{
  "object": "list",
  "generated_at": "2026-10-05T04:09:54.581Z",
  "total": 3,
  "limit": 50,
  "offset": 0,
  "count": 3,
  "filters": {
    "category": null
  },
  "categories": [
    {
      "code": "compliance",
      "label": "Compliance"
    },
    {
      "code": "vulnerability",
      "label": "Vulnerability"
    },
    {
      "code": "incident",
      "label": "Incident"
    },
    {
      "code": "subprocessor",
      "label": "Sub-processor"
    },
    {
      "code": "general",
      "label": "General"
    }
  ],
  "format": {
    "body_structure": [
      "summary",
      "background",
      "details",
      "remediation"
    ],
    "reference_scheme": "PNSV-<CATEGORY>-<YEAR>-<NN>",
    "standard_doc_id": "NTC-GL-021"
  },
  "feeds": {
    "rss": "https://trust.pensievelabs.org/updates.rss",
    "page": "https://trust.pensievelabs.org/updates"
  },
  "data": [
    {
      "reference": "PNSV-SEC-2026-01",
      "slug": "certification-position",
      "title": "Pensieve holds no security certifications, and says so",
      "category": "compliance",
      "category_label": "Compliance",
      "severity": null,
      "pinned": true,
      "published_at": "2026-07-31T09:30:00.000Z",
      "summary": "Pensieve holds no ISO 27001, no SOC 2, no HITRUST, no CE marking and no ARTG listing. The Assurance page states what exists instead, and what is in progress with dates.",
      "background": "Buyers discover certification gaps anyway. Discovering them from the vendor first is disarming, and it removes the discovery from the security review, which removes days.",
      "details": "What exists today: an ISO 27001 Statement of Applicability without certification, a self-assessed CAIQ, published policies, an SBOM, and the security grades for this site. What is deliberately out of scope: ABDM M1/M2/M3 and NHCX certification. Pensieve integrates using the hospital's own credentials under a BYOK/BYOC model and is not the regulated participant.",
      "remediation": "Read the Assurance page and the Integration Boundary Statement.",
      "related_documents": [
        {
          "doc_id": "WPR-GL-005",
          "title": "Trust & Assurance Overview (What Pensieve Has, What Is Coming, What It Does Not Have)",
          "tier": "T_PUBLIC",
          "url": "https://trust.pensievelabs.org/documents/wpr-gl-005-trust-and-assurance-overview-what-pensieve-has-what-is-coming"
        },
        {
          "doc_id": "DIS-GL-024",
          "title": "Integration Boundary Statement",
          "tier": "T_NDA",
          "url": "https://trust.pensievelabs.org/documents/dis-gl-024-integration-boundary-statement"
        },
        {
          "doc_id": "DIS-GL-025",
          "title": "BYOK / BYOC Credential Handling Disclosure",
          "tier": "T_NDA",
          "url": "https://trust.pensievelabs.org/documents/dis-gl-025-byok-byoc-credential-handling-disclosure"
        },
        {
          "doc_id": "DIS-GL-026",
          "title": "ABDM / NHCX Responsibility Matrix (Sequencing, Owners and Acknowledgement)",
          "tier": "T_NDA",
          "url": "https://trust.pensievelabs.org/documents/dis-gl-026-abdm-nhcx-responsibility-matrix-sequencing-owners-and"
        }
      ],
      "url": "https://trust.pensievelabs.org/updates/certification-position"
    },
    {
      "reference": "PNSV-GEN-2026-01",
      "slug": "trust-center-published",
      "title": "The Pensieve Trust Center is live",
      "category": "general",
      "category_label": "General",
      "severity": null,
      "pinned": true,
      "published_at": "2026-07-31T09:00:00.000Z",
      "summary": "Every formal artefact between Pensieve and a hospital customer is now published, versioned and retrievable: 108 documents with no gate at all.",
      "background": "Pensieve is an unknown vendor selling an operating system for hospitals. A hospital's legal, security, finance and IT reviewers each need evidence before they will spend time on a conversation. Making them ask for it costs days.",
      "details": "The Trust Center publishes the standard MSA, DPA, SLA, security whitepaper, architecture overview, sub-processor register, exit and data-portability commitment without a gate. The security policy set, full assessment reports, detailed network diagrams, continuity test evidence and insurance documents sit behind the mutual NDA and an access request an administrator approves.",
      "remediation": "No action required.",
      "related_documents": [
        {
          "doc_id": "POL-GL-500",
          "title": "Trust Center Access Policy, Document Classification & Publication Policy",
          "tier": "T_PUBLIC",
          "url": "https://trust.pensievelabs.org/documents/pol-gl-500-trust-center-access-policy-document-classification-and"
        },
        {
          "doc_id": "POL-GL-501",
          "title": "Document Classification & Publication Policy",
          "tier": "T_PUBLIC",
          "url": "https://trust.pensievelabs.org/documents/pol-gl-501-document-classification-and-publication-policy"
        },
        {
          "doc_id": "WPR-GL-001",
          "title": "Pensieve Security Whitepaper",
          "tier": "T_NDA",
          "url": "https://trust.pensievelabs.org/documents/wpr-gl-001-pensieve-security-whitepaper"
        }
      ],
      "url": "https://trust.pensievelabs.org/updates/trust-center-published"
    },
    {
      "reference": "PNSV-SUB-2026-01",
      "slug": "subprocessor-register-published",
      "title": "Sub-processor register published with change notification",
      "category": "subprocessor",
      "category_label": "Sub-processor",
      "severity": null,
      "pinned": false,
      "published_at": "2026-07-31T10:00:00.000Z",
      "summary": "The live sub-processor register is public, and any addition is notified in advance to subscribers under NTC-GL-001.",
      "background": "A sub-processor list that is only produced on request, as a PDF, dated last year, is the most common failure in this category.",
      "details": "Four sub-processors are listed, each with purpose, data categories, location and the deployment models it applies to. The register distinguishes Pensieve platform sub-processors from Trust Center sub-processors.",
      "remediation": "Subscribe to updates to receive change notices.",
      "related_documents": [
        {
          "doc_id": "DIS-GL-009",
          "title": "Subprocessor Register",
          "tier": "T_NDA",
          "url": "https://trust.pensievelabs.org/documents/dis-gl-009-subprocessor-register"
        },
        {
          "doc_id": "DIS-GL-010",
          "title": "Sub-Processor Change Log & Notification Feed",
          "tier": "T_NDA",
          "url": "https://trust.pensievelabs.org/documents/dis-gl-010-sub-processor-change-log-and-notification-feed"
        },
        {
          "doc_id": "NTC-GL-001",
          "title": "Sub-Processor Change Notice",
          "tier": "T_NDA",
          "url": "https://trust.pensievelabs.org/documents/ntc-gl-001-sub-processor-change-notice"
        }
      ],
      "url": "https://trust.pensievelabs.org/updates/subprocessor-register-published"
    }
  ]
}