{
  "schema_version": "1.0.0",
  "release": "v1.0.0",
  "generated_at": "2026-08-06T18:01:29+01:00",
  "truth_status": {
    "ro": "Toate cele patru bonuri sunt scenarii sintetice de calibrare. Niciunul nu descrie o instituție sau aplicație reală.",
    "en": "All four receipts are synthetic calibration scenarios. None describes a real institution or app."
  },
  "receipts": [
    {
      "id": "calibrare-sesizari",
      "slug": "calibrare-sesizari",
      "is_calibration": true,
      "app": {
        "name": "Oraș Test — Sesizări",
        "package_id": "org.example.orastest",
        "version": "4.8.1",
        "apk_sha256": "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
      },
      "owner": "Instituție fictivă pentru calibrare",
      "supplier": "Furnizor fictiv pentru calibrare",
      "journey": {
        "ro": "Trimiterea unei sesizări privind iluminatul public",
        "en": "Submitting a street-lighting report"
      },
      "device": {
        "model": "Pixel 8a (laborator)",
        "os": "Android 16",
        "locale": "ro-RO",
        "lane": "stock + instrumented"
      },
      "tested_at": "2026-08-05T10:12:00+03:00",
      "method_version": "PPR-1.0",
      "audit_level": "CAL",
      "headline": {
        "ro": "Un serviciu de analiză a pornit înainte ca alegerea opțională să fie afișată.",
        "en": "An analytics service started before the optional choice was shown."
      },
      "dek": {
        "ro": "Exemplu sintetic construit pentru a demonstra cum separăm o conexiune observată de o concluzie despre conținutul transmis.",
        "en": "Synthetic example showing how the product separates an observed connection from a conclusion about transmitted content."
      },
      "verdict": "observed_not_clearly_described",
      "states": [
        {
          "id": "before_choice",
          "label": {
            "ro": "Înainte să alegi",
            "en": "Before choice"
          },
          "service_result": {
            "ro": "Aplicația s-a deschis. Formularul nu fusese încă folosit.",
            "en": "The app opened. The form had not yet been used."
          },
          "events": [
            {
              "moment": "app_open",
              "policy": {
                "ro": "Politica menționează analize opționale după acord.",
                "en": "The policy describes optional analytics after consent."
              },
              "store": {
                "ro": "Magazinul declară colectarea activității în scop de analiză.",
                "en": "The store label declares app activity for analytics."
              },
              "device": {
                "ro": "Telefonul a contactat analytics.example la 420 ms după deschidere, înaintea ecranului de alegere.",
                "en": "The phone contacted analytics.example 420 ms after launch, before the choice screen."
              },
              "evidence_strength": "connection_observed",
              "limitations": {
                "ro": "Conținutul complet era criptat; numai destinația și metadatele conexiunii au fost stabilite.",
                "en": "The full content was encrypted; only destination and connection metadata were established."
              },
              "domains": [
                "api.orastest.example",
                "analytics.example"
              ]
            },
            {
              "moment": "choice_screen",
              "policy": {
                "ro": "Acordul este descris ca opțional.",
                "en": "Consent is described as optional."
              },
              "store": {
                "ro": "Magazinul nu descrie momentul inițializării.",
                "en": "The store label does not describe initialization timing."
              },
              "device": {
                "ro": "Ecranul de alegere a apărut după prima conexiune către serviciul de analiză.",
                "en": "The choice screen appeared after the first analytics connection."
              },
              "evidence_strength": "screen_and_connection",
              "limitations": {
                "ro": "Nu rezultă că un identificator personal a fost transmis.",
                "en": "This does not establish that a personal identifier was transmitted."
              },
              "domains": [
                "analytics.example"
              ]
            }
          ]
        },
        {
          "id": "refused",
          "label": {
            "ro": "După ce ai refuzat",
            "en": "After refusal"
          },
          "service_result": {
            "ro": "Sesizarea a putut fi trimisă fără analiza opțională.",
            "en": "The report could be submitted without optional analytics."
          },
          "events": [
            {
              "moment": "refusal",
              "policy": {
                "ro": "Politica spune că refuzul nu afectează serviciul de bază.",
                "en": "The policy says refusal does not affect the core service."
              },
              "store": {
                "ro": "Magazinul indică faptul că utilizatorul poate solicita ștergerea.",
                "en": "The store label says deletion can be requested."
