{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:5f55a0147eca9a82d821b7cfb73339dd8059c146b9acbb6ed66c9e3d40a8e1b0",
  "snapshot_id": "sha256:fbf4583b80f8936d9b7b75906adc86f38f5612cd0a7329839daea7b71ad2b9ce",
  "artifact_sha256": "sha256:ec393385ec4e7be15a393d925f0df78d54a12787f2995a84fad1b570583dac06",
  "data": {
    "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t",
    "entity_slug": "cloudflare",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01m08rqxyvw1151ymp6kaxfgcc",
      "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t",
      "scope": {
        "product": {
          "key": "cloudflare-public-dns",
          "name": "Cloudflare 1.1.1.1 Public DNS"
        },
        "funnel": {
          "key": "dns-over-https-query",
          "name": "DNS over HTTPS query"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:8986cb1640fd748dd005e5c94c7b02d3f44a3d39ff6b72573091bd81af84c61e",
        "entity_revision_digest": "sha256:cddeb11506db30b6ffb13fcff407b1931f123a1eb2cc8edf5ca023ba03c71100"
      },
      "declaration_revision_digest": "sha256:65bf30248c0a730476c82afd8471be2e33d54397a1e8a63b0e34d235315bed5f",
      "declaration": {
        "declaration_id": "declaration_cloudflare_public_dns_over_https",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "ca383f7867c18d91567fcb8326be55f7411d9554",
          "path": "entities/cl/cloudflare.yaml",
          "git_blob_oid": "945a41470397eec65308a077818a125d882b4fb6",
          "blob_digest": "sha256:8f7c08b148f13ff27375b1eadb4dd67641c32716a13168bcf8468e3801bdcaf7"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Resolve public DNS records through DNS over HTTPS",
            "interface_ids": [
              "doh-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "cloudflare-public-dns",
            "roles": [
              "operations_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyh8jtf535570d9z2bng6j1t"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "doh-json-contract",
            "uri": "https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-https/make-api-requests/dns-json/",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "doh-reference",
            "uri": "https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-https/make-api-requests/",
            "roles": [
              "discovery",
              "documentation",
              "operations",
              "status"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "extended-errors",
            "uri": "https://developers.cloudflare.com/1.1.1.1/infrastructure/extended-dns-error-codes/",
            "roles": [
              "documentation",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "public-dns-overview",
            "uri": "https://developers.cloudflare.com/1.1.1.1/",
            "roles": [
              "discovery",
              "documentation",
              "eligibility",
              "pricing"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "public-dns-terms",
            "uri": "https://www.cloudflare.com/policies/terms/",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          },
          {
            "resource_id": "upstream-resolution",
            "uri": "https://developers.cloudflare.com/1.1.1.1/upstream-resolution/",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "doh-endpoint",
            "uri": "https://cloudflare-dns.com/dns-query",
            "transport": "http",
            "roles": [
              "service"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "doh-api",
            "modality": "network_api",
            "functions": [
              "service_operation"
            ],
            "endpoint_ids": [
              "doh-endpoint"
            ],
            "resource_ids": [
              "doh-json-contract",
              "doh-reference",
              "extended-errors",
              "upstream-resolution"
            ],
            "operated_by_participant_id": "cloudflare-public-dns",
            "standard_bindings": []
          }
        ],
        "relations": [
          {
            "relation_id": "doh-json-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "doh-json-contract"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "doh-api"
            }
          },
          {
            "relation_id": "doh-reference-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "doh-reference"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "doh-api"
            }
          },
          {
            "relation_id": "errors-describe-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "extended-errors"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "doh-api"
            }
          },
          {
            "relation_id": "upstream-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "upstream-resolution"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "doh-api"
            }
          }
        ],
        "surface_exclusions": [
          {
            "exclusion_id": "no-access-bootstrap",
            "role": "access",
            "rationale": "The public DNS resolver is available without a subscription or Cloudflare account, so no access bootstrap applies."
          },
          {
            "exclusion_id": "no-checkout-step",
            "role": "checkout",
            "rationale": "The public DNS resolver is available without a subscription or Cloudflare account, so no checkout step applies."
          },
          {
            "exclusion_id": "no-operation-authentication",
            "role": "authentication",
            "rationale": "Cloudflare states that no authentication is required to send requests to the DNS over HTTPS API."
          },
          {
            "exclusion_id": "no-provisioning-step",
            "role": "provisioning",
            "rationale": "DNS queries are submitted directly to the public endpoint, so no resource provisioning step applies."
          }
        ]
      },
      "lifecycle": "active",
      "effective_from": "2026-09-06T08:47:58Z",
      "revision_digest": "sha256:bb60075bc7f861d12d3036e87a62c90ecf7af6d7385cdba7c530785e0ded6100",
      "policy_digest": "sha256:fc9e8f046d86fcf19ab2f1bc547219e503cdc11ffa135d020db7285965cd7d1d",
      "policy_version": "service-use-2026-09-07-blocking-barriers-r12",
      "policy_as_of": "2026-09-07T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "pass",
      "public_state": "ready",
      "state_label": "Ready",
      "grade": "A+",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect Blocked stages by lifecycle severity.",
        "coverage_rule": "Coverage is complete only when every graded signal has supported, fresh, non-conflicting evidence. Barrier and informational signals do not change coverage; only fresh, supported barrier values that passed their admission evidence rule participate in stage outcomes.",
        "outcome_rule": "Each stage takes its worst graded signal or verified barrier. A fresh, supported mandatory barrier that passed its admission evidence rule can block that stage; incomplete or stale barrier evidence remains context only. The overall grade is derived from the five stage states."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "limitations": [],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "service_discovery",
            "condition": "Can an agent find the exact service and its stable entrypoints?",
            "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
            "context": "Cloudflare's DNS over HTTPS (DoH) resolver endpoint is located at https://cloudflare-dns.com/dns-query and requires no authentication."
          },
          "secondary_context": [
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence does not provide explicit web agent access rules or directives such as robots.txt rules for the assessed service."
            },
            {
              "signal_code": "terms_access",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "context": "Cloudflare's Website and Online Services Terms of Use apply to publicly available Online Services, explicitly including the 1.1.1.1 Public DNS Resolver service."
