{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:d1cb219c8f6be3606007166b616e13fb46fee27507930122f428f1d5487097e1",
  "snapshot_id": "sha256:8db906c37dc35bf6e8df843040b7f32c327bba323267bca2883a52bb1d8067fd",
  "artifact_sha256": "sha256:87212334630b6cafa0454a71349079c604bd4373a0518fb676c7623bfd194016",
  "data": {
    "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t",
    "entity_slug": "cloudflare",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01m08rqxyvw1151ymp6kaxfgcc",
      "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t",
      "scope": {
        "product": {
          "key": "cloudflare-public-dns",
          "name": "Cloudflare 1.1.1.1 Public DNS"
        },
        "funnel": {
          "key": "dns-over-https-query",
          "name": "DNS over HTTPS query"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:cddeb11506db30b6ffb13fcff407b1931f123a1eb2cc8edf5ca023ba03c71100"
      },
      "declaration_revision_digest": "sha256:65bf30248c0a730476c82afd8471be2e33d54397a1e8a63b0e34d235315bed5f",
      "declaration": {
        "declaration_id": "declaration_cloudflare_public_dns_over_https",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/cl/cloudflare.yaml",
          "git_blob_oid": "4499cb0c38945f75501557dd38021a37d46c2f87",
          "blob_digest": "sha256:55def0b3b8a18e6566c98d0ba1f514659988fd9dad49d001a7125194470f8948"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Resolve public DNS records through DNS over HTTPS",
            "interface_ids": [
              "doh-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "cloudflare-public-dns",
            "roles": [
              "operations_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "doh-json-contract",
            "uri": "https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-https/make-api-requests/dns-json/",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "doh-reference",
            "uri": "https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-https/make-api-requests/",
            "roles": [
              "discovery",
              "documentation",
              "operations",
              "status"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "extended-errors",
            "uri": "https://developers.cloudflare.com/1.1.1.1/infrastructure/extended-dns-error-codes/",
            "roles": [
              "documentation",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "public-dns-overview",
            "uri": "https://developers.cloudflare.com/1.1.1.1/",
            "roles": [
              "discovery",
              "documentation",
              "eligibility",
              "pricing"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "public-dns-terms",
            "uri": "https://www.cloudflare.com/policies/terms/",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "upstream-resolution",
            "uri": "https://developers.cloudflare.com/1.1.1.1/upstream-resolution/",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "doh-endpoint",
            "uri": "https://cloudflare-dns.com/dns-query",
            "transport": "http",
            "roles": [
              "service"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "doh-api",
            "modality": "network_api",
            "functions": [
              "service_operation"
            ],
            "endpoint_ids": [
              "doh-endpoint"
            ],
            "resource_ids": [
              "doh-json-contract",
              "doh-reference",
              "extended-errors",
              "upstream-resolution"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          }
        ],
        "relations": [
          {
            "relation_id": "doh-json-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "doh-json-contract"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "doh-api"
            }
          },
          {
            "relation_id": "doh-reference-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "doh-reference"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "doh-api"
            }
          },
          {
            "relation_id": "errors-describe-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "extended-errors"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "doh-api"
            }
          },
          {
            "relation_id": "upstream-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "upstream-resolution"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "doh-api"
            }
          }
        ],
        "surface_exclusions": [
          {
            "exclusion_id": "no-access-bootstrap",
            "role": "access",
            "rationale": "The public DNS resolver is available without a subscription or Cloudflare account, so no access bootstrap applies."
          },
          {
            "exclusion_id": "no-checkout-step",
            "role": "checkout",
            "rationale": "The public DNS resolver is available without a subscription or Cloudflare account, so no checkout step applies."
          },
          {
            "exclusion_id": "no-operation-authentication",
            "role": "authentication",
            "rationale": "Cloudflare states that no authentication is required to send requests to the DNS over HTTPS API."
          },
          {
            "exclusion_id": "no-provisioning-step",
            "role": "provisioning",
            "rationale": "DNS queries are submitted directly to the public endpoint, so no resource provisioning step applies."
          }
        ]
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T05:45:00.000Z",
      "revision_digest": "sha256:9aee48b9f63de43781929ede8fdf938fceb211061e3c5a27d84d941bf3359370",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "pass",
      "public_state": "ready",
      "state_label": "Ready",
      "grade": "A+",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "limitations": [],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "service_discovery",
            "condition": "Can an agent find the exact service and its stable entrypoints?",
            "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
            "context": "The exact DNS over HTTPS resolver endpoint for programmatic API requests is publicly discoverable at https://cloudflare-dns.com/dns-query and requires no authentication."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "terms_access",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "context": "Cloudflare's Website and Online Services Terms of Use explicitly govern publicly available services including the 1.1.1.1 Public DNS Resolver service."
