{
  "profile_version": "1.0",
  "payment_journey": "checkout-card-entry",
  "page_states": [
    "default-consent",
    "analytics-consent",
    "payment-provider-error"
  ],
  "observation_scope": {
    "scripts": true,
    "resource_origins": true,
    "selected_dom_structure": true,
    "selected_security_headers": true
  },
  "sensitive_data_exclusions": [
    "payment field values",
    "cookies",
    "authorization tokens",
    "customer identifiers",
    "free-form form values"
  ],
  "normalization_rules": [
    {
      "signal": "script nonce",
      "reason": "Expected per-response volatility",
      "owner": "application-security",
      "review_reference": "TUNE-004"
    }
  ],
  "baseline": {
    "version": "baseline-2026-07-20.2",
    "owner": "checkout-platform",
    "approval_reference": "CHG-1838"
  },
  "routing": {
    "primary_role": "appsec-on-call",
    "escalation_role": "incident-response",
    "release_context_source": "change-management"
  },
  "retention": {
    "policy_reference": "RET-PAYMENT-PAGE-01",
    "period": "Set by the customer control owner and assessor"
  },
  "note": "Illustrative implementation profile, not a Cartelta API contract."
}