            },
            {
              "signal_code": "eligibility_decidability",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "context": "Cloudflare 1.1.1.1 is Cloudflare's public DNS resolver available on all plans. Setting it up takes minutes and does not require any special software."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "Cloudflare explicitly declares that 1.1.1.1 is free."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Verified structured artifacts accelerate discovery of the evaluation surface.",
              "context": "A documentation index is explicitly available at https://developers.cloudflare.com/1.1.1.1/llms.txt to discover all available pages."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "informational",
              "required": false,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Eligibility conditions and required inputs are explicit and decidable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:50:23.426Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ac15f97e8fd9445cbde2fe06ab8e24e8f3f22f201755179042679fd45e70fe2f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:109a0bbccec2bc7a379364697733d6dbbb8f3f8e2759aa30256b9edf3b3142b7",
                    "sha256:673eaf8df5c6bc83c24de1c4d2da3acd33432d4a4c18e6a48fe27fe652bf23c9",
                    "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded",
                    "sha256:bc5d5a8be0a1705e30933c569f6868c567a9240dc7eb5fde8f5b311552b7b217"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded",
                      "start_byte": 9870,
                      "end_byte": 10669,
                      "value_digest": "sha256:8e7e7b3b908c2278eaacf81fc5c44983a7632fefbcfc58f568a08f414a534f7e"
                    },
                    {
                      "artifact_digest": "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded",
                      "start_byte": 9054,
                      "end_byte": 9869,
                      "value_digest": "sha256:a97676fe5a1508d0238fe028050e322a20175829b1d6326cf2f88c3654bd3432"
                    }
                  ]
                }
              ],
              "note": "Cloudflare 1.1.1.1 is Cloudflare's public DNS resolver available on all plans. Setting it up takes minutes and does not require any special software."
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:50:23.426Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ac15f97e8fd9445cbde2fe06ab8e24e8f3f22f201755179042679fd45e70fe2f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:109a0bbccec2bc7a379364697733d6dbbb8f3f8e2759aa30256b9edf3b3142b7",
                    "sha256:34ecd12389052884274a15f41c5734c02520928ffab90274ebe043caccf28437",
                    "sha256:673eaf8df5c6bc83c24de1c4d2da3acd33432d4a4c18e6a48fe27fe652bf23c9",
                    "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded",
                      "start_byte": 9870,
                      "end_byte": 10669,
                      "value_digest": "sha256:8e7e7b3b908c2278eaacf81fc5c44983a7632fefbcfc58f568a08f414a534f7e"
                    }
                  ]
                }
              ],
              "note": "Cloudflare explicitly declares that 1.1.1.1 is free."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:35.415Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "doh-reference"
                },
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4d4d7b2c1080a10856806a552eaa79b1cbb5ba59db0d9e252ce98441b538be82",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1956c9a5145cb53ff4a76397618c4ac375610113ada80051e8955328c8e7e642",
                    "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:57db4350cf5dfeb2dc75dc436d8d6153da78f1194ba988cfcd86b5bb594c7e1c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "doh-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                      "start_byte": 10060,
                      "end_byte": 10856,
                      "value_digest": "sha256:53c66d17b6c439f6d3cbc3bfa80e3416443535e382981f97fc3ead21a2443306"
                    }
                  ]
                }
              ],
              "note": "Cloudflare's DNS over HTTPS (DoH) resolver endpoint is located at https://cloudflare-dns.com/dns-query and requires no authentication."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Verified structured artifacts accelerate discovery of the evaluation surface.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:50:23.426Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "doh-reference"
                },
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ac15f97e8fd9445cbde2fe06ab8e24e8f3f22f201755179042679fd45e70fe2f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:109a0bbccec2bc7a379364697733d6dbbb8f3f8e2759aa30256b9edf3b3142b7",
                    "sha256:673eaf8df5c6bc83c24de1c4d2da3acd33432d4a4c18e6a48fe27fe652bf23c9",
                    "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded",
                    "sha256:ca7f573f48e577f9d7f1a9f81e6966e2b53df4f84eb6e8bea46d0d0cf09627d0"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded",
                      "start_byte": 8264,
                      "end_byte": 9053,
                      "value_digest": "sha256:119ff6e3687df3bea122fb9ebb6e515293851a233532043b03281aa6a967174f"
                    }
                  ]
                }
              ],
              "note": "A documentation index is explicitly available at https://developers.cloudflare.com/1.1.1.1/llms.txt to discover all available pages."
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Applicable terms are stable, readable, retrievable, and materially complete.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:58.297Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-terms"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1bbb29a32cef8321cd540c15744e5096b86a687da3d8ab9a773a9137da832221",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1a85cae032b6df6c7bfffa3b9eee84542877989b41d46d86a820715e1457a60f",
                    "sha256:6c45ec5e814c4eceaf9ae4e6b8f26c65caaa7fc8c9be3acc67a045ac102a1957",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 3964,
                      "end_byte": 4764,
                      "value_digest": "sha256:94bff3842bcbd936614c23b62afdf18317fdfe7ff902d13ce8bcc56dc4193486"
                    },
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare's Website and Online Services Terms of Use apply to publicly available Online Services, explicitly including the 1.1.1.1 Public DNS Resolver service."
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:35.415Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "doh-reference"
                },
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [],
              "note": "The retained evidence does not provide explicit web agent access rules or directives such as robots.txt rules for the assessed service."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "not_applicable",
          "public_state": "not_applicable",
          "state_label": "Not applicable",
          "primary_finding": {
            "signal_code": "access_entrypoint_stability",
            "condition": "Is there a stable route to begin obtaining service access?",
            "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
            "context": "Cloudflare Terms of Use explicitly state that 1.1.1.1 Public DNS Resolver is available without a subscription or a Cloudflare account, making sign up access entrypoints non-applicable."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare 1.1.1.1 Public DNS is an Online Service publicly available without a subscription or account, and no authentication is required to send API requests over DoH."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare 1.1.1.1 Public DNS is publicly available without requiring an account or subscription, so sign-up CAPTCHA boundaries do not apply."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare 1.1.1.1 Public DNS is accessible without an account or subscription, making sign-up phone verification non-applicable."