              },
              "device": {
                "ro": "După refuz, nu au mai fost observate conexiuni către analytics.example în cele două rulări.",
                "en": "After refusal, no further connections to analytics.example were observed in two runs."
              },
              "evidence_strength": "repeated_non_observation",
              "limitations": {
                "ro": "Absența într-un traseu nu dovedește că serviciul nu poate fi folosit în alte funcții sau prin configurare la distanță.",
                "en": "Absence in one journey does not prove the service cannot appear in other features or under remote configuration."
              },
              "domains": []
            },
            {
              "moment": "submit",
              "policy": {
                "ro": "Politica descrie trimiterea fotografiei, localizării și textului către instituție.",
                "en": "The policy describes sending the photo, location and text to the institution."
              },
              "store": {
                "ro": "Magazinul declară fotografii și localizare pentru funcționalitatea aplicației.",
                "en": "The store label declares photos and location for app functionality."
              },
              "device": {
                "ro": "Valoarea sintetică LAMPA-7Q2 a fost observată în cererea către api.orastest.example.",
                "en": "The synthetic value LAMPA-7Q2 was observed in the request to api.orastest.example."
              },
              "evidence_strength": "exact_synthetic_token",
              "limitations": {
                "ro": "Valoarea dovedește transmiterea către endpointul serviciului; nu stabilește singură rolul juridic al fiecărui operator.",
                "en": "The value establishes transmission to the service endpoint; it does not by itself establish each operator’s legal role."
              },
              "domains": [
                "api.orastest.example"
              ]
            }
          ]
        },
        {
          "id": "accepted",
          "label": {
            "ro": "După ce ai acceptat",
            "en": "After acceptance"
          },
          "service_result": {
            "ro": "Serviciul de bază și analiza opțională au funcționat.",
            "en": "The core service and optional analytics operated."
          },
          "events": [
            {
              "moment": "acceptance",
              "policy": {
                "ro": "Politica descrie evenimente de utilizare pseudonimizate.",
                "en": "The policy describes pseudonymous usage events."
              },
              "store": {
                "ro": "Magazinul declară activitatea aplicației.",
                "en": "The store label declares app activity."
              },
              "device": {
                "ro": "Conexiunile către analytics.example au continuat. Un câmp event_name=report_submitted a fost lizibil; identificatorul complet nu a fost interpretat.",
                "en": "Connections to analytics.example continued. A readable event_name=report_submitted field was observed; the full identifier was not interpreted."
              },
              "evidence_strength": "readable_data_category",
              "limitations": {
                "ro": "Un nume de eveniment nu arată dacă furnizorul îl poate lega de o persoană.",
                "en": "An event name does not show whether the provider can link it to a person."
              },
              "domains": [
                "analytics.example"
              ]
            }
          ]
        },
        {
          "id": "withdrawn",
          "label": {
            "ro": "După retragere",
            "en": "After withdrawal"
          },
          "service_result": {
            "ro": "Sesizările au rămas disponibile.",
            "en": "Reporting remained available."
          },
          "events": [
            {
              "moment": "withdrawal",
              "policy": {
                "ro": "Politica promite oprirea analizelor viitoare.",
                "en": "The policy promises to stop future analytics."
              },
              "store": {
                "ro": "Magazinul nu oferă detalii despre retragere.",
                "en": "The store label gives no withdrawal detail."
              },
              "device": {
                "ro": "După retragere și repornire, analytics.example nu a mai fost contactat în două rulări.",
                "en": "After withdrawal and restart, analytics.example was not contacted in two runs."
              },
              "evidence_strength": "repeated_non_observation",
              "limitations": {
                "ro": "Testul nu verifică ștergerea datelor deja aflate pe server.",
                "en": "The test does not verify deletion of data already held server-side."
              },
              "domains": []
            }
          ]
        }
      ],
      "destinations": [
        {
          "domain": "api.orastest.example",
          "owner": "Instituția fictivă",
          "role": {
            "ro": "API al serviciului de sesizări",
            "en": "Reporting-service API"
          },
          "relationship": "first_party",
          "first_seen": "app_open",
          "states_seen": [
            "before_choice",
            "refused",
            "accepted",
            "withdrawn"
          ],
          "payload_evidence": "exact_synthetic_token",
          "payload_summary": {
            "ro": "Textul sintetic al sesizării a fost observat în payload.",
            "en": "The synthetic report text was observed in the payload."
