{
  "accepted_pcr0s": [
    "c0b3e5d96c3af6a61861d21ba93b6b80606c80d941e48c098a56acd4616ce23cd9ce9520baf35dc1798134939cc41f2b"
  ],
  "api_base_url": "https://api-aws.trustedrouter.com/v1",
  "attestation_format": "cose-sign1-nitro-attestation-document",
  "attestation_root": "https://aws-nitro-enclaves.amazonaws.com/AWS_NitroEnclaves_Root-G1.zip",
  "data_policy": {
    "client_telemetry_content_free": true,
    "client_telemetry_disclosure": "https://trustedrouter.com/docs/telemetry",
    "control_plane_prompt_access": false,
    "prompt_output_storage": false
  },
  "measurement_type": "nitro-pcr0-sha384",
  "observed_module_id": "i-0dd7ffc39f21a031f-enc01a088362c640489",
  "pcr0": "c0b3e5d96c3af6a61861d21ba93b6b80606c80d941e48c098a56acd4616ce23cd9ce9520baf35dc1798134939cc41f2b",
  "platform": "aws-nitro-enclaves",
  "release_state": "current",
  "reproduce": "tools/verify-pcr0.sh",
  "source_commit": "00573cf9e6445c5cf1a078a88a3b053e8360547d",
  "source_commit_provenance": "operator-asserted",
  "source_repo": "https://github.com/Lore-Hex/quill-cloud-proxy",
  "tls": {
    "certificate_binding": "user_data[0:32]=SHA-256 of the served certificate (DER), user_data[64:96]=TLS exporter channel binding",
    "hostname": "api-aws.trustedrouter.com",
    "mode": "acme-inside-nitro-enclave"
  },
  "transparency": {
    "bundle": "aws-release.json.bundle",
    "certificate_identity": "https://github.com/Lore-Hex/quill-cloud-proxy/.github/workflows/publish-trust-aws.yml@refs/heads/main",
    "certificate_oidc_issuer": "https://token.actions.githubusercontent.com",
    "newest_check": "The signature proves who wrote this record and when, not that it is the newest one. Search the transparency log for the identity above; the log is append-only, so a newer entry cannot be hidden from you. The bundle carries a Signed Entry Timestamp but no inclusion proof, so confirming log membership requires querying Rekor.",
    "running_check": "Neither the signature nor the log says this measurement is still what is RUNNING \u2014 an unchanged deployment should carry an old signature, so age is not drift. Fetch a live attestation from api_base_url and compare it against the accepted set in this record.",
    "transparency_log": "https://rekor.sigstore.dev",
    "verify": "cosign verify-blob --bundle aws-release.json.bundle --certificate-identity https://github.com/Lore-Hex/quill-cloud-proxy/.github/workflows/publish-trust-aws.yml@refs/heads/main --certificate-oidc-issuer https://token.actions.githubusercontent.com aws-release.json"
  }
}