            },
            {
              "signal_code": "delegated_identity_access",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare explicitly states that no authentication is required to send requests to the 1.1.1.1 DoH API."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:37.784Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-access-bootstrap"
                },
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ac2c099c7a4ba429663d7e32fa71e73f9c942f44e8f517a260bc39edd22b2421",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:15853432469b8e98fcda3633fbda47e0154efba55bb30a527228d7169cd14109",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:a67aeaa63b05338a3314855b01ecbb6a705645e347776a71ff0b9ab422319ff2",
                    "sha256:e163daed9a81485942124b5f26ebe2f416bc3d54477fed65863de6fd21ace1a6",
                    "sha256:e739c465f45f1d7b99693e13c13d96197338d8e5aa0503d9a57e55d0a5e64b9d",
                    "sha256:f45b58f49a5eca61e8f6de2f3b78e8334a71024e8d15ed23fa1c6d8594c2e850"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:f45b58f49a5eca61e8f6de2f3b78e8334a71024e8d15ed23fa1c6d8594c2e850",
                      "start_byte": 10868,
                      "end_byte": 11665,
                      "value_digest": "sha256:f8878c44ced7526f3237b6d06e0c5e39368bda51882dd1c13bcfcca7cb2d8c55"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:969a16011bb677b72734ca9a0bf93ab5ef7f6cbe30fd2ae69fbd5b1d78b95983",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1d83b7dba5d0f912f4c943a79d0e8e96f9b3524715f8c48a5f0d9a235896d430",
                    "sha256:42d7ffd57ce1df726c13710ea22f1c4903ff15d0d084c42bbd97c19546364a15",
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0",
                    "sha256:e1518371fced0b17554e22d7fb51a833b95e73f0cdbb1db92373457bf1d17680"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-access-bootstrap"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare 1.1.1.1 Public DNS is an Online Service publicly available without a subscription or account, and no authentication is required to send API requests over DoH."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:06.043Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-access-bootstrap"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:969a16011bb677b72734ca9a0bf93ab5ef7f6cbe30fd2ae69fbd5b1d78b95983",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1d83b7dba5d0f912f4c943a79d0e8e96f9b3524715f8c48a5f0d9a235896d430",
                    "sha256:42d7ffd57ce1df726c13710ea22f1c4903ff15d0d084c42bbd97c19546364a15",
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0",
                    "sha256:e1518371fced0b17554e22d7fb51a833b95e73f0cdbb1db92373457bf1d17680"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-access-bootstrap"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare Terms of Use explicitly state that 1.1.1.1 Public DNS Resolver is available without a subscription or a Cloudflare account, making sign up access entrypoints non-applicable."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:06.043Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-access-bootstrap"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:969a16011bb677b72734ca9a0bf93ab5ef7f6cbe30fd2ae69fbd5b1d78b95983",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1d83b7dba5d0f912f4c943a79d0e8e96f9b3524715f8c48a5f0d9a235896d430",
                    "sha256:42d7ffd57ce1df726c13710ea22f1c4903ff15d0d084c42bbd97c19546364a15",
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0",
                    "sha256:e1518371fced0b17554e22d7fb51a833b95e73f0cdbb1db92373457bf1d17680"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-access-bootstrap"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare 1.1.1.1 Public DNS is publicly available without requiring an account or subscription, so sign-up CAPTCHA boundaries do not apply."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:35.415Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4d4d7b2c1080a10856806a552eaa79b1cbb5ba59db0d9e252ce98441b538be82",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1956c9a5145cb53ff4a76397618c4ac375610113ada80051e8955328c8e7e642",
                    "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:f886e3144e29479375251afe44fc6df111d8287793fcb09a7a5bf113b9c2ccc0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                      "start_byte": 10857,
                      "end_byte": 11654,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "Cloudflare explicitly states that no authentication is required to send requests to the 1.1.1.1 DoH API."
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:06.043Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-access-bootstrap"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:969a16011bb677b72734ca9a0bf93ab5ef7f6cbe30fd2ae69fbd5b1d78b95983",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1d83b7dba5d0f912f4c943a79d0e8e96f9b3524715f8c48a5f0d9a235896d430",
                    "sha256:42d7ffd57ce1df726c13710ea22f1c4903ff15d0d084c42bbd97c19546364a15",
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0",
                    "sha256:e1518371fced0b17554e22d7fb51a833b95e73f0cdbb1db92373457bf1d17680"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-access-bootstrap"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "Cloudflare 1.1.1.1 Public DNS is accessible without an account or subscription, making sign-up phone verification non-applicable."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
            "context": "Documentation explicitly declares that 1.1.1.1 is free, takes minutes to set up, and does not require any special software."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "The Cloudflare Terms of Use explicitly state that 1.1.1.1 Public DNS Resolver is an Online Service publicly available without a subscription or a Cloudflare account."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "The Cloudflare Terms of Use explicitly state that 1.1.1.1 Public DNS Resolver is an Online Service publicly available without a subscription or account, so payment authorization does not apply."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "The Cloudflare Terms of Use explicitly state that 1.1.1.1 Public DNS Resolver is an Online Service publicly available without a subscription or a Cloudflare account."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:58.297Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-checkout-step"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1bbb29a32cef8321cd540c15744e5096b86a687da3d8ab9a773a9137da832221",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:6c45ec5e814c4eceaf9ae4e6b8f26c65caaa7fc8c9be3acc67a045ac102a1957",
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-checkout-step"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "The Cloudflare Terms of Use explicitly state that 1.1.1.1 Public DNS Resolver is an Online Service publicly available without a subscription or a Cloudflare account."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "Charge or no-charge status, currency, recurrence, and material conditions are disclosed.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:50:23.426Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "public-dns-overview"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:ac15f97e8fd9445cbde2fe06ab8e24e8f3f22f201755179042679fd45e70fe2f",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:109a0bbccec2bc7a379364697733d6dbbb8f3f8e2759aa30256b9edf3b3142b7",
                    "sha256:34ecd12389052884274a15f41c5734c02520928ffab90274ebe043caccf28437",
                    "sha256:673eaf8df5c6bc83c24de1c4d2da3acd33432d4a4c18e6a48fe27fe652bf23c9",
                    "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "public-dns-overview"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:98149780ff64e0e8eec28536579ec38be4636d724723ef0911ff303ef456eded",
                      "start_byte": 9870,
                      "end_byte": 10669,
                      "value_digest": "sha256:8e7e7b3b908c2278eaacf81fc5c44983a7632fefbcfc58f568a08f414a534f7e"
                    }
                  ]
                }
              ],
              "note": "Documentation explicitly declares that 1.1.1.1 is free, takes minutes to set up, and does not require any special software."
