# Source register and limitations

Access date for every source: September 21, 2026.

| Source | Direct URL | Material use | Limitation |
| --- | --- | --- | --- |
| National Institute of Standards and Technology, AI Risk Management Framework Core | https://airc.nist.gov/airmf-resources/airmf/5-sec-core/ | Continuing governance, monitoring, intended context, accountable roles and human oversight across the AI lifecycle. | Voluntary, cross-sector framework. It does not prescribe this self-storage release gate, approve a product or establish certification. |
| National Institute of Standards and Technology, AI RMF Playbook, Manage 2.3 | https://airc.nist.gov/docs/AI_RMF_Playbook.pdf | Monitoring for drift, decontextualization and changes that affect AI-system behavior. | General playbook guidance. It does not define the register or prove implementation effectiveness. |
| World Wide Web Consortium, PROV-O | https://www.w3.org/TR/prov-o/ | General provenance concepts for entities, activities, agents, generation and invalidation. | Web standard for representing provenance. It does not define a facility decision queue or validate the proposed control. |
| Internet Engineering Task Force, RFC 9110, Section 13.1.1 | https://www.rfc-editor.org/rfc/rfc9110.html#section-13.1.1 | Architecture analogy for checking a current representation before a state-changing operation. | The standard governs HTTP semantics. It does not prescribe AI, self-storage or facility governance. |

All four direct URLs returned HTTP 200 during final source verification. No source establishes a real customer, deployment, incident, performance result, product capability, legal duty or certification for Jared Mastroianni, modSTORAGE or Facily.ai.
