{
  "data": [
    {
      "provider": {
        "id": "oneleet",
        "name": "Oneleet",
        "tier": "tier1",
        "adapter_status": "implemented",
        "connect_method": "public_rest",
        "auth": "none (tenant host is the API key in the path)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": true,
          "subprocessors": false,
          "documents": true,
          "securityUpdates": false
        },
        "rate_limit": {
          "recommendedRps": 12,
          "maxConcurrency": 12,
          "readCeiling": "no 429 to 60rps but latency-bound: slow ~1.1s origin (Cloudflare passthrough); median balloons 4-5s past ~20rps",
          "limiter": "Cloudflare -> slow origin; concurrency-bound, NOT quota-bound",
          "penalty": "none (no 429/403; latency only)",
          "backoff": "keep ~10-15 in flight; do not push RPS to chase throughput"
        },
        "stats": {
          "providerId": "oneleet",
          "name": "Oneleet",
          "adapterStatus": "implemented",
          "organizations": 101,
          "trustCenters": 101,
          "certifications": 161,
          "controls": 7605,
          "subprocessors": 0,
          "documents": 555,
          "securityUpdates": 0,
          "sources": 101
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync",
        "rate_limit": {
          "recommendedRps": 12,
          "maxConcurrency": 12,
          "readCeiling": "no 429 to 60rps but latency-bound: slow ~1.1s origin (Cloudflare passthrough); median balloons 4-5s past ~20rps",
          "limiter": "Cloudflare -> slow origin; concurrency-bound, NOT quota-bound",
          "penalty": "none (no 429/403; latency only)",
          "backoff": "keep ~10-15 in flight; do not push RPS to chase throughput"
        },
        "known_source_count": 103,
        "harvestable_source_count": 102,
        "seed": "seeds/oneleet-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 101,
        "trust_centers": 101,
        "certifications": 161,
        "controls": 7605,
        "subprocessors": 0,
        "documents": 555,
        "security_updates": 0,
        "sources": 101
      },
      "data_surface": {
        "score": 72,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "high_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": false,
          "documents": true,
          "security_updates": false,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "documents",
          "provenance"
        ],
        "missing_capabilities": [
          "subprocessors",
          "security_updates"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": false,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": false,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 101,
          "certifications": 161,
          "controls": 7605,
          "subprocessors": 0,
          "documents": 555,
          "security_updates": 0,
          "sources": 101
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "oneleet_public_rest",
            "count": 101
          }
        ],
        "access_levels": [
          {
            "key": "request",
            "count": 87
          },
          {
            "key": "mixed",
            "count": 14
          }
        ],
        "data_access": {
          "certifications": 98,
          "controls": 100,
          "subprocessors": 0,
          "documents": 61,
          "security_updates": 0
        }
      },
      "source_registry": {
        "rank": 6,
        "segment": "startup_smb",
        "owner": "Oneleet (independent; YC-backed, security compliance platform)",
        "auth": "none",
        "connect": {
          "method": "public_rest",
          "fetch": "GET https://api.oneleet.com/api/v1/tenants/{tenantDomain}/trust",
          "meta": "GET https://api.oneleet.com/api/v1/meta (env flags, posthog key)",
          "key": "tenantDomain = the trust-center hostname itself (e.g. security.archil.com) in the path",
          "cors": "open; single unauthenticated GET returns the whole trust center",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "trust.oneleet.com",
          "handleInCname": false,
          "note": "shared CNAME target (handle NOT in CNAME), but the tenant hostname IS the API key, so CNAME sweep -> hostname -> direct API",
          "fingerprints": [
            "CNAME trust.oneleet.com",
            "api.oneleet.com/api/v1/tenants/{domain}/trust",
            "assets index-*.js SPA shell",
            "config.js + version.json"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:Oneleet"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 61,
          "harvestableNow": 102,
          "netNew": 42,
          "netNewFromCommonCrawl": 23,
          "totalKnown": 103,
          "seed": "seeds/oneleet-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/oneleet",
        "provider": "/v1/providers/oneleet",
        "companies": "/v1/companies?provider=oneleet",
        "trust_centers": "/v1/trust-centers?provider=oneleet",
        "sources": "/v1/sources?provider=oneleet"
      }
    },
    {
      "provider": {
        "id": "upguard",
        "name": "UpGuard Trust Page",
        "tier": "tier1",
        "adapter_status": "implemented",
        "connect_method": "public_rest",
        "auth": "none (served same-origin at tenant host; CORS *)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": true,
          "subprocessors": false,
          "documents": true,
          "securityUpdates": false
        },
        "rate_limit": {
          "recommendedRps": 20,
          "maxConcurrency": 20,
          "readCeiling": ">=60rps (no throttle observed; ~210ms warm, degrades gracefully with zero failures)",
          "limiter": "none observed",
          "penalty": "none",
          "backoff": "exponential on any 429/5xx + jitter"
        },
        "stats": {
          "providerId": "upguard",
          "name": "UpGuard Trust Page",
          "adapterStatus": "implemented",
          "organizations": 18,
          "trustCenters": 18,
          "certifications": 79,
          "controls": 372,
          "subprocessors": 0,
          "documents": 294,
          "securityUpdates": 0,
          "sources": 18
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync",
        "rate_limit": {
          "recommendedRps": 20,
          "maxConcurrency": 20,
          "readCeiling": ">=60rps (no throttle observed; ~210ms warm, degrades gracefully with zero failures)",
          "limiter": "none observed",
          "penalty": "none",
          "backoff": "exponential on any 429/5xx + jitter"
        },
        "known_source_count": 18,
        "harvestable_source_count": 18,
        "seed": "seeds/upguard-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 18,
        "trust_centers": 18,
        "certifications": 79,
        "controls": 372,
        "subprocessors": 0,
        "documents": 294,
        "security_updates": 0,
        "sources": 18
      },
      "data_surface": {
        "score": 72,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "high_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": false,
          "documents": true,
          "security_updates": false,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "documents",
          "provenance"
        ],
        "missing_capabilities": [
          "subprocessors",
          "security_updates"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": false,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": false,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 18,
          "certifications": 79,
          "controls": 372,
          "subprocessors": 0,
          "documents": 294,
          "security_updates": 0,
          "sources": 18
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "upguard_public_rest",
            "count": 18
          }
        ],
        "access_levels": [
          {
            "key": "request",
            "count": 18
          }
        ],
        "data_access": {
          "certifications": 17,
          "controls": 6,
          "subprocessors": 0,
          "documents": 17,
          "security_updates": 0
        }
      },
      "source_registry": {
        "rank": 7,
        "segment": "midmarket_enterprise",
        "owner": "UpGuard (independent; TPRM/security-ratings platform)",
        "auth": "none",
        "connect": {
          "method": "public_rest",
          "fetch": "GET https://{tenantDomain}/api/trustpage/public/v1/",
          "key": "implicit by Host header; served same-origin at the tenant domain (proxied through customer.trust.upguard.com). Apex customer.trust.upguard.com w/o tenant Host -> 404",
          "cors": "open (access-control-allow-origin: *); single unauthenticated GET",
          "officialApi": "UpGuard has a vendor-risk API (per-customer key) - NOT used here"
        },
        "discovery": {
          "cnameTarget": "customer.trust.upguard.com",
          "handleInCname": false,
          "note": "domain must be pre-scanned/onboarded by the customer's UpGuard org; score data comes from UpGuard outside-in scanning",