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:58.297Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-checkout-step"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1bbb29a32cef8321cd540c15744e5096b86a687da3d8ab9a773a9137da832221",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3c1f003217ba7da29cea6be24d99546dcfe14cc1cec6f38819d3d67e7e0296b0",
                    "sha256:6c45ec5e814c4eceaf9ae4e6b8f26c65caaa7fc8c9be3acc67a045ac102a1957",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-checkout-step"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 10380,
                      "end_byte": 11184,
                      "value_digest": "sha256:bfe3af35084b3ca847d383c0c07798834ae1db37c52bd59fa215a746308dfcf7"
                    }
                  ]
                }
              ],
              "note": "The Cloudflare Terms of Use explicitly state that 1.1.1.1 Public DNS Resolver is an Online Service publicly available without a subscription or account, so payment authorization does not apply."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:58.297Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-checkout-step"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:1bbb29a32cef8321cd540c15744e5096b86a687da3d8ab9a773a9137da832221",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:6c45ec5e814c4eceaf9ae4e6b8f26c65caaa7fc8c9be3acc67a045ac102a1957",
                    "sha256:7efe682f409c95be9ac1a7d752e5807766d3afd61df13ff941570abe707597e1",
                    "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                    "sha256:d740c266d6091292b036b60ec75b1f21c0157ca022a9697e5548c3bef0e687e0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-checkout-step"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:86aa71aa4ebc810bf819188d5a3eb280b3c8e0f82029c4ba6310f3cac5dac0e3",
                      "start_byte": 4765,
                      "end_byte": 5580,
                      "value_digest": "sha256:f9b13ad7e475b189f91389ede716f30da710d20705af95bac03e8f820f8a4402"
                    }
                  ]
                }
              ],
              "note": "The Cloudflare Terms of Use explicitly state that 1.1.1.1 Public DNS Resolver is an Online Service publicly available without a subscription or a Cloudflare account."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "not_applicable",
          "public_state": "not_applicable",
          "state_label": "Not applicable",
          "primary_finding": {
            "signal_code": "provisioning_operability",
            "condition": "Can provisioning be initiated within supported agent authority?",
            "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
            "context": "The public DNS over HTTPS query endpoint responds directly without requiring a prior provisioning procedure."
          },
          "secondary_context": [
            {
              "signal_code": "access_material_delivery",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Cloudflare's documentation explicitly states that no authentication is required to send requests to the DNS over HTTPS API."
            },
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Documentation states that no authentication is required to send requests to this API, establishing that provisioning does not apply to this public DNS over HTTPS query endpoint."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:35.415Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4d4d7b2c1080a10856806a552eaa79b1cbb5ba59db0d9e252ce98441b538be82",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1956c9a5145cb53ff4a76397618c4ac375610113ada80051e8955328c8e7e642",
                    "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:f886e3144e29479375251afe44fc6df111d8287793fcb09a7a5bf113b9c2ccc0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                      "start_byte": 10857,
                      "end_byte": 11654,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "Cloudflare's documentation explicitly states that no authentication is required to send requests to the DNS over HTTPS API."
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:35.415Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-provisioning-step"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4d4d7b2c1080a10856806a552eaa79b1cbb5ba59db0d9e252ce98441b538be82",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1956c9a5145cb53ff4a76397618c4ac375610113ada80051e8955328c8e7e642",
                    "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:f886e3144e29479375251afe44fc6df111d8287793fcb09a7a5bf113b9c2ccc0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-provisioning-step"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                      "start_byte": 10857,
                      "end_byte": 11654,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "Documentation states that no authentication is required to send requests to this API, establishing that provisioning does not apply to this public DNS over HTTPS query endpoint."
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:01.791Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "doh-endpoint"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0b211c50cee7bbf2f9a4dc71594c4c8df159522287d956a0aa8706e7e802ad09",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0e1c476feb821a63ed4dda799c8147211ffd9ad42be48b33e7bb70ee5f5ba6f0",
                    "sha256:1041f8c6d224b09653dccae534450ab5507e60ec2c61c4e193aa85cc290a9ea1",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:9c1bc85e4a003c926a32e0b521527a27e00ce262b6553a3a09c3e6b5be6cba1e"
                  ],
                  "source_surface": {
                    "node_kind": "endpoint",
                    "node_id": "doh-endpoint"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:9c1bc85e4a003c926a32e0b521527a27e00ce262b6553a3a09c3e6b5be6cba1e",
                      "start_byte": 0,
                      "end_byte": 250,
                      "value_digest": "sha256:2e8bdb9215b998b084bcba2503f52c5abb4c64bee5741ad6a1ba619e78e5c2e5"
                    }
                  ]
                }
              ],
              "note": "The public DNS over HTTPS query endpoint responds directly without requiring a prior provisioning procedure."
            }
          ],
          "blockers": [],
          "remediations": []
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "pass",
          "public_state": "ready",
          "state_label": "Ready",
          "primary_finding": {
            "signal_code": "target_interface_access",
            "condition": "Can an agent perform every essential assessment target through a usable interface?",
            "finding": "Every essential target has a stable documented agent-usable interface alternative.",
            "context": "All essential targets are accessible and executable via usable HTTP endpoints (`https://cloudflare-dns.com/dns-query` and `https://one.one.one.one/dns-query`) using standard JSON or DNS wireformat interfaces."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained excerpts describe REST or RPC interfaces, SDKs and CLIs for Cloudflare 1.1.1.1 Public DNS; they contain no first-party statement that an agent-native protocol interface is absent, and several navigation excerpts mention MCP resources without establishing coverage of the assessed targets."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "The essential DoH targets have stable and decidable request parameters, MIME types, GET/POST methods, response JSON schemas/wireformats, extended error codes, and upstream resolution behavior clearly documented."
