{
  "ok": true,
  "storage": "durable-object",
  "endpoint": "https://test.onebrick.io/v3/integration/security-logs",
  "count": 139,
  "filters": {},
  "security_logs": [
    {
      "id": "1786410660782-12d8345d2f5d",
      "received_at": "2026-08-11T01:11:00.782Z",
      "service": "redirect",
      "reference_id": "CLIENT-DEMO",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786410652759-a24711c2a38a",
      "received_at": "2026-08-11T01:10:52.759Z",
      "service": "redirect",
      "reference_id": null,
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786407378147-840372a20c8f",
      "received_at": "2026-08-11T00:16:18.147Z",
      "service": "redirect",
      "reference_id": "CLIENT-DEMO",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786407289426-2bc6d13b5f6e",
      "received_at": "2026-08-11T00:14:49.426Z",
      "service": "redirect",
      "reference_id": "CLIENT-DEMO",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786407281010-78fbdc84ea15",
      "received_at": "2026-08-11T00:14:41.010Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786407064809-3a096ad31297",
      "received_at": "2026-08-11T00:11:04.809Z",
      "service": "redirect",
      "reference_id": "CLIENT-DEMO",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786407064354-a4e26094d87a",
      "received_at": "2026-08-11T00:11:04.354Z",
      "service": "redirect",
      "reference_id": "CLIENT-DEMO",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786406899956-99b6f4000ad8",
      "received_at": "2026-08-11T00:08:19.956Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786385321986-9e4827db6acf",
      "received_at": "2026-08-10T18:08:41.986Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786368182962-93af2fa4f53f",
      "received_at": "2026-08-10T13:23:02.962Z",
      "service": "generic",
      "reference_id": "client-qa-connected-flow-bricko-bricki-a-i-stage-a-only-20260810190411-c-owner-delegation-20260810201919-testing-env-delegated",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786316168646-6ab6b47a3eff",
      "received_at": "2026-08-09T22:56:08.646Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786265551894-b4578aad4cfe",
      "received_at": "2026-08-09T08:52:31.894Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786255815650-2ccc297c53a4",
      "received_at": "2026-08-09T06:10:15.650Z",
      "service": "generic",
      "reference_id": "client-qa-connected-flow-bricko-bricki-a-i-akb2b-20260809123919-testingEnvironment-20260809130443-testing-env-delegated",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786168205665-1081cae11b42",
      "received_at": "2026-08-08T05:50:05.665Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786160041546-bb797f60398a",
      "received_at": "2026-08-08T03:34:01.546Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786157454597-d50933df2af3",
      "received_at": "2026-08-08T02:50:54.597Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786156929960-3601e30e8994",
      "received_at": "2026-08-08T02:42:09.960Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786156426249-1abf1737e91a",
      "received_at": "2026-08-08T02:33:46.249Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786138166287-80f5925d4a44",
      "received_at": "2026-08-07T21:29:26.287Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786133886851-90d0a9b4d752",
      "received_at": "2026-08-07T20:18:06.851Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786128509041-1b0133f349c0",
      "received_at": "2026-08-07T18:48:29.041Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786127019494-31a6d35d5ab3",
      "received_at": "2026-08-07T18:23:39.494Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786059313899-9230a43ac75b",
      "received_at": "2026-08-06T23:35:13.899Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-01",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059312874-51b89e757b6c",
      "received_at": "2026-08-06T23:35:12.874Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-07",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059311869-30627397a060",
      "received_at": "2026-08-06T23:35:11.869Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-10",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059310859-2d1acad94b6c",
      "received_at": "2026-08-06T23:35:10.859Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-03",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059309878-1f9e9e5cb2b2",
      "received_at": "2026-08-06T23:35:09.878Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-09",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059308837-c03106fa69fb",
      "received_at": "2026-08-06T23:35:08.837Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-06",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059307866-3e49838dc47a",
      "received_at": "2026-08-06T23:35:07.866Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-05",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059307793-e1342c03cc98",