          "fingerprints": [
            "CNAME customer.trust.upguard.com",
            "/api/trustpage/public/v1/",
            "/assets/v1/trustpagepublic.bundle.js",
            "storage.googleapis.com/vendor-risk-production-default-bucket"
          ],
          "channels": [
            "dns_cname_sweep",
            "builtwith:UpGuard",
            "crt.sh"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 17,
          "harvestableNow": 18,
          "netNew": 1,
          "netNewFromCommonCrawl": 0,
          "totalKnown": 18,
          "seed": "seeds/upguard-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/upguard",
        "provider": "/v1/providers/upguard",
        "companies": "/v1/companies?provider=upguard",
        "trust_centers": "/v1/trust-centers?provider=upguard",
        "sources": "/v1/sources?provider=upguard"
      }
    },
    {
      "provider": {
        "id": "hypercomply",
        "name": "HyperComply",
        "tier": "tier1",
        "adapter_status": "implemented",
        "connect_method": "public_rest_cms",
        "auth": "none (tenant host passed as ?domain=)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": "inferred_from_names",
          "controls": "cms_modules",
          "subprocessors": false,
          "documents": true,
          "securityUpdates": false
        },
        "rate_limit": {
          "recommendedRps": 6,
          "maxConcurrency": 6,
          "readCeiling": "HARD LIMIT ~10-11 req/s (token bucket); 429 {\"error\":\"rate limit exceeded\"}, no Retry-After",
          "limiter": "token bucket ~10-11/s per IP — the binding constraint of the set",
          "penalty": "429 (no Retry-After)",
          "backoff": "self-driven exponential backoff on 429 (start ~1s); stay <=6rps"
        },
        "stats": {
          "providerId": "hypercomply",
          "name": "HyperComply",
          "adapterStatus": "implemented",
          "organizations": 12,
          "trustCenters": 12,
          "certifications": 37,
          "controls": 75,
          "subprocessors": 0,
          "documents": 257,
          "securityUpdates": 0,
          "sources": 12
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync",
        "rate_limit": {
          "recommendedRps": 6,
          "maxConcurrency": 6,
          "readCeiling": "HARD LIMIT ~10-11 req/s (token bucket); 429 {\"error\":\"rate limit exceeded\"}, no Retry-After",
          "limiter": "token bucket ~10-11/s per IP — the binding constraint of the set",
          "penalty": "429 (no Retry-After)",
          "backoff": "self-driven exponential backoff on 429 (start ~1s); stay <=6rps"
        },
        "known_source_count": 18,
        "harvestable_source_count": 13,
        "seed": "seeds/hypercomply-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 12,
        "trust_centers": 12,
        "certifications": 37,
        "controls": 75,
        "subprocessors": 0,
        "documents": 257,
        "security_updates": 0,
        "sources": 12
      },
      "data_surface": {
        "score": 72,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "high_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": false,
          "documents": true,
          "security_updates": false,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "documents",
          "provenance"
        ],
        "missing_capabilities": [
          "subprocessors",
          "security_updates"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": false,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": false,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 12,
          "certifications": 37,
          "controls": 75,
          "subprocessors": 0,
          "documents": 257,
          "security_updates": 0,
          "sources": 12
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "hypercomply_public_rest_cms",
            "count": 12
          }
        ],
        "access_levels": [
          {
            "key": "mixed",
            "count": 12
          }
        ],
        "data_access": {
          "certifications": 11,
          "controls": 12,
          "subprocessors": 0,
          "documents": 11,
          "security_updates": 0
        }
      },
      "source_registry": {
        "rank": 9,
        "segment": "smb_midmarket",
        "owner": "HyperComply (independent; security questionnaire + trust platform)",
        "auth": "none",
        "connect": {
          "method": "public_rest",
          "fetch": "GET https://questionnaire-storage.hypercomply.com/public_trust_api/1/trust_page?domain={tenantDomain}",
          "key": "domain query param = the trust-center hostname (e.g. trust.observe.ai)",
          "cors": "open; single unauthenticated GET returns the whole trust center snapshot",
          "correction": "registry previously guessed 'GraphQL' — it is plain REST (the SPA uses Apollo but data comes from this REST endpoint)",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "proxy.hypercomplytrust.com",
          "handleInCname": false,
          "note": "shared CNAME target (handle NOT in CNAME); the tenant hostname is the API key via ?domain=. assets.hypercomply.com / hypercomply-public-files-prod.s3 / 'Powered by HyperComply' svg confirm",
          "fingerprints": [
            "CNAME proxy.hypercomplytrust.com",
            "questionnaire-storage.hypercomply.com/public_trust_api",
            "assets.hypercomply.com",
            "PoweredByHyperComply svg"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:HyperComply"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 11,
          "harvestableNow": 13,
          "netNew": 7,
          "netNewFromCommonCrawl": 4,
          "totalKnown": 18,
          "seed": "seeds/hypercomply-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/hypercomply",
        "provider": "/v1/providers/hypercomply",
        "companies": "/v1/companies?provider=hypercomply",
        "trust_centers": "/v1/trust-centers?provider=hypercomply",
        "sources": "/v1/sources?provider=hypercomply"
      }
    },
    {
      "provider": {
        "id": "rfpio",
        "name": "RFPIO / Responsive (Profile Center)",
        "tier": "tier1",
        "adapter_status": "implemented",
        "connect_method": "public_rest_multistep",
        "auth": "none (guest_v3/public; domain->companyId->profileId)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": true,
          "subprocessors": true,
          "documents": true,
          "securityUpdates": true
        },
        "rate_limit": {
          "recommendedRps": 20,
          "maxConcurrency": 20,
          "readCeiling": ">=60rps (no throttle; read path cached server-side, flat ~45ms even at 60rps)",
          "limiter": "none observed (CDN-cached reads despite real app pods)",
          "penalty": "none",
          "backoff": "exponential on any 429/5xx + jitter"
        },
        "stats": {
          "providerId": "rfpio",
          "name": "RFPIO / Responsive (Profile Center)",
          "adapterStatus": "implemented",
          "organizations": 11,
          "trustCenters": 11,
          "certifications": 69,
          "controls": 75,
          "subprocessors": 24,
          "documents": 297,
          "securityUpdates": 78,
          "sources": 11
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync_plus_intraday_updates_when_enabled",
        "rate_limit": {
          "recommendedRps": 20,
          "maxConcurrency": 20,
          "readCeiling": ">=60rps (no throttle; read path cached server-side, flat ~45ms even at 60rps)",
          "limiter": "none observed (CDN-cached reads despite real app pods)",
          "penalty": "none",
          "backoff": "exponential on any 429/5xx + jitter"
        },
        "known_source_count": 11,
        "harvestable_source_count": 11,
        "seed": "seeds/rfpio-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 11,
        "trust_centers": 11,
        "certifications": 69,
        "controls": 75,
        "subprocessors": 24,
        "documents": 297,
        "security_updates": 78,
        "sources": 11
      },
      "data_surface": {
        "score": 100,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "deep_security_posture",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": true,
          "documents": true,
          "security_updates": true,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "subprocessors",
          "documents",
          "security_updates",
          "provenance"
        ],
        "missing_capabilities": [],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": true,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": true,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 11,
          "certifications": 69,
          "controls": 75,
          "subprocessors": 24,
          "documents": 297,
          "security_updates": 78,
          "sources": 11
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "rfpio_profile_center_rest",
            "count": 11
          }
        ],
