{
  "record_id": "WEB-20260804-01",
  "scope": "https://theseengroup.ai/",
  "scope_description": "The theseengroup.ai public website and its published paths; other domains, subdomains and product systems are excluded.",
  "observed_at": "2026-08-04T08:28:55+10:00",
  "evidence_type": "point-in-time",
  "disclaimer": "This record is not continuous monitoring, a penetration test, audit opinion, Essential Eight assessment, certification, accreditation or statement about The SEEN Group's wider systems or any product system.",
  "checks": [
    {
      "id": "delivery-boundary",
      "state": "observed-live",
      "evidence_class": ["publicly-verifiable", "operator-verified"],
      "evidence_basis": "Live HTTPS response and delivery configuration",
      "observation": "HTTP redirects to HTTPS; TLS 1.2 or later is required at the viewer boundary; HSTS is enabled; HTTP/2 and HTTP/3 are available.",
      "limit": "No penetration test or client-compatibility assessment was performed."
    },
    {
      "id": "response-policy",
      "state": "observed-live",
      "evidence_class": ["publicly-verifiable"],
      "evidence_basis": "Headers returned by the live website",
      "observation": "The live response includes Content Security Policy, frame denial, MIME-sniffing protection, restrictive referrer and browser-permission policies, and cross-origin opener and resource policies.",
      "limit": "Presence of a header does not establish the effectiveness of every browser or application control."
    },
    {
      "id": "content-origin",
      "state": "configured-when-checked",
      "evidence_class": ["operator-verified"],
      "evidence_basis": "Storage and content-delivery configuration",
      "observation": "The storage origin is not publicly readable; public-access blocks are enabled; the bucket policy is non-public; website objects are delivered through restricted origin access at the edge.",
      "limit": "Account administration, identity controls and provider effectiveness were not assessed."
    },
    {
      "id": "published-runtime",
      "state": "observed-live",
      "evidence_class": ["publicly-verifiable"],
      "evidence_basis": "Deployed pages, assets and network requests",
      "observation": "No third-party executable script, advertising tag, analytics runtime or embedded contact form was present in the published pages inspected. Fonts, styles, scripts and media are served locally.",
      "limit": "Network and email providers still process routine connection data; email correspondence occurs outside this website."
    },
    {
      "id": "object-recovery",
      "state": "configured-when-checked",
      "evidence_class": ["operator-verified"],
      "evidence_basis": "Storage configuration",
      "observation": "Storage object versioning was enabled when checked and may help recover an overwritten website object.",
      "limit": "This is not evidence of an independent backup, immutable retention, disaster-recovery capability or a tested restore."
    },
    {
      "id": "request-visibility",
      "state": "known-limitation",
      "evidence_class": ["operator-verified"],
      "evidence_basis": "Content-delivery configuration",
      "observation": "Standard content-delivery request logging was not enabled when checked.",
      "limit": "No statement is made here about request-level monitoring or incident-detection coverage."
    },
    {
      "id": "security-contact",
      "state": "observed-live",
      "evidence_class": ["publicly-verifiable"],
      "evidence_basis": "https://theseengroup.ai/.well-known/security.txt",
      "observation": "A canonical machine-readable security contact is published with an expiry of 31 July 2027 and points back to the trust policy.",
      "limit": "Email contact only; no response-time commitment or bug-bounty programme is stated."
    }
  ]
}