            },
            {
              "signal_code": "eligibility_decidability",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "context": "Cloudflare's public DNS resolver 1.1.1.1 is available on all plans and free, requiring no special software and taking minutes to set up."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "Cloudflare explicitly declares that 1.1.1.1 is free."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:55:57.821Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:014f9f042a74e6d24c7dbe144137861f5c17b370b7b6ba8d79784f049c4d2026",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:109a0bbccec2bc7a379364697733d6dbbb8f3f8e2759aa30256b9edf3b3142b7",
                    "sha256:34c623d9d676e73b828ecbe56320fbb80fc121024c9613853a3133a7620d4fb9",
                    "sha256:732f5d65d11ece9f9d28b6d45c362b690dec582a9e1020cd2e5e4889f2fc46be",
                    "sha256:f7099461e39814dc4f353ace71fb90a2c495f9fbbb4d89763f3530c34eddb5af"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:34c623d9d676e73b828ecbe56320fbb80fc121024c9613853a3133a7620d4fb9",
                      "start_byte": 8294,
                      "end_byte": 9109,
                      "value_digest": "sha256:a97676fe5a1508d0238fe028050e322a20175829b1d6326cf2f88c3654bd3432"
                    },
                    {
                      "artifact_digest": "sha256:34c623d9d676e73b828ecbe56320fbb80fc121024c9613853a3133a7620d4fb9",
                      "start_byte": 9110,
                      "end_byte": 9909,
                      "value_digest": "sha256:8e7e7b3b908c2278eaacf81fc5c44983a7632fefbcfc58f568a08f414a534f7e"
                    }
                  ]
                }
              ],
              "note": "Cloudflare's public DNS resolver 1.1.1.1 is available on all plans and free, requiring no special software and taking minutes to set up."
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:55:57.821Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:014f9f042a74e6d24c7dbe144137861f5c17b370b7b6ba8d79784f049c4d2026",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0a23244f05e7ec8f98b96ba6d9987e31e455c4a0898443ef899fad384d5f1e39",
                    "sha256:109a0bbccec2bc7a379364697733d6dbbb8f3f8e2759aa30256b9edf3b3142b7",
                    "sha256:34c623d9d676e73b828ecbe56320fbb80fc121024c9613853a3133a7620d4fb9",
                    "sha256:732f5d65d11ece9f9d28b6d45c362b690dec582a9e1020cd2e5e4889f2fc46be"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:34c623d9d676e73b828ecbe56320fbb80fc121024c9613853a3133a7620d4fb9",
                      "start_byte": 9110,
                      "end_byte": 9909,
                      "value_digest": "sha256:8e7e7b3b908c2278eaacf81fc5c44983a7632fefbcfc58f568a08f414a534f7e"
                    }
                  ]
                }
              ],
              "note": "Cloudflare explicitly declares that 1.1.1.1 is free."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:44.351Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "doh-reference"
                },
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0f3f03b6852ce5cf5f3197c0d49e60030caf36368e8284e7c558ec33075c8aa5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4ee40bf93450098770ac2deb7c285d5571991c974301a646489ecd610c9263ae",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                    "sha256:f4a5981ff39dbbd738ca38c0c59a6f5be4c4f3e98c6f1271c96f959a328facaa"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "doh-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                      "start_byte": 9300,
                      "end_byte": 10096,
                      "value_digest": "sha256:53c66d17b6c439f6d3cbc3bfa80e3416443535e382981f97fc3ead21a2443306"
                    }
                  ]
                }
              ],
              "note": "The exact DNS over HTTPS resolver endpoint for programmatic API requests is publicly discoverable at https://cloudflare-dns.com/dns-query and requires no authentication."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:17.521Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d6cecb57cc9c83d8ad9c6fba671be9f07496adf8a979cd0a084e33549e6c85e3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1a85cae032b6df6c7bfffa3b9eee84542877989b41d46d86a820715e1457a60f",
                    "sha256:2b9377eaffebbce4fc8a3a6fd599d5a4c1c14450a429613350045dc3bead2cae",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 3964,
                      "end_byte": 4764,
                      "value_digest": "sha256:94bff3842bcbd936614c23b62afdf18317fdfe7ff902d13ce8bcc56dc4193486"
                    },
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare's Website and Online Services Terms of Use explicitly govern publicly available services including the 1.1.1.1 Public DNS Resolver service."
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "not_applicable",
          "public_state": "not_applicable",
          "state_label": "Not applicable",
          "primary_finding": {
            "signal_code": "access_entrypoint_stability",
            "condition": "Is there a stable route to begin obtaining service access?",
            "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
            "context": "Cloudflare Terms of Use explicitly defines Online Services like the 1.1.1.1 Public DNS Resolver service as publicly available without a subscription or a Cloudflare account."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare 1.1.1.1 Public DNS is an Online Service publicly available without a subscription or account, requiring no authentication to send DoH requests."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "The 1.1.1.1 Public DNS Resolver service is publicly available without requiring a Cloudflare account or registration flow where CAPTCHA would apply."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "1.1.1.1 Public DNS is publicly available without a subscription or account, so phone verification does not apply to accessing the service."
