{
  "schemaVersion": 1,
  "fedRampPackageId": "FR2628650874",
  "offering": "Tarly Cowork",
  "publicSharingDecision": {
    "decision": "Share selected desensitized certification materials publicly; keep detailed or sensitive package materials in controlled access.",
    "adverseEffectAssessment": "The listed public artifacts are limited to offering identity and scope, secure-use guidance, high-level control status, availability, and desensitized recurring reports. Publishing that subset is not expected to enable unauthorized access, operational disruption, or other adverse effect.",
    "publiclyShare": [
      "Certification Package Overview and service-scope summary",
      "Secure Configuration Guide",
      "Desensitized KSI status and availability reports",
      "Desensitized Ongoing Certification Reports after certification"
    ],
    "keepControlled": [
      "Credentials, tokens, keys, and recovery material",
      "Federal customer data, agency identities, and personal information",
      "Internal resource identifiers, detailed network paths, raw logs, and scanner payloads",
      "Exploit-enabling vulnerability detail and unredacted findings",
      "Detailed Security Decision Record evidence, independent assessments, and unmodified FedRAMP Certification Reports"
    ],
    "reviewOwner": "FedRAMP Program Owner",
    "reviewedAt": "2026-08-14",
    "reReviewedAt": "2026-08-26",
    "reReviewedFor": "Publication of the gated Significant Change Notices page (public page shell; all rendered records remain in the entitlement-gated controlled bundle).",
    "reviewTriggers": [
      "Before a new certification artifact type is made public",
      "Material boundary or service-scope change",
      "Significant change or reportable incident",
      "Quarterly certification-data review"
    ]
  },
  "publicArtifacts": [
    {
      "name": "Certification Package Overview",
      "humanReadableUrl": "https://gov.tarly.co/trust/",
      "machineReadableUrl": "https://gov.tarly.co/trust/fedramp.json",
      "authenticationRequired": false
    },
    {
      "name": "Key Security Indicator status",
      "humanReadableUrl": "https://github.com/patrick-tarly-co/trust-center/blob/main/KSI-STATUS.md",
      "machineReadableUrl": "https://raw.githubusercontent.com/patrick-tarly-co/trust-center/main/ksi-results.json",
      "authenticationRequired": false
    },
    {
      "name": "Service availability",
      "humanReadableUrl": "https://github.com/patrick-tarly-co/trust-center/blob/main/STATUS.md",
      "machineReadableUrl": "https://raw.githubusercontent.com/patrick-tarly-co/trust-center/main/status.json",
      "authenticationRequired": false
    },
    {
      "name": "Secure Configuration Guide",
      "humanReadableUrl": "https://gov.tarly.co/trust/secure-configuration-guide.html",
      "machineReadableUrl": "https://gov.tarly.co/trust/secure-configuration-guide.json",
      "authenticationRequired": false
    },
    {
      "name": "Quarterly Review meeting information",
      "humanReadableUrl": "https://gov.tarly.co/trust/#quarterly-review",
      "machineReadableUrl": "https://gov.tarly.co/trust/quarterly-review-2026-q4.ics",
      "authenticationRequired": false
    }
  ],
  "controlledArtifacts": {
    "artifacts": [
      "Security Decision Record and evidence manifests",
      "Policy and procedure index in human-readable Markdown and machine-readable JSON",
      "Complete policy/procedure documents and rule/KSI supporting packages with their retained evidence dates",
      "Ongoing Certification Reports and snapshots",
      "Vulnerability Detail and Historical VER reports",
      "Significant Change Notifications and audit history",
      "Initial, Ongoing, and Final Incident Reports for FedRAMP Reportable Incidents",
      "Independent assessment and FedRAMP Certification Reports"
    ],
    "requestUrl": "mailto:security@tarly.co?subject=Tarly%20Cowork%20FedRAMP%20Certification%20Data%20access",
    "requestDecision": {
      "owner": "FedRAMP Program Owner",
      "presumption": "Approve verified agency requests for the Tarly Cowork FedRAMP Certification Package.",
      "approvalCriteria": [
        "The requester is acting for a government agency or its authorized assessor.",
        "The request concerns package FR2628650874 and supports an authorization, assessment, oversight, or procurement decision.",
        "The requester accepts the handling restrictions and time-limited authenticated HTTPS delivery method."
