{"schema":"bay-run.assurance.v1","service":"bay-run","build":{"release_id":"bay-run-mvp-mvp32-acd874527730dc7f94c07eecd696a9f26f281d12","release_id_source":"cloud_run_revision","source_sha":"acd874527730dc7f94c07eecd696a9f26f281d12","image_digest":"us-central1-docker.pkg.dev/barneyserver/hugging-bay-workers/bay-run@sha256:fb33127a500c5feb547645731b4bf45df293a36a32fb2f8b718564ab88a4288c","binding_status":"complete","generated_at":"2026-08-15T03:31:20Z"},"effective_date":"2026-08-13","decision_model":"task_specific_owner_authorized","summary":"Bay Run publishes evidence for a human owner and delegated agent to decide whether a specific task fits the declared data, provider, region, retention, spending, and verification controls. It does not claim universal safety.","assurance_status":{"assessment_type":"implementation-backed self-assessment","independent_security_audit_completed":false,"penetration_test_claimed":false,"certifications_claimed":[],"universal_safe_or_secure_claim":false,"customer_specific_review_required_for_restricted_data":true},"standards_mapping":[{"reference":"RFC 9116","status":"implemented_contact_surface","scope":"machine-readable vulnerability disclosure contact","evidence":"https://run.huggingbay.xyz/.well-known/security.txt","limitation":"Publication and RFC 9116 syntax do not independently verify mailbox delivery, alerting, monitoring, or response time.","reference_url":"https://www.rfc-editor.org/rfc/rfc9116.html","certification":false},{"reference":"RFC 9700 OAuth 2.0 Security BCP","status":"partial","implemented_controls":["authorization-code PKCE","exact redirect comparison during token exchange","durable atomic one-time authorization-code consumption","confidential-client authentication during code exchange","strict scope and resource allowlists with audience-bound access tokens","short-lived access tokens without unbound refresh tokens","trusted-client-IP throttling on pre-authentication OAuth endpoints","authorization-server metadata","least-privilege resource scopes","owner-management scopes excluded from public OAuth authorization","public demo principals are ephemeral and cannot administer developer credentials","durable credential administration requires confidential-client authentication"],"known_gaps":["bearer access tokens are not sender-constrained","the auto-approved authorization-code flow is not human login or consent"],"reference_url":"https://www.rfc-editor.org/rfc/rfc9700.html","certification":false},{"reference":"OWASP API Security Top 10 2023","status":"self_assessed_control_mapping","implemented_controls":["tenant predicates on task and memory object access","separate function-level owner, spend, deletion, and execution scopes","bounded request schemas, rate limits, idempotency, and hard price ceilings","strict Host allowlist and no ambient forwarded-header trust","fail-closed payment settlement and nonchargeable unusable outputs"],"limitations":["This mapping is not an OWASP certification or independent audit.","Database row-level security is not claimed."],"reference_url":"https://owasp.org/API-Security/editions/2023/en/0x11-t10/","certification":false},{"reference":"NIST AI RMF 1.0","status":"informative_mapping","implemented_controls":{"govern":"human-owned authorization, spending, retention, and route-switch policy","map":"task-specific schemas, constraints, provider and data-policy declaration","measure":"candidate quality, latency, cost, failure, and provenance evidence","manage":"fail closed on conflicts, preserve receipts, and require owner approval where configured"},"limitations":["Use of the voluntary framework is not certification.","The task owner remains responsible for context-specific risk acceptance."],"reference_url":"https://www.nist.gov/itl/ai-risk-management-framework","certification":false},{"reference":"NIST Privacy Framework","status":"informative_mapping","implemented_controls":["identify and communicate current processing and subprocessor facts","owner-selected retention and external-provider constraints","data minimization, scoped deletion or redaction, and no-training default","transport and managed at-rest encryption claims with explicit assurance limits"],"limitations":["This is not a NIST assessment, certification, or legal compliance opinion."],"reference_url":"https://www.nist.gov/privacy-framework/privacy-framework","certification":false}],"owner_decision_evidence":{"data_policy":"https://run.huggingbay.xyz/.well-known/data-policy.json","free_quote":"https://run.huggingbay.xyz/v1/task/quote","identity_introspection":"https://run.huggingbay.xyz/v1/identity","pricing":"https://run.huggingbay.xyz/.well-known/pricing","receipt_verification":"https://run.huggingbay.xyz/v1/task/verify","openapi":"https://run.huggingbay.xyz/openapi.json","health":"https://run.huggingbay.xyz/health","security_contact":"https://run.huggingbay.xyz/.well-known/security.txt","security_policy":"https://run.huggingbay.xyz/security"},"agent_required_sequence":["minimize the input and exclude credentials","quote with explicit region, provider, external-API, retention, quality, latency, and price constraints","stop when the quote reports a constraint failure or lacks owner-required evidence","obtain human approval when owner policy requires it","execute with a least-privilege credential and a hard maximum price","verify the returned receipt and report its explicit limitations to the owner"],"memory":{"shared_demo_warning":"Static demo identity is shared and must not hold secrets or private memory.","owner_attested_memory_credential_required":true,"public_oauth_alone_sufficient":false,"principal_scoped":true,"ttl_delete_export_controls":true,"deletion_requires_separate_owner_scope":"data:delete","private_search_body_endpoint":"POST https://run.huggingbay.xyz/v1/memory/search","injected_memory_treated_as_untrusted_data":true,"rag_context_prompt_injection_guard":true,"memory_failure_logs_include_raw_exception_text":false,"automatic_memory_default_ttl_seconds":2592000,"credential_pattern_filter_is_general_dlp":false,"automatic_cross_tool_injection":false,"customer_memory_used_for_training":false,"details":"https://run.huggingbay.xyz/.well-known/data-policy.json"},"software_supply_chain":{"runtime_requirements_pinned":true,"release_dependency_audit":"pip-audit against the pinned production requirements","continuous_vulnerability_monitoring_claimed":false,"limitation":"The dependency audit is a point-in-time release gate, not an independent assessment, SBOM attestation, or guarantee against later disclosures."}}