{
  "accessibility": {
    "assessment_status": "automated_policy_checks_only",
    "known_limitations": [
      "A complete published manual test matrix for screen readers, keyboard-only use, reflow at 200 percent, and supported platforms is not yet available.",
      "Caption, transcript, and audio-alternative coverage can vary by content and release and is not yet represented by a complete public inventory.",
      "Linked third-party learning resources are outside the project's direct accessibility control."
    ],
    "last_independent_assessment_at": null,
    "page": "/accessibility.html",
    "scope": [
      "Public Adaptive Tutor website",
      "Adaptive Tutor learning app",
      "LexiSphere browser client"
    ],
    "statement_status": "published_engineering_statement_not_independently_assessed",
    "target_standard": "WCAG 2.2 Level AA"
  },
  "incident_history": {
    "coverage_started_at": null,
    "coverage_status": "unavailable",
    "empty_state": "No reviewed public incident history is available. The empty incident list is not a claim that no incidents occurred.",
    "incidents": [],
    "last_reviewed_at": null
  },
  "publication": {
    "published_at": "2026-08-16T04:00:00Z",
    "review_due_at": "2026-09-15T04:00:00Z",
    "review_scope": "Checked-in routes, policies, and release trust identities only; not live provider state, uptime, incident completeness, legal approval, or accessibility certification.",
    "reviewed_at": "2026-08-16T04:00:00Z",
    "reviewer_role": "repository_maintainer",
    "stale_behavior": "show_unavailable_without_preserving_a_positive_status",
    "status": "repository_facts_reviewed_external_evidence_unavailable"
  },
  "record_id": "adaptive-tutor-public-operations",
  "record_version": "2026-08-16.2",
  "release_verification": {
    "active_key_id": "7f04cee04f03ed44c82f00eb246db4186eb2e80dd4f2147bc3ae2c1045778d2d",
    "algorithm": "ed25519",
    "browser_manifest": "/website-build.json",
    "browser_manifest_assurance": "checksums_only_not_a_signature_verification",
    "checksum_algorithm": "sha256",
    "checksum_filename": "SHA256SUMS",
    "domain": "adaptive-learning-release-bundle-v1",
    "local_verifier": "scripts/public_transparency.py verify-release",
    "page": "/source.html#verify-release",
    "provider": "adaptive_learning_ed25519",
    "repository": "Adaptive-Learning-AI-Company/Adaptive-Learning",
    "signer_identity_pattern": "https://github.com/Adaptive-Learning-AI-Company/Adaptive-Learning/.github/workflows/signed-release.yml@refs/tags/v{version}",
    "signer_workflow": "Adaptive-Learning-AI-Company/Adaptive-Learning/.github/workflows/signed-release.yml",
    "status": "available_when_a_published_release_bundle_is_downloaded",
    "trust_metadata": "/release-trust.json"
  },
  "schema_version": 1,
  "security": {
    "contact": "mailto:admin@adaptivetutor.ai?subject=PRIVATE%20SECURITY%20REPORT",
    "external_review_status": "not_asserted",
    "page": "/security.html",
    "private_reporting_required": true,
    "public_key_status": "not_published",
    "security_txt": "/.well-known/security.txt"
  },
  "service_status": {
    "components": [
      {
        "detail": "A browser check can confirm that the Adaptive Tutor server answered one basic request.",
        "id": "api_process",
        "last_observed_at": null,
        "name": "App server",
        "probe_path": "/livez",
        "state": "unavailable_until_checked"
      },
      {
        "detail": "A browser check can report whether the services required by Adaptive Tutor are ready.",
        "id": "required_dependencies",
        "last_observed_at": null,
        "name": "Required services",
        "probe_path": "/readyz",
        "state": "unavailable_until_checked"
      }
    ],
    "limitations": [
      "A successful browser probe is a point-in-time observation, not historical uptime or an SLA measurement.",
      "A failed probe can reflect the service, the network, browser policy, or missing release configuration.",
      "No tracker, hosted analytics script, or background cross-origin monitor runs on the public status page."
