An agency verifies your package, ungated. No one else can show you that.
CR26 makes you serve your certification data programmatically, ungated, with an access log. We generate that package and serve it through a conformant trust center that runs in your own account. A practitioner signs it. An agency verifies it against your account, and we never touch the bytes.
Three obligations, satisfied on their face.
CR26 turns 'publish a trust page' into a hard, testable contract. A gated portal fails it. A conformant trust center meets each rule the way an assessor checks it.
- CDS-TRC-PAC
Programmatic access
An agency pulls all of your certification data over one documented API route, the human-readable materials included, with no login in the way.
served from your account, one route - CDS-TRC-USH
Uninterrupted sharing
Every authorized party gets the data on demand. No request-and-approve step stands between an agency and a pull.
on demand, no manual approval - CDS-TRC-ACL
Access logging
Every pull is logged, and the summaries are retained for at least six months.
logged, 6-month retention
In your account, read-only, never ours.
The agents run read-only inside your own account. CR26 binds the provider, and the provider is you. Only aggregate counts, one-way digests, a signature, and a rules version reach TRGR.
Generated from live state. Signed by a practitioner.
We generate every artifact CR26 requires from your running system and validate it against the FedRAMP schema. A practitioner reviews and signs before an agency can pull anything. AI drafts the narrative, but never gets the last word.
The authorization keeps pace with the system.
A package is accurate the day it is signed. Continuous monitoring compares the running system to the authorized baseline, surfaces drift from the approved state, and routes a change to a practitioner. The checking is deterministic, and nothing is applied on its own. You choose the cadence, from one hour to thirty days.
Explore the agent suite