          },
          "attribution_certainty": "documented"
        },
        {
          "domain": "analytics.example",
          "owner": "Analiză Exemplu SA",
          "role": {
            "ro": "serviciu comercial de analiză",
            "en": "commercial analytics service"
          },
          "relationship": "third_party",
          "first_seen": "app_open",
          "states_seen": [
            "before_choice",
            "accepted"
          ],
          "payload_evidence": "readable_data_category",
          "payload_summary": {
            "ro": "Destinația și un nume de eveniment au fost observate; identificatorul complet nu a fost stabilit.",
            "en": "The destination and an event name were observed; the full identifier was not established."
          },
          "attribution_certainty": "documented"
        }
      ],
      "claims": [
        {
          "id": "CAL-001",
          "classification": "observed_not_clearly_described",
          "statement": {
            "ro": "Serviciul de analiză a fost contactat înaintea afișării alegerii opționale.",
            "en": "The analytics service was contacted before the optional choice was shown."
          },
          "maximum_wording": {
            "ro": "Putem spune când a început conexiunea; nu putem spune că profilarea a avut loc.",
            "en": "We can state when the connection began; we cannot state that profiling occurred."
          },
          "status": "calibration"
        },
        {
          "id": "CAL-002",
          "classification": "declared_and_observed",
          "statement": {
            "ro": "Textul sintetic al sesizării a fost transmis către API-ul documentat al serviciului.",
            "en": "The synthetic report text was sent to the service’s documented API."
          },
          "maximum_wording": {
            "ro": "Valoarea exactă a părăsit dispozitivul în cererea observată.",
            "en": "The exact value left the device in the observed request."
          },
          "status": "calibration"
        }
      ],
      "repairs": [
        {
          "id": "REP-CAL-001",
          "actor": "Furnizor fictiv",
          "minimum_change": {
            "ro": "Inițializează SDK-ul de analiză numai după acceptarea explicită sau scoate-l din traseul de bază.",
            "en": "Initialize the analytics SDK only after explicit acceptance, or remove it from the core journey."
          },
          "verification": {
            "ro": "Repetă traseul pe instalare curată și confirmă absența conexiunii înainte de alegere.",
            "en": "Repeat the journey on a clean install and confirm no pre-choice connection."
          },
          "status": "proposed"
        }
      ],
      "limitations": {
        "ro": [
          "Aplicație și date complet fictive.",
          "Două rulări nu acoperă toate funcțiile.",
          "Atribuirea juridică nu rezultă numai din trafic."
        ],
        "en": [
          "The app and all data are fictional.",
          "Two runs do not cover every feature.",
          "Legal attribution does not follow from traffic alone."
        ]
      }
    },
    {
      "id": "calibrare-plati",
      "slug": "calibrare-plati",
      "is_calibration": true,
      "app": {
        "name": "Plăți Test",
        "package_id": "org.example.platitest",
        "version": "2.3.0",
        "apk_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
      },
      "owner": "Instituție fictivă pentru calibrare",
      "supplier": "Furnizor fictiv pentru calibrare",
      "journey": {
        "ro": "Plata unei taxe fictive fără autentificare",
        "en": "Paying a fictional fee without signing in"
      },
      "device": {
        "model": "Pixel 8a (laborator)",
        "os": "Android 16",
        "locale": "ro-RO",
        "lane": "stock + instrumented"
      },
      "tested_at": "2026-08-05T12:40:00+03:00",
      "method_version": "PPR-1.0",
      "audit_level": "CAL",
      "headline": {
        "ro": "Politica, declarația magazinului și traseul testat au fost consecvente.",
        "en": "The policy, store declaration and tested journey were consistent."
      },
      "dek": {
        "ro": "Un rezultat bun este publicat cu aceeași precizie ca o discrepanță.",
        "en": "A good result is published with the same precision as a discrepancy."
      },
      "verdict": "declared_and_observed",
      "states": [
        {
          "id": "before_choice",
          "label": {
            "ro": "Înainte să alegi",
            "en": "Before choice"
          },
          "service_result": {
            "ro": "Aplicația a afișat taxa și opțiunile fără servicii opționale.",
            "en": "The app displayed the fee and options without optional services."
          },
          "events": [
            {
              "moment": "app_open",
              "policy": {
                "ro": "Politica descrie numai infrastructura de serviciu și procesatorul de plăți.",
                "en": "The policy describes only service infrastructure and the payment processor."
              },
              "store": {
                "ro": "Magazinul declară date financiare pentru funcționalitate.",
                "en": "The store label declares financial data for functionality."
