{
  "publicSanitized": [
    {
      "surface": "/",
      "classification": "public-sanitized",
      "purpose": "enterprise portal"
    },
    {
      "surface": "/command.html",
      "classification": "public-sanitized",
      "purpose": "operator command center"
    },
    {
      "surface": "/pinnacle.html",
      "classification": "public-sanitized",
      "purpose": "board-level proof room"
    },
    {
      "surface": "/deal.html",
      "classification": "public-sanitized",
      "purpose": "buyer/investor deal room"
    },
    {
      "surface": "/diligence.html",
      "classification": "public-sanitized",
      "purpose": "role-based review room"
    },
    {
      "surface": "/genesis.html",
      "classification": "public-sanitized",
      "purpose": "system map and proof index"
    },
    {
      "surface": "/sovereignty.html",
      "classification": "public-sanitized",
      "purpose": "authority and boundary registry"
    },
    {
      "surface": "/horizon.html",
      "classification": "public-sanitized",
      "purpose": "capability and moat map"
    },
    {
      "surface": "/releases.html",
      "classification": "public-sanitized",
      "purpose": "release ledger"
    },
    {
      "surface": "/trust.html",
      "classification": "public-sanitized",
      "purpose": "trust center controls"
    },
    {
      "surface": "/status.html",
      "classification": "public-sanitized",
      "purpose": "status and incident history"
    },
    {
      "surface": "/proof/*.json",
      "classification": "public-sanitized",
      "purpose": "sanitized proof assets only"
    }
  ],
  "privateProtected": [
    {
      "surface": "/admin.html",
      "classification": "private-protected",
      "protection": "Basic Auth"
    },
    {
      "surface": "/api/admin/*",
      "classification": "private-protected",
      "protection": "Basic Auth + X-AMGS-Admin-Secret"
    },
    {
      "surface": "/home/kpjadmin/AMGS_ADMIN_SECRET_PRIVATE_CURRENT.txt",
      "classification": "private-secret",
      "protection": "filesystem only"
    },
    {
      "surface": "/home/kpjadmin/AMGS_ADMIN_BASIC_AUTH_PRIVATE_CURRENT.txt",
      "classification": "private-secret",
      "protection": "filesystem only"
    },
    {
      "surface": "/home/kpjadmin/amgs-auditor-packs",
      "classification": "private-evidence",
      "protection": "filesystem only"
    },
    {
      "surface": "/home/kpjadmin/amgs-platform-dossiers",
      "classification": "private-dossier",
      "protection": "filesystem only"
    },
    {
      "surface": "/home/kpjadmin/amgs-readiness-certificates",
      "classification": "private-certificate",
      "protection": "filesystem only"
    }
  ],
  "principle": "Public proof surfaces expose sanitized evidence only. Private admin, secret, dossier, and evidence-pack surfaces remain protected."
}
