Skip to main content

Trust Center

samaydlette.com

This system is built to adhere to the FedRAMP 20x Class C Certification requirements at the Moderate impact level. It is a self-attested proof of concept: it is not FedRAMP Certified, has no agency sponsor, and has not been assessed by a third party.

The page is written from the seat of an Authorizing Official: the person at an agency who would decide whether to rely on a system like this one. You are probably not one, and no agency has been asked to rely on this system; if you are an AO, welcome. Either way, the sections below walk through the questions an AO would ask, in the order they would ask them, so you can judge the answers for yourself.

Loading the trust center…

1 Is this picture true?

Every check below ran during the deploy that published this page, against the artifacts it published. A check that could not run says so; it is never shown as passing.

    2 What is waiting on a decision?

    The automation settles what recorded policy already covers. Only what it cannot settle waits here for the Authorizing Official; for this system that is the operator, acting as AO.

    3 Where am I exposed?

    Nothing on the map is drawn by hand. Select a flow to trace it, or any component for its classification, findings and the flows through it.

    Text view of the map: components, data flows, leveraged services and FIPS modules

    The reasoning behind the boundary (what is in, what is out, and why) is on the authorization boundary page.

    4 How are decisions made here?

    Every automated decision falls under one of four kinds of policy. Knowing which is which tells you what a person can change, and how.

    5 What was decided, by whom, and why?

    Every human decision the automation now applies as precedent. Each records who made it, when, why, and when it is next reviewed; a field that was not recorded is shown as a gap, never filled in.

    6 Posture

    7 Verify it yourself

    Nothing on this page asks to be trusted. Each document it renders is signed by the deploy workflow through Sigstore; check any of them with cosign:

    BASE=https://samaydlette.com/.well-known
    curl -sO $BASE/trust-center.json -sO $BASE/trust-center.bundle
    cosign verify-blob trust-center.json --bundle trust-center.bundle \
      --certificate-oidc-issuer https://token.actions.githubusercontent.com \
      --certificate-identity \
      https://github.com/sam-aydlette/samaydlette.com/.github/workflows/deploy-with-opa.yml@refs/heads/main

    The same command verifies every JSON artifact below except the runtime signal, each from the .bundle beside it. verify-published.sh checks them all, including that each is bound to the same inventory.