        "access_levels": [
          {
            "key": "request",
            "count": 6
          },
          {
            "key": "public",
            "count": 5
          }
        ],
        "data_access": {
          "certifications": 8,
          "controls": 8,
          "subprocessors": 2,
          "documents": 11,
          "security_updates": 7
        }
      },
      "source_registry": {
        "rank": 10,
        "segment": "midmarket_enterprise",
        "owner": "Responsive (formerly RFPIO, renamed 2022; RFP/questionnaire automation). 'Profile Center' (public profile) is the trust-center product (Summer 2023 release)",
        "auth": "none",
        "connect": {
          "method": "public_rest",
          "resolve": "GET https://app.rfpio.com/rfpserver/auth-custom-domain/verify?domain={tenantDomain} -> {companyId, podName}",
          "domainDetails": "GET https://{tenantDomain}/rfpserver/guest_v3/{companyId}/get-domain-details?domain={tenantDomain} -> customDomainVO{companyId, entityId=profileId, module PROFILE}",
          "fetch": "GET https://{tenantDomain}/rfpserver/guest_v3/public/{companyId}/profiles/v2/{profileId}/get -> profileVO (sections[])",
          "subprocessors": "GET .../profiles/{profileId}/SUB_PROCESSOR -> {artifacts[].answers[], allSubprocessorCategories}",
          "faq": "GET .../profiles/{profileId}/FAQ",
          "updates": "POST .../profiles/{profileId}/feeds  body {profileIds:[profileId], limit, lastId} -> {profileFeedVOList[], totalCount}",
          "cors": "guest_v3/public path = unauthenticated",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "profiles.rfpio.com",
          "handleInCname": false,
          "note": "custom domains CNAME to profiles.rfpio.com (verified via app.rfpio.com/rfpserver/auth-custom-domain/verify). Two-step keying: domain -> companyId -> profileId",
          "fingerprints": [
            "CNAME profiles.rfpio.com",
            "/rfpserver/guest_v3/ API path",
            "app.rfpio.com/rfpserver/auth-custom-domain/verify",
            "/profile-guest/ assets"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:RFPIO/Responsive"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 0,
          "harvestableNow": 11,
          "netNew": 11,
          "netNewFromCommonCrawl": 0,
          "totalKnown": 11,
          "seed": "seeds/rfpio-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/rfpio",
        "provider": "/v1/providers/rfpio",
        "companies": "/v1/companies?provider=rfpio",
        "trust_centers": "/v1/trust-centers?provider=rfpio",
        "sources": "/v1/sources?provider=rfpio"
      }
    },
    {
      "provider": {
        "id": "trustshare",
        "name": "TrustShare (TrustCloud / Kintent)",
        "tier": "tier1",
        "adapter_status": "implemented",
        "connect_method": "public_rest_2step",
        "auth": "public_token (static SPA cred, reusable across tenants; Origin-keyed)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": true,
          "subprocessors": true,
          "documents": true,
          "securityUpdates": true
        },
        "rate_limit": {
          "recommendedRps": 20,
          "maxConcurrency": 20,
          "readCeiling": ">=60rps (no throttle observed; backend.trustcloud.ai flat ~107ms)",
          "mintCeiling": "POST /auth/public/login hard-limits ~4rps (429 at 5+); cache the ~8h token per tenant, re-mint only on 401/expiry, keep concurrent logins <=3/s",
          "limiter": "reads unmetered to 60; login is the bottleneck",
          "penalty": "login 429 (no Retry-After)",
          "backoff": "exponential on 429 (start ~1s) + jitter"
        },
        "stats": {
          "providerId": "trustshare",
          "name": "TrustShare (TrustCloud / Kintent)",
          "adapterStatus": "implemented",
          "organizations": 31,
          "trustCenters": 31,
          "certifications": 81,
          "controls": 4633,
          "subprocessors": 1080,
          "documents": 993,
          "securityUpdates": 49,
          "sources": 31
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync_plus_intraday_updates_when_enabled",
        "rate_limit": {
          "recommendedRps": 20,
          "maxConcurrency": 20,
          "readCeiling": ">=60rps (no throttle observed; backend.trustcloud.ai flat ~107ms)",
          "mintCeiling": "POST /auth/public/login hard-limits ~4rps (429 at 5+); cache the ~8h token per tenant, re-mint only on 401/expiry, keep concurrent logins <=3/s",
          "limiter": "reads unmetered to 60; login is the bottleneck",
          "penalty": "login 429 (no Retry-After)",
          "backoff": "exponential on 429 (start ~1s) + jitter"
        },
        "known_source_count": 32,
        "harvestable_source_count": 27,
        "seed": "seeds/trustshare-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 31,
        "trust_centers": 31,
        "certifications": 81,
        "controls": 4633,
        "subprocessors": 1080,
        "documents": 993,
        "security_updates": 49,
        "sources": 31
      },
      "data_surface": {
        "score": 100,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "deep_security_posture",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": true,
          "documents": true,
          "security_updates": true,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "subprocessors",
          "documents",
          "security_updates",
          "provenance"
        ],
        "missing_capabilities": [],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": true,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": true,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 31,
          "certifications": 81,
          "controls": 4633,
          "subprocessors": 1080,
          "documents": 993,
          "security_updates": 49,
          "sources": 31
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "trustshare_public_token_rest",
            "count": 31
          }
        ],
        "access_levels": [
          {
            "key": "transparent",
            "count": 28
          },
          {
            "key": "private",
            "count": 3
          }
        ],
        "data_access": {
          "certifications": 29,
          "controls": 30,
          "subprocessors": 30,
          "documents": 25,
          "security_updates": 5
        }
      },
      "source_registry": {
        "rank": 8,
        "segment": "smb_midmarket",
        "owner": "TrustCloud (aka Kintent, 2020 Boston). 'TrustShare' is TrustCloud's public trust-center product",
        "auth": "public_token_2step",
        "connect": {
          "method": "public_rest",
          "apiHost": "backend.trustcloud.ai",
          "step1_login": "POST /auth/public/login with header 'X-Kintent-Auth: Basic {static-baked-in-SPA-cred}' and 'Origin: https://{tenantDomain}' -> {teamId, token} (token = public JWT, type=public, ~8h TTL). Basic cred is the SAME public client for all tenants (baked into the SPA bundle); Origin header keys it to the tenant",
          "step2_data": "GET endpoints with 'X-Kintent-Auth: Bearer {token}' + Origin header",
          "endpoints": [
            "/trustshare/program-content/{programId} (page config, access levels, FAQ)",
            "/teams/{teamId} (org)",
            "/teams/{teamId}/settings",
            "/teams/{teamId}/certifications",
            "/teams/{teamId}/documents",
            "/teams/{teamId}/leaders (key people)",
            "/controls?includeComplianceMapping=true",
            "/vendors (subprocessors)",
            "/policies",
            "/trustshare/notifications (update feed)"
          ],
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "{handle}.trustshare.com",
          "handleInCname": true,
          "note": "handle in CNAME (e.g. cribl.trustshare.com, netdocuments.trustshare.com); programContentUrl uses {programId-uuid}.trustshare.com form. SPA shows trustcloud_logo + cdn.kintent.com assets",
          "fingerprints": [
            "CNAME *.trustshare.com",
            "backend.trustcloud.ai API calls",
            "cdn.kintent.com assets",
            "trustcloud_logo svg",
            "X-Kintent-Auth header"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh:trustshare.com",
            "builtwith:TrustCloud"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 13,
          "harvestableNow": 27,
          "netNew": 19,
          "netNewFromCommonCrawl": 16,
          "totalKnown": 32,
          "seed": "seeds/trustshare-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/trustshare",
        "provider": "/v1/providers/trustshare",
        "companies": "/v1/companies?provider=trustshare",
        "trust_centers": "/v1/trust-centers?provider=trustshare",
        "sources": "/v1/sources?provider=trustshare"
      }
    },
    {
      "provider": {
        "id": "sprinto",
        "name": "Sprinto",
        "tier": "tier1",
        "adapter_status": "implemented",
        "connect_method": "rsc_flight",
