{
  "source": "https://pntmap.co.uk/capability-status.json",
  "updated": "2026-08-15",
  "node_offline_threshold_minutes": 10,
  "transport_posture": "Transport uses TLS 1.3 with hybrid post-quantum key agreement (X25519MLKEM768, ML-KEM / FIPS 203) negotiated by default at the edge and on the backend link, for supporting clients (Chrome/Edge 124+, Firefox 132+, recent OpenSSL). Older clients fall back gracefully to classical X25519, and certificate authentication remains classical (ECDSA/RSA).",
  "capabilities": [
    {
      "id": "adsb_integrity_monitoring",
      "capability": "ADS-B-derived integrity anomaly monitoring",
      "state": "live",
      "status": "Live",
      "detail": "Cell-level low-NIC proportions are computed continuously from node telemetry and published on the map and stats surfaces."
    },
    {
      "id": "phase1_nodes",
      "capability": "Phase 1 nodes",
      "state": "partial",
      "status": "2 of 20 live",
      "detail": "Coverage is exactly the reception footprint of the live nodes. Absence of a record outside that footprint carries no information."
    },
    {
      "id": "mldsa_signing",
      "capability": "ML-DSA telemetry signing",
      "state": "live",
      "status": "Live on all current nodes",
      "detail": "ML-DSA-65 (FIPS 204) signatures are generated at each sensor and verified at ingest before storage. This covers origin and integrity at ingest only."
    },
    {
      "id": "rf_sensing",
      "capability": "Direct RF sensing and corroboration",
      "state": "not_live",
      "status": "No live RF node",
      "detail": "No node measures the GNSS bands today, so no ADS-B anomaly on the platform is RF-corroborated."
    },
    {
      "id": "event_lifecycle",
      "capability": "Automatic event lifecycle",
      "state": "not_live",
      "status": "Not live; operator-curated",
      "detail": "Sustained anomalies are submitted for operator review. Opening, revision and closure of event records are manual."
    },
    {
      "id": "evidence_anchoring",
      "capability": "Independent evidence anchoring",
      "state": "live",
      "status": "Live",
      "detail": "Live. Each ledger block header is independently timestamped via two unrelated mechanisms: the Bitcoin blockchain (OpenTimestamps) and an RFC 3161 timestamp authority (DigiCert). First confirmed Bitcoin attestation: ledger block 55 → Bitcoin block 962625 (2026-08-15 21:00:27 UTC), externally verified against two independent block explorers; RFC 3161 timestamps verified against DigiCert's root CA. Recent blocks are anchored on the next scheduled run."
    },
    {
      "id": "node_ingest_commitments",
      "capability": "Per-node signed ingest commitments (completeness)",
      "state": "live",
      "status": "Live on all current nodes",
      "detail": "Each node publishes a daily ML-DSA-65 (FIPS 204)-signed commitment to its ingest chain, independently anchored via OpenTimestamps (Bitcoin)."
    },
    {
      "id": "commercial_api",
      "capability": "Commercial API SLA and pricing",
      "state": "not_published",
      "status": "Not yet published",
      "detail": "Latency and availability targets, commercial model and pricing are not published. Access is arranged case by case."
    },
    {
      "id": "classified_deployment",
      "capability": "Classified deployment",
      "state": "not_published",
      "status": "Separate scoped engagement, not the public platform",
      "detail": "The public platform operates at OFFICIAL and holds no classified-handling accreditation. Requirements above OFFICIAL are an individually scoped engagement."
    }
  ]
}