{
  "schemaVersion": "0.1",
  "subject": {
    "name": "NobleCloak",
    "trustCenterUrl": "https://trust.noblecloak.com"
  },
  "registry": {
    "sourceRepo": "bianoble/noblecloak-intel",
    "sourcePath": "packages/noblecloakintel-db/src/seed/attribute-definitions.ts",
    "commitSha": "2a36d3267e29d6ea3e144178755bf5408b52e652",
    "snapshotDate": "2026-07-27"
  },
  "generatedFrom": "https://trust.noblecloak.com",
  "claims": [
    {
      "attribute": "trains_on_data_by_default",
      "label": "Trains on customer data by default",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "affirmed",
      "value": false,
      "citation": {
        "source": "AWS Service Terms § Bedrock",
        "url": "https://aws.amazon.com/service-terms/"
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "training_use_opt_out",
      "label": "Training-use opt-out mechanism",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "affirmed",
      "value": "not_applicable_no_default_training",
      "citation": {
        "source": "AWS Service Terms § Bedrock",
        "url": "https://aws.amazon.com/service-terms/"
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "data_residency_options",
      "label": "Data residency options",
      "domain": "ai_risk",
      "datatype": "string_array",
      "state": "absent",
      "note": "Inference routing is pinned to US regions at the IAM boundary and fails closed rather than falling back to another region. This is a code-enforced routing control, not a contractual at-rest data-residency commitment.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "tenant_isolation",
      "label": "Tenant isolation model",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "affirmed",
      "value": "dedicated_single_tenant_available",
      "availability": "on_request",
      "citation": {
        "source": "NobleCloak Security Overview",
        "url": "https://trust.noblecloak.com/policies/security-overview",
        "quote": "We document five tenant-isolation tiers, ranging from shared multi-tenant infrastructure with logical (row-level) separation up to a fully isolated AWS account running its own dedicated Kubernetes cluster"
      },
      "note": "Architecture documented across five isolation tiers. A dedicated single-tenant deployment is provisioned per engagement, not a self-serve or currently-running purchase.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "deployment_models",
      "label": "Deployment models offered",
      "domain": "ai_risk",
      "datatype": "string_array",
      "state": "affirmed",
      "value": [
        "saas_multi_tenant",
        "dedicated_cloud",
        "on_premises"
      ],
      "availability": "on_request",
      "citation": {
        "source": "NobleCloak Security Overview",
        "url": "https://trust.noblecloak.com/policies/security-overview",
        "quote": "Dedicated-account and on-premises deployments (tier 4, and above the table for on-prem) are provisioned per engagement — they are not a self-serve purchase today."
      },
      "note": "Architecture documented across five isolation tiers. Dedicated-account and on-premises deployments are provisioned per engagement.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "model_providers",
      "label": "Underlying model providers",
      "domain": "ai_risk",
      "datatype": "string_array",
      "state": "affirmed",
      "value": [
        "anthropic"
      ],
      "citation": {
        "source": "NobleCloak Subprocessors",
        "url": "https://trust.noblecloak.com/policies/subprocessors",
        "quote": "Foundation models, accessed via Amazon Bedrock — AWS is the processor and Anthropic is a fourth party under AWS terms"
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 90
    },
    {
      "attribute": "model_hosting_architecture",
      "label": "Model hosting architecture",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "affirmed",
      "value": "third_party_hosted_apis",
      "citation": {
        "source": "NobleCloak Subprocessors",
        "url": "https://trust.noblecloak.com/policies/subprocessors",
        "quote": "Foundation models, accessed via Amazon Bedrock — AWS is the processor and Anthropic is a fourth party under AWS terms"
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "cloud_infrastructure_providers",
      "label": "Cloud infrastructure providers",
      "domain": "ai_risk",
      "datatype": "string_array",
      "state": "affirmed",
      "value": [
        "aws"
      ],
      "citation": {
        "source": "NobleCloak Subprocessors",
        "url": "https://trust.noblecloak.com/policies/subprocessors",
        "quote": "EKS, RDS PostgreSQL, S3, CloudFront, Cognito, Secrets Manager, Bedrock"
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "subprocessors_disclosed",
      "label": "Subprocessor list published",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "affirmed",
      "value": true,
      "citation": {
        "source": "NobleCloak Subprocessors",
        "url": "https://trust.noblecloak.com/policies/subprocessors",
        "quote": "Vendors that process data on NobleCloak's behalf."
