[doc] trust · sha:7292d14c1aa3 · build:2026-08-18T00:08:45.256Z

Trust Center.

Selected company identity, public release, and product-boundary claims resolve to frozen authority artifacts. This page consolidates the attestation surfaces in one place. What is not yet provable is labeled pending — the absence is part of the record, not hidden from it.

Centennial Defense Systems, Inc. of Colorado Springs builds audit-first software and is not affiliated with the unrelated firearms-parts retailer operating at centennialdefensesystems.com.

Release manifest

live

Per-release public package versions, licenses, and observed source SHAs are fetched from PyPI and GitHub at build time with no stale fallback.

/receipts

Machine-readable attestation

live

The same data in a structured, machine-readable manifest under an immutable schema version (cds-attestation-v1).

/manifest.json

Build provenance

live

The public receipts page and manifest expose the deployment commit SHA and build timestamp. They attest to this site and its observed package data, not private runtime state.

inspect receipts

Data-handling boundary

live

Local processing is stated per product. Archivist's core archive workflows run locally; purchase, support, and website traffic use standard external services. This public site uses no analytics, trackers, or chat widgets.

security policy

Vulnerability disclosure

live

A published security policy and disclosure contact.

/.well-known/security.txt

Software bill of materials (SBOM)

pending

Per-release CycloneDX SBOM with every dependency declared by version, license, and provenance, included in the evidence package. Planned; not yet published.

Signed provenance

pending

Signed release tags and a build attestation tying source commit → build environment → artifact → deployed site into one cryptographically closed chain. In progress; not yet closed end-to-end. Python packages are currently published via Twine, not Trusted Publishing.

Independent review

pending

External technical review or customer validation, distinct from self-issued QA. Not yet published — internal QA receipts are not a substitute.

/receipts carries the authoritative per-release record · back to home