            },
            {
              "signal_code": "delegated_identity_access",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Documentation explicitly states that no authentication is required to send requests to the 1.1.1.1 DNS over HTTPS API."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:31.072Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-access-bootstrap"
                },
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:5d901b47b65af34944acd1683223b77529a97f83924dc229b71cce51b993057e",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:21466df82082a51544519f41c9c76f1b8005becb76a0499fbb5144dcc8e2819c",
                    "sha256:31c51c9ca5828bcd6b2e382ddd049153e38b500f42d960349083395a49266221",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:5bb4c1541aff0547286ccbac6b870aa434a828481f885de843357507ff8cd5f1",
                    "sha256:a67aeaa63b05338a3314855b01ecbb6a705645e347776a71ff0b9ab422319ff2",
                    "sha256:bbdb3c9aa744964129f0274a0d2482d89dfc56adc9a5e4ae5ac9a31d8ed9f6c8"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:31c51c9ca5828bcd6b2e382ddd049153e38b500f42d960349083395a49266221",
                      "start_byte": 10108,
                      "end_byte": 10905,
                      "value_digest": "sha256:f8878c44ced7526f3237b6d06e0c5e39368bda51882dd1c13bcfcca7cb2d8c55"
                    }
                  ]
                }
              ],
              "note": "Cloudflare 1.1.1.1 Public DNS is an Online Service publicly available without a subscription or account, requiring no authentication to send DoH requests."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:09.643Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-access-bootstrap"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:87e81c0640c92dc50a4f17b3d273a0ce01297036120e8114d23e8b80874bafa9",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:aef8a8db2d84601e15fa958a913c5d8c44e20595ed46954240fafbae48c9cf7f",
                    "sha256:d14c9d0a971026b0345207ba8d92ff7529b7668764146d79cf8b8a2d8c83cc8e",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0",
                    "sha256:e1518371fced0b17554e22d7fb51a833b95e73f0cdbb1db92373457bf1d17680"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-access-bootstrap"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare Terms of Use explicitly defines Online Services like the 1.1.1.1 Public DNS Resolver service as publicly available without a subscription or a Cloudflare account."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:09.643Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-access-bootstrap"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:87e81c0640c92dc50a4f17b3d273a0ce01297036120e8114d23e8b80874bafa9",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:aef8a8db2d84601e15fa958a913c5d8c44e20595ed46954240fafbae48c9cf7f",
                    "sha256:d14c9d0a971026b0345207ba8d92ff7529b7668764146d79cf8b8a2d8c83cc8e",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0",
                    "sha256:e1518371fced0b17554e22d7fb51a833b95e73f0cdbb1db92373457bf1d17680"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-access-bootstrap"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "The 1.1.1.1 Public DNS Resolver service is publicly available without requiring a Cloudflare account or registration flow where CAPTCHA would apply."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:44.351Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0f3f03b6852ce5cf5f3197c0d49e60030caf36368e8284e7c558ec33075c8aa5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                    "sha256:b838be85eb5fe2cd801a0017b4bd011eaa29adb148fe318941b434b6ff9dab24",
                    "sha256:f4a5981ff39dbbd738ca38c0c59a6f5be4c4f3e98c6f1271c96f959a328facaa"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                      "start_byte": 10097,
                      "end_byte": 10894,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "Documentation explicitly states that no authentication is required to send requests to the 1.1.1.1 DNS over HTTPS API."
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:09.643Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-access-bootstrap"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:87e81c0640c92dc50a4f17b3d273a0ce01297036120e8114d23e8b80874bafa9",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:aef8a8db2d84601e15fa958a913c5d8c44e20595ed46954240fafbae48c9cf7f",
                    "sha256:d14c9d0a971026b0345207ba8d92ff7529b7668764146d79cf8b8a2d8c83cc8e",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0",
                    "sha256:e1518371fced0b17554e22d7fb51a833b95e73f0cdbb1db92373457bf1d17680"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-access-bootstrap"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "1.1.1.1 Public DNS is publicly available without a subscription or account, so phone verification does not apply to accessing the service."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "Cloudflare's official documentation explicitly discloses that 1.1.1.1 is free, takes minutes to set up, and does not require special software."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare 1.1.1.1 Public DNS Resolver service is defined under the Terms of Use as an Online Service publicly available without a subscription or a Cloudflare account. Therefore, checkout step does not apply."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare 1.1.1.1 Public DNS Resolver service is provided without a subscription or account as a free Online Service, so payment authorization does not apply."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare 1.1.1.1 Public DNS Resolver service is an Online Service provided publicly without a subscription or account, so self-service paid access does not apply."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:17.521Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-checkout-step"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d6cecb57cc9c83d8ad9c6fba671be9f07496adf8a979cd0a084e33549e6c85e3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2b9377eaffebbce4fc8a3a6fd599d5a4c1c14450a429613350045dc3bead2cae",
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-checkout-step"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare 1.1.1.1 Public DNS Resolver service is defined under the Terms of Use as an Online Service publicly available without a subscription or a Cloudflare account. Therefore, checkout step does not apply."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:55:57.821Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:014f9f042a74e6d24c7dbe144137861f5c17b370b7b6ba8d79784f049c4d2026",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0a23244f05e7ec8f98b96ba6d9987e31e455c4a0898443ef899fad384d5f1e39",
                    "sha256:109a0bbccec2bc7a379364697733d6dbbb8f3f8e2759aa30256b9edf3b3142b7",
