Compliance Posture, Full Package (Gated)
8 source changes since auditThis page confirms that a full compliance package exists and explains how to request it. It is a pointer, not the package. The audit-grade material itself is confidential and is never built into these public docs.
What it is
Behind the public summary at Compliance posture sits a complete compliance package: System Security Plans, control crosswalks against the relevant NIST families, control narratives, plans of action with milestones, and the evidence that backs each one. We keep that package in a private home and treat it as the source of record for assessors and auditors.
The public summary tells you where we stand, in plain language. This package is what an assessor reads when they need the detail behind that summary. We do not reproduce any of that detail here: no control scores, no plan-of-action items, no evidence, and no named third parties appear on this page or anywhere in the public docs.
How to request access
Access is for people with a contractual reason to read the package: contracted assessors, issued auditors, and named principals running due diligence, each under a non-disclosure agreement.
- Ask through your commercial or compliance contact at Citrate, or through your account channel.
- We confirm your role and put the non-disclosure agreement in place.
- We grant time-bound access to the package in its private home.
Access and canon
The full package is confidential. It is served at request time from its private home, under a non-disclosure agreement, to named recipients only. It is never copied into this documentation tree, and the public build never includes it. Every access is logged. The sanitized public summary, which anyone may read, is at Compliance posture.
Some of the frameworks the package covers are certified and some are in progress. We label each one honestly in the package and in the public summary, and we show no scores on this page.
Source and verification
Private source: the citrate-compliance corpus and its audit archive. Audited against citrate-compliance SHA 8757357. Status: Implemented (the package exists and is maintained); certifications in progress are labeled as in progress, with no scores shown here.