{
  "manifest": {
    "bundle_id": "illustrative-sample-soc2-0001",
    "catalogue_version": "illustrative",
    "content_digest": "5990e711543aba8c48b8801de926dfeb042a2e392f0c144625637ee8f316ee98",
    "cpa_boundary_disclaimer": "This bundle is runtime evidence for the deployer's SOC 2 examination. It is not a SOC 2 report, and Quantlix is not a CPA firm. Only a licensed CPA firm can attest under AICPA standards.",
    "evidence_scope_notice": "Demo model deployments (qx-example and related sample workspaces) are excluded from evidence exports and audit bundles by policy.",
    "format": "json",
    "framework": "soc2_tsc",
    "framework_scope_statement": "Scope: in-scope AI systems routed through the Quantlix gateway — evidence for the AI-runtime slice of a SOC 2 examination, not an organization-wide assessment.",
    "generated_at": "2026-08-01T12:00:00Z",
    "generated_by": {
      "email": "sample@quantlix.ai",
      "user_id": "illustrative"
    },
    "illustrative_notice": "ILLUSTRATIVE SAMPLE ONLY — synthetic structure for buyer and auditor review. Not exported from a live tenant. Rekor anchors omitted intentionally.",
    "integrity": {
      "anchors": [],
      "chain_id": "00000000-0000-0000-0000-000000000001",
      "head_hash": "illustrative-head-hash-not-real",
      "head_sequence": 42,
      "integrity_status": "illustrative",
      "last_anchor_sequence": 40
    },
    "policy_versions_in_force": [
      {
        "content_hash": "illustrative-policy-hash-not-real",
        "deployment_id": "dep-illustrative-hr-assistant",
        "model_id": "gpt-4o",
        "pack_revision": "gdpr-pack-v2",
        "policy_version": "3"
      }
    ],
    "provenance_disclaimer": "This bundle contains runtime evidence produced by Quantlix. It does not constitute a compliance assessment.",
    "scope": {
      "deployment_count": 1,
      "deployment_ids": [
        "dep-illustrative-hr-assistant"
      ],
      "org_id": "00000000-0000-0000-0000-000000000001",
      "org_name": "Illustrative Example Org (not a live tenant)",
      "period_end": "2026-07-31T23:59:59Z",
      "period_start": "2026-05-01T00:00:00Z"
    },
    "section_counts": {
      "action_evidence": 0,
      "attestations_history": 0,
      "attestations_summary": 4,
      "change_history": 1,
      "coverage": 1,
      "criterion_mapping": 9,
      "enforcement_records": 2,
      "policy_configuration": 1,
      "provider_activity": 2,
      "redaction_evidence": 1,
      "register_extract": 1
    }
  },
  "schema_version": "audit-bundle.v1",
  "sections": {
    "action_evidence": [],
    "action_evidence_empty_note": "No agent action events in period.",
    "attestations": {
      "catalogue_version": "illustrative",
      "history": [],
      "summary": [
        {
          "article": "TSC CC6.1–6.3",
          "attested_at": "2026-07-01T09:00:00Z",
          "attested_by_email": "secops@example.com",
          "label": "Logical access controls",
          "obligation_id": "soc2_cc6_logical_access",
          "owner": "Security / IT admin",
          "review_by": "2027-07-01",
          "scope_type": "organization",
          "status": "attested"
        },
        {
          "article": "TSC CC7.3–7.5",
          "label": "Incident management",
          "obligation_id": "soc2_cc7_incident",
          "owner": "Risk owner / ops lead",
          "scope_type": "organization",
          "status": "no_attestation_recorded"
        },
        {
          "article": "TSC CC3 / CC9",
          "label": "Risk assessment & vendor management",
          "obligation_id": "soc2_cc3_cc9_risk_vendor",
          "owner": "Risk owner",
          "scope_type": "organization",
          "status": "no_attestation_recorded"
        },
        {
          "article": "TSC A1",
          "attested_at": "2026-07-15T09:00:00Z",
          "attested_by_email": "ops@example.com",
          "label": "Availability",
          "obligation_id": "soc2_a1_availability",
          "owner": "Platform operator",
          "review_by": "2027-07-15",
          "scope_type": "organization",
          "status": "attested"
        }
      ]
    },
    "change_history": [
      {
        "action": "deployment.lifecycle.stopped",
        "deployment_id": "dep-illustrative-hr-assistant",
        "new_status": "stopped",
        "occurred_at": "2026-07-20T16:00:00Z",
        "performed_by": "user-illustrative-admin",
        "previous_status": "active",
        "reason": "scheduled maintenance window",
        "source": "platform_audit"
      }
    ],
    "coverage": {
      "gatewayed_deployment_count": 1,
      "illustrative": true,
      "summary": "Gatewayed systems in scope for this illustrative export."