            },
            {
              "signal_code": "failure_contract",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Applicable limits, errors, retry, idempotency, cancellation, and reconciliation semantics are documented.",
              "context": "1.1.1.1 documents the failure contract that applies to a stateless read-only resolver query: the JSON error response and DNS Status code, Extended DNS Error codes with their meaning and next steps, and the retry behaviour that returns SERVFAIL or REFUSED to the client only when every authoritative nameserver failed. Idempotency, cancellation and reconciliation semantics concern stateful operations and do not apply to a read-only query."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Documentation explicitly states that no authentication is required to send requests to the 1.1.1.1 DoH API."
            },
            {
              "signal_code": "credential_lifecycle",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "context": "Documentation explicitly declares that no authentication is required to send requests to the 1.1.1.1 DoH API, making credential lifecycle management not applicable."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:45.033Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "doh-api"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [],
              "note": "The retained excerpts describe REST or RPC interfaces, SDKs and CLIs for Cloudflare 1.1.1.1 Public DNS; they contain no first-party statement that an agent-native protocol interface is absent, and several navigation excerpts mention MCP resources without establishing coverage of the assessed targets."
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:35.415Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4d4d7b2c1080a10856806a552eaa79b1cbb5ba59db0d9e252ce98441b538be82",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1956c9a5145cb53ff4a76397618c4ac375610113ada80051e8955328c8e7e642",
                    "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:f886e3144e29479375251afe44fc6df111d8287793fcb09a7a5bf113b9c2ccc0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                      "start_byte": 10857,
                      "end_byte": 11654,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "Documentation explicitly declares that no authentication is required to send requests to the 1.1.1.1 DoH API, making credential lifecycle management not applicable."
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Applicable limits, errors, retry, idempotency, cancellation, and reconciliation semantics are documented.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:45.033Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "doh-json-contract"
                },
                {
                  "node_kind": "resource",
                  "node_id": "extended-errors"
                },
                {
                  "node_kind": "resource",
                  "node_id": "upstream-resolution"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:77ac2744fd689882848816d8ea64549efc21c39e5c716e6148ee25bace738310",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:c707420613ed53b9d354cec37e2ba6950cde7d432fe57539141346268c0735f4",
                    "sha256:cdbd38c13928a07c811be242793df7acaffeffd354134884b60a93fa3e8a7c6b",
                    "sha256:f43ed47b543c11ac5c01d7ccc16a812f10aebddb521c7a882fddd238b1a19540",
                    "sha256:fba42eaa35a58732108546661d3d415d596959fbaa756395e4af62109181b47f"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "upstream-resolution"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:fba42eaa35a58732108546661d3d415d596959fbaa756395e4af62109181b47f",
                      "start_byte": 11938,
                      "end_byte": 12270,
                      "value_digest": "sha256:9a6672b90ec08f2abf12810585b3092c4420bb8de5fdfc6b18bed2a7ae8ddba8"
                    },
                    {
                      "artifact_digest": "sha256:fba42eaa35a58732108546661d3d415d596959fbaa756395e4af62109181b47f",
                      "start_byte": 13916,
                      "end_byte": 14088,
                      "value_digest": "sha256:972a6d335176333c4a1907ddf1f0e39426c2a4dbb51c1ca37faa099745cf09c0"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:9dd68a3565ea5415765a3bd6be587e79821455071b69c8ea8950189bfd784bdf",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:22c0aa9d3ad4d493eccc8a0a75b283dac84cda4bb8ab2776e76c7bbb20102d6e",
                    "sha256:6158813b0004259ed7f20c7463cbf60f4e89e9f15b5bd930bfd7ef3589778b3e",
                    "sha256:c586fca2f6a22d97f83878100bddac0d425f76ce96a213faefbc247fc792c4cf",
                    "sha256:c60f37e3faaef60ad8a0d1806444b1d1dcdaa0b2a0888dda867ebd3e9f2357fc"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "doh-json-contract"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c586fca2f6a22d97f83878100bddac0d425f76ce96a213faefbc247fc792c4cf",
                      "start_byte": 12436,
                      "end_byte": 12478,
                      "value_digest": "sha256:87dcaf6ca61bce992b9689d77ba1c61bf9b12f9a661f9d8944915c987a687ac9"
                    },
                    {
                      "artifact_digest": "sha256:c586fca2f6a22d97f83878100bddac0d425f76ce96a213faefbc247fc792c4cf",
                      "start_byte": 14979,
                      "end_byte": 15060,
                      "value_digest": "sha256:95ed1feb3344026ea6285fe10b98ea5b7584aa3a4a452cd46eb38a786d0d5b91"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0191811a554056886cb63f6864fabac767fee7225fbd1966f6bbdc903812b263",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:089a423bf8efc8ce84ec819dc86238a4f49a8eb9b0bd2295b5011bec32c1a30e",
                    "sha256:0d061e69967fa57f1d9ad87f2276b0c87218f412fe476fd508bc19f8d24af67f",
                    "sha256:4aa46e85a076dc10d4d12dac82b4d1df9eb8c960f2d7f8d93a25a702ec76f2ba",
                    "sha256:b72c0acab99ab10f50818d05f2f16a267c483ff97634fc1d14e4088f1add262a"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "extended-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b72c0acab99ab10f50818d05f2f16a267c483ff97634fc1d14e4088f1add262a",
                      "start_byte": 10613,
                      "end_byte": 10941,
                      "value_digest": "sha256:f61bf2929bc651e83ede70af6689d88c3e1dbd8bb24035df09660f82093bfed0"
                    }
                  ]
                }
              ],
              "note": "1.1.1.1 documents the failure contract that applies to a stateless read-only resolver query: the JSON error response and DNS Status code, Extended DNS Error codes with their meaning and next steps, and the retry behaviour that returns SERVFAIL or REFUSED to the client only when every authoritative nameserver failed. Idempotency, cancellation and reconciliation semantics concern stateful operations and do not apply to a read-only query."
