{"version":"2026-08-26.1","product":"Secure Raven","generatedAt":"2026-09-13T15:31:18.994Z","claims":{"hipaaCertified":false,"connectingCreatesBaa":false,"soc2IndependentlyAudited":false,"externalPentestCompleted":false,"sitsInFrontOfSubscriberApi":false},"connectionModes":[{"id":"public_web","label":"Public website scan","credentialHeldBySecureRaven":"None","defaultFor":"web"},{"id":"push_probe","label":"Subscriber-hosted push probe","credentialHeldBySecureRaven":"Ingest token + HMAC only. No database credential.","defaultFor":"supabase recommended"},{"id":"restricted_role","label":"Restricted Postgres scanner role","credentialHeldBySecureRaven":"Dedicated login with no BYPASSRLS and no table DML","defaultFor":"direct Postgres when approved"},{"id":"privileged_api","label":"Privileged Supabase API mode","credentialHeldBySecureRaven":"service_role or sb_secret_ key","defaultFor":"optional, highest risk, off in production"},{"id":"shield_apply","label":"Shield apply","credentialHeldBySecureRaven":"None by default. Subscriber pastes digest-bound signed SQL.","defaultFor":"never implicit"}],"productionDefaults":{"privilegedConnections":false,"regulatedDataConnections":false,"remoteShieldApply":false,"ingestHmacRequired":true,"privilegedStepUpRequired":true,"shieldApplyOnScanCredential":false},"gates":[{"id":"A","name":"Safe beta","status":"code_complete","productionEnabled":false,"summary":"Public web scan and subscriber-hosted push probe. Privileged credentials stay off in production by default."},{"id":"B","name":"Restricted direct scan","status":"code_complete","productionEnabled":false,"summary":"Restricted scanner role and MFA/step-up exist in code. Independent SQL review is still required before calling this gate open."},{"id":"C","name":"Privileged Supabase API mode","status":"blocked","productionEnabled":false,"summary":"Blocked until an external pen test closes critical/high findings. Privileged mode is optional and off in production unless explicitly enabled."},{"id":"D","name":"Remote Shield apply","status":"blocked","productionEnabled":false,"summary":"Default apply is subscriber-executed signed SQL. REMOTE_SHIELD_APPLY_ENABLED stays off."},{"id":"E","name":"Regulated data","status":"blocked","productionEnabled":false,"summary":"REGULATED_DATA_CONNECTIONS_ENABLED stays off until BAA, subprocessors, and counsel approve HIPAA operational scope. A signed BAA is not a certification."}],"retention":{"eventsDays":90,"findingsResolvedDays":730,"agentRunsDays":365,"auditLogNeverDeleted":true},"encryption":{"credentialEnvelope":"AES-256-GCM envelope v3 bound to tenant, source, kind, and format","productionKek":"External KMS wrap/unwrap. Local KEK is refused in production unless ENVELOPE_ALLOW_LOCAL_KEK is explicitly set."},"pentest":{"status":"not_commissioned","lastCompleted":null,"scope":"/docs/PENTEST_SCOPE.md"},"soc2":{"independentlyAudited":false,"reportType":null,"note":"A control map exists. Secure Raven is not independently audited for SOC 2 Type I or Type II."},"slos":[{"id":"credential.unwrap_success","description":"Authorized broker unwraps of live, non-erased envelopes","target":"99.9% excluding revoked or disconnected sources","measuredInProduct":false},{"id":"credential.time_to_revoke","description":"Disconnect to claim/unwrap refusal","target":"Next claim cycle; queued jobs skipped","measuredInProduct":false},{"id":"scan.isolation","description":"Scan grants never include shield.apply","target":"100% of planned and claimed runs","measuredInProduct":false},{"id":"ingest.hmac_rejection","description":"Unsigned or tampered ingest rejected when HMAC is required","target":"100% of fail-closed production traffic","measuredInProduct":false},{"id":"shield.rollback_time","description":"Time to stop remote apply and keep subscriber SQL as the path","target":"Flag off immediately; no global remote apply","measuredInProduct":false}],"scanForbiddenCapabilities":["shield.apply"],"links":{"trust":"/trust","manifest":"/api/trust/manifest","subprocessors":"/trust#subprocessors","disclosureEmail":"security@secureraven.com"}}