{
  "schema_version": "1.0",
  "package_name": "codecr Automated Security Questionnaire / RFP Package",
  "package_status": "evidence-gated template",
  "product": "codecr enterprise AI code control plane",
  "purpose": "Structured intake for vendor security assessment, RFP review, data-processing terms, and deployment-specific evidence requests.",
  "claim_control": {
    "verified_evidence_attached": false,
    "publication_rule": "Do not represent a framework, attestation, certification, authorization, SLA, or benchmark as achieved until the named evidence object is attached, current, in scope, and approved for disclosure.",
    "customer_specific_terms_required": true
  },
  "compliance_status": [
    {
      "framework": "SOC 2 Type II",
      "status": "evidence_required",
      "required_objects": [
        "independent auditor report",
        "system and service scope",
        "review period",
        "exceptions and management response"
      ]
    },
    {
      "framework": "ISO/IEC 27001",
      "status": "certificate_required",
      "required_objects": [
        "certificate number",
        "certification body",
        "validity dates",
        "statement of applicability",
        "organizational and service scope"
      ]
    },
    {
      "framework": "HIPAA DPA / BAA",
      "status": "execution_required",
      "required_objects": [
        "data processing agreement",
        "Business Associate Agreement where applicable",
        "approved PHI workload configuration",
        "subprocessor and breach-notification terms"
      ]
    },
    {
      "framework": "FedRAMP Moderate Readiness",
      "status": "target_mapping_only",
      "required_objects": [
        "system boundary",
        "Moderate control mapping",
        "readiness assessment evidence",
        "agency sponsorship or applicable program evidence",
        "current Marketplace designation if one exists"
      ],
      "disclaimer": "No FedRAMP designation, certification, authorization, or government approval is asserted by this template."
    }
  ],
  "questionnaire": [
    {
      "id": "ARCH-001",
      "domain": "Architecture and data flow",
      "question": "Which source, prompt, model, telemetry, and evidence objects cross the selected deployment boundary?",
      "response_status": "deployment_specific",
      "evidence_requested": "approved data-flow diagram and control-responsibility matrix"
    },
    {
      "id": "DATA-001",
      "domain": "Retention and model use",
      "question": "What source content is retained, for how long, in which stores, and for what model-training purpose?",
      "response_status": "contract_required",
      "evidence_requested": "retention schedule, logging exclusions, backup scope, and model-use terms"
    },
    {
      "id": "IAM-001",
      "domain": "Identity and access",
      "question": "How are workforce, workload, repository, support, and emergency identities authenticated and reviewed?",
      "response_status": "evidence_required",
      "evidence_requested": "identity architecture, role matrix, access-review record, and break-glass procedure"
    },
    {
      "id": "CRYPTO-001",
      "domain": "Encryption and key management",
      "question": "Who controls encryption keys, rotation policy, revocation, and recovery for each deployment model?",
      "response_status": "deployment_specific",
      "evidence_requested": "KMS or HSM design, key ownership, rotation evidence, and recovery procedure"
    },
    {
      "id": "SDLC-001",
      "domain": "Secure development",
      "question": "Which controls govern code review, dependency risk, vulnerability remediation, release signing, and production promotion?",
      "response_status": "evidence_required",
      "evidence_requested": "secure SDLC policy, test evidence, release controls, and remediation SLA"
    },
    {
      "id": "IR-001",
      "domain": "Incident response",
      "question": "How are security events detected, triaged, contained, communicated, and preserved for customer review?",
      "response_status": "contract_required",
      "evidence_requested": "incident response plan, notification terms, exercise record, and escalation matrix"
    },
    {
      "id": "BCP-001",
      "domain": "Resilience",
      "question": "What availability, recovery, backup, and regional-failure commitments apply to the selected architecture?",
      "response_status": "contract_required",
      "evidence_requested": "SLA, RTO and RPO schedule, recovery test, and production performance report"
    },
    {
      "id": "TPRM-001",
      "domain": "Subprocessors and supply chain",
      "question": "Which subprocessors, model providers, infrastructure providers, and software dependencies can affect the customer boundary?",
      "response_status": "deployment_specific",
      "evidence_requested": "subprocessor schedule, software bill of materials, dependency policy, and change-notice terms"
    }
  ],
  "rfp_response_fields": {
    "customer_organization": "",
    "deployment_model": "Dedicated Cloud | VPC Peering | Air-Gapped / On-Prem",
    "data_regions": [],
    "regulated_data_types": [],
    "required_frameworks": [],
    "required_contracts": [],
    "evidence_deadline": "",
    "security_owner": "",
    "procurement_owner": "",
    "exceptions": []
  },
  "usage_notice": "This package is a structured diligence template, not a completed security assessment. All responses, evidence references, dates, scopes, and legal terms must be completed and approved by authorized representatives before external reliance."
}