        "auth": "none (browser UA required)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": false,
          "subprocessors": "best_effort_rendered",
          "documents": false,
          "securityUpdates": false
        },
        "rate_limit": {
          "recommendedRps": 2,
          "maxConcurrency": 3,
          "readCeiling": "latency cliff at ~5rps (med 0.8s -> 3.3s); origin-render-bound, NOT quota-bound",
          "limiter": "CloudFront passthrough to UNCACHED dynamic SSR (x-cache: Miss); origin re-renders the heavy RSC page (~0.8s) per request and saturates fast",
          "penalty": "none observed (no 429/403; just latency blowup)",
          "backoff": "concurrency-limit (~3 in flight); space requests, do not raise RPS to push throughput"
        },
        "stats": {
          "providerId": "sprinto",
          "name": "Sprinto",
          "adapterStatus": "implemented",
          "organizations": 3,
          "trustCenters": 3,
          "certifications": 9,
          "controls": 0,
          "subprocessors": 2,
          "documents": 0,
          "securityUpdates": 0,
          "sources": 3
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync",
        "rate_limit": {
          "recommendedRps": 2,
          "maxConcurrency": 3,
          "readCeiling": "latency cliff at ~5rps (med 0.8s -> 3.3s); origin-render-bound, NOT quota-bound",
          "limiter": "CloudFront passthrough to UNCACHED dynamic SSR (x-cache: Miss); origin re-renders the heavy RSC page (~0.8s) per request and saturates fast",
          "penalty": "none observed (no 429/403; just latency blowup)",
          "backoff": "concurrency-limit (~3 in flight); space requests, do not raise RPS to push throughput"
        },
        "known_source_count": 3,
        "harvestable_source_count": 0,
        "seed": "seeds/sprinto-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 3,
        "trust_centers": 3,
        "certifications": 9,
        "controls": 0,
        "subprocessors": 2,
        "documents": 0,
        "security_updates": 0,
        "sources": 3
      },
      "data_surface": {
        "score": 50,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "medium_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": false,
          "subprocessors": true,
          "documents": false,
          "security_updates": false,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "subprocessors",
          "provenance"
        ],
        "missing_capabilities": [
          "controls",
          "documents",
          "security_updates"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": false,
          "subprocessor_monitoring": true,
          "document_inventory": false,
          "compliance_tracking": true,
          "security_advisory_monitoring": false,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 3,
          "certifications": 9,
          "controls": 0,
          "subprocessors": 2,
          "documents": 0,
          "security_updates": 0,
          "sources": 3
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "sprinto_rendered_rsc_partial",
            "count": 3
          }
        ],
        "access_levels": [
          {
            "key": "unknown",
            "count": 3
          }
        ],
        "data_access": {
          "certifications": 2,
          "controls": 0,
          "subprocessors": 1,
          "documents": 0,
          "security_updates": 0
        }
      },
      "source_registry": {
        "rank": 15,
        "segment": "smb_startup",
        "owner": "Sprinto (independent)",
        "auth": "none (browser UA required)",
        "connect": {
          "method": "rsc_flight",
          "fetch": "GET https://{tenantDomain}/",
          "key": "browser-rendered Next.js App Router payload in self.__next_f; use a real Chrome UA",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "*.trustcenter.sprinto.com",
          "handleInCname": false,
          "note": "CloudFront-hosted Sprinto trust center; non-browser UAs get 403, so adapters need a real browser UA and RSC chunk parsing.",
          "fingerprints": [
            "CNAME *.trustcenter.sprinto.com",
            "server: sprinto server",
            "self.__next_f.push([...])",
            "app.sprinto.com/trust-center/view/{uuid}"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:Sprinto"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 3,
          "harvestableNow": 0,
          "netNew": 0,
          "netNewFromCommonCrawl": 0,
          "totalKnown": 3,
          "seed": "seeds/sprinto-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/sprinto",
        "provider": "/v1/providers/sprinto",
        "companies": "/v1/companies?provider=sprinto",
        "trust_centers": "/v1/trust-centers?provider=sprinto",
        "sources": "/v1/sources?provider=sprinto"
      }
    },
    {
      "provider": {
        "id": "scrut",
        "name": "Scrut",
        "tier": "tier2",
        "adapter_status": "implemented",
        "connect_method": "public_rest_2step",
        "auth": "public_token (domainConnector -> auth-id-token)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": false,
          "subprocessors": true,
          "documents": true,
          "securityUpdates": "update_details_feed"
        },
        "rate_limit": {
          "recommendedRps": 20,
          "maxConcurrency": 20,
          "readCeiling": ">=30rps (no throttle; latency flat ~0.8s across all rungs, well-provisioned)",
          "mintCeiling": "domainConnector token resolve not stress-probed (politeness); token lives ~7d, so cache per tenant and keep mints <=3/s",
          "limiter": "data reads unmetered to 30; ~0.8s is fixed per-request latency, not load-induced",
          "penalty": "none observed (one transient 500 at 15rps, <1%)",
          "backoff": "exponential on 429/5xx + jitter"
        },
        "stats": {
          "providerId": "scrut",
          "name": "Scrut",
          "adapterStatus": "implemented",
          "organizations": 11,
          "trustCenters": 11,
          "certifications": 33,
          "controls": 0,
          "subprocessors": 36,
          "documents": 83,
          "securityUpdates": 3,
          "sources": 11
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync",
        "rate_limit": {
          "recommendedRps": 20,
          "maxConcurrency": 20,
          "readCeiling": ">=30rps (no throttle; latency flat ~0.8s across all rungs, well-provisioned)",
          "mintCeiling": "domainConnector token resolve not stress-probed (politeness); token lives ~7d, so cache per tenant and keep mints <=3/s",
          "limiter": "data reads unmetered to 30; ~0.8s is fixed per-request latency, not load-induced",
          "penalty": "none observed (one transient 500 at 15rps, <1%)",
          "backoff": "exponential on 429/5xx + jitter"
        },
        "known_source_count": 20,
        "harvestable_source_count": 6,
        "seed": "seeds/scrut-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 11,
        "trust_centers": 11,
        "certifications": 33,
        "controls": 0,
        "subprocessors": 36,
        "documents": 83,
        "security_updates": 3,
        "sources": 11
      },
      "data_surface": {
        "score": 78,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "high_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": false,
          "subprocessors": true,
          "documents": true,
          "security_updates": true,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "subprocessors",
          "documents",
          "security_updates",
          "provenance"
        ],
        "missing_capabilities": [
          "controls"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": false,
          "subprocessor_monitoring": true,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": true,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 11,
          "certifications": 33,
          "controls": 0,
          "subprocessors": 36,
          "documents": 83,
          "security_updates": 3,
          "sources": 11
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "scrut_public_token_rest",
            "count": 11
          }
        ],
        "access_levels": [
          {
            "key": "unknown",
            "count": 11
          }
        ],
        "data_access": {
          "certifications": 11,
          "controls": 0,
          "subprocessors": 6,
          "documents": 8,
          "security_updates": 2
        }
      },
      "source_registry": {
        "rank": 16,
        "segment": "smb_midmarket",
        "owner": "Scrut Automation (independent)",
        "auth": "none (domainConnector -> auth-id-token)",
        "connect": {
          "method": "public_rest_2step",
          "resolve": "POST https://app.scrut.io/api/v1/trustCenterService/domainConnector/get-domain",
          "fetch": "GET https://app.scrut.io/api/v1/trustCenterService/trust-portal/*",
          "key": "tenant domain resolves to auth-id-token, then trust-portal endpoints return the public profile",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "*.scrut.io",