      "received_at": "2026-08-06T23:35:07.793Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-07",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059306829-8975edd02a9b",
      "received_at": "2026-08-06T23:35:06.829Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-04",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059306761-64465b79eec9",
      "received_at": "2026-08-06T23:35:06.761Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-01",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786059305895-3e883d56b2c2",
      "received_at": "2026-08-06T23:35:05.895Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-08",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059305792-028a60cb4d41",
      "received_at": "2026-08-06T23:35:05.792Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-06",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059304863-cd8b50a3d241",
      "received_at": "2026-08-06T23:35:04.863Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-02",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059304751-d5ac3a8f7e5b",
      "received_at": "2026-08-06T23:35:04.751Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-02",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059304232-339987cd798f",
      "received_at": "2026-08-06T23:35:04.232Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-05",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1786059303258-269eaf7784c9",
      "received_at": "2026-08-06T23:35:03.258Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-08",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1786028870150-126aa01487da",
      "received_at": "2026-08-06T15:07:50.150Z",
      "service": "redirect",
      "reference_id": "ORDER-1001",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785986705556-3033fcd4627a",
      "received_at": "2026-08-06T03:25:05.556Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-10",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986699152-1f6d50b838d3",
      "received_at": "2026-08-06T03:24:59.152Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-09",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986695929-ad200ca2050a",
      "received_at": "2026-08-06T03:24:55.929Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-08",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986692786-8dc8b47f78c2",
      "received_at": "2026-08-06T03:24:52.786Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-07",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986689587-0b0d0a240b25",
      "received_at": "2026-08-06T03:24:49.587Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-06",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986687478-b82a08893183",
      "received_at": "2026-08-06T03:24:47.478Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-05",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986684361-b134fb569729",
      "received_at": "2026-08-06T03:24:44.361Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-04",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986681133-e47118261f53",
      "received_at": "2026-08-06T03:24:41.133Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-03",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986676922-31daa071a9f4",
      "received_at": "2026-08-06T03:24:36.922Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-02",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986671657-f8f1077a1b72",
      "received_at": "2026-08-06T03:24:31.657Z",
      "service": "qris",
      "reference_id": "qaj-ead1376723-qr-01",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986668855-590a663c4374",
      "received_at": "2026-08-06T03:24:28.855Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-10",
      "transaction_id": "PAY_48fbe3b96fd2bfb16a9afc59a1358a21",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986667997-0e2277d1a10d",
      "received_at": "2026-08-06T03:24:27.997Z",
      "service": "disbursement",
      "reference_id": "qaj-ead1376723-sm-09",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986666922-4d3d5174e4be",
      "received_at": "2026-08-06T03:24:26.922Z",
      "service": "disbursement",
      "reference_id": "qaj-ead1376723-sm-05",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986665696-5fa784bdd9dc",
      "received_at": "2026-08-06T03:24:25.696Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-09",
      "transaction_id": "PAY_f9e26ab7d32cd0f5457b946933c2d4e2",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986662527-42e49b4f83c9",
      "received_at": "2026-08-06T03:24:22.527Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-08",
      "transaction_id": "PAY_f49b36f37290c3b6a0dfa1526ccf8e57",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986660408-fac3476bed51",
      "received_at": "2026-08-06T03:24:20.408Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-07",
      "transaction_id": "PAY_37d30eced597476bbb3173bfb8cec166",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986658449-619c3416709c",
      "received_at": "2026-08-06T03:24:18.449Z",
