Programmatic access to FedRAMP Certification Data
Specset Cloud Platform · FedRAMP ID FR2631258135 · Spot.xyz Corporation DBA Specset
Specset shares its FedRAMP Certification Data through the trust center at trust.specset.com. This page documents the programmatic route to the same data, for necessary parties who retrieve it by automation. The files are not public: they are held in a private Google Cloud Storage bucket and read with an authorized Google identity. The public Certification Package Overview is at www.specset.com/fedramp.
gs://specset-prod-certification-dataIndex:
index.json, described by certification-data.schema.jsonAPI: the Google Cloud Storage JSON API,
https://storage.googleapis.com/storage/v1/b/specset-prod-certification-data/o/What is available
| Trust-center files | Every file a necessary party can request on the trust center, in the same format (PDF, JSON or plain text) and byte for byte the same file. This includes the human-readable documents. |
|---|---|
| Vulnerability activity | Historical vulnerability detection and response activity for the preceding 14 days, in FedRAMP's historical-activity JSON format, with a new edition at least every 14 days starting 2026-10-14. |
| Index | index.json lists every file with its title, media type, size, SHA-256 and object name. It is replaced at each publication. |
| History | Files are never overwritten: each is stored under a name that includes its SHA-256 (trust-center files) or its period (vulnerability activity). Every index ever published is kept under snapshots/<time>/index.json, so earlier editions remain retrievable. |
Who can read
| GSA | Every account in GSA's Google Workspace (the gsa.gov domain) can read without asking, as the trust center approves gsa.gov requests automatically. |
|---|---|
| Other necessary parties | FedRAMP staff with a Google account outside GSA's Workspace, and agency customers, write to fedramp@specset.com naming the Google account, Google group or Workload Identity Federation principal to be granted. The grant is made once and stays in place; no request is needed for each retrieval. No agreement or terms have to be accepted. |
| What a grant allows | Listing and reading the objects in this bucket. Nothing can be written, and no other bucket or project is accessible. |
Authenticate
Any Google OAuth 2.0 access token for an authorized identity works, with the scope https://www.googleapis.com/auth/devstorage.read_only or https://www.googleapis.com/auth/cloud-platform.
- A person: install the Google Cloud CLI and run
gcloud auth loginwith the authorized Google account.gcloud auth print-access-tokenthen prints a one-hour token for the HTTP example below. - An unattended system: use Workload Identity Federation from your own identity provider, with the federated principal granted as above. It needs no long-lived keys, and the client library or CLI renews the short-lived token without human interaction.
Retrieve with the Google Cloud CLI
gcloud storage cat gs://specset-prod-certification-data/index.json > index.json
gcloud storage cp -r gs://specset-prod-certification-data/resources \
gs://specset-prod-certification-data/vulnerability-activity ./specset-certification-data/
Retrieve with plain HTTPS
TOKEN="$(gcloud auth print-access-token)" # or a token from your own federation
API="https://storage.googleapis.com/storage/v1/b/specset-prod-certification-data/o"
curl -fsS -H "Authorization: Bearer $TOKEN" "$API/index.json?alt=media" -o index.json
jq -r '.resources[].object, .vulnerabilityActivity[].object' index.json |
while read -r name; do
curl -fsS -H "Authorization: Bearer $TOKEN" --create-dirs -o "$name" \
"$API/$(jq -rn --arg n "$name" '$n|@uri')?alt=media"
done
Verify what you retrieved
Every file's SHA-256 is in the index. From the directory holding the files:
jq -r '(.resources[], .vulnerabilityActivity[]) | "\(.sha256) \(.object)"' index.json | shasum -a 256 -c
A trust-center file's hash is that of the file Specset uploaded to the trust center. A PDF downloaded from the trust center's web interface may carry a viewer watermark and then differs from it.
Earlier editions
gcloud storage ls gs://specset-prod-certification-data/snapshots/
gcloud storage cat gs://specset-prod-certification-data/snapshots/<time>/index.json
Every object named in an earlier index can still be retrieved.
Responses
| 200 | The object's bytes, with its media type and Cache-Control: no-store. |
|---|---|
| 401 | No token, or an expired one. Obtain a new token. |
| 403 | The identity is not granted. Write to fedramp@specset.com. |
| 404 | No object by that name. Take object names from the index. |
| 429, 5xx | Transient. Retry with exponential backoff. |
Google Cloud Data Access audit logging is enabled for the project that holds the bucket.