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "not_applicable",
              "value_label": "Not applicable",
              "outcome": "not_applicable",
              "public_state": "not_applicable",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Admitted evidence establishes that this step does not apply to the assessed service.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:35.415Z",
              "tested_surfaces": [
                {
                  "node_kind": "surface_exclusion",
                  "node_id": "no-operation-authentication"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4d4d7b2c1080a10856806a552eaa79b1cbb5ba59db0d9e252ce98441b538be82",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1956c9a5145cb53ff4a76397618c4ac375610113ada80051e8955328c8e7e642",
                    "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:f886e3144e29479375251afe44fc6df111d8287793fcb09a7a5bf113b9c2ccc0"
                  ],
                  "source_surface": {
                    "node_kind": "surface_exclusion",
                    "node_id": "no-operation-authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                      "start_byte": 10857,
                      "end_byte": 11654,
                      "value_digest": "sha256:25fdd276f87744f11a54ece7eb60035f5ba67910733dd05cf439f22435ea80f0"
                    }
                  ]
                }
              ],
              "note": "Documentation explicitly states that no authentication is required to send requests to the 1.1.1.1 DoH API."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:45.033Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "doh-api"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:9dd68a3565ea5415765a3bd6be587e79821455071b69c8ea8950189bfd784bdf",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:22c0aa9d3ad4d493eccc8a0a75b283dac84cda4bb8ab2776e76c7bbb20102d6e",
                    "sha256:5100d45a6cd64384d959ba0e8ba301bc787adc950bdcf7d0a9d248879ad10b81",
                    "sha256:6158813b0004259ed7f20c7463cbf60f4e89e9f15b5bd930bfd7ef3589778b3e",
                    "sha256:c586fca2f6a22d97f83878100bddac0d425f76ce96a213faefbc247fc792c4cf"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "doh-json-contract"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c586fca2f6a22d97f83878100bddac0d425f76ce96a213faefbc247fc792c4cf",
                      "start_byte": 11289,
                      "end_byte": 12083,
                      "value_digest": "sha256:3ad7aa73fab81e6370f99557b7d198c490343284256767db74f38ed62214a3a5"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4d4d7b2c1080a10856806a552eaa79b1cbb5ba59db0d9e252ce98441b538be82",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1956c9a5145cb53ff4a76397618c4ac375610113ada80051e8955328c8e7e642",
                    "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:57db4350cf5dfeb2dc75dc436d8d6153da78f1194ba988cfcd86b5bb594c7e1c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "doh-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                      "start_byte": 10060,
                      "end_byte": 10856,
                      "value_digest": "sha256:53c66d17b6c439f6d3cbc3bfa80e3416443535e382981f97fc3ead21a2443306"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0191811a554056886cb63f6864fabac767fee7225fbd1966f6bbdc903812b263",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:089a423bf8efc8ce84ec819dc86238a4f49a8eb9b0bd2295b5011bec32c1a30e",
                    "sha256:0d061e69967fa57f1d9ad87f2276b0c87218f412fe476fd508bc19f8d24af67f",
                    "sha256:3a096131d3bd82d5d318663145c81cca67c909f49b4a968a7ef04e60db602f43",
                    "sha256:b72c0acab99ab10f50818d05f2f16a267c483ff97634fc1d14e4088f1add262a"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "extended-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b72c0acab99ab10f50818d05f2f16a267c483ff97634fc1d14e4088f1add262a",
                      "start_byte": 10561,
                      "end_byte": 11360,
                      "value_digest": "sha256:18e93aa3188a3ce63ffa1843d0f2c06fea8e5e8f7c24bbb2ac372d173cae7ef7"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:77ac2744fd689882848816d8ea64549efc21c39e5c716e6148ee25bace738310",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:73498cb2beddbd607359b0b0d959c8b97f50d0a49357c060fd98450d679e797f",
                    "sha256:cdbd38c13928a07c811be242793df7acaffeffd354134884b60a93fa3e8a7c6b",
                    "sha256:f43ed47b543c11ac5c01d7ccc16a812f10aebddb521c7a882fddd238b1a19540",
                    "sha256:fba42eaa35a58732108546661d3d415d596959fbaa756395e4af62109181b47f"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "upstream-resolution"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:fba42eaa35a58732108546661d3d415d596959fbaa756395e4af62109181b47f",
                      "start_byte": 9897,
                      "end_byte": 10696,
                      "value_digest": "sha256:2fedd0562e970b0a32b032eecf618e654775118a0f5c03bf1b0bde5977105eba"
                    }
                  ]
                }
              ],
              "note": "The essential DoH targets have stable and decidable request parameters, MIME types, GET/POST methods, response JSON schemas/wireformats, extended error codes, and upstream resolution behavior clearly documented."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-09-06T08:51:45.033Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "doh-api"
                }
              ],
              "assessment_method": {
                "name": "public-semantic-assessment",
                "version": "2026-09-06",
                "method_digest": "sha256:02ec902925d3816c86a32a3d15dc2e7af6ce9931c24b9cf264063e596952d1c4"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0191811a554056886cb63f6864fabac767fee7225fbd1966f6bbdc903812b263",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:089a423bf8efc8ce84ec819dc86238a4f49a8eb9b0bd2295b5011bec32c1a30e",
                    "sha256:0d061e69967fa57f1d9ad87f2276b0c87218f412fe476fd508bc19f8d24af67f",
                    "sha256:0da425c96137448a51fd9d685d061f64ca4fcd9c4445024fca13fdcb39e500ec",