      "service": "disbursement",
      "reference_id": "qaj-ead1376723-sm-10",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986657445-df1f25478fac",
      "received_at": "2026-08-06T03:24:17.445Z",
      "service": "disbursement",
      "reference_id": "qaj-ead1376723-sm-02",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986657243-af4b9fc0e63b",
      "received_at": "2026-08-06T03:24:17.243Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-06",
      "transaction_id": "PAY_58c5c61fd6ae769c1267fe3154e03a5b",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986654095-c521694dd430",
      "received_at": "2026-08-06T03:24:14.095Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-05",
      "transaction_id": "PAY_ff722483c04f79bdf7dc51e3431abff9",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986650918-363bfdc5b482",
      "received_at": "2026-08-06T03:24:10.918Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-04",
      "transaction_id": "PAY_03a8ecab692591059c60809513884e11",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986647780-0514b59fe3ac",
      "received_at": "2026-08-06T03:24:07.780Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-03",
      "transaction_id": "PAY_2759968401d5b930699bea1165493441",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986645749-07baffcf0e74",
      "received_at": "2026-08-06T03:24:05.749Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-02",
      "transaction_id": "PAY_aaac13720737f4bbdbf0317f239e170f",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785986640815-9beb0f321920",
      "received_at": "2026-08-06T03:24:00.815Z",
      "service": "virtual_account",
      "reference_id": "qaj-ead1376723-va-01",
      "transaction_id": "PAY_545b1fd6a37e60c036946e385628fdd4",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985619386-3d482cabb42c",
      "received_at": "2026-08-06T03:06:59.386Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-09",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985616148-12934ba02a10",
      "received_at": "2026-08-06T03:06:56.148Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-08",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985612985-069dad9a99b9",
      "received_at": "2026-08-06T03:06:52.985Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-07",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985609808-c8926a9269c3",
      "received_at": "2026-08-06T03:06:49.808Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-06",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985606639-7bab0a37a83f",
      "received_at": "2026-08-06T03:06:46.639Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-05",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985603472-f43afb036cd7",
      "received_at": "2026-08-06T03:06:43.472Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-04",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985600320-e8edf965c80e",
      "received_at": "2026-08-06T03:06:40.320Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-03",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985596151-2fe2ef0a6c23",
      "received_at": "2026-08-06T03:06:36.151Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-02",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985590811-cfefc6dd4820",
      "received_at": "2026-08-06T03:06:30.811Z",
      "service": "qris",
      "reference_id": "qaj-767195b641-qr-01",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985588179-1a315caa448b",
      "received_at": "2026-08-06T03:06:28.179Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-10",
      "transaction_id": "PAY_995e5e4ae367e0ef35dcf809463ee3fc",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985584967-af3ec1e96782",
      "received_at": "2026-08-06T03:06:24.967Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-09",
      "transaction_id": "PAY_0713d9c164ee3c4c8b4bfc513a8fa8b1",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985584185-80f742f7eb71",
      "received_at": "2026-08-06T03:06:24.185Z",
      "service": "disbursement",
      "reference_id": "qaj-767195b641-sm-10",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985584133-3562502be2fc",
      "received_at": "2026-08-06T03:06:24.133Z",
      "service": "disbursement",
      "reference_id": "qaj-767195b641-sm-03",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785985583055-60fb44e5b130",
      "received_at": "2026-08-06T03:06:23.055Z",
      "service": "disbursement",
      "reference_id": "qaj-767195b641-sm-06",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985581801-945e83ba03b6",
      "received_at": "2026-08-06T03:06:21.801Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-08",
      "transaction_id": "PAY_27953253a98b00c297e68200bab3367e",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985578632-0a038d35c636",
      "received_at": "2026-08-06T03:06:18.632Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-07",
      "transaction_id": "PAY_4da5cd29d5a80243f3cdbb29519cedfc",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985575464-200dead5b0ef",