    },
    "criterion_mapping": {
      "catalogue_version": "illustrative",
      "counts_basis": "Counts are evidence rows included in this bundle's sections. Enforcement-derived counts (decisions, blocked, approvals, redactions) are bounded by the bundle's enforcement-record row cap and can understate a high-volume period; run counts are full-period aggregates. Sample against the cited sections; use the evidence workspace for full-period enumeration.",
      "criteria": [
        {
          "attestation": {
            "attested_at": "2026-07-01T09:00:00Z",
            "attested_by_email": "secops@example.com",
            "review_by": "2027-07-01",
            "section": "attestations",
            "status": "attested"
          },
          "backing_sections": [],
          "criterion_id": "soc2_cc6_logical_access",
          "evidence_counts": {},
          "evidence_sources": [],
          "label": "Logical access controls",
          "owner": "Security / IT admin",
          "reference": "TSC CC6.1–6.3",
          "source_tag": "attested"
        },
        {
          "backing_sections": [
            "enforcement_records"
          ],
          "criterion_id": "soc2_cc6_boundary",
          "evidence_counts": {
            "blocked_events": 1
          },
          "evidence_sources": [
            "blocked_events"
          ],
          "label": "System boundaries & transmission",
          "owner": "Platform operator",
          "reference": "TSC CC6.6–6.7",
          "source_tag": "runtime"
        },
        {
          "backing_sections": [
            "enforcement_records",
            "policy_configuration"
          ],
          "criterion_id": "soc2_cc7_monitoring",
          "evidence_counts": {
            "enforcement_decisions": 2
          },
          "evidence_sources": [
            "enforcement_decisions"
          ],
          "label": "Monitoring & anomaly detection",
          "owner": "Platform operator",
          "reference": "TSC CC7.1–7.2",
          "source_tag": "runtime"
        },
        {
          "attestation": {
            "section": "attestations",
            "status": "no_attestation_recorded"
          },
          "backing_sections": [
            "enforcement_records"
          ],
          "criterion_id": "soc2_cc7_incident",
          "evidence_counts": {
            "blocked_events": 1
          },
          "evidence_sources": [
            "blocked_events"
          ],
          "label": "Incident management",
          "owner": "Risk owner / ops lead",
          "reference": "TSC CC7.3–7.5",
          "source_tag": "mixed"
        },
        {
          "backing_sections": [
            "enforcement_records",
            "policy_configuration"
          ],
          "criterion_id": "soc2_cc8_change_management",
          "evidence_counts": {
            "enforcement_decisions": 2
          },
          "evidence_sources": [
            "enforcement_decisions"
          ],
          "label": "Change management",
          "owner": "Platform operator",
          "reference": "TSC CC8.1",
          "source_tag": "runtime"
        },
        {
          "attestation": {
            "section": "attestations",
            "status": "no_attestation_recorded"
          },
          "backing_sections": [],
          "criterion_id": "soc2_cc3_cc9_risk_vendor",
          "evidence_counts": {},
          "evidence_sources": [],
          "label": "Risk assessment & vendor management",
          "owner": "Risk owner",
          "reference": "TSC CC3 / CC9",
          "source_tag": "attested"
        },
        {
          "attestation": {
            "attested_at": "2026-07-15T09:00:00Z",
            "attested_by_email": "ops@example.com",
            "review_by": "2027-07-15",
            "section": "attestations",
            "status": "attested"
          },
          "backing_sections": [
            "provider_activity"
          ],
          "criterion_id": "soc2_a1_availability",
          "evidence_counts": {
            "traces": 128
          },
          "evidence_sources": [
            "traces"
          ],
          "label": "Availability",
          "owner": "Platform operator",
          "reference": "TSC A1",
          "source_tag": "mixed"
        },
        {
          "backing_sections": [
            "enforcement_records",
            "policy_configuration"
          ],
          "criterion_id": "soc2_pi1_processing_integrity",
          "evidence_counts": {
            "approval_events": 0,
            "enforcement_decisions": 2
          },
          "evidence_sources": [
            "enforcement_decisions",
            "approval_events"
          ],
          "label": "Processing integrity (AI calls)",
          "owner": "Platform operator",
          "reference": "TSC PI1",
          "source_tag": "runtime"
        },
        {
          "backing_sections": [
            "redaction_evidence"
          ],
          "criterion_id": "soc2_c1_confidentiality",
          "evidence_counts": {
            "redaction_events": 1
          },
          "evidence_sources": [
            "redaction_events"
          ],
          "label": "Confidentiality",
          "owner": "Security / DPO",
          "reference": "TSC C1",
          "source_tag": "runtime"
        }
      ],
      "criteria_count": 9,
      "enforcement_rows_at_cap": false,
      "framework": "soc2_tsc",
      "out_of_scope": {
        "areas": [
          "HR and personnel controls",
          "endpoint management",
          "physical security",
          "business continuity and disaster-recovery programs",
          "organization-wide vendor management",
          "the Privacy category"
        ],
        "statement": "SOC 2 scopes an entire service organization. Quantlix is an evidence source for the AI-runtime slice; your readiness platform and auditor cover the rest."