                    "sha256:b72c0acab99ab10f50818d05f2f16a267c483ff97634fc1d14e4088f1add262a"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "extended-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:b72c0acab99ab10f50818d05f2f16a267c483ff97634fc1d14e4088f1add262a",
                      "start_byte": 12155,
                      "end_byte": 12951,
                      "value_digest": "sha256:cc76ec2a66104cde5c06ebac59730d7cec5457e86e48e6bfd23715c71c8f518e"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4d4d7b2c1080a10856806a552eaa79b1cbb5ba59db0d9e252ce98441b538be82",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1956c9a5145cb53ff4a76397618c4ac375610113ada80051e8955328c8e7e642",
                    "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                    "sha256:56402c0e12997bbac9b4889239e01bf59c60e25ff3726b537a31aac237e683e3",
                    "sha256:57db4350cf5dfeb2dc75dc436d8d6153da78f1194ba988cfcd86b5bb594c7e1c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "doh-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1a0c864ead5297a948190b0f1c5f570af0d66dfb362e23aacf09344782c6cfe3",
                      "start_byte": 10060,
                      "end_byte": 10856,
                      "value_digest": "sha256:53c66d17b6c439f6d3cbc3bfa80e3416443535e382981f97fc3ead21a2443306"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:9dd68a3565ea5415765a3bd6be587e79821455071b69c8ea8950189bfd784bdf",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:22c0aa9d3ad4d493eccc8a0a75b283dac84cda4bb8ab2776e76c7bbb20102d6e",
                    "sha256:6158813b0004259ed7f20c7463cbf60f4e89e9f15b5bd930bfd7ef3589778b3e",
                    "sha256:c586fca2f6a22d97f83878100bddac0d425f76ce96a213faefbc247fc792c4cf",
                    "sha256:ef1c408053e6b5381d7d8cd2426d0e57a65f0491ec402f6fa642cccef2985a2b"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "doh-json-contract"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:c586fca2f6a22d97f83878100bddac0d425f76ce96a213faefbc247fc792c4cf",
                      "start_byte": 10538,
                      "end_byte": 11288,
                      "value_digest": "sha256:cdd6f45ec997155a571170bc24d40217d65869c1ad553c154c3ab2c94170eb36"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:77ac2744fd689882848816d8ea64549efc21c39e5c716e6148ee25bace738310",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2ad303d3b0180c2d2e5a10ef94c5a40f30e26a12f8169deddbca653c906c72d4",
                    "sha256:cdbd38c13928a07c811be242793df7acaffeffd354134884b60a93fa3e8a7c6b",
                    "sha256:f43ed47b543c11ac5c01d7ccc16a812f10aebddb521c7a882fddd238b1a19540",
                    "sha256:fba42eaa35a58732108546661d3d415d596959fbaa756395e4af62109181b47f"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "upstream-resolution"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:fba42eaa35a58732108546661d3d415d596959fbaa756395e4af62109181b47f",
                      "start_byte": 9080,
                      "end_byte": 9896,
                      "value_digest": "sha256:56a78fc1ae483ff0eef369d760efcb83335a088bf2c64ccbd57859535aa3d05f"
                    }
                  ]
                }
              ],
              "note": "All essential targets are accessible and executable via usable HTTP endpoints (`https://cloudflare-dns.com/dns-query` and `https://one.one.one.one/dns-query`) using standard JSON or DNS wireformat interfaces."
            }
          ],
          "blockers": [],
          "remediations": []
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 14,
        "covered_signals": 14,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 5,
        "barrier_ratio": 1
      },
      "last_tested_at": "2026-09-06T08:51:58.297Z",
      "freshness": "fresh",
      "provenance": {
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:fc9e8f046d86fcf19ab2f1bc547219e503cdc11ffa135d020db7285965cd7d1d",
        "freshness_policy_digest": "sha256:b71bacf415fdbef01024355fb3d080df7a9dca05d2cce9a2a1f691fe8a60f579",
        "basis_event_ids": [
          "sha256:04bb61a1637d7a09264f707679571d98be6d9109b2ee50ca191dca00c2cad3c0",
          "sha256:0c989b2eecacf2e4f2ad2de3fcde17237b2bf090409af0c62f0955d9ff591ec8",
          "sha256:0d8d4d3e570c84059ce2ae958173010c967b79cb1d53d9f319b736d27018ae5f",
          "sha256:12a6b154e383b75c7f002562056c2812b97cd4bd0eba5ffe1a127e34725f996c",
          "sha256:18bce93564ad8bb6c754036d77070fcb836d52eb6b58f5f855e8e3b8d0469e75",
          "sha256:18ff0c2bfada5db5978dae6281abd668f106afe5877c0cdc3beb045b1daa8368",
          "sha256:202aa63608387c771582956429e895c7f4739a4c293844d5eec02121a9b31b00",
          "sha256:252de7bb522fe3bca82fcdc6c039ecb2a6621a3fae50769231eca9baf3922a36",
          "sha256:26994027b28669cb3ff9c1fdf59e78fc941819143207309031a9724415884719",
          "sha256:275d375adcac0615bc94310be40d50f3cdf6f07551360b7f1ae7232685c4f343",
          "sha256:294138193c097b64b5e3f5b4304c162d499c6594848e7319ac967cf1814ae0a6",
          "sha256:2b0b664daae6da00f7f5d9a9fe9e1485e8d6f2512970ed369ae38e80479e3bf1",
          "sha256:34611ecd284dddee8f60320798aa2d58f07c11e3b1a5ca33ed8f415ee76f0946",
          "sha256:35d19724e7b112210b6b16ba91a750a05fbf2373086c4107e6d33cd10b747820",
          "sha256:37674c425972dcbf1f897a456d158d0d58114f9c145942f0e73c21fd634fff47",
          "sha256:4d346e3b80ec16c2c1bcaf5f2d0ef1c503fff6341519311d4d090b81eafc4b36",
          "sha256:53ea2a5e5a199cabdcd1914b8e72905726d1125739b8beb8de8a5600a4ccf93a",
          "sha256:62810dbad7da9487b1fd4978014e63893d28949aa86f4ec1f7b99812797e4107",
          "sha256:6fecfc88abdc0947a338427d01a2083338bd3a4c58355e072cf6f6e5a3d25b5a",
          "sha256:8e4e03dfde0cca179a12a1e375602e04675e28b4cedf169c9cd119d6251b9bdd",
          "sha256:9eb93718bea8c6f26bab8cb1cb7eff9d5612ec7264dda98a8e86e497bc0299a6",
          "sha256:abaa328d7c8493ef699230d6b35f1ad25e92172cc92163cff6b6492dfccd88e5",
          "sha256:af39d7ba1d758df90bec0880ff075baed87e9fad288e0241f5616bb8b255cd88",
          "sha256:b07d79dc0ce9c931c85ac71af3a09b0c428bd813d35e4ffa775cb1e74e31c0de",
          "sha256:b8f8a7d49afc8f448c18fb94e31bffa539fdcb8dafe720d4474f1696b09e5b14",
          "sha256:ba0e1577a215c3bea6afefa295da43d419bff36158d51d1a8073f68faf2276e7",
          "sha256:d4adc8586830f0adde109e1abec2aa33c2aec3bf088e39e1dd4e2440e4c388b8",