      "received_at": "2026-08-06T03:06:15.464Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-06",
      "transaction_id": "PAY_59ea5744103b5dd4309373f171259d63",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985572306-27225a96c101",
      "received_at": "2026-08-06T03:06:12.306Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-05",
      "transaction_id": "PAY_f4f2ea969fe7a56859e5fcf0d7383c9f",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985570191-3e25d98427e0",
      "received_at": "2026-08-06T03:06:10.191Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-04",
      "transaction_id": "PAY_873ccaf1c6ae54f1dc54228e3b4711fc",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985567063-8803a38d42d4",
      "received_at": "2026-08-06T03:06:07.063Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-03",
      "transaction_id": "PAY_452c965e7a8b7b16752da5037d77104d",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985563648-6bd86aeb02c2",
      "received_at": "2026-08-06T03:06:03.648Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-02",
      "transaction_id": "PAY_def98a3dce760a7d7efd83e4da68977c",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785985557661-63310cca7b21",
      "received_at": "2026-08-06T03:05:57.661Z",
      "service": "virtual_account",
      "reference_id": "qaj-767195b641-va-01",
      "transaction_id": "PAY_a6fd17026feba1f1e9c04660b6b4047a",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785972905738-7860c5754360",
      "received_at": "2026-08-05T23:35:05.738Z",
      "service": "virtual_account",
      "reference_id": "qaj-d1a7389077-va-10",
      "transaction_id": "PAY_8bf619a3cd0bec6bda424f926ceb837d",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785972905637-07e3aa294675",
      "received_at": "2026-08-05T23:35:05.637Z",
      "service": "virtual_account",
      "reference_id": "qaj-d1a7389077-va-05",
      "transaction_id": "PAY_82a13eb339504c76949ae25457d9d52a",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785972903954-7de85c75e779",
      "received_at": "2026-08-05T23:35:03.951Z",
      "service": "virtual_account",
      "reference_id": "qaj-2c6fac45bd-va-02",
      "transaction_id": "PAY_b439dabf7d62a8112de601869db60fe9",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785953409981-c4c6b1347512",
      "received_at": "2026-08-05T18:10:09.981Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-03",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953408966-2ce1fb0fa02d",
      "received_at": "2026-08-05T18:10:08.966Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-09",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953408023-1846e9e06344",
      "received_at": "2026-08-05T18:10:08.023Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-07",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953406956-25b502abe765",
      "received_at": "2026-08-05T18:10:06.956Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-04",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953405974-b85cd4d523b0",
      "received_at": "2026-08-05T18:10:05.974Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-08",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953404958-ef41ca62f3d4",
      "received_at": "2026-08-05T18:10:04.958Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-05",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953404248-f123a2153e7f",
      "received_at": "2026-08-05T18:10:04.248Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-02",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953403486-eaa23361b4e3",
      "received_at": "2026-08-05T18:10:03.486Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-06",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953402384-da056b35b7b1",
      "received_at": "2026-08-05T18:10:02.384Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-01",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785953401212-075ef1241a02",
      "received_at": "2026-08-05T18:10:01.212Z",
      "service": "qris",
      "reference_id": "qaj-d1a7389077-qr-10",
      "transaction_id": null,
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "possible_replay_or_retry",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945011801-338add545ade",
      "received_at": "2026-08-05T15:50:11.801Z",
      "service": "virtual_account",
      "reference_id": "qaj-456b4dc790-va-08",
      "transaction_id": "PAY_6f3251505e650c052f1e1fd887727df5",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945011395-5aa72573be77",
      "received_at": "2026-08-05T15:50:11.395Z",
      "service": "virtual_account",
      "reference_id": "qaj-b08a930fbb-va-08",
      "transaction_id": "PAY_3d3b9521847ca8e8a1c33c016380697e",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945011192-32b2c3a6413a",
      "received_at": "2026-08-05T15:50:11.192Z",
      "service": "virtual_account",
      "reference_id": "qaj-b08a930fbb-va-02",
      "transaction_id": "PAY_07283853a80656876d1c98af850b39a5",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945010949-62ae56f4ec1f",