          "handleInCname": false,
          "note": "login-looking SPA backed by a public REST surface; the tenant-domain lookup is separate from the data read path.",
          "fingerprints": [
            "CNAME *.scrut.io",
            "app.scrut.io/api/v1/trustCenterService",
            "auth-id-token header",
            "trust-portal/* endpoints"
          ],
          "channels": [
            "dns_cname_sweep",
            "common_crawl_athena",
            "builtwith:Scrut"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 1,
          "harvestableNow": 6,
          "netNew": 19,
          "netNewFromCommonCrawl": 19,
          "totalKnown": 20,
          "seed": "seeds/scrut-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/scrut",
        "provider": "/v1/providers/scrut",
        "companies": "/v1/companies?provider=scrut",
        "trust_centers": "/v1/trust-centers?provider=scrut",
        "sources": "/v1/sources?provider=scrut"
      }
    },
    {
      "provider": {
        "id": "wolfia",
        "name": "Wolfia",
        "tier": "tier2",
        "adapter_status": "implemented",
        "connect_method": "embedded_json + public_rest_fallback",
        "auth": "none",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": "products_when_present",
          "subprocessors": true,
          "documents": true,
          "securityUpdates": true
        },
        "rate_limit": {
          "recommendedRps": 10,
          "maxConcurrency": 10,
          "headerAware": true,
          "readCeiling": "page edge advertises x-ratelimit-limit:200 per ~6-min window (per IP); CloudFront cache HITS do not consume it; api.wolfia.com data path is unmetered (45 req @ ~6rps clean, no headers)",
          "limiter": "friendliest of the set — proactive x-ratelimit-{limit,remaining,reset} headers on the CloudFront page",
          "penalty": "presumed 429 at budget exhaustion (not forced — honored the advertised 200/6min instead)",
          "backoff": "header-aware: throttle when x-ratelimit-remaining is low; stay <=200 uncached origin fetches / 6min; <=10rps on api.wolfia.com"
        },
        "stats": {
          "providerId": "wolfia",
          "name": "Wolfia",
          "adapterStatus": "implemented",
          "organizations": 11,
          "trustCenters": 11,
          "certifications": 67,
          "controls": 0,
          "subprocessors": 176,
          "documents": 30,
          "securityUpdates": 25,
          "sources": 11
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync_plus_intraday_updates_when_enabled",
        "rate_limit": {
          "recommendedRps": 10,
          "maxConcurrency": 10,
          "headerAware": true,
          "readCeiling": "page edge advertises x-ratelimit-limit:200 per ~6-min window (per IP); CloudFront cache HITS do not consume it; api.wolfia.com data path is unmetered (45 req @ ~6rps clean, no headers)",
          "limiter": "friendliest of the set — proactive x-ratelimit-{limit,remaining,reset} headers on the CloudFront page",
          "penalty": "presumed 429 at budget exhaustion (not forced — honored the advertised 200/6min instead)",
          "backoff": "header-aware: throttle when x-ratelimit-remaining is low; stay <=200 uncached origin fetches / 6min; <=10rps on api.wolfia.com"
        },
        "known_source_count": 13,
        "harvestable_source_count": 6,
        "seed": "seeds/wolfia-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 11,
        "trust_centers": 11,
        "certifications": 67,
        "controls": 0,
        "subprocessors": 176,
        "documents": 30,
        "security_updates": 25,
        "sources": 11
      },
      "data_surface": {
        "score": 78,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "high_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": false,
          "subprocessors": true,
          "documents": true,
          "security_updates": true,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "subprocessors",
          "documents",
          "security_updates",
          "provenance"
        ],
        "missing_capabilities": [
          "controls"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": false,
          "subprocessor_monitoring": true,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": true,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 11,
          "certifications": 67,
          "controls": 0,
          "subprocessors": 176,
          "documents": 30,
          "security_updates": 25,
          "sources": 11
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "wolfia_embedded_next_data",
            "count": 11
          }
        ],
        "access_levels": [
          {
            "key": "unknown",
            "count": 11
          }
        ],
        "data_access": {
          "certifications": 10,
          "controls": 0,
          "subprocessors": 11,
          "documents": 7,
          "security_updates": 7
        }
      },
      "source_registry": {
        "rank": 17,
        "segment": "enterprise",
        "owner": "Wolfia (independent)",
        "auth": "none",
        "connect": {
          "method": "embedded_json_or_public_api",
          "fetch": "GET https://{tenantDomain}/",
          "key": "embedded Next.js JSON island with api.wolfia.com fallback",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "connect.wolfia.com / *.trust.wolfia.com",
          "handleInCname": false,
          "note": "custom domains CNAME to connect.wolfia.com; the trust center is an embedded JSON island with an API fallback.",
          "fingerprints": [
            "CNAME connect.wolfia.com",
            "CNAME *.trust.wolfia.com",
            "__NEXT_DATA__ initialPortal",
            "api.wolfia.com/trustportal/public"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:Wolfia"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 5,
          "harvestableNow": 6,
          "netNew": 8,
          "netNewFromCommonCrawl": 4,
          "totalKnown": 13,
          "seed": "seeds/wolfia-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/wolfia",
        "provider": "/v1/providers/wolfia",
        "companies": "/v1/companies?provider=wolfia",
        "trust_centers": "/v1/trust-centers?provider=wolfia",
        "sources": "/v1/sources?provider=wolfia"
      }
    },
    {
      "provider": {
        "id": "konfirmity",
        "name": "Konfirmity",
        "tier": "tier2",
        "adapter_status": "implemented",
        "connect_method": "embedded_json",
        "auth": "none",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": "posture_headings",
          "subprocessors": "posture_text",
          "documents": false,
          "securityUpdates": false
        },
        "rate_limit": {
          "recommendedRps": 5,
          "maxConcurrency": 5,
          "readCeiling": "clean to 15rps but latency-bound (med 0.75s baseline -> ~2s at 15rps); no 429/403",
          "limiter": "self-hosted Caddy reverse proxy (tiny startup origin) — latency-bound, not quota-bound",
          "penalty": "none observed; courtesy matters (small origin)",
          "backoff": "keep RPS + concurrency low; only ~3-4 tenants so 5rps clears them instantly"
        },
        "stats": {
          "providerId": "konfirmity",
          "name": "Konfirmity",
          "adapterStatus": "implemented",
          "organizations": 5,
          "trustCenters": 5,
          "certifications": 22,
          "controls": 260,
          "subprocessors": 0,
          "documents": 0,
          "securityUpdates": 0,
          "sources": 5
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync",
        "rate_limit": {
          "recommendedRps": 5,
          "maxConcurrency": 5,
          "readCeiling": "clean to 15rps but latency-bound (med 0.75s baseline -> ~2s at 15rps); no 429/403",
          "limiter": "self-hosted Caddy reverse proxy (tiny startup origin) — latency-bound, not quota-bound",
          "penalty": "none observed; courtesy matters (small origin)",
          "backoff": "keep RPS + concurrency low; only ~3-4 tenants so 5rps clears them instantly"
        },
        "known_source_count": 6,
        "harvestable_source_count": 2,
        "seed": "seeds/konfirmity-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 5,
        "trust_centers": 5,
        "certifications": 22,
        "controls": 260,
        "subprocessors": 0,
        "documents": 0,
        "security_updates": 0,
        "sources": 5
      },
      "data_surface": {
        "score": 56,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "medium_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": false,
          "documents": false,
          "security_updates": false,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "provenance"
        ],
        "missing_capabilities": [
          "subprocessors",
          "documents",
          "security_updates"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": false,
          "document_inventory": false,