          "sha256:d64e3d819de483eafe3664a2468af0dbe4961d5cd9dd202afa7702e43c837cbd",
          "sha256:d72ad032263aa48f646e251a484602dbe1626b6650dda004250e79b0ab855e78",
          "sha256:dfd8b29bde96c2c62f10ad136cdd545ee702aca0fbef2cb13245481ceb9ab543",
          "sha256:e8150152715ac1bb4f8cf53371e1fa047e22a0b9ef7b84d3be0d7f4821c516ed",
          "sha256:e87020fe70f93984083925daf44a625a0ed76c3476cd4db51496e40ffd18da21",
          "sha256:ea215856166248764bd1bf9f2b3955e898a6bb304a86eab29133f56ec0f1bf1c",
          "sha256:fe6f83c0733db61bd27b89af9ac45ec07ac60c38e419953e365f67321a320a88"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:dfd8b29bde96c2c62f10ad136cdd545ee702aca0fbef2cb13245481ceb9ab543"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:50:23.426Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:6fecfc88abdc0947a338427d01a2083338bd3a4c58355e072cf6f6e5a3d25b5a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:50:23.426Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:35d19724e7b112210b6b16ba91a750a05fbf2373086c4107e6d33cd10b747820"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:35.415Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:abaa328d7c8493ef699230d6b35f1ad25e92172cc92163cff6b6492dfccd88e5"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:50:23.426Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:294138193c097b64b5e3f5b4304c162d499c6594848e7319ac967cf1814ae0a6"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:58.297Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:2b0b664daae6da00f7f5d9a9fe9e1485e8d6f2512970ed369ae38e80479e3bf1"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:35.415Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:0d8d4d3e570c84059ce2ae958173010c967b79cb1d53d9f319b736d27018ae5f",
              "sha256:4d346e3b80ec16c2c1bcaf5f2d0ef1c503fff6341519311d4d090b81eafc4b36"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:37.784Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:53ea2a5e5a199cabdcd1914b8e72905726d1125739b8beb8de8a5600a4ccf93a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:06.043Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:e87020fe70f93984083925daf44a625a0ed76c3476cd4db51496e40ffd18da21"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:06.043Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:fe6f83c0733db61bd27b89af9ac45ec07ac60c38e419953e365f67321a320a88"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:35.415Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:62810dbad7da9487b1fd4978014e63893d28949aa86f4ec1f7b99812797e4107"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:06.043Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:202aa63608387c771582956429e895c7f4739a4c293844d5eec02121a9b31b00"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:58.297Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:d72ad032263aa48f646e251a484602dbe1626b6650dda004250e79b0ab855e78"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:50:23.426Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:d64e3d819de483eafe3664a2468af0dbe4961d5cd9dd202afa7702e43c837cbd"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:58.297Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:26994027b28669cb3ff9c1fdf59e78fc941819143207309031a9724415884719"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:58.297Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:252de7bb522fe3bca82fcdc6c039ecb2a6621a3fae50769231eca9baf3922a36"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:35.415Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:0c989b2eecacf2e4f2ad2de3fcde17237b2bf090409af0c62f0955d9ff591ec8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:35.415Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:b8f8a7d49afc8f448c18fb94e31bffa539fdcb8dafe720d4474f1696b09e5b14"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:01.791Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:9eb93718bea8c6f26bab8cb1cb7eff9d5612ec7264dda98a8e86e497bc0299a6",
              "sha256:af39d7ba1d758df90bec0880ff075baed87e9fad288e0241f5616bb8b255cd88"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:45.033Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:18ff0c2bfada5db5978dae6281abd668f106afe5877c0cdc3beb045b1daa8368"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:35.415Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:37674c425972dcbf1f897a456d158d0d58114f9c145942f0e73c21fd634fff47",
              "sha256:b07d79dc0ce9c931c85ac71af3a09b0c428bd813d35e4ffa775cb1e74e31c0de",
              "sha256:ba0e1577a215c3bea6afefa295da43d419bff36158d51d1a8073f68faf2276e7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:45.033Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/21",
            "supporting_event_ids": [
              "sha256:d4adc8586830f0adde109e1abec2aa33c2aec3bf088e39e1dd4e2440e4c388b8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:35.415Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/22",
            "supporting_event_ids": [
              "sha256:04bb61a1637d7a09264f707679571d98be6d9109b2ee50ca191dca00c2cad3c0",
              "sha256:18bce93564ad8bb6c754036d77070fcb836d52eb6b58f5f855e8e3b8d0469e75",
              "sha256:34611ecd284dddee8f60320798aa2d58f07c11e3b1a5ca33ed8f415ee76f0946",
              "sha256:ea215856166248764bd1bf9f2b3955e898a6bb304a86eab29133f56ec0f1bf1c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:45.033Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/23",
            "supporting_event_ids": [
              "sha256:12a6b154e383b75c7f002562056c2812b97cd4bd0eba5ffe1a127e34725f996c",
              "sha256:275d375adcac0615bc94310be40d50f3cdf6f07551360b7f1ae7232685c4f343",
              "sha256:8e4e03dfde0cca179a12a1e375602e04675e28b4cedf169c9cd119d6251b9bdd",
              "sha256:e8150152715ac1bb4f8cf53371e1fa047e22a0b9ef7b84d3be0d7f4821c516ed"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-09-06T08:51:45.033Z",
            "freshness": "fresh"
          }
        ],
        "vendor_attestation": {
          "status": "none"
        }
      },
      "canonical_url": "https://sourcey.com/log/cloudflare/agent-readiness/cloudflare-public-dns/dns-over-https-query",
      "projection_digest": "sha256:69a02202d628fe399fb80b2bf149bde071db8ac72471c5743cbf11711859cb5a"
    }
  }
}
