{
  "$schema": "https://finance.entelekron.org/schemas/sandbox-isolation-profile.schema.json",
  "schemaVersion": "1.0.0",
  "controlPlaneId": "tvk-group:entelekron-financial-infrastructure",
  "canonicalAssetId": "tvk-group:tvkusd",
  "profileId": "tvkusd-sandbox-isolation-v1",
  "status": "not-configured",
  "asOf": "2026-08-14T00:00:00Z",
  "environmentId": null,
  "publicEndpoint": null,
  "activeSyntheticAccountCount": 0,
  "dataBoundary": {
    "syntheticDataOnly": true,
    "productionPersonalDataPermitted": false,
    "productionBankDataPermitted": false,
    "productionCredentialsAccessible": false,
    "productionSigningKeysAccessible": false,
    "realValueMovementPermitted": false
  },
  "networkBoundary": {
    "productionNetworksAccessible": false,
    "productionProvidersAccessible": false,
    "allowlistRequired": true,
    "outboundDestinationLoggingRequired": true,
    "defaultOutboundPolicy": "deny"
  },
  "testAssetBoundary": {
    "canonicalProductionContractPermitted": false,
    "productionAssetIdentifiersPermitted": false,
    "testAssetsMustBeVisiblyNonProduction": true,
    "testBalancesHaveNoRedemptionRight": true
  },
  "promotion": {
    "environmentVariableAloneCanPromote": false,
    "codeMergeAloneCanPromote": false,
    "signedPolicyBundleRequired": true,
    "independentSecurityApprovalRequired": true,
    "independentOperationsApprovalRequired": true,
    "newJurisdictionAndProviderEvidenceRequired": true
  },
  "authority": {
    "aiCanConnectProductionCredentials": false,
    "aiCanPromoteEnvironment": false,
    "singleOperatorCanRemoveIsolation": false
  },
  "notice": "No sandbox is represented as active. Any future test environment must use synthetic identities, visibly non-production assets and hard separation from production credentials, networks and value."
}