          "compliance_tracking": true,
          "security_advisory_monitoring": false,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 5,
          "certifications": 22,
          "controls": 260,
          "subprocessors": 0,
          "documents": 0,
          "security_updates": 0,
          "sources": 5
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "konfirmity_embedded_next_data",
            "count": 5
          }
        ],
        "access_levels": [
          {
            "key": "unknown",
            "count": 5
          }
        ],
        "data_access": {
          "certifications": 5,
          "controls": 5,
          "subprocessors": 0,
          "documents": 0,
          "security_updates": 0
        }
      },
      "source_registry": {
        "rank": 18,
        "segment": "startup_smb",
        "owner": "Konfirmity (independent)",
        "auth": "none",
        "connect": {
          "method": "embedded_json",
          "fetch": "GET https://{tenantDomain}/",
          "key": "props.pageProps.vendor.security_posture is the structured payload",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "trust-portals.konfirmity.com",
          "handleInCname": false,
          "note": "custom domains CNAME to trust-portals.konfirmity.com; the trust-page payload is an embedded JSON island with ProseMirror content.",
          "fingerprints": [
            "CNAME trust-portals.konfirmity.com",
            "__NEXT_DATA__ props.pageProps.vendor",
            "security_posture ProseMirror"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:Konfirmity"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 4,
          "harvestableNow": 2,
          "netNew": 2,
          "netNewFromCommonCrawl": 0,
          "totalKnown": 6,
          "seed": "seeds/konfirmity-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/konfirmity",
        "provider": "/v1/providers/konfirmity",
        "companies": "/v1/companies?provider=konfirmity",
        "trust_centers": "/v1/trust-centers?provider=konfirmity",
        "sources": "/v1/sources?provider=konfirmity"
      }
    },
    {
      "provider": {
        "id": "noru",
        "name": "Noru",
        "tier": "tier2",
        "adapter_status": "implemented",
        "connect_method": "rsc_flight",
        "auth": "none",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": true,
          "subprocessors": true,
          "documents": "policies",
          "securityUpdates": false
        },
        "rate_limit": {
          "recommendedRps": 10,
          "maxConcurrency": 10,
          "readCeiling": "clean to 15rps; Vercel WAF sheds 403 challenges at ~20rps (12%), 100% 403 by 30rps",
          "limiter": "Vercel edge WAF/bot-challenge — throttles via 403 (NOT 429)",
          "penalty": "403 challenge page (fast ~16ms reject); appears transient, but treat 403 as backpressure",
          "backoff": "treat a 403 spike as throttle; back off + exponential retry. ~2-3 tenants so 10rps is ample"
        },
        "stats": {
          "providerId": "noru",
          "name": "Noru",
          "adapterStatus": "implemented",
          "organizations": 3,
          "trustCenters": 3,
          "certifications": 8,
          "controls": 421,
          "subprocessors": 156,
          "documents": 111,
          "securityUpdates": 0,
          "sources": 3
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync",
        "rate_limit": {
          "recommendedRps": 10,
          "maxConcurrency": 10,
          "readCeiling": "clean to 15rps; Vercel WAF sheds 403 challenges at ~20rps (12%), 100% 403 by 30rps",
          "limiter": "Vercel edge WAF/bot-challenge — throttles via 403 (NOT 429)",
          "penalty": "403 challenge page (fast ~16ms reject); appears transient, but treat 403 as backpressure",
          "backoff": "treat a 403 spike as throttle; back off + exponential retry. ~2-3 tenants so 10rps is ample"
        },
        "known_source_count": 3,
        "harvestable_source_count": 1,
        "seed": "seeds/noru-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 3,
        "trust_centers": 3,
        "certifications": 8,
        "controls": 421,
        "subprocessors": 156,
        "documents": 111,
        "security_updates": 0,
        "sources": 3
      },
      "data_surface": {
        "score": 88,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "deep_security_posture",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": true,
          "documents": true,
          "security_updates": false,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "subprocessors",
          "documents",
          "provenance"
        ],
        "missing_capabilities": [
          "security_updates"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": true,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": false,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 3,
          "certifications": 8,
          "controls": 421,
          "subprocessors": 156,
          "documents": 111,
          "security_updates": 0,
          "sources": 3
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "noru_rsc_flight",
            "count": 3
          }
        ],
        "access_levels": [
          {
            "key": "unknown",
            "count": 3
          }
        ],
        "data_access": {
          "certifications": 3,
          "controls": 2,
          "subprocessors": 3,
          "documents": 3,
          "security_updates": 0
        }
      },
      "source_registry": {
        "rank": 19,
        "segment": "startup_smb",
        "owner": "Noru (independent)",
        "auth": "none",
        "connect": {
          "method": "rsc_flight",
          "fetch": "GET https://{tenantDomain}/",
          "key": "self.__next_f flight payload with trust_page_id item list",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "trust-proxy.noru.tech",
          "handleInCname": false,
          "note": "Next.js App Router trust page behind Vercel; the interesting content is in the RSC flight payload.",
          "fingerprints": [
            "CNAME trust-proxy.noru.tech",
            "self.__next_f flight",
            "trust_page_id item list"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:Noru"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 2,
          "harvestableNow": 1,
          "netNew": 1,
          "netNewFromCommonCrawl": 0,
          "totalKnown": 3,
          "seed": "seeds/noru-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/noru",
        "provider": "/v1/providers/noru",
        "companies": "/v1/companies?provider=noru",
        "trust_centers": "/v1/trust-centers?provider=noru",
        "sources": "/v1/sources?provider=noru"
      }
    },
    {
      "provider": {
        "id": "platformed",
        "name": "Platformed",
        "tier": "tier2",
        "adapter_status": "implemented",
        "connect_method": "public_rest",
        "auth": "none (Basic base64(account_id:))",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": false,
          "subprocessors": "showcase_graph",
          "documents": true,
          "securityUpdates": false
        },
        "rate_limit": {
          "recommendedRps": 15,
          "maxConcurrency": 15,
          "readCeiling": "clean + flat to 20rps (~184ms); deliberately capped at 20 (Google Frontend infra, same family as SecurityPal's sharp cliff + multi-min block — not worth pinpointing)",
          "limiter": "Google Frontend in front of app.platformed.com REST",
          "penalty": "none observed to 20; assume a sharp Google-Frontend cliff somewhere past there",
          "backoff": "stay <=15rps; exponential backoff on any 429. ~4 tenants x 2-3 calls = trivial volume"
        },
        "stats": {
          "providerId": "platformed",
          "name": "Platformed",
          "adapterStatus": "implemented",
          "organizations": 2,
          "trustCenters": 2,
          "certifications": 4,
          "controls": 0,
          "subprocessors": 22,
          "documents": 19,
          "securityUpdates": 0,
          "sources": 2
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync",
        "rate_limit": {
          "recommendedRps": 15,
          "maxConcurrency": 15,
          "readCeiling": "clean + flat to 20rps (~184ms); deliberately capped at 20 (Google Frontend infra, same family as SecurityPal's sharp cliff + multi-min block — not worth pinpointing)",
          "limiter": "Google Frontend in front of app.platformed.com REST",
          "penalty": "none observed to 20; assume a sharp Google-Frontend cliff somewhere past there",
          "backoff": "stay <=15rps; exponential backoff on any 429. ~4 tenants x 2-3 calls = trivial volume"
        },
        "known_source_count": 5,
        "harvestable_source_count": 1,
        "seed": "seeds/platformed-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 2,
        "trust_centers": 2,
        "certifications": 4,
        "controls": 0,
        "subprocessors": 22,
        "documents": 19,
        "security_updates": 0,