                    "sha256:34c623d9d676e73b828ecbe56320fbb80fc121024c9613853a3133a7620d4fb9",
                    "sha256:732f5d65d11ece9f9d28b6d45c362b690dec582a9e1020cd2e5e4889f2fc46be"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:34c623d9d676e73b828ecbe56320fbb80fc121024c9613853a3133a7620d4fb9",
                      "start_byte": 9110,
                      "end_byte": 9909,
                      "value_digest": "sha256:8e7e7b3b908c2278eaacf81fc5c44983a7632fefbcfc58f568a08f414a534f7e"
                    }
                  ]
                }
              ],
              "note": "Cloudflare's official documentation explicitly discloses that 1.1.1.1 is free, takes minutes to set up, and does not require special software."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:17.521Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-checkout-step"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d6cecb57cc9c83d8ad9c6fba671be9f07496adf8a979cd0a084e33549e6c85e3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2b9377eaffebbce4fc8a3a6fd599d5a4c1c14450a429613350045dc3bead2cae",
                    "sha256:3c1f003217ba7da29cea6be24d99546dcfe14cc1cec6f38819d3d67e7e0296b0",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-checkout-step"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 10380,
                      "end_byte": 11184,
                      "value_digest": "sha256:bfe3af35084b3ca847d383c0c07798834ae1db37c52bd59fa215a746308dfcf7"
                    }
                  ]
                }
              ],
              "note": "Cloudflare 1.1.1.1 Public DNS Resolver service is provided without a subscription or account as a free Online Service, so payment authorization does not apply."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:17.521Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-checkout-step"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:d6cecb57cc9c83d8ad9c6fba671be9f07496adf8a979cd0a084e33549e6c85e3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2b9377eaffebbce4fc8a3a6fd599d5a4c1c14450a429613350045dc3bead2cae",
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-checkout-step"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare 1.1.1.1 Public DNS Resolver service is an Online Service provided publicly without a subscription or account, so self-service paid access does not apply."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "not_applicable",
          "public_state": "not_applicable",
          "state_label": "Not applicable",
          "primary_finding": {
            "signal_code": "provisioning_operability",
            "condition": "Can provisioning be initiated within supported agent authority?",
            "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
            "context": "Direct queries to the Cloudflare 1.1.1.1 DNS over HTTPS endpoint execute immediately without requiring any provisioning step."
          },
          "secondary_context": [
            {
              "signal_code": "access_material_delivery",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare explicitly declares that no authentication is required to send requests to this API."
            },
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare explicitly declares that no authentication is required to send requests to this API, meaning provisioning is not applicable."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:44.351Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0f3f03b6852ce5cf5f3197c0d49e60030caf36368e8284e7c558ec33075c8aa5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                    "sha256:b838be85eb5fe2cd801a0017b4bd011eaa29adb148fe318941b434b6ff9dab24",
                    "sha256:f4a5981ff39dbbd738ca38c0c59a6f5be4c4f3e98c6f1271c96f959a328facaa"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                      "start_byte": 10097,
                      "end_byte": 10894,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "Cloudflare explicitly declares that no authentication is required to send requests to this API."
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:44.351Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-provisioning-step"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0f3f03b6852ce5cf5f3197c0d49e60030caf36368e8284e7c558ec33075c8aa5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                    "sha256:b838be85eb5fe2cd801a0017b4bd011eaa29adb148fe318941b434b6ff9dab24",
                    "sha256:f4a5981ff39dbbd738ca38c0c59a6f5be4c4f3e98c6f1271c96f959a328facaa"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-provisioning-step"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                      "start_byte": 10097,
                      "end_byte": 10894,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "Cloudflare explicitly declares that no authentication is required to send requests to this API, meaning provisioning is not applicable."
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:41.421Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "doh-endpoint"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:6561adcd7c8f0f7381124365c1679803b4e7ae7d157ad86ceea0b8eb96d6327a",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:a2f590d0096a2a00c0fbe6f4adc100df8bfec536f195997646cf6db7970a5c74",
                    "sha256:a365ddef1181b3864e6adf834466119fe5bc14fe5d3c550407e5ccbf8f4bffb0",
                    "sha256:d316fe3695f0b5b422e906a5ea4e6a4e8a152cf2587ef87a74cba05b80ea7dd1"
                  ],
                  "source_surface": {
                    "node_kind": "endpoint",
                    "node_id": "doh-endpoint"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:a365ddef1181b3864e6adf834466119fe5bc14fe5d3c550407e5ccbf8f4bffb0",
                      "start_byte": 0,
                      "end_byte": 251,
                      "value_digest": "sha256:e660a59c5b8345e9b43d2c995cfaa19f3d2c0874456cfde9a03406fd440ef453"
                    }
                  ]
                }
              ],
              "note": "Direct queries to the Cloudflare 1.1.1.1 DNS over HTTPS endpoint execute immediately without requiring any provisioning step."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "target_interface_access",
            "condition": "Can an agent perform every essential assessment target through a usable interface?",
            "finding": "Every essential target has a stable documented agent-usable interface alternative.",
            "context": "Every essential target is accessible through documented machine-usable HTTP interfaces (supporting GET/POST with JSON or DNS wireformat MIME types)."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "Essential operation inputs, outputs, schemas, HTTP methods, MIME types, and upstream response resolution effects are stably documented across all essential targets."