              },
              "device": {
                "ro": "Au fost observate numai config.platitest.example și api.platitest.example.",
                "en": "Only config.platitest.example and api.platitest.example were observed."
              },
              "evidence_strength": "connection_observed",
              "limitations": {
                "ro": "Testul nu stabilește ce funcții neexercitate ar putea folosi alte servicii.",
                "en": "The test does not establish what unexercised features might use."
              },
              "domains": [
                "config.platitest.example",
                "api.platitest.example"
              ]
            }
          ]
        },
        {
          "id": "refused",
          "label": {
            "ro": "După ce ai refuzat",
            "en": "After refusal"
          },
          "service_result": {
            "ro": "Nu exista o alegere de analiză; notificările opționale au fost refuzate fără efect asupra plății.",
            "en": "There was no analytics choice; optional notifications were refused without affecting payment."
          },
          "events": [
            {
              "moment": "notifications_refused",
              "policy": {
                "ro": "Politica separă notificările de plata de bază.",
                "en": "The policy separates notifications from core payment."
              },
              "store": {
                "ro": "Magazinul declară notificările ca opționale.",
                "en": "The store label describes notifications as optional."
              },
              "device": {
                "ro": "Plata a rămas disponibilă și nu a apărut nicio destinație suplimentară.",
                "en": "Payment remained available and no additional destination appeared."
              },
              "evidence_strength": "service_outcome_and_connections",
              "limitations": {
                "ro": "Nu rezultă că toate notificările viitoare sunt imposibile.",
                "en": "This does not establish that every future notification is impossible."
              },
              "domains": []
            }
          ]
        },
        {
          "id": "accepted",
          "label": {
            "ro": "După ce ai acceptat",
            "en": "After acceptance"
          },
          "service_result": {
            "ro": "Plata de test a fost inițiată și anulată înainte de autorizarea bancară.",
            "en": "The test payment was initiated and cancelled before bank authorisation."
          },
          "events": [
            {
              "moment": "payment_start",
              "policy": {
                "ro": "Politica numește procesatorul fictiv și categoriile de date.",
                "en": "The policy names the fictional processor and data categories."
              },
              "store": {
                "ro": "Magazinul declară informații financiare.",
                "en": "The store label declares financial information."
              },
              "device": {
                "ro": "Tokenul sintetic INV-TEST-884 a fost observat către pay.example; datele cardului nu au fost introduse.",
                "en": "The synthetic token INV-TEST-884 was observed going to pay.example; no card data was entered."
              },
              "evidence_strength": "exact_synthetic_token",
              "limitations": {
                "ro": "Testul nu a traversat pagina procesatorului bancar.",
                "en": "The test did not proceed through the bank processor page."
              },
              "domains": [
                "pay.example"
              ]
            }
          ]
        },
        {
          "id": "withdrawn",
          "label": {
            "ro": "După retragere",
            "en": "After withdrawal"
          },
          "service_result": {
            "ro": "Nu era aplicabilă o retragere de analiză. Contul nu a fost creat.",
            "en": "Analytics withdrawal was not applicable. No account was created."
          },
          "events": [
            {
              "moment": "not_applicable",
              "policy": {
                "ro": "Politica descrie plata fără cont.",
                "en": "The policy describes payment without an account."
              },
              "store": {
                "ro": "Magazinul declară că datele pot fi șterse la cerere.",
                "en": "The store label says deletion can be requested."
              },
              "device": {
                "ro": "Nu a fost creat niciun cont sau identificator persistent în traseul testat.",
                "en": "No account or persistent identifier was created in the tested journey."
              },
              "evidence_strength": "local_and_network_observation",
              "limitations": {
                "ro": "Absența unui cont nu stabilește retenția server-side a jurnalelor de plată.",
                "en": "Absence of an account does not establish server-side payment-log retention."
              },
              "domains": []
            }
          ]
        }
      ],
      "destinations": [
        {
          "domain": "api.platitest.example",
          "owner": "Instituția fictivă",
          "role": {
            "ro": "API de taxe",
            "en": "fee API"
          },
          "relationship": "first_party",
          "first_seen": "app_open",
          "states_seen": [
            "before_choice",
            "refused",
            "accepted"
          ],
          "payload_evidence": "exact_synthetic_token",
          "payload_summary": {
            "ro": "Codul taxei și suma de test au fost observate.",
            "en": "The test fee code and amount were observed."