        "sources": 2
      },
      "data_surface": {
        "score": 66,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "high_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": false,
          "subprocessors": true,
          "documents": true,
          "security_updates": false,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "subprocessors",
          "documents",
          "provenance"
        ],
        "missing_capabilities": [
          "controls",
          "security_updates"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": false,
          "subprocessor_monitoring": true,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": false,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 2,
          "certifications": 4,
          "controls": 0,
          "subprocessors": 22,
          "documents": 19,
          "security_updates": 0,
          "sources": 2
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "platformed_public_rest",
            "count": 2
          }
        ],
        "access_levels": [
          {
            "key": "unknown",
            "count": 2
          }
        ],
        "data_access": {
          "certifications": 2,
          "controls": 0,
          "subprocessors": 2,
          "documents": 2,
          "security_updates": 0
        }
      },
      "source_registry": {
        "rank": 20,
        "segment": "startup_smb",
        "owner": "Platformed (independent)",
        "auth": "none (Basic base64(account_id:))",
        "connect": {
          "method": "public_rest",
          "resolve": "GET https://app.platformed.com/external_api/accounts_by_slug/{slug} -> {accountId, region}",
          "fetch": "GET https://app.platformed.com/region/{region}/external_api/accounts/{accountId}/showcase/{config,faq,documents,graph}",
          "key": "slug from trust.platformed.com/{slug}/info; auth is Basic base64(account_id:)",
          "officialApi": null
        },
        "discovery": {
          "cnameTarget": "dns0.trust.platformed.com",
          "handleInCname": false,
          "note": "React SPA fronted by a public REST API; the slug is resolved server-side before the showcase payload is fetched.",
          "fingerprints": [
            "trust.platformed.com/{slug}/info",
            "app.platformed.com/external_api/accounts_by_slug",
            "app.platformed.com/region/{region}/external_api/accounts/{id}/showcase"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:Platformed"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 1,
          "harvestableNow": 1,
          "netNew": 4,
          "netNewFromCommonCrawl": 0,
          "totalKnown": 5,
          "seed": "seeds/platformed-backfill-2026-06-11.json"
        }
      },
      "links": {
        "self": "/v1/coverage/providers/platformed",
        "provider": "/v1/providers/platformed",
        "companies": "/v1/companies?provider=platformed",
        "trust_centers": "/v1/trust-centers?provider=platformed",
        "sources": "/v1/sources?provider=platformed"
      }
    },
    {
      "provider": {
        "id": "vanta",
        "name": "Vanta Trust Center",
        "tier": "tier1",
        "adapter_status": "implemented",
        "connect_method": "signed_graphql",
        "auth": "none (constant CSRF header + pre-signed query manifest)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": true,
          "subprocessors": true,
          "documents": true,
          "securityUpdates": "publicUpdates_when_present"
        },
        "rate_limit": {
          "recommendedRps": 8,
          "maxConcurrency": 6,
          "readCeiling": "Cloudflare-fronted same-origin GraphQL; ~2 signed POSTs/tenant. No 429 observed at low concurrency.",
          "limiter": "Cloudflare in front of the tenant origin / app.vanta.com",
          "penalty": "401 Invalid signature if the pinned query text drifts from the live bundle version (re-capture queries + manifest)",
          "backoff": "keep <=6 concurrent; memoize the signature manifest per client version across the batch"
        },
        "stats": {
          "providerId": "vanta",
          "name": "Vanta Trust Center",
          "adapterStatus": "implemented",
          "organizations": 2106,
          "trustCenters": 2106,
          "certifications": 5425,
          "controls": 132783,
          "subprocessors": 15140,
          "documents": 8380,
          "securityUpdates": 0,
          "sources": 2106
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync_with_provider_rate_limit",
        "rate_limit": {
          "recommendedRps": 8,
          "maxConcurrency": 6,
          "readCeiling": "Cloudflare-fronted same-origin GraphQL; ~2 signed POSTs/tenant. No 429 observed at low concurrency.",
          "limiter": "Cloudflare in front of the tenant origin / app.vanta.com",
          "penalty": "401 Invalid signature if the pinned query text drifts from the live bundle version (re-capture queries + manifest)",
          "backoff": "keep <=6 concurrent; memoize the signature manifest per client version across the batch"
        },
        "known_source_count": 2675,
        "harvestable_source_count": 2675,
        "seed": "seeds/vanta-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 2106,
        "trust_centers": 2106,
        "certifications": 5425,
        "controls": 132783,
        "subprocessors": 15140,
        "documents": 8380,
        "security_updates": 0,
        "sources": 2106
      },
      "data_surface": {
        "score": 88,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "deep_security_posture",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": true,
          "documents": true,
          "security_updates": false,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "subprocessors",
          "documents",
          "provenance"
        ],
        "missing_capabilities": [
          "security_updates"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": true,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": false,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 2106,
          "certifications": 5425,
          "controls": 132783,
          "subprocessors": 15140,
          "documents": 8380,
          "security_updates": 0,
          "sources": 2106
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "vanta_signed_graphql",
            "count": 2106
          }
        ],
        "access_levels": [
          {
            "key": "unknown",
            "count": 2106
          }
        ],
        "data_access": {
          "certifications": 1894,
          "controls": 2038,
          "subprocessors": 1431,
          "documents": 1287,
          "security_updates": 0
        }
      },
      "source_registry": {
        "rank": 2,
        "segment": "smb_to_enterprise",
        "owner": "Vanta (independent; platform cites 16k+ customers)",
        "auth": "signed_graphql_query_reusable_across_tenants",
        "connect": {
          "method": "graphql",
          "fetchSlug": "GET https://{tenantDomain}/ -> html attr data-slugid",
          "fetch": "POST https://{tenantDomain}/graphql?operation=fetchDataForTrustReport",
          "body": "captured {query, extensions.signedQuery} with variables.slugId swapped per tenant",
          "operations": [
            "fetchDataForTrustReport",
            "fetchReportContext",
            "fetchCustomizableControlsDataForExternalTrustCenter",
            "SubprocessorsSectionPaginated",
            "fetchFaqsForOverviewPage",
            "linkedTrustCenters"
          ],
          "signatureNote": "signature signs query string only, NOT variables; one capture harvests all tenants; re-capture on TTL/schema change",
          "officialApi": "GET api.vanta.com/v1/trust-centers/{slugId} (OAuth bearer, per-customer, NOT usable cross-tenant)"
        },
        "discovery": {
          "cnameTarget": "{trustCenterId24hex}.cname.vantatrust.com",
          "handleInCname": false,
          "fingerprints": [
            "CNAME *.cname.vantatrust.com",
            "assets.vanta.com bundles",
            "data-slugid attr"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:Vanta"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 6,
          "harvestableNow": 2675,
          "netNew": 2669,
          "totalKnown": 2675,
          "commonCrawlFloor": 2455,
          "observedHostDomains": 2628,
          "missingObservedHostDomains": 47,
          "unit": "companyDomain; observedHosts retained where present in raw CNAME resolution files",
          "sourceChannels": [
            "Common Crawl ccindex host enumeration over trust/security/compliance prefixes",
            "live CNAME resolution against vendor fingerprints",
            "URLScan and Certificate Transparency enrichment",
            "7,144-company status-page corpus CNAME sweep"
          ],
          "seed": "seeds/vanta-backfill-2026-06-11.json",
          "notes": "Confirmed source-registry floor from full top-five discovery pass; adapter hydration still needs signed GraphQL replay."