            },
            {
              "signal_code": "failure_contract",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Applicable limits, errors, retry, idempotency, cancellation, and reconciliation semantics are documented.",
              "context": "Applicable failure codes (such as HTTP status 400, 413, 415, 504 and Extended DNS Error codes), retry behavior against alternative nameservers for temporary errors/unresponsive servers, and request deduplication semantics are documented."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "The documentation explicitly states that no authentication is required to send requests to this API, establishing that operation authentication does not apply to this service."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "The documentation explicitly states that no authentication is required to send requests to this API, establishing that credential lifecycle operations do not apply to this service."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:44.351Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0f3f03b6852ce5cf5f3197c0d49e60030caf36368e8284e7c558ec33075c8aa5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                    "sha256:b838be85eb5fe2cd801a0017b4bd011eaa29adb148fe318941b434b6ff9dab24",
                    "sha256:f4a5981ff39dbbd738ca38c0c59a6f5be4c4f3e98c6f1271c96f959a328facaa"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                      "start_byte": 10097,
                      "end_byte": 10894,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "The documentation explicitly states that no authentication is required to send requests to this API, establishing that credential lifecycle operations do not apply to this service."
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Applicable limits, errors, retry, idempotency, cancellation, and reconciliation semantics are documented.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.849Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "doh-json-contract"
                },
                {
                  "node_kind": "resource",
                  "node_id": "extended-errors"
                },
                {
                  "node_kind": "resource",
                  "node_id": "upstream-resolution"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:5ee3b304259561f9a74849300a0b6a4bcb92f55e69705d989b84d584fe9c133f",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:8e6c644f4fb282cbc1c86119e2cc6cf181a2f0e03970a6df58b45f166835449e",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:d7b093fcb35da23becb45bc32dd0195f017d205eb4c1befe2eb0012a8d25a075",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:03f6e0ca50209db3b002eb200d82f608eb34e1e1b196cbb6ebd5e57f94808be6",
                    "sha256:089a423bf8efc8ce84ec819dc86238a4f49a8eb9b0bd2295b5011bec32c1a30e",
                    "sha256:0bf816e13b86cac29e24dcd79f59fd376ca5a3117c3888bc9eb33afb7d6c6d3f",
                    "sha256:21a9e4d0bc8d7e20921e8a01692f0d95da8be923f2e59b8ef9375025e3b4f2a6",
                    "sha256:24c809e2523e70982093083c1739ffa945d88a5802166dff6ddda0e4e096596a",
                    "sha256:2986052a1dca853f3426f20a547a058fd009e5817f7d2ff05b823374e9bc8cce",
                    "sha256:6158813b0004259ed7f20c7463cbf60f4e89e9f15b5bd930bfd7ef3589778b3e",
                    "sha256:7db699380853401d7630ee6f1748b38e4f911dd6d1115d7186dcdff34d125747",
                    "sha256:d796dc4fa95a4ec74df93d7f533e34c83ccce6db3118f25c0d787712e2c9bbc6",
                    "sha256:e4ae39f67be78aa0c88c8f2ee915e62542b133fdfa7f12b51daac4b8f5fb715e",
                    "sha256:f43ed47b543c11ac5c01d7ccc16a812f10aebddb521c7a882fddd238b1a19540",
                    "sha256:fbe612c864a86517339f0691c335ddab586a2af2c52bbe29348254bdad57092d"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:21a9e4d0bc8d7e20921e8a01692f0d95da8be923f2e59b8ef9375025e3b4f2a6",
                      "start_byte": 13672,
                      "end_byte": 14468,
                      "value_digest": "sha256:3dd91d8589db851d1803a721289a9cbe2b55c09757fc5a9839977e37f07828a8"
                    },
                    {
                      "artifact_digest": "sha256:2986052a1dca853f3426f20a547a058fd009e5817f7d2ff05b823374e9bc8cce",
                      "start_byte": 9800,
                      "end_byte": 10599,
                      "value_digest": "sha256:18e93aa3188a3ce63ffa1843d0f2c06fea8e5e8f7c24bbb2ac372d173cae7ef7"
                    },
                    {
                      "artifact_digest": "sha256:e4ae39f67be78aa0c88c8f2ee915e62542b133fdfa7f12b51daac4b8f5fb715e",
                      "start_byte": 10740,
                      "end_byte": 11540,
                      "value_digest": "sha256:68fc335892938701eec6af019676ff90fac8ff63e57eff9286a1289193b0b898"
                    }
                  ]
                }
              ],
              "note": "Applicable failure codes (such as HTTP status 400, 413, 415, 504 and Extended DNS Error codes), retry behavior against alternative nameservers for temporary errors/unresponsive servers, and request deduplication semantics are documented."
