{
  "claimBoundary": "CapitalGuard Agent Security License 1.0 verifies an owner-controlled Ed25519 authority, an owner-issued agent security license, a current signed revocation history and anchor, and an agent-key proof bound to the exact Enforced Mode launch material before an authenticated managed session starts. It proves possession of the enrolled agent private key at enrollment and launch within the configured trust domain. It does not prove the human or legal identity behind enrollment, attest an unmeasured host, kernel, OCI runtime, or model, prevent private-key theft or host compromise, continuously re-attest a running process, control agents launched outside the authenticated path, or prove revocation freshness if the separately protected current anchor is rolled back with the ledger.",
  "licensedExecutable": {
    "bytes": 803051,
    "distribution": "licensed_delivery_only",
    "filename": "capitalguard-agent-identity-gate.cjs",
    "sha256": "e5df05005ffb2a801be02b8a133bb69f486f8f6619dd40717822cf07549b1fbb"
  },
  "protocolVersion": "1.0.0",
  "publicArtifacts": [
    {
      "bytes": 4082,
      "filename": "authority.schema.json",
      "sha256": "6ae487c95cafd2b4a4c15657e6a98b987b9f97afd14187a34ba7073f658ca316"
    },
    {
      "bytes": 5414,
      "filename": "enrollment-request.schema.json",
      "sha256": "0e439685346fb939cb34e4d1fdf304e4d22e32597c0b2e129c9750b4c97d8030"
    },
    {
      "bytes": 5865,
      "filename": "license.schema.json",
      "sha256": "81094895d953a27db9a61400bbd1388ed4906909b0aaa98bbb74fd390ed5b748"
    },
    {
      "bytes": 3103,
      "filename": "methodology.json",
      "sha256": "dd55e289ffd5c41ac1acd98daf40a6eb04966685446b98cf652929b23b901e58"
    },
    {
      "bytes": 6140,
      "filename": "public-record.schema.json",
      "sha256": "0de7e1f92f04c3229717972e1021d68fbece320096f99de74cc71bae8c98fb06"
    },
    {
      "bytes": 2940,
      "filename": "revocation-anchor.schema.json",
      "sha256": "2a74bd560f66ee11319e2f446aa67485f604ce0066a29ecd46528434e2f1eb0b"
    },
    {
      "bytes": 5203,
      "filename": "revocation-ledger.schema.json",
      "sha256": "0a8edc1733c960cd8bb3ba905e437cdc8c3e0bd849be02d4160c0f15c7af2a08"
    },
    {
      "bytes": 5125,
      "filename": "session-proof.schema.json",
      "sha256": "c7af8fff085bb11a31c2ae7688aacff8e34b3845e2cf13d73fc99967b1cd9601"
    },
    {
      "bytes": 3605,
      "filename": "support-matrix.json",
      "sha256": "8a77db259d17a37e31323932981e4145f097dcbbd4dd9e3259f904eebdd33739"
    },
    {
      "bytes": 13629,
      "filename": "test-vectors.json",
      "sha256": "0abf2f9446223c4028c15911eef716ddd0fe69655cc2a915b105712d9b3b2303"
    },
    {
      "bytes": 2038,
      "filename": "threat-model.json",
      "sha256": "de7d2ee9a9a61cba23d8389b71d57c6c2f5af1933f7b1756369bdf22489b2cfc"
    }
  ],
  "releaseDigestSha256": "1c88d63229874a9afb2d5e7ff83603d2b2e99850cf6353426defd710e6b0da47",
  "releasedAt": "2026-07-23T13:13:17.000Z",
  "requiredLicensedCompanion": "capitalguard-enclave-mcp.mjs",
  "schemas": {
    "authority": "cg-agent-security-license-authority-1.0.0",
    "enrollmentRequest": "cg-agent-security-license-enrollment-1.0.0",
    "license": "cg-agent-security-license-1.0.0",
    "publicRecord": "cg-agent-security-license-record-1.0.0",
    "revocationAnchor": "cg-agent-security-license-revocation-anchor-1.0.0",
    "revocationLedger": "cg-agent-security-license-revocation-ledger-1.0.0",
    "sessionProof": "cg-agent-security-license-session-proof-1.0.0"
  },
  "version": "1.0.0"
}