        }
      },
      "links": {
        "self": "/v1/coverage/providers/vanta",
        "provider": "/v1/providers/vanta",
        "companies": "/v1/companies?provider=vanta",
        "trust_centers": "/v1/trust-centers?provider=vanta",
        "sources": "/v1/sources?provider=vanta"
      }
    },
    {
      "provider": {
        "id": "safebase",
        "name": "SafeBase",
        "tier": "tier1",
        "adapter_status": "implemented",
        "connect_method": "impersonated_rest",
        "auth": "none (Cloudflare bot-protected; curl_cffi Chrome TLS impersonation via scripts/safebase-fetch.py)",
        "normalized_coverage": {
          "organizations": true,
          "certifications": true,
          "controls": true,
          "subprocessors": "when_public",
          "documents": true,
          "securityUpdates": true
        },
        "rate_limit": {
          "recommendedRps": 4,
          "maxConcurrency": 4,
          "readCeiling": "Cloudflare bot mode blocks plain Node/curl entirely; curl_cffi chrome136 passes. ~3 GETs/tenant.",
          "limiter": "Cloudflare bot management (TLS/JA3 + challenge) on the tenant origin",
          "penalty": "blocked_challenge ('Just a moment...') for non-impersonated clients",
          "backoff": "stay <=4 concurrent on the Python side; min request interval courtesy throttle"
        },
        "stats": {
          "providerId": "safebase",
          "name": "SafeBase",
          "adapterStatus": "implemented",
          "organizations": 754,
          "trustCenters": 754,
          "certifications": 4013,
          "controls": 56823,
          "subprocessors": 0,
          "documents": 16187,
          "securityUpdates": 1126,
          "sources": 754
        }
      },
      "target_support": {
        "support_status": "supported",
        "sync_cadence": "daily_full_sync_with_provider_rate_limit",
        "rate_limit": {
          "recommendedRps": 4,
          "maxConcurrency": 4,
          "readCeiling": "Cloudflare bot mode blocks plain Node/curl entirely; curl_cffi chrome136 passes. ~3 GETs/tenant.",
          "limiter": "Cloudflare bot management (TLS/JA3 + challenge) on the tenant origin",
          "penalty": "blocked_challenge ('Just a moment...') for non-impersonated clients",
          "backoff": "stay <=4 concurrent on the Python side; min request interval courtesy throttle"
        },
        "known_source_count": 1104,
        "harvestable_source_count": 1104,
        "seed": "seeds/safebase-backfill-2026-06-11.json"
      },
      "counts": {
        "companies": 754,
        "trust_centers": 754,
        "certifications": 4013,
        "controls": 56823,
        "subprocessors": 0,
        "documents": 16187,
        "security_updates": 1126,
        "sources": 754
      },
      "data_surface": {
        "score": 84,
        "score_kind": "bounded_0_to_100_observed_normalized_trust_center_coverage",
        "granularity_tier": "high_granularity",
        "observed_capabilities": {
          "trust_centers": true,
          "certifications": true,
          "controls": true,
          "subprocessors": false,
          "documents": true,
          "security_updates": true,
          "provenance": true
        },
        "available_capabilities": [
          "trust_centers",
          "certifications",
          "controls",
          "documents",
          "security_updates",
          "provenance"
        ],
        "missing_capabilities": [
          "subprocessors"
        ],
        "analysis_readiness": {
          "vendor_risk_profile": true,
          "security_questionnaire_evidence": true,
          "subprocessor_monitoring": false,
          "document_inventory": true,
          "compliance_tracking": true,
          "security_advisory_monitoring": true,
          "provenance_audit": true
        },
        "counts": {
          "trust_centers": 754,
          "certifications": 4013,
          "controls": 56823,
          "subprocessors": 0,
          "documents": 16187,
          "security_updates": 1126,
          "sources": 754
        }
      },
      "trust_centers": {
        "access_profiles": [
          {
            "key": "safebase_curl_cffi_rest",
            "count": 754
          }
        ],
        "access_levels": [
          {
            "key": "unknown",
            "count": 754
          }
        ],
        "data_access": {
          "certifications": 732,
          "controls": 722,
          "subprocessors": 0,
          "documents": 697,
          "security_updates": 230
        }
      },
      "source_registry": {
        "rank": 1,
        "segment": "enterprise",
        "owner": "Drata (acquired ~2025, ~$250M)",
        "auth": "none (Chrome TLS/client fingerprint required for direct HTTP)",
        "connect": {
          "method": "embedded_json_or_public_rest_curl_cffi",
          "fetch": "GET https://{tenantDomain}/ with curl_cffi impersonate=chrome136",
          "extract": "script#__NEXT_DATA__ -> props.pageProps.orgInfo",
          "officialApi": "app.safebase.io/api/ext/v1/rest (per-customer API key, NOT usable cross-tenant)",
          "publicApi": "tenant-relative /api/trust-center/public/{orgUuid} and /api/statuspage/share/{orgUuid}/public/compliance-update"
        },
        "discovery": {
          "cnameTarget": "{companyHandle}.portals.safebase.io",
          "handleInCname": true,
          "fingerprints": [
            "CNAME *.portals.safebase.io",
            "app.safebase.io assets",
            "__NEXT_DATA__ orgInfo",
            "Powered by SafeBase footer"
          ],
          "channels": [
            "dns_cname_sweep",
            "crt.sh",
            "builtwith:SafeBase"
          ]
        },
        "backfill_2026_06_11": {
          "priorKnown": 7,
          "harvestableNow": 1104,
          "netNew": 1097,
          "totalKnown": 1104,
          "commonCrawlFloor": 969,
          "observedHostDomains": 1073,
          "missingObservedHostDomains": 31,
          "unit": "companyDomain; observedHosts retained where present in raw CNAME resolution files",
          "sourceChannels": [
            "Common Crawl ccindex host enumeration over trust/security/compliance prefixes",
            "live CNAME resolution against vendor fingerprints",
            "URLScan and Certificate Transparency enrichment",
            "7,144-company status-page corpus CNAME sweep"
          ],
          "seed": "seeds/safebase-backfill-2026-06-11.json",
          "notes": "Confirmed source-registry floor; SafeBase disables SEO crawling on many tenants, so this is strong but not a full census."
        }
      },
      "links": {
        "self": "/v1/coverage/providers/safebase",
        "provider": "/v1/providers/safebase",
        "companies": "/v1/companies?provider=safebase",
        "trust_centers": "/v1/trust-centers?provider=safebase",
        "sources": "/v1/sources?provider=safebase"
      }
    }
  ],
  "pagination": {
    "total": 13,
    "limit": 50,
    "offset": 0,
    "nextOffset": null,
    "next_offset": null
  }
}