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:44.351Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0f3f03b6852ce5cf5f3197c0d49e60030caf36368e8284e7c558ec33075c8aa5",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                    "sha256:b838be85eb5fe2cd801a0017b4bd011eaa29adb148fe318941b434b6ff9dab24",
                    "sha256:f4a5981ff39dbbd738ca38c0c59a6f5be4c4f3e98c6f1271c96f959a328facaa"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                      "start_byte": 10097,
                      "end_byte": 10894,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "The documentation explicitly states that no authentication is required to send requests to this API, establishing that operation authentication does not apply to this service."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.849Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "doh-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0f3f03b6852ce5cf5f3197c0d49e60030caf36368e8284e7c558ec33075c8aa5",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:5ee3b304259561f9a74849300a0b6a4bcb92f55e69705d989b84d584fe9c133f",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:8e6c644f4fb282cbc1c86119e2cc6cf181a2f0e03970a6df58b45f166835449e",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:d7b093fcb35da23becb45bc32dd0195f017d205eb4c1befe2eb0012a8d25a075",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:03f6e0ca50209db3b002eb200d82f608eb34e1e1b196cbb6ebd5e57f94808be6",
                    "sha256:089a423bf8efc8ce84ec819dc86238a4f49a8eb9b0bd2295b5011bec32c1a30e",
                    "sha256:0bf816e13b86cac29e24dcd79f59fd376ca5a3117c3888bc9eb33afb7d6c6d3f",
                    "sha256:21a9e4d0bc8d7e20921e8a01692f0d95da8be923f2e59b8ef9375025e3b4f2a6",
                    "sha256:24c809e2523e70982093083c1739ffa945d88a5802166dff6ddda0e4e096596a",
                    "sha256:2986052a1dca853f3426f20a547a058fd009e5817f7d2ff05b823374e9bc8cce",
                    "sha256:4ee40bf93450098770ac2deb7c285d5571991c974301a646489ecd610c9263ae",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:6158813b0004259ed7f20c7463cbf60f4e89e9f15b5bd930bfd7ef3589778b3e",
                    "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                    "sha256:b02a94cf28c6cc0cf8ee8f3a58aeabd1231cc40b8a72e92c35114c040f217da9",
                    "sha256:c9d2097cb1e11504e9c2b706fdcd74f2d3c4055f97255262c9b6c19867a52437",
                    "sha256:e4ae39f67be78aa0c88c8f2ee915e62542b133fdfa7f12b51daac4b8f5fb715e",
                    "sha256:f43ed47b543c11ac5c01d7ccc16a812f10aebddb521c7a882fddd238b1a19540",
                    "sha256:f4a5981ff39dbbd738ca38c0c59a6f5be4c4f3e98c6f1271c96f959a328facaa",
                    "sha256:fbe612c864a86517339f0691c335ddab586a2af2c52bbe29348254bdad57092d"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:21a9e4d0bc8d7e20921e8a01692f0d95da8be923f2e59b8ef9375025e3b4f2a6",
                      "start_byte": 10529,
                      "end_byte": 11323,
                      "value_digest": "sha256:3ad7aa73fab81e6370f99557b7d198c490343284256767db74f38ed62214a3a5"
                    },
                    {
                      "artifact_digest": "sha256:2986052a1dca853f3426f20a547a058fd009e5817f7d2ff05b823374e9bc8cce",
                      "start_byte": 9800,
                      "end_byte": 10599,
                      "value_digest": "sha256:18e93aa3188a3ce63ffa1843d0f2c06fea8e5e8f7c24bbb2ac372d173cae7ef7"
                    },
                    {
                      "artifact_digest": "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                      "start_byte": 9300,
                      "end_byte": 10096,
                      "value_digest": "sha256:53c66d17b6c439f6d3cbc3bfa80e3416443535e382981f97fc3ead21a2443306"
                    },
                    {
                      "artifact_digest": "sha256:e4ae39f67be78aa0c88c8f2ee915e62542b133fdfa7f12b51daac4b8f5fb715e",
                      "start_byte": 11541,
                      "end_byte": 12347,
                      "value_digest": "sha256:d620c57769868569aa591bda0a4fa203461ea48c1ca5b7b754b447ee562dab4f"
                    }
                  ]
                }
              ],
              "note": "Essential operation inputs, outputs, schemas, HTTP methods, MIME types, and upstream response resolution effects are stably documented across all essential targets."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:04.849Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "doh-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0f3f03b6852ce5cf5f3197c0d49e60030caf36368e8284e7c558ec33075c8aa5",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:5ee3b304259561f9a74849300a0b6a4bcb92f55e69705d989b84d584fe9c133f",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:8e6c644f4fb282cbc1c86119e2cc6cf181a2f0e03970a6df58b45f166835449e",
                      "capture_rung": "http"
                    },
                    {
                      "retained_capture_digest": "sha256:d7b093fcb35da23becb45bc32dd0195f017d205eb4c1befe2eb0012a8d25a075",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:089a423bf8efc8ce84ec819dc86238a4f49a8eb9b0bd2295b5011bec32c1a30e",