          },
          "attribution_certainty": "documented"
        },
        {
          "domain": "pay.example",
          "owner": "Procesator Fictiv SA",
          "role": {
            "ro": "procesator de plăți documentat",
            "en": "documented payment processor"
          },
          "relationship": "processor",
          "first_seen": "payment_start",
          "states_seen": [
            "accepted"
          ],
          "payload_evidence": "exact_synthetic_token",
          "payload_summary": {
            "ro": "Referința sintetică a plății a fost observată; nu au fost introduse date de card.",
            "en": "The synthetic payment reference was observed; no card details were entered."
          },
          "attribution_certainty": "documented"
        }
      ],
      "claims": [
        {
          "id": "CAL-101",
          "classification": "declared_and_observed",
          "statement": {
            "ro": "Destinațiile observate în traseul testat corespund infrastructurii și procesatorului documentate.",
            "en": "Destinations observed in the tested journey match the documented infrastructure and processor."
          },
          "maximum_wording": {
            "ro": "Putem descrie consecvența acestui traseu, nu certifica întreaga aplicație.",
            "en": "We can describe consistency in this journey, not certify the whole app."
          },
          "status": "calibration"
        }
      ],
      "repairs": [],
      "limitations": {
        "ro": [
          "Aplicație și date complet fictive.",
          "Plata a fost anulată înainte de autorizarea bancară.",
          "Nu este o certificare de conformitate."
        ],
        "en": [
          "The app and all data are fictional.",
          "Payment was cancelled before bank authorisation.",
          "This is not a compliance certification."
        ]
      }
    },
    {
      "id": "calibrare-transport",
      "slug": "calibrare-transport",
      "is_calibration": true,
      "app": {
        "name": "Transport Test",
        "package_id": "org.example.transporttest",
        "version": "7.1.2",
        "apk_sha256": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
      },
      "owner": "Operator fictiv de transport",
      "supplier": "Furnizor fictiv pentru calibrare",
      "journey": {
        "ro": "Planificarea unui traseu după refuzul localizării",
        "en": "Planning a journey after refusing location"
      },
      "device": {
        "model": "Pixel 8a (laborator)",
        "os": "Android 16",
        "locale": "ro-RO",
        "lane": "stock + instrumented"
      },
      "tested_at": "2026-08-05T14:05:00+03:00",
      "method_version": "PPR-1.0",
      "audit_level": "CAL",
      "headline": {
        "ro": "Destinația a fost identificată; câmpurile transmise nu au putut fi stabilite.",
        "en": "The destination was identified; transmitted fields could not be established."
      },
      "dek": {
        "ro": "Exemplul arată de ce „a contactat un domeniu” nu înseamnă automat „a trimis localizarea”.",
        "en": "This example shows why “contacted a domain” does not automatically mean “sent location”."
      },
      "verdict": "destination_identified_fields_unknown",
      "states": [
        {
          "id": "before_choice",
          "label": {
            "ro": "Înainte să alegi",
            "en": "Before choice"
          },
          "service_result": {
            "ro": "Harta s-a încărcat la nivelul orașului.",
            "en": "The map loaded at city level."
          },
          "events": [
            {
              "moment": "app_open",
              "policy": {
                "ro": "Politica menționează furnizorul cartografic.",
                "en": "The policy names the mapping provider."
              },
              "store": {
                "ro": "Magazinul declară localizare aproximativă opțională.",
                "en": "The store label declares optional approximate location."
              },
              "device": {
                "ro": "Telefonul a contactat tiles.maps.example și transit-cloud.example.",
                "en": "The phone contacted tiles.maps.example and transit-cloud.example."
              },
              "evidence_strength": "connection_observed",
              "limitations": {
                "ro": "Traficul către transit-cloud.example a rămas criptat și prins cu pinning.",
                "en": "Traffic to transit-cloud.example remained encrypted and pinned."
              },
              "domains": [
                "tiles.maps.example",
                "transit-cloud.example"
              ]
            }
          ]
        },
        {
          "id": "refused",
          "label": {
            "ro": "După ce ai refuzat",
            "en": "After refusal"
          },
          "service_result": {
            "ro": "Traseul a putut fi introdus manual.",
            "en": "The journey could be entered manually."
          },
          "events": [
            {
              "moment": "location_refused",
              "policy": {
                "ro": "Politica promite introducerea manuală a punctelor.",
                "en": "The policy promises manual entry of points."
              },
              "store": {
                "ro": "Magazinul declară localizarea ca opțională.",
                "en": "The store label declares location as optional."
