{
  "payload": {
    "tool": "Bastion",
    "version": "3.2",
    "attestationVersion": 1,
    "assessedAt": "2026-09-13T18:08:17.712Z",
    "host": "audioprism.pro",
    "profile": "saas",
    "depth": "Adversarial",
    "mode": "public-verified",
    "highRiskMode": false,
    "posture": {
      "grade": "STRONG",
      "score": 85,
      "conclusive": true
    },
    "findings": {
      "critical": 0,
      "high": 0,
      "medium": 1,
      "low": 3,
      "info": 3,
      "catastrophic": 0,
      "immediate": 0
    },
    "evidence": {
      "verifiedLiveHttp": 7,
      "manualReview": 0
    },
    "riskByFunction": [
      {
        "dimension": "reputational",
        "level": 2
      },
      {
        "dimension": "customer_data",
        "level": 1
      }
    ],
    "gate": {
      "passed": true,
      "violations": [],
      "policy": {
        "min_score": 70,
        "max_catastrophic": 0,
        "max_critical": 0,
        "max_high": 3,
        "fail_on_immediate": true,
        "fail_on_unresolved_manual": false,
        "_comment": "Pass/fail gate thresholds. Used by `bastion gate` for CI / release gating. Tune per asset risk."
      }
    },
    "methodology": "external read-only assessment; no exploitation; manual-review items not auto-proven"
  },
  "hash": "39b205fb9c4f3215f2779943ec7f8889e440ffc605c26e08e65dfac04d195702",
  "signature": {
    "alg": "Ed25519",
    "sig": "N1ouO4+/9lutzSO0IrC/SFvrz6ghuCWtwgl31w73Uul+4pAcK36ysaRJ0G36MYNw2vEcumm4j5PbDLnk7msqBw==",
    "publicKey": "MCowBQYDK2VwAyEAAYwDpYJbsBjJ0iKZmVDnYQ9gsASlCwAmRRbbYe6wlDE=",
    "keyId": "df85ea24ec23b3c7"
  }
}