07-23","product":"HumanProof deterministic anti-cheat","certifications":[],"certificationStatement":"No third-party certification is claimed by these materials.","materials":[{"id":"data-boundary","title":"Data and privacy boundary","summary":"Content-blind collection, app-scoped identifiers, bounded raw-batch derivation, and plan-bound retention.","controls":["No prompts, generated output, typed content, pointer coordinates, payment data, or raw IPs in customer telemetry.","Account and device references are re-hashed per app.","Enterprise customer history is retained for 90 days."]},{"id":"access","title":"Identity and access","summary":"SAML/OIDC SSO, SCIM lifecycle enforcement, organization roles, and redacted immutable audit history.","controls":["SSO providers are exact-domain and organization bound.","SCIM deactivation removes organization access immediately.","Owner-only permissions cannot be delegated through custom roles."]},{"id":"delivery","title":"Application and delivery security","summary":"One reviewed image, additive migrations, dependency scanning, health-gated rollout, and automatic rollback.","controls":["All production deployments promote immutable GHCR digests.","Failed health attestations restore the prior digest.","Enterprise capacity uses shared code and automated regional provisioning, never a customer fork."]},{"id":"resilience","title":"Resilience and incident response","summary":"Durable backups, restore exercises, bounded workers, public service status, and explicit incident reporting.","controls":["Database-aware health checks gate deployment.","SLA reports disclose missing observation coverage.","Security reports must exclude credentials, request bodies, evidence, and customer data."]}]}