{
  "schema": "kallipolis.resource-quality.v1",
  "id": "resource.provenance.slsa-1.2-verification-profile",
  "version": "1.0.0",
  "title": "SLSA 1.2 provenance verification profile",
  "summary": "Official SLSA 1.2 facts for recording exact supply-chain track, level, attestation, trusted builder, expectations, and verification evidence without turning provenance into an unsupported all-purpose security claim.",
  "content": {
    "kind": "implementation-checklist",
    "facts": [
      {
        "id": "fact.slsa.levels",
        "statement": "SLSA 1.2 defines tracks and levels with increasing supply-chain security guarantees; an evidence record should name the exact track and level rather than claiming generic SLSA compliance.",
        "normativeLevel": "informative",
        "sourceIds": ["source.slsa.spec-1.2"]
      },
      {
        "id": "fact.slsa.build-level-differences",
        "statement": "SLSA Build L1 provides build provenance but is trivial to forge, Build L2 adds signed provenance from a hosted platform, and Build L3 adds a hardened build platform.",
        "normativeLevel": "informative",
        "sourceIds": ["source.slsa.build-basics"]
      },
      {
        "id": "fact.slsa.verification-required",
        "statement": "Provenance has no protective effect unless it is verified; verification checks the trusted builder identity, envelope signature, artifact relationship, build type, external parameters, and policy expectations.",
        "normativeLevel": "informative",
        "sourceIds": ["source.slsa.verifying-artifacts"]
      },
      {
        "id": "fact.slsa.scope-boundary",
        "statement": "A SLSA result is evidence about specified source and build supply-chain properties. It should not be reported as proof that an artifact has no vulnerabilities or that a deployed system is secure in every context.",
        "normativeLevel": "informative",
        "sourceIds": ["source.slsa.spec-1.2", "source.slsa.verifying-artifacts"]
      }
    ]
  },
  "language": "en",
  "category": "ai-safety-provenance-and-audit",
  "state": "prepared",
  "canonicalUrl": "https://platoskallipolis.com/resources/ai-safety-provenance-and-audit/slsa-1.2-verification-profile.json",
  "contentHash": "sha256:7f3248281b1eb81906f84d6924111d543de8f37e3b938989d1ea2acb870586a4",
  "owner": {
    "id": "platos-kallipolis",
    "name": "Plato's Kallipolis",
    "type": "organization",
    "accountabilityUrl": "https://platoskallipolis.com/about"
  },
  "access": {
    "mode": "public",
    "url": "https://platoskallipolis.com/resources/ai-safety-provenance-and-audit/slsa-1.2-verification-profile.json",
    "authentication": "none",
    "robotsAllowed": true
  },
  "provenance": {
    "method": "official-specification",
    "sources": [
      {
        "id": "source.slsa.spec-1.2",
        "url": "https://slsa.dev/spec/v1.2/",
        "title": "SLSA specification version 1.2",
        "publisher": "SLSA Project",
        "observedAt": "2026-08-26T15:38:00Z"
      },
      {
        "id": "source.slsa.build-basics",
        "url": "https://slsa.dev/spec/v1.2/build-track-basics",
        "title": "SLSA Build Track Basics",
        "publisher": "SLSA Project",
        "observedAt": "2026-08-26T15:38:00Z"
      },
      {
        "id": "source.slsa.verifying-artifacts",
        "url": "https://slsa.dev/spec/v1.2/verifying-artifacts",
        "title": "SLSA Build Verifying Artifacts",
        "publisher": "SLSA Project",
        "observedAt": "2026-08-26T15:38:00Z"
      }
    ]
  },
  "observedAt": "2026-08-26T15:38:00Z",
  "freshness": {
    "policy": "version-bound",
    "state": "current",
    "nextReviewAt": "2026-09-02T15:38:00Z",
    "sourceVersion": "1.2"
  },
  "license": {
    "id": "community-specification-license-1.0",
    "url": "https://github.com/slsa-framework/governance",
    "redistributionAllowed": false
  },
  "evidence": [
    {
      "id": "evidence.slsa.spec-1.2",
      "type": "source-claim",
      "url": "https://slsa.dev/spec/v1.2/",
      "observedAt": "2026-08-26T15:38:00Z"
    }
  ]
}