              },
              "device": {
                "ro": "Permisiunea nu a fost acordată. transit-cloud.example a rămas contactat când traseul manual a fost calculat.",
                "en": "Permission was not granted. transit-cloud.example remained contacted when the manual route was calculated."
              },
              "evidence_strength": "permission_and_connection",
              "limitations": {
                "ro": "Faptul că domeniul a rămas contactat nu stabilește că localizarea dispozitivului a fost transmisă.",
                "en": "Continued contact does not establish that device location was transmitted."
              },
              "domains": [
                "transit-cloud.example"
              ]
            }
          ]
        },
        {
          "id": "accepted",
          "label": {
            "ro": "După ce ai acceptat",
            "en": "After acceptance"
          },
          "service_result": {
            "ro": "Punctul de pornire a fost completat din poziția dispozitivului.",
            "en": "The origin was filled from device position."
          },
          "events": [
            {
              "moment": "location_accepted",
              "policy": {
                "ro": "Politica descrie folosirea poziției pentru punctul de plecare.",
                "en": "The policy describes using position for the origin."
              },
              "store": {
                "ro": "Magazinul declară localizare aproximativă.",
                "en": "The store label declares approximate location."
              },
              "device": {
                "ro": "Conexiunea către transit-cloud.example a avut dimensiune diferită, dar payloadul nu a putut fi citit.",
                "en": "The connection to transit-cloud.example had a different size, but the payload could not be read."
              },
              "evidence_strength": "metadata_only",
              "limitations": {
                "ro": "Dimensiunea diferită nu dovedește că poziția a fost transmisă.",
                "en": "A different size does not prove that position was transmitted."
              },
              "domains": [
                "transit-cloud.example"
              ]
            }
          ]
        },
        {
          "id": "withdrawn",
          "label": {
            "ro": "După retragere",
            "en": "After withdrawal"
          },
          "service_result": {
            "ro": "După revocarea permisiunii, traseele manuale au rămas disponibile.",
            "en": "After permission revocation, manual journeys remained available."
          },
          "events": [
            {
              "moment": "permission_revoked",
              "policy": {
                "ro": "Politica spune că utilizatorul poate revoca permisiunea în sistem.",
                "en": "The policy says the user can revoke permission in system settings."
              },
              "store": {
                "ro": "Magazinul nu detaliază retragerea.",
                "en": "The store label does not detail withdrawal."
              },
              "device": {
                "ro": "Aplicația a cerut din nou permisiunea numai la folosirea funcției „poziția mea”.",
                "en": "The app requested permission again only when “my location” was used."
              },
              "evidence_strength": "screen_and_permission",
              "limitations": {
                "ro": "Nu a fost verificată retenția traseelor pe server.",
                "en": "Server-side journey retention was not tested."
              },
              "domains": []
            }
          ]
        }
      ],
      "destinations": [
        {
          "domain": "tiles.maps.example",
          "owner": "Hărți Exemplu",
          "role": {
            "ro": "serviciu cartografic documentat",
            "en": "documented mapping service"
          },
          "relationship": "third_party",
          "first_seen": "app_open",
          "states_seen": [
            "before_choice",
            "refused",
            "accepted",
            "withdrawn"
          ],
          "payload_evidence": "connection_only",
          "payload_summary": {
            "ro": "Au fost observate cereri pentru dale cartografice; nu date personale lizibile.",
            "en": "Map-tile requests were observed; no readable personal data."
          },
          "attribution_certainty": "documented"
        },
        {
          "domain": "transit-cloud.example",
          "owner": "Cloud Tranzit SA",
          "role": {
            "ro": "backend de trasee; rolul exact necesită confirmare",
            "en": "route backend; exact role needs confirmation"
          },
          "relationship": "unresolved",
          "first_seen": "app_open",
          "states_seen": [
            "before_choice",
            "refused",
            "accepted"
          ],
          "payload_evidence": "encrypted_unknown",
          "payload_summary": {
            "ro": "Destinația a fost observată; TLS pinning a împiedicat stabilirea câmpurilor.",
            "en": "The destination was observed; TLS pinning prevented field-level determination."
          },
          "attribution_certainty": "inferred"
        }
      ],
      "claims": [
        {
          "id": "CAL-201",
          "classification": "destination_identified_fields_unknown",
          "statement": {
            "ro": "Backendul de trasee a fost contactat atât fără, cât și cu permisiunea de localizare.",
            "en": "The route backend was contacted both without and with location permission."