    ],
    "observation_mode": "user_initiated_browser_probe",
    "summary_state": "unavailable_until_checked"
  },
  "source_and_license": {
    "corresponding_source": {
      "archive_kind": "agpl_corresponding_source",
      "backend_archive": "/api/v1/source/archive",
      "backend_independent_deployment_binding": true,
      "backend_manifest": "/api/v1/source/manifest",
      "backend_revision_binding": "source_commit",
      "browser_manifest": "/website-build.json",
      "delivery": "same_origin_network_server_at_no_charge",
      "git_history_included": false,
      "lexisphere_revision_binding": "source_offer.lexisphere_source_commit",
      "path_template": "/source/Adaptive-Tutor-Source-{root_source_commit}.tar.gz",
      "root_revision_binding": "source_offer.root_source_commit",
      "source_and_build_files_included": true,
      "status": "release_bound_same_origin_archive",
      "untracked_files_included": false
    },
    "license": "AGPL-3.0-only",
    "license_text": "/LICENSE.txt",
    "page": "/source.html",
    "public_repository_access": false,
    "repository_visibility": "private",
    "sbom": "/sbom.cdx.json",
    "third_party_notices": "/THIRD_PARTY_NOTICES.txt"
  },
  "subprocessors": {
    "inventory_status": "candidate_inventory_not_verified_as_current_production_configuration",
    "notice": "The listed providers are the candidate service inventory. Contracting entities, enabled routes, account settings, regions, retention, and transfer terms remain unverified; a row is not an approval or a claim that the provider currently receives learner data.",
    "policy_candidate_date": "2026-09-01",
    "policy_inventory_status": "requires_contract_inventory_region_validation_and_counsel_approval",
    "policy_publication_status": "draft_pending_configuration_and_counsel",
    "policy_version": "2026-09-01.1",
    "providers": [
      {
        "contract_basis": "DPA, security terms, deletion terms, and transfer mechanism must be recorded",
        "data": "Account, learning, security, support, and billing metadata processed by the backend; ordinary public web request metadata and source-derived browser assets processed by the separate Static Site",
        "location": "Backend deployment region and Static Site/CDN processing locations must be recorded from the Adaptive Learning Render configuration",
        "provider": "Render (exact contracting legal entity must be verified for the Adaptive Learning account only)",
        "purpose": "Backend application, managed database, public Static Site, CDN delivery, and related infrastructure",
        "status": "requires_adaptive_learning_render_account_contract_and_region_verification"
      },
      {
        "contract_basis": "Service terms, DPA applicability, security and cache/log retention settings, subprocessors, and transfer mechanism must be recorded",
        "data": "Public DNS records and ordinary public web request, connection, security, and cache metadata; the API remains DNS-only pending a separate ingress review",
        "location": "Authoritative DNS and edge processing locations, logs, and account settings must be recorded",
        "provider": "Cloudflare (exact contracting legal entity must be verified)",
        "purpose": "Authoritative DNS, DNSSEC, TLS edge, denial-of-service protection, and optional proxy/cache for public site records",
        "status": "requires_contract_account_zone_and_region_verification"
      },
      {
        "contract_basis": "Registrar/mail/hosting terms, DPA applicability, log retention, deletion after migration, and transfer mechanism must be recorded",
        "data": "Domain registration/contact data, email content and delivery metadata, and ordinary request metadata only while the retained rollback host remains reachable",
        "location": "Registrar, mail, and temporary rollback-host processing and log locations must be recorded",
        "provider": "IONOS (exact contracting legal entity must be verified)",
        "purpose": "Domain registration and transactional email; temporary static-host rollback during the migration observation window",
        "status": "requires_contract_and_region_verification"
      },
      {
        "contract_basis": "Controller/processor roles, DPA, consumer terms, and transfer mechanism must be approved",
        "data": "Purchaser identity and contact details, payment details handled by Stripe, and subscription metadata",
        "location": "Processing and transfer locations must be confirmed from the applicable Stripe agreement",
        "provider": "Stripe (exact contracting legal entity must be verified)",
        "purpose": "Planned checkout, subscription, payment, invoice, refund, and billing portal processing; Stripe checkout is not active in the current release",
        "status": "requires_contract_role_and_region_verification"
      },
      {
        "contract_basis": "Education use, DPA, zero-retention or eligible retention controls, and transfer mechanism must be approved",
        "data": "Prompt, lesson context, learner response, safety context, transient microphone audio for transcription, resulting transcript, and limited request metadata selected by the product flow; Adaptive Tutor does not intentionally retain the raw audio",
        "location": "Account project, Responses and Realtime API surfaces, model, region options, retention controls, and training settings must be recorded",
        "provider": "OpenAI (only when the hosted OpenAI route or a user's selected provider route is enabled)",
        "purpose": "Generate optional AI tutoring responses and safety-related output, and transcribe an explicitly requested realtime voice input",
        "status": "requires_account_configuration_contract_and_data_control_verification"
      },
      {
        "contract_basis": "Applicable cloud or API terms, DPA, education eligibility, and transfer mechanism must be approved",
        "data": "Prompt, lesson context, learner response, safety context, and limited request metadata selected by the product flow",
        "location": "Project, API surface, model, location, logging, retention, and training settings must be recorded",
        "provider": "Google Gemini / Google Cloud (only for a grandfathered text-model route)",
        "purpose": "Generate optional text-based AI tutoring responses and safety-related output for a retained legacy selection; not speech transcription",
        "status": "requires_account_configuration_contract_and_data_control_verification"
      },
      {
        "contract_basis": "Provider terms, DPA, retention, subprocessor, and transfer terms must be approved",
        "data": "Recipient address, message subject/body, delivery status, and limited account context",
        "location": "Actual provider, sending region, and log locations are not yet recorded",
        "provider": "Deployment-specific transactional email provider",
        "purpose": "Password recovery, account notices, safety/support messages, and billing communications",
        "status": "requires_real_provider_configuration_and_contract_verification"
      }
    ],
    "source": "config/legal/policy-source.json"
  },
  "support": {
    "attachments_allowed": false,
    "automatic_diagnostics_collected": false,
    "categories": [
      "account_access",
      "billing",
      "privacy_or_learner_records",
      "product_defect",
      "general_support",
      "accessibility"
    ],
    "category_transport": "allowlisted_prefix_inside_message",
    "email": "admin@adaptivetutor.ai",
    "endpoint": "/request-help",
    "page": "/support.html",
    "retention_status": "pending_accountable_owner_and_counsel_approval",
    "status": "public_intake_configured_staffing_evidence_not_public",
    "submitted_fields": [
      "name",
      "email",
      "message"
    ],
    "warning": "Do not submit passwords, tokens, provider keys, payment-card data, exploit details, or unnecessary learner records."
  }
}