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 90
    },
    {
      "attribute": "subprocessor_list_url",
      "label": "Subprocessor list URL",
      "domain": "ai_risk",
      "datatype": "url",
      "state": "affirmed",
      "value": "https://trust.noblecloak.com/policies/subprocessors",
      "citation": {
        "source": "NobleCloak Subprocessors",
        "url": "https://trust.noblecloak.com/policies/subprocessors",
        "quote": "Vendors that process data on NobleCloak's behalf."
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 90
    },
    {
      "attribute": "trust_center_url",
      "label": "Trust center URL",
      "domain": "osint",
      "datatype": "url",
      "state": "affirmed",
      "value": "https://trust.noblecloak.com",
      "citation": {
        "source": "NobleCloak Trust Center",
        "url": "https://trust.noblecloak.com",
        "quote": "Every affirmed claim carries a citation and the date we last verified it."
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "hq_country",
      "label": "Headquarters country",
      "domain": "firmographic",
      "datatype": "string",
      "state": "affirmed",
      "value": "us",
      "citation": {
        "source": "NobleCloak Privacy Policy",
        "url": "https://trust.noblecloak.com/policies/privacy",
        "quote": "NobleCloak was founded in 2026 as a United States company."
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "founded_year",
      "label": "Year founded",
      "domain": "firmographic",
      "datatype": "number",
      "state": "affirmed",
      "value": 2026,
      "citation": {
        "source": "NobleCloak Privacy Policy",
        "url": "https://trust.noblecloak.com/policies/privacy",
        "quote": "NobleCloak was founded in 2026 as a United States company."
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 730
    },
    {
      "attribute": "model_documentation_published",
      "label": "Model/system cards published",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "not_applicable",
      "reason": "NobleCloak does not develop foundation models. Model and system cards for the models we consume are published by their developers.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "fedramp_status",
      "label": "FedRAMP status",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "not_applicable",
      "reason": "NobleCloak does not currently sell to US federal agencies, so no FedRAMP designation applies.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "parent_company",
      "label": "Parent company",
      "domain": "firmographic",
      "datatype": "string",
      "state": "not_applicable",
      "reason": "NobleCloak is independently owned and has no controlling parent.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "soc2_report_period_end",
      "label": "SOC 2 report period end",
      "domain": "ai_risk",
      "datatype": "date",
      "state": "not_applicable",
      "reason": "No SOC 2 report has been issued, so there is no report period.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "soc2_type",
      "label": "SOC 2 attestation",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "absent",
      "note": "Our SOC 2 program has not started. We will publish dates when it does.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "cyber_insurance_disclosed",
      "label": "Cyber insurance disclosed",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "note": "Cyber liability coverage will be bound before the platform serves live customers.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "security_breach_disclosed",
      "label": "Public breach disclosure",
      "domain": "osint",
      "datatype": "boolean",
      "state": "absent",
      "note": "This attribute is assert-true-only: a claim appears here only when there is a disclosed breach to report. Its absence means no such event has been disclosed, not that we decline to answer.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 90
    },
    {
      "attribute": "regulatory_action_disclosed",
      "label": "Regulatory enforcement action",
      "domain": "osint",
      "datatype": "boolean",
      "state": "absent",
      "note": "This attribute is assert-true-only: a claim appears here only when there is a disclosed regulatory enforcement action to report. Its absence means no such action has been disclosed, not that we decline to answer.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 90
    },
    {
      "attribute": "customer_data_sold_or_shared",
      "label": "Sells or shares customer data",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "affirmed",
      "value": false,
      "citation": {
        "source": "NobleCloak Privacy Policy",
        "url": "https://trust.noblecloak.com/policies/privacy",
        "quote": "NobleCloak does not sell or share personal information."