          },
          "maximum_wording": {
            "ro": "Nu putem spune că localizarea a fost transmisă în oricare dintre stări.",
            "en": "We cannot say location was transmitted in either state."
          },
          "status": "calibration"
        }
      ],
      "repairs": [
        {
          "id": "REP-CAL-201",
          "actor": "Operator fictiv",
          "minimum_change": {
            "ro": "Publică rolul contractual și categoriile de date ale backendului de trasee.",
            "en": "Publish the route backend’s contractual role and data categories."
          },
          "verification": {
            "ro": "Verificare documentară; nu presupune modificarea aplicației.",
            "en": "Documentary verification; no app change is necessarily required."
          },
          "status": "proposed"
        }
      ],
      "limitations": {
        "ro": [
          "Aplicație și date complet fictive.",
          "TLS pinning a limitat inspecția.",
          "Metadatele de dimensiune nu sunt dovadă de conținut."
        ],
        "en": [
          "The app and all data are fictional.",
          "TLS pinning limited inspection.",
          "Size metadata is not evidence of content."
        ]
      }
    },
    {
      "id": "calibrare-remediata",
      "slug": "calibrare-remediata",
      "is_calibration": true,
      "app": {
        "name": "Identitate Test",
        "package_id": "org.example.idtest",
        "version": "3.0.1",
        "apk_sha256": "cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"
      },
      "owner": "Instituție fictivă pentru calibrare",
      "supplier": "Furnizor fictiv pentru calibrare",
      "journey": {
        "ro": "Activarea unui cont fictiv și retragerea analizei",
        "en": "Activating a fictional account and withdrawing analytics"
      },
      "device": {
        "model": "Pixel 8a (laborator)",
        "os": "Android 16",
        "locale": "ro-RO",
        "lane": "stock + instrumented"
      },
      "tested_at": "2026-08-05T16:30:00+03:00",
      "method_version": "PPR-1.0",
      "audit_level": "CAL",
      "headline": {
        "ro": "O conexiune pre-consimțământ a dispărut după actualizare și retestare.",
        "en": "A pre-consent connection disappeared after an update and retest."
      },
      "dek": {
        "ro": "Bonul păstrează constatarea inițială și arată reparația verificată, în loc să șteargă istoria.",
        "en": "The receipt preserves the original finding and shows the verified repair instead of erasing history."
      },
      "verdict": "repair_verified",
      "states": [
        {
          "id": "before_choice",
          "label": {
            "ro": "Versiunea 3.0.1",
            "en": "Version 3.0.1"
          },
          "service_result": {
            "ro": "Ecranul de alegere a apărut înaintea inițializării analizei.",
            "en": "The choice screen appeared before analytics initialisation."
          },
          "events": [
            {
              "moment": "retest_open",
              "policy": {
                "ro": "În politica revizuită, analiza rămâne opțională.",
                "en": "In the revised policy, analytics remains optional."
              },
              "store": {
                "ro": "Declarația magazinului a fost actualizată la 4 august 2026.",
                "en": "The store declaration was updated on 4 August 2026."
              },
              "device": {
                "ro": "În trei rulări curate, nu a fost observată nicio conexiune la metrics.example înainte de acceptare.",
                "en": "Across three clean runs, no connection to metrics.example was observed before acceptance."
              },
              "evidence_strength": "repeated_non_observation",
              "limitations": {
                "ro": "Nu dovedește absența în funcții netestate sau în configurații viitoare.",
                "en": "This does not prove absence in untested features or future configurations."
              },
              "domains": []
            }
          ]
        },
        {
          "id": "refused",
          "label": {
            "ro": "După refuz",
            "en": "After refusal"
          },
          "service_result": {
            "ro": "Activarea contului a continuat fără analiză.",
            "en": "Account activation continued without analytics."
          },
          "events": [
            {
              "moment": "retest_refusal",
              "policy": {
                "ro": "Politica afirmă că serviciul de bază rămâne disponibil.",
                "en": "The policy states that the core service remains available."
              },
              "store": {
                "ro": "Magazinul marchează analiza drept opțională.",
                "en": "The store label marks analytics as optional."
              },
              "device": {
                "ro": "metrics.example nu a fost contactat după refuz în trei rulări.",
                "en": "metrics.example was not contacted after refusal in three runs."
