Programmatic access to FedRAMP Certification Data

Specset Cloud Platform · FedRAMP ID FR2631258135 · Spot.xyz Corporation DBA Specset

Specset shares its FedRAMP Certification Data through the trust center at trust.specset.com. This page documents the programmatic route to the same data, for necessary parties who retrieve it by automation. The files are not public: they are held in a private Google Cloud Storage bucket and read with an authorized Google identity. The public Certification Package Overview is at www.specset.com/fedramp.

Bucket: gs://specset-prod-certification-data
Index: index.json, described by certification-data.schema.json
API: the Google Cloud Storage JSON API, https://storage.googleapis.com/storage/v1/b/specset-prod-certification-data/o/

What is available

Trust-center filesEvery file a necessary party can request on the trust center, in the same format (PDF, JSON or plain text) and byte for byte the same file. This includes the human-readable documents.
Vulnerability activityHistorical vulnerability detection and response activity for the preceding 14 days, in FedRAMP's historical-activity JSON format, with a new edition at least every 14 days starting 2026-10-14.
Indexindex.json lists every file with its title, media type, size, SHA-256 and object name. It is replaced at each publication.
HistoryFiles are never overwritten: each is stored under a name that includes its SHA-256 (trust-center files) or its period (vulnerability activity). Every index ever published is kept under snapshots/<time>/index.json, so earlier editions remain retrievable.

Who can read

GSAEvery account in GSA's Google Workspace (the gsa.gov domain) can read without asking, as the trust center approves gsa.gov requests automatically.
Other necessary partiesFedRAMP staff with a Google account outside GSA's Workspace, and agency customers, write to fedramp@specset.com naming the Google account, Google group or Workload Identity Federation principal to be granted. The grant is made once and stays in place; no request is needed for each retrieval. No agreement or terms have to be accepted.
What a grant allowsListing and reading the objects in this bucket. Nothing can be written, and no other bucket or project is accessible.

Authenticate

Any Google OAuth 2.0 access token for an authorized identity works, with the scope https://www.googleapis.com/auth/devstorage.read_only or https://www.googleapis.com/auth/cloud-platform.

Retrieve with the Google Cloud CLI

gcloud storage cat gs://specset-prod-certification-data/index.json > index.json
gcloud storage cp -r gs://specset-prod-certification-data/resources \
  gs://specset-prod-certification-data/vulnerability-activity ./specset-certification-data/

Retrieve with plain HTTPS

TOKEN="$(gcloud auth print-access-token)"   # or a token from your own federation
API="https://storage.googleapis.com/storage/v1/b/specset-prod-certification-data/o"
curl -fsS -H "Authorization: Bearer $TOKEN" "$API/index.json?alt=media" -o index.json
jq -r '.resources[].object, .vulnerabilityActivity[].object' index.json |
while read -r name; do
  curl -fsS -H "Authorization: Bearer $TOKEN" --create-dirs -o "$name" \
    "$API/$(jq -rn --arg n "$name" '$n|@uri')?alt=media"
done

Verify what you retrieved

Every file's SHA-256 is in the index. From the directory holding the files:

jq -r '(.resources[], .vulnerabilityActivity[]) | "\(.sha256)  \(.object)"' index.json | shasum -a 256 -c

A trust-center file's hash is that of the file Specset uploaded to the trust center. A PDF downloaded from the trust center's web interface may carry a viewer watermark and then differs from it.

Earlier editions

gcloud storage ls gs://specset-prod-certification-data/snapshots/
gcloud storage cat gs://specset-prod-certification-data/snapshots/<time>/index.json

Every object named in an earlier index can still be retrieved.

Responses

200The object's bytes, with its media type and Cache-Control: no-store.
401No token, or an expired one. Obtain a new token.
403The identity is not granted. Write to fedramp@specset.com.
404No object by that name. Take object names from the index.
429, 5xxTransient. Retry with exponential backoff.

Google Cloud Data Access audit logging is enabled for the project that holds the bucket.