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "vulnerability_disclosure_program",
      "label": "Vulnerability disclosure program",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "affirmed",
      "value": "disclosure_policy_only",
      "citation": {
        "source": "NobleCloak Vulnerability Disclosure Policy",
        "url": "https://trust.noblecloak.com/policies/disclosure",
        "quote": "We do not currently operate a paid bug bounty."
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "security_txt_published",
      "label": "security.txt published",
      "domain": "osint",
      "datatype": "boolean",
      "state": "affirmed",
      "value": true,
      "citation": {
        "source": "NobleCloak security.txt",
        "url": "https://trust.noblecloak.com/.well-known/security.txt",
        "quote": "Contact: mailto:security@noblecloak.com"
      },
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 90
    },
    {
      "attribute": "ownership_type",
      "label": "Ownership structure",
      "domain": "firmographic",
      "datatype": "enum",
      "state": "absent",
      "note": "Ownership structure will be published with a citation once a company/about page states it directly.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "zero_data_retention_available",
      "label": "Zero-data-retention mode available",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "customer_content_retention",
      "label": "Customer content retention window",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "human_review_of_customer_data",
      "label": "Human review of customer content",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "customer_managed_keys_available",
      "label": "Customer-managed encryption keys",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "deletion_on_termination_days",
      "label": "Contractual deletion window after termination",
      "domain": "ai_risk",
      "datatype": "number",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "encryption_at_rest",
      "label": "Encryption at rest",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "encryption_in_transit",
      "label": "Encryption in transit",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "iso_27001_certified",
      "label": "ISO/IEC 27001 certified",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "iso_42001_certified",
      "label": "ISO/IEC 42001 certified",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "hipaa_baa_available",
      "label": "HIPAA BAA available",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "dpf_certified",
      "label": "Data Privacy Framework certified",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "dpa_available",
      "label": "DPA offered",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "output_ip_ownership",
      "label": "Output IP ownership",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "copyright_indemnification",
      "label": "Output copyright indemnification",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "uptime_sla_pct",
      "label": "Uptime SLA",
      "domain": "ai_risk",
      "datatype": "number",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "sso_support",
      "label": "SSO (SAML/OIDC) support",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "absent",
      "note": "SSO is included on our first paid tier. The registry enum cannot yet express that, so we make no coded claim rather than assert a value that would misrepresent our posture in either direction.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "scim_provisioning",
      "label": "SCIM provisioning",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "audit_log_availability",
      "label": "Audit log availability",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "affirmed",
      "value": "in_product_only",
      "citation": {
        "source": "NobleCloak Security Overview",
        "url": "https://trust.noblecloak.com/policies/security-overview",
        "quote": "Every organization has access to the Execution Ledger, an org-scoped, customer-facing audit log viewable in-product and exportable as a CSV file."
      },
      "note": "Logs are viewable in-product (org-scoped Execution Ledger) and exportable as CSV. We render the conservative in_product_only rung rather than api_or_siem_export; whether the CSV export qualifies as the stronger tier is a call for the claim owner, not an inference from the code alone.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "third_party_pentest",
      "label": "Third-party penetration testing",
      "domain": "ai_risk",
      "datatype": "enum",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "bcdr_documented",
      "label": "BC/DR program documented",
      "domain": "ai_risk",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 365
    },
    {
      "attribute": "public_status_page",
      "label": "Public status page",
      "domain": "osint",
      "datatype": "boolean",
      "state": "absent",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 180
    },
    {
      "attribute": "last_security_incident_date",
      "label": "Most recent disclosed security incident",
      "domain": "osint",
      "datatype": "date",
      "state": "absent",
      "note": "This attribute is assert-true-only: a date appears here only when there is a disclosed security incident to report. Its absence means no such incident has been disclosed, not that we decline to answer.",
      "verifiedAt": "2026-07-27",
      "reverifyCadenceDays": 90
    }
  ]
}