                    "sha256:0bf816e13b86cac29e24dcd79f59fd376ca5a3117c3888bc9eb33afb7d6c6d3f",
                    "sha256:21a9e4d0bc8d7e20921e8a01692f0d95da8be923f2e59b8ef9375025e3b4f2a6",
                    "sha256:24c809e2523e70982093083c1739ffa945d88a5802166dff6ddda0e4e096596a",
                    "sha256:2986052a1dca853f3426f20a547a058fd009e5817f7d2ff05b823374e9bc8cce",
                    "sha256:4ee40bf93450098770ac2deb7c285d5571991c974301a646489ecd610c9263ae",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:6158813b0004259ed7f20c7463cbf60f4e89e9f15b5bd930bfd7ef3589778b3e",
                    "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                    "sha256:c3f34440bfa8246f2c93d3375591984a8fe71a1e71ee384fa34ec8966be85fd3",
                    "sha256:c41927e793a923c9f703d83222761720ccfd3be045326ad81654d67974c267e0",
                    "sha256:e4ae39f67be78aa0c88c8f2ee915e62542b133fdfa7f12b51daac4b8f5fb715e",
                    "sha256:e6dcf9fe1d4f4243c26e9b39b33b6b6009b0a3a0c4b19465d729f263381d57cf",
                    "sha256:f43ed47b543c11ac5c01d7ccc16a812f10aebddb521c7a882fddd238b1a19540",
                    "sha256:f4a5981ff39dbbd738ca38c0c59a6f5be4c4f3e98c6f1271c96f959a328facaa",
                    "sha256:fbe612c864a86517339f0691c335ddab586a2af2c52bbe29348254bdad57092d"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:21a9e4d0bc8d7e20921e8a01692f0d95da8be923f2e59b8ef9375025e3b4f2a6",
                      "start_byte": 9778,
                      "end_byte": 10528,
                      "value_digest": "sha256:cdd6f45ec997155a571170bc24d40217d65869c1ad553c154c3ab2c94170eb36"
                    },
                    {
                      "artifact_digest": "sha256:2986052a1dca853f3426f20a547a058fd009e5817f7d2ff05b823374e9bc8cce",
                      "start_byte": 11394,
                      "end_byte": 12190,
                      "value_digest": "sha256:cc76ec2a66104cde5c06ebac59730d7cec5457e86e48e6bfd23715c71c8f518e"
                    },
                    {
                      "artifact_digest": "sha256:8bf4d7084c7adbfb2f440c7043af29a5ba7c4757060de2712fb018508e7404c3",
                      "start_byte": 9300,
                      "end_byte": 10096,
                      "value_digest": "sha256:53c66d17b6c439f6d3cbc3bfa80e3416443535e382981f97fc3ead21a2443306"
                    },
                    {
                      "artifact_digest": "sha256:e4ae39f67be78aa0c88c8f2ee915e62542b133fdfa7f12b51daac4b8f5fb715e",
                      "start_byte": 8320,
                      "end_byte": 9136,
                      "value_digest": "sha256:56a78fc1ae483ff0eef369d760efcb83335a088bf2c64ccbd57859535aa3d05f"
                    }
                  ]
                }
              ],
              "note": "Every essential target is accessible through documented machine-usable HTTP interfaces (supporting GET/POST with JSON or DNS wireformat MIME types)."
            }
          ],
          "blockers": [],
          "remediations": []
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 5,
        "barrier_ratio": 1
      },
      "last_tested_at": "2026-08-20T15:57:04.849Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:09f5e452247e9da5c67cd0c9b240c92268b6c85b602bec8057f65467052be130",
          "sha256:0a32fbec1e28b237bbe4680bea025fddac9dbc7dd474997855834011947425bf",
          "sha256:0be56f0c4c9b35e88c4ecbb36818fb165b31ae2a44cb9c96ed7b15c8331d7f72",
          "sha256:16410bab2fb8d5e4c2d4d617e1f54cb06df49820f6b447883a4b5805b09de0f4",
          "sha256:171fc517595771930cb4c6a6ae392224406cce2fc952d9d8e69d0eb6ef8ce29f",
          "sha256:24990716ab9c37ef256c2f659eb8fa380ba408e2a81bfd414601598560d4ad29",
          "sha256:26b44aaf036ce458fa3b88669008880baa1a299d5b98e9ddf18614d185571e16",
          "sha256:2872bc4a03d20e8d544fb2a0a9ef0583e661ce717a30edf561913df7e2f84863",
          "sha256:28c436250ad86119b9233c80b5084e21f6b747464c67b54b50446559e7c281f3",
          "sha256:28db301521f188dc99d33a0c522ae5d509959e04f26491f5532ae50b709e9d34",
          "sha256:296ccc8cb6ff173abf490637d4e568632805e0be0d16e173a0404296d61c9f44",
          "sha256:47942f83746a0ca1932c83e820c0698c96af6c3307050f0b3b32638cd86a3fe5",
          "sha256:57ab46943540c4aed4cb79e4ca5a67d65236704d4b465e325f8f091918615829",
          "sha256:57ef112cc1d8efa3148cbe16fee2e8ec6c63395fc60523c8fbee07aca478428a",
          "sha256:596e4a8842012d4c943c360404642db897dc8ff620d0776577643a5c89db141d",
          "sha256:5e17588ff67f2fe459a1229595e0e9c5d252aaa53136a5473978b982c08e6469",
          "sha256:7c3167732435e23e4f9ab50bcea7a08e6368893cc49ce8fca03003cb695dab04",
          "sha256:9204bc79de5e9f0c9ce8db3a28c1f3cfb28fa0d4924aed0a8ceb7ebee4ece285",
          "sha256:962b053a819bfae61d45b449c8b7241759e8596eefc01e1a98e91c2201eb93ed",
          "sha256:97d5a1f0f4fbd29935885065e51b094ba7da8605d4a98b4b10af90e77efc145b",
          "sha256:9dc14f448cc114ff032d493c700d84be348ae009fe9266a028f7b275e35f24f6",
          "sha256:9fe37c4c170a7191944c95fa71c58689e15fa7168e27465b095d8e417bfd9410",
          "sha256:a49b8acf2ba96b2246b8a3fe33d2a78f70791ea67a51c0fdec583380b6ae07d8",