              },
              "evidence_strength": "repeated_non_observation",
              "limitations": {
                "ro": "Nu verifică ștergerea evenimentelor colectate de versiunea veche.",
                "en": "It does not verify deletion of events collected by the old version."
              },
              "domains": []
            }
          ]
        },
        {
          "id": "accepted",
          "label": {
            "ro": "După acceptare",
            "en": "After acceptance"
          },
          "service_result": {
            "ro": "Analiza a pornit după acțiunea afirmativă.",
            "en": "Analytics started after affirmative action."
          },
          "events": [
            {
              "moment": "retest_acceptance",
              "policy": {
                "ro": "Politica descrie momentul și scopul.",
                "en": "The policy describes timing and purpose."
              },
              "store": {
                "ro": "Magazinul declară activitatea aplicației.",
                "en": "The store label declares app activity."
              },
              "device": {
                "ro": "Prima conexiune la metrics.example a apărut la 310 ms după apăsarea butonului „Accept”.",
                "en": "The first connection to metrics.example appeared 310 ms after pressing “Accept”."
              },
              "evidence_strength": "screen_and_connection",
              "limitations": {
                "ro": "Momentul conexiunii nu stabilește toate câmpurile transmise.",
                "en": "Connection timing does not establish every transmitted field."
              },
              "domains": [
                "metrics.example"
              ]
            }
          ]
        },
        {
          "id": "withdrawn",
          "label": {
            "ro": "După retragere",
            "en": "After withdrawal"
          },
          "service_result": {
            "ro": "Autentificarea a rămas disponibilă.",
            "en": "Sign-in remained available."
          },
          "events": [
            {
              "moment": "retest_withdrawal",
              "policy": {
                "ro": "Politica descrie oprirea analizelor viitoare.",
                "en": "The policy describes stopping future analytics."
              },
              "store": {
                "ro": "Magazinul nu detaliază mecanismul.",
                "en": "The store label does not detail the mechanism."
              },
              "device": {
                "ro": "După retragere și repornire, metrics.example nu a mai fost contactat în trei rulări.",
                "en": "After withdrawal and restart, metrics.example was not contacted in three runs."
              },
              "evidence_strength": "repeated_non_observation",
              "limitations": {
                "ro": "Nu verifică retenția server-side.",
                "en": "Server-side retention was not tested."
              },
              "domains": []
            }
          ]
        }
      ],
      "destinations": [
        {
          "domain": "metrics.example",
          "owner": "Metrici Exemplu SA",
          "role": {
            "ro": "serviciu fictiv de analiză",
            "en": "fictional analytics service"
          },
          "relationship": "third_party",
          "first_seen": "acceptance",
          "states_seen": [
            "accepted"
          ],
          "payload_evidence": "connection_only",
          "payload_summary": {
            "ro": "Conexiunea a apărut numai după acceptare în retestare.",
            "en": "The connection appeared only after acceptance in the retest."
          },
          "attribution_certainty": "documented"
        }
      ],
      "claims": [
        {
          "id": "CAL-301",
          "classification": "repair_verified",
          "statement": {
            "ro": "Problema pre-consimțământ documentată în versiunea 2.9.4 nu a mai fost reprodusă în versiunea 3.0.1.",
            "en": "The pre-consent issue documented in version 2.9.4 was not reproduced in version 3.0.1."
          },
          "maximum_wording": {
            "ro": "Putem spune că reparația a trecut traseul de retestare, nu că orice comportament viitor este garantat.",
            "en": "We can say the repair passed the retest journey, not guarantee all future behaviour."
          },
          "status": "verified"
        }
      ],
      "repairs": [
        {
          "id": "REP-CAL-301",
          "actor": "Furnizor fictiv",
          "minimum_change": {
            "ro": "Amânarea inițializării SDK-ului până după acceptare.",
            "en": "Delay SDK initialisation until after acceptance."
          },
          "verification": {
            "ro": "Trei instalări curate, refuz, acceptare și retragere.",
            "en": "Three clean installs covering refusal, acceptance and withdrawal."
          },
          "status": "verified",
          "verified_at": "2026-08-05"
        }
      ],
      "limitations": {
        "ro": [
          "Aplicație și date complet fictive.",
          "Constatarea veche este parte a scenariului de calibrare.",
          "Retestarea nu certifică întreaga aplicație."
        ],
        "en": [
          "The app and all data are fictional.",
          "The prior finding is part of the calibration scenario.",
          "The retest does not certify the whole app."
        ]
      }
    }
  ]
}