      },
      "provenance_note": "This mapping cites which evidence sections in this bundle back which criteria. It is a projection of stored runtime evidence, not a control-effectiveness assessment.",
      "scope_statement": "Scope: in-scope AI systems routed through the Quantlix gateway — evidence for the AI-runtime slice of a SOC 2 examination, not an organization-wide assessment."
    },
    "enforcement_records": [
      {
        "action_taken": "allowed",
        "contextual_json": {
          "verdict": "allowed_with_redaction"
        },
        "deployment_id": "dep-illustrative-hr-assistant",
        "event_id": "evt-illustrative-001",
        "policy_version": "3",
        "request_id": "req-illustrative-001"
      },
      {
        "action_taken": "blocked",
        "contextual_json": {
          "reason_codes": [
            "policy_violation"
          ],
          "verdict": "blocked"
        },
        "deployment_id": "dep-illustrative-hr-assistant",
        "event_id": "evt-illustrative-002",
        "policy_version": "3",
        "request_id": "req-illustrative-002"
      }
    ],
    "enforcement_records_scope_note": "Evidence in this bundle covers gatewayed systems only — see Coverage.",
    "policy_configuration": [
      {
        "content_hash": "illustrative-policy-hash-not-real",
        "deployment_id": "dep-illustrative-hr-assistant",
        "detector_revision": "pii-detector-v1",
        "effective_at": "2026-04-15T09:00:00Z",
        "model_id": "gpt-4o",
        "pack": "gdpr",
        "pack_revision": "gdpr-pack-v2",
        "policy_version": "3"
      }
    ],
    "policy_configuration_scope_note": "Evidence in this bundle covers gatewayed systems only — see Coverage.",
    "provider_activity": [
      {
        "call_count": 128,
        "deployment_id": "dep-illustrative-hr-assistant",
        "model_id": "gpt-4o",
        "provider_id": "prov-openai",
        "provider_name": "openai",
        "record_kind": "run_attribution"
      },
      {
        "deployment_id": "dep-illustrative-hr-assistant",
        "failover_events": 1,
        "fallback_provider": "anthropic",
        "occurred_at": "2026-07-18T08:11:00Z",
        "primary_provider": "openai",
        "reason": "circuit_open",
        "record_kind": "provider_failover",
        "request_id": "req-illustrative-failover"
      }
    ],
    "redaction_evidence": [
      {
        "action": "redact",
        "created_at": "2026-07-12T14:22:01Z",
        "deployment_id": "dep-illustrative-hr-assistant",
        "detection_count": 2,
        "detection_types": [
          "email",
          "phone_number"
        ],
        "event_id": "evt-illustrative-001",
        "pack_revision": "gdpr-pack-v2",
        "policy_pack": "gdpr",
        "reason_codes": [
          "redaction_applied"
        ],
        "request_id": "req-illustrative-001",
        "source_side": "input"
      }
    ],
    "register_extract": {
      "deployments": [
        {
          "deployment_id": "dep-illustrative-hr-assistant",
          "name": "HR screening assistant (illustrative)",
          "risk_tier": "high"
        }
      ],
      "generated_at": "2026-08-01T12:00:00Z"
    }
  }
}
