{
  "_about": "Release manifest for the Agentic Security Control Matrix dataset. Verify content_sha256 against agentic-controls-full.json (sha256 of the served file).",
  "version": "1.2",
  "dataset_as_of": "2026-06-25T02:04Z",
  "generated_at": "2026-06-28T04:07:14.224Z",
  "dataset": "agentic-controls-full.json",
  "schema": "agentic-controls.schema.json",
  "content_sha256": "c72f772674694c45e85738171d978fe6382b5eb40adc7a45506eb2b2aee9e5a8",
  "signature_alg": null,
  "signature": null,
  "signature_target": "content_sha256",
  "public_key_url": null,
  "signature_note": "Unsigned build. A signed release sets signature_alg=ed25519 and a base64 signature; provision APEIRIS_RELEASE_PRIVATE_KEY_PEM in CI to enable.",
  "counts": {
    "controls": 51,
    "sources": 75,
    "layers": 6,
    "gaps": 3,
    "profiles": 6,
    "vendor_features": 16,
    "vendors": 4
  },
  "warning_count": 70,
  "warnings": {
    "indicative_mappings": 55,
    "unverified_validation_entries": 15,
    "note": "Not errors: indicative = a mapping not yet confirmed against a primary source; unverified = a validation step with no primary source on hand yet. Both are honesty markers, surfaced so nothing reads as more settled than it is."
  },
  "files": [
    "agentic-controls-full.json",
    "agentic-controls.schema.json",
    "release-manifest.json",
    "INTEGRATION-GUIDE.md",
    "vendor-coverage.json",
    "vendor-coverage.csv",
    "sources.json"
  ],
  "license": "CC BY-NC 4.0; commercial use requires a written RiskOne license (aisecurity@risk.one)."
}