      ],
      "denialCriteria": [
        "Identity or agency affiliation cannot be verified.",
        "The requested material is unrelated to the Tarly Cowork package or stated official purpose.",
        "Delivery would violate law, contract, FedRAMP direction, or another agency's confidentiality; Tarly offers a safe subset when possible."
      ],
      "targetResponseBusinessDays": 5,
      "denialNoticeForm": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51829826617243"
    },
    "deliveryMechanism": "Time-limited authenticated HTTPS bundle containing human-readable files, JSON artifacts, SHA-256 manifest, and signature verification metadata; Tarly retains the delivery and expiration timestamps, bundle receipt, and manifest SHA-256.",
    "supportedAutomation": "Authorized agency systems may retrieve every file directly with standard HTTPS using the supplied time-limited credentials; filenames, media types, hashes, and schema identifiers are included in manifest.json.",
    "programmaticInterface": {
      "status": "available",
      "authenticationRequired": true,
      "authentication": "Trust Center access token issued after identity verification and approval.",
      "documentationUrl": "https://gov.tarly.co/trust/package.html#programmatic-access",
      "documentationAuthenticationRequired": true,
      "summary": "Sign in to the certification package to view API instructions, manifest verification guidance, and token-management options.",
      "browserAccess": {
        "url": "https://gov.tarly.co/trust/package.html",
        "description": "Sign in with your issued Trust Center token to browse and download certification documents, the full package ZIP, and its signed manifest.",
        "significantChangesUrl": "https://gov.tarly.co/trust/significant-changes.html"
      }
    },
    "denialNotification": "If an agency request is denied, Tarly records the reason, notifies FedRAMP through the [CSP] Agency Access Denial form within five business days, and retains the submission receipt.",
    "selfServiceManagement": {
      "status": "available",
      "authenticationRequired": true,
      "summary": "Approved reviewers can use the authenticated API to view their entitlement and rotate or revoke their token. Instructions are available after signing in. Repeated retrievals require no further approval until expiry or revocation.",
      "instructionsUrl": "https://gov.tarly.co/trust/package.html#programmatic-access"
    }
  },
  "incidentReporting": {
    "status": "implemented; no real reportable incident or real report has occurred",
    "requiredRoutes": {
      "fedRamp": "Email fedramp_security@fedramp.gov",
      "affectedAgencies": "Follow each affected agency's verified agency-specific incident reporting procedure",
      "allNecessaryParties": "Publish an update through the entitlement-gated controlled certification-data channel"
    },
    "controlledManifestCategory": "incident-reports",
    "artifactFormat": "Exact validated human-readable Markdown and official-schema JSON report pair",
    "verification": "The signed bundle is published generation-first, pointer-last; the operator verifies the served report SHA-256 and reconciles a digest-bound delivery result for every required recipient.",
    "procedure": "compliance/docs/incident-reporting-procedure.md"
  },
  "accessLogging": {
    "public": "Azure Front Door logs gov.tarly.co Trust Center retrievals in the central security workspace. Reads of the independent GitHub trust repository are summarized through GitHub repository traffic statistics captured on a recurring schedule; a failed capture is recorded as an explicit coverage gap.",
    "controlled": "Every controlled-bundle retrieval attempt (served or denied) is appended to an immutable retrieval log recording party, timestamp, artifact, served SHA-256, manifest SHA-256, and result; the log is retained beyond 180 days in the database and the Locked 400-day evidence archive.",
    "summaryRetentionDays": 365
  }
}
