{
  "bundle_id": "sovereign-defense-turnkey-v2",
  "bundle_type": "sovereign_defense_turnkey_evidence",
  "published_at": "2026-09-23T00:00:00Z",
  "system": "CAIN sovereign deployment self-check (Channel 12)",
  "status": "SELF_CHECK_TOOL_NO_ENGAGEMENTS",
  "what_exists": [
    "cain.sovereign self-check: measures the host's default routes and real outbound TCP reachability to fixed public targets; declared egress rules can only worsen the result.",
    "Local software root of trust: Ed25519 + ML-DSA-65 (FIPS 204 algorithm, via OpenSSL 3.5) keys stored 0600; evidence receipts carry both signatures.",
    "The CAIN VPS itself is NOT air-gapped and reports DEFICIENT (measured 2026-09-23)."
  ],
  "what_does_not_exist": [
    "No sovereign/defense engagement or deployment has taken place.",
    "No accreditation for classified systems; classification labels are free-text fields, not supported security levels.",
    "No hardware security module; no FIPS 140-3 validated module.",
    "No WORM/Merkle ledger in this module; no side-channel (acoustic/timing) defences."
  ],
  "statutory_defense_compliance": [
    {
      "framework": "NIST SP 800-218",
      "title": "Secure Software Development Framework (SSDF)",
      "conformity_status": "SELF_ASSESSED_NOT_AUDITED"
    },
    {
      "framework": "FIPS 140-3 Level 3",
      "title": "Security Requirements for Cryptographic Modules",
      "conformity_status": "NOT_VALIDATED",
      "note": "No CMVP-validated cryptographic module; no hardware security module."
    },
    {
      "framework": "Regulation (EU) 2024/1689 (EU AI Act)",
      "title": "High-Risk AI Systems Annex III (Critical Infrastructure & Public Order)",
      "conformity_status": "SELF_ASSESSED_NOT_AUDITED"
    }
  ],
  "supersedes": {
    "sha256": "4e308a105e306d600381682ee0a63f5fd17e5f3267dc3468c8514d5ce15b2a5d",
    "previous_status": "PRODUCTION_OPERATIONAL",
    "reason": "The previous version declared PRODUCTION_OPERATIONAL, support for SECRET/TOP_SECRET classification levels, coverage of acoustic/timing side-channel exfiltration, and benchmark counts (120 air-gap audits, 45 WAN-leak tests, 8,500 ops/s) with no source. The self-check it described certified any host as air-gapped unless the caller listed a WAN rule, so this internet-connected VPS certified itself."
  },
  "source_modules": [
    "cain/sovereign.py"
  ]
}