          "sha256:b5a33bcc3e87333d66ea43b9f582e591363f065ee2626ef157c2181deb7b2538",
          "sha256:ba1b7f9983d463457b028830996e5d1693d7eff2aacd62ec1c6777422f5dd98f",
          "sha256:bcd90016a8bebf83d12ed2a2046758d656269d23bb606337c21addedf125cfa7",
          "sha256:ee0fadaf957996d4d57517d2e985df620eb94131425e41ca962f1d5e01c446c3",
          "sha256:f4949d6a7573f8724002ef4bbe635d16b879730ebb09e10916a8926038f300c3",
          "sha256:fd97c1f36eaf63bd0e1240a2e2b2216882edad326412dfbc9ba150a0d5c3b2be"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:47942f83746a0ca1932c83e820c0698c96af6c3307050f0b3b32638cd86a3fe5"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:55:57.821Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:9fe37c4c170a7191944c95fa71c58689e15fa7168e27465b095d8e417bfd9410"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:55:57.821Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:9204bc79de5e9f0c9ce8db3a28c1f3cfb28fa0d4924aed0a8ceb7ebee4ece285"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:44.351Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:57ab46943540c4aed4cb79e4ca5a67d65236704d4b465e325f8f091918615829"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:17.521Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:ba1b7f9983d463457b028830996e5d1693d7eff2aacd62ec1c6777422f5dd98f"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:31.072Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:171fc517595771930cb4c6a6ae392224406cce2fc952d9d8e69d0eb6ef8ce29f"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:09.643Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:5e17588ff67f2fe459a1229595e0e9c5d252aaa53136a5473978b982c08e6469"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:09.643Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:a49b8acf2ba96b2246b8a3fe33d2a78f70791ea67a51c0fdec583380b6ae07d8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:44.351Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:9dc14f448cc114ff032d493c700d84be348ae009fe9266a028f7b275e35f24f6"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:09.643Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:962b053a819bfae61d45b449c8b7241759e8596eefc01e1a98e91c2201eb93ed"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:17.521Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:97d5a1f0f4fbd29935885065e51b094ba7da8605d4a98b4b10af90e77efc145b"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:55:57.821Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:28db301521f188dc99d33a0c522ae5d509959e04f26491f5532ae50b709e9d34"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:17.521Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:b5a33bcc3e87333d66ea43b9f582e591363f065ee2626ef157c2181deb7b2538"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:17.521Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:09f5e452247e9da5c67cd0c9b240c92268b6c85b602bec8057f65467052be130"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:44.351Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:57ef112cc1d8efa3148cbe16fee2e8ec6c63395fc60523c8fbee07aca478428a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:44.351Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:16410bab2fb8d5e4c2d4d617e1f54cb06df49820f6b447883a4b5805b09de0f4"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:41.421Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:bcd90016a8bebf83d12ed2a2046758d656269d23bb606337c21addedf125cfa7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:44.351Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:26b44aaf036ce458fa3b88669008880baa1a299d5b98e9ddf18614d185571e16",
              "sha256:596e4a8842012d4c943c360404642db897dc8ff620d0776577643a5c89db141d",
              "sha256:fd97c1f36eaf63bd0e1240a2e2b2216882edad326412dfbc9ba150a0d5c3b2be"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.849Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:28c436250ad86119b9233c80b5084e21f6b747464c67b54b50446559e7c281f3"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:44.351Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:0a32fbec1e28b237bbe4680bea025fddac9dbc7dd474997855834011947425bf",
              "sha256:0be56f0c4c9b35e88c4ecbb36818fb165b31ae2a44cb9c96ed7b15c8331d7f72",
              "sha256:2872bc4a03d20e8d544fb2a0a9ef0583e661ce717a30edf561913df7e2f84863",
              "sha256:ee0fadaf957996d4d57517d2e985df620eb94131425e41ca962f1d5e01c446c3"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.849Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:24990716ab9c37ef256c2f659eb8fa380ba408e2a81bfd414601598560d4ad29",
              "sha256:296ccc8cb6ff173abf490637d4e568632805e0be0d16e173a0404296d61c9f44",
              "sha256:7c3167732435e23e4f9ab50bcea7a08e6368893cc49ce8fca03003cb695dab04",
              "sha256:f4949d6a7573f8724002ef4bbe635d16b879730ebb09e10916a8926038f300c3"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:04.849Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/agent-readiness/cloudflare/cloudflare-public-dns/dns-over-https-query",
      "projection_digest": "sha256:72ecc2111edfcb77df45983492b31b95f12bb0d410fa8b3237710af856e65f18"
    }
  }
}
