{
  "name": "City of Hats procurement evidence pack",
  "version": "1.0",
  "reviewed": "2026-08-10",
  "canonical_url": "https://cityofhats.com/procurement/",
  "disclaimer": "These machine-readable files are designed for due diligence and internal review. They do not constitute a certification, warranty, completed customer questionnaire, or legal opinion.",
  "evidence_snapshot": [
    {
      "label": "Public Security Evidence Center",
      "state": "available",
      "status": "Available",
      "detail": "Claims, boundaries, architecture, limitations, and verification dates."
    },
    {
      "label": "Responsible disclosure and security.txt",
      "state": "available",
      "status": "Available",
      "detail": "A published reporting route for security researchers."
    },
    {
      "label": "Public cryptographic architecture description",
      "state": "available",
      "status": "Available",
      "detail": "Algorithm and data-boundary claims are documented as first-party technical material."
    },
    {
      "label": "Independent cryptographic audit",
      "state": "not",
      "status": "Not published",
      "detail": "Do not treat internal review or documentation as an independent audit."
    },
    {
      "label": "Public penetration-test report",
      "state": "not",
      "status": "Not published",
      "detail": "A buyer should request current private evidence if required for procurement."
    },
    {
      "label": "Public customer case studies",
      "state": "not",
      "status": "Not published",
      "detail": "No customer names, outcomes, or metrics are invented for this page."
    },
    {
      "label": "Formal compliance certifications",
      "state": "not",
      "status": "Not claimed here",
      "detail": "Certification and legal applicability require scoped, current evidence."
    }
  ],
  "buyer_questions": [
    {
      "area": "Architecture",
      "question": "Where does plaintext exist, and which components can access message keys?",
      "answer": "City of Hats documents plaintext at authorized endpoints and describes the delivery service as handling ciphertext. Buyers should validate this against current implementation evidence."
    },
    {
      "area": "Identity",
      "question": "Are phone numbers, emails, address books, or recovery identities required?",
      "answer": "Creating a Hat does not require a phone number or email. Optional workflows and business services may have separate data requirements that must be reviewed."
    },
    {
      "area": "Cryptography",
      "question": "Which algorithms and protocol versions protect messages and calls?",
      "answer": "Current first-party documentation describes X25519 plus ML-KEM-768 hybrid key agreement, Double Ratchet-style key evolution, and AES-256-GCM. Independent verification status must be evaluated separately."
    },
    {
      "area": "Metadata",
      "question": "Which routing, timing, abuse-prevention, device, and account records remain outside message encryption?",
      "answer": "The Security Evidence Center states boundaries and limitations. Encryption does not eliminate all operational metadata."
    },
    {
      "area": "Retention",
      "question": "What is retained, for how long, and what does deletion actually guarantee?",
      "answer": "Retention depends on feature lifecycle and endpoint behavior. Buyers should distinguish server deletion, endpoint deletion, backups, screenshots, and recipient copies."
    },
    {
      "area": "Access",
      "question": "How are privileged access, deployment duties, and support operations controlled and logged?",
      "answer": "Public material does not currently provide a complete independent control assessment. Request current operational evidence where this matters."
    },
    {
      "area": "Assurance",
      "question": "Which claims have been independently tested, and what evidence can be shared under NDA?",
      "answer": "No independent cryptographic audit or public penetration-test report is currently published. This limitation is explicit."
    },
    {
      "area": "Resilience",
      "question": "What happens during service outage, device loss, key loss, or regional blocking?",
      "answer": "No secure service guarantees availability. Organizations need fallback communications and recovery procedures that match the no-recovery design."
    },
    {
      "area": "Legal",
      "question": "Which contract, privacy, residency, and regulatory commitments apply to this deployment?",
      "answer": "Public pages are not a substitute for a scoped contract, data-processing review, or legal advice."
    },
    {
      "area": "Change control",
      "question": "How are security-relevant changes disclosed and dated?",
      "answer": "The public Website Changelog records trust, research, and website changes. Product-release evidence should be requested separately."
    }
  ],
  "references": {
    "security_evidence": "https://cityofhats.com/security-evidence/",
    "responsible_disclosure": "https://cityofhats.com/.well-known/security.txt",
    "threat_model_advisor": "https://cityofhats.com/threat-model-advisor/",
    "website_changelog": "https://cityofhats.com/changelog/"
  }
}
