{"rule":"Describe implemented controls accurately; never imply an external certification that has not been obtained.","operatingStandard":"docs/NEXUS_TRUST_OPERATIONS_STANDARD.md","dimensions":[{"name":"Payment integrity","status":"implemented","evidence":"Server-side LIVE Stripe entitlement verification."},{"name":"Auditability","status":"implemented","evidence":"API gateway audit middleware and audit repository."},{"name":"Rate limiting","status":"implemented","evidence":"Gateway rate-limit middleware plus tests."},{"name":"Project isolation","status":"implemented","evidence":"Supabase RLS/project-isolation security tests."},{"name":"Least privilege","status":"partial","evidence":"Scoped agent/tool architecture and credential-operations controls exist; per-product provider credential/network scope review remains in progress.","nextAction":"Complete and retain a provider-by-provider privilege-scope review."},{"name":"Secret rotation","status":"partial","evidence":"Environment/secret-manager based secrets and a rotation runbook now exist; a completed production rotation evidence record is still required.","nextAction":"Perform and record a production secret rotation without exposing secret values."},{"name":"Data minimization","status":"implemented","evidence":"Nexus sales telemetry stores product/event/payment metadata rather than raw customer working payloads; operating standard prohibits copying prompts, documents, API payloads or secrets into analytics merely for telemetry."},{"name":"Retention policy","status":"partial","evidence":"A technical retention standard is now defined; definitive public retention periods still require owner/legal approval and corresponding enforcement where applicable.","nextAction":"Approve final customer-facing retention periods and implement any required expiry/archive jobs."},{"name":"Uptime/SLO history","status":"partial","evidence":"Runtime health and Nexus telemetry-health endpoints exist; long-term production availability history still needs to accumulate before an uptime percentage is published.","nextAction":"Accumulate dated production measurements before publishing an SLA/SLO percentage."},{"name":"Incident response","status":"partial","evidence":"Autonomous recovery/circuit-breaker architecture and a formal incident lifecycle/severity standard now exist; an exercised tabletop or live drill evidence record is still needed.","nextAction":"Run and retain evidence from an incident-response tabletop/drill."},{"name":"External attestation","status":"external_action_needed","evidence":"SOC 2, ISO 27001, independent penetration-test attestation or similar external assurance has not been claimed.","nextAction":"Engage an independent assessor only when commercially justified."}]}