      "received_at": "2026-08-05T15:50:10.949Z",
      "service": "virtual_account",
      "reference_id": "qaj-456b4dc790-va-09",
      "transaction_id": "PAY_07f2a9613289d48fa208f98053ef7ec1",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785945010856-52ca9b147d73",
      "received_at": "2026-08-05T15:50:10.856Z",
      "service": "virtual_account",
      "reference_id": "qaj-456b4dc790-va-10",
      "transaction_id": "PAY_57d44e6cf7de819d50da94bd5921c6bd",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785945010245-226ca4afb0f2",
      "received_at": "2026-08-05T15:50:10.245Z",
      "service": "virtual_account",
      "reference_id": "qaj-b08a930fbb-va-10",
      "transaction_id": "PAY_6ab9899b9c29ea59ffeaef82eafdbcc0",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945009958-353a72f7e957",
      "received_at": "2026-08-05T15:50:09.958Z",
      "service": "virtual_account",
      "reference_id": "qaj-be447bbd11-va-05",
      "transaction_id": "PAY_8a203bb26844bb713c6a8852320966e3",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945009581-b5381d26f1c2",
      "received_at": "2026-08-05T15:50:09.581Z",
      "service": "virtual_account",
      "reference_id": "qaj-738cf59da6-va-05",
      "transaction_id": "PAY_0a3286f795347be68518e1c09450b673",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945009469-fc2e59af9bc2",
      "received_at": "2026-08-05T15:50:09.459Z",
      "service": "virtual_account",
      "reference_id": "qaj-456b4dc790-va-07",
      "transaction_id": "PAY_c2b38bfc67a894509e39a37219364ac9",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785945009322-c98f1425ecea",
      "received_at": "2026-08-05T15:50:09.322Z",
      "service": "checkout_page",
      "reference_id": "qaj-456b4dc790-co-03",
      "transaction_id": "PAY_a86495be43a408434092fe9508125fcc",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945009176-16af4cc790b1",
      "received_at": "2026-08-05T15:50:09.176Z",
      "service": "virtual_account",
      "reference_id": "qaj-b08a930fbb-va-07",
      "transaction_id": "PAY_71e6e1e2d89903ad4dbbeec82c3bea04",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785945008731-36600317b69f",
      "received_at": "2026-08-05T15:50:08.731Z",
      "service": "virtual_account",
      "reference_id": "qaj-456b4dc790-va-01",
      "transaction_id": "PAY_2d568c4501dd96beacea7b821b78fcc0",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945008603-d3779a0f2f92",
      "received_at": "2026-08-05T15:50:08.603Z",
      "service": "virtual_account",
      "reference_id": "qaj-be447bbd11-va-10",
      "transaction_id": "PAY_f938e16e02614ef5687b53778b3c9bc7",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785945008248-06945de9838d",
      "received_at": "2026-08-05T15:50:08.248Z",
      "service": "virtual_account",
      "reference_id": "qaj-0779596246-va-09",
      "transaction_id": "PAY_d2e8167d122027b8dff21a089495c65e",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945008077-89b1297f67f4",
      "received_at": "2026-08-05T15:50:08.077Z",
      "service": "virtual_account",
      "reference_id": "qaj-b08a930fbb-va-03",
      "transaction_id": "PAY_ae89e46eed15063d8c88b88d8b0dfca9",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945007793-61a602c4ba80",
      "received_at": "2026-08-05T15:50:07.793Z",
      "service": "checkout_page",
      "reference_id": "qaj-738cf59da6-co-03",
      "transaction_id": "PAY_82144e899928f8a5037edffb9f5d48ba",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945007368-70fb2d1c0bd9",
      "received_at": "2026-08-05T15:50:07.368Z",
      "service": "virtual_account",
      "reference_id": "qaj-be447bbd11-va-02",
      "transaction_id": "PAY_6e6a8b192adc4c7f77b056d49379467b",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945006798-9c55185d25d5",
      "received_at": "2026-08-05T15:50:06.798Z",
      "service": "virtual_account",
      "reference_id": "qaj-be447bbd11-va-08",
      "transaction_id": "PAY_6cd6c017d7d5901a05e439af6dd27a6b",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945006152-95a7a263baf4",
      "received_at": "2026-08-05T15:50:06.152Z",
      "service": "checkout_page",
      "reference_id": "qaj-be447bbd11-co-03",
      "transaction_id": "PAY_7fc0755f4416c22bdc4d338b59ffed04",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785945006023-3e3f4068f8cc",
      "received_at": "2026-08-05T15:50:06.023Z",
      "service": "virtual_account",
      "reference_id": "qaj-be447bbd11-va-03",
      "transaction_id": "PAY_961678b13c4cdc56698504430753e601",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944722323-5cf2516649a6",
      "received_at": "2026-08-05T15:45:22.323Z",
      "service": "virtual_account",
      "reference_id": "qaj-cd68a6c800-va-03",
      "transaction_id": "PAY_cc718fbd598602a23606ba1dbd285a53",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944722032-5c8ad1b4ef73",
      "received_at": "2026-08-05T15:45:22.032Z",
      "service": "virtual_account",
      "reference_id": "qaj-7aea1a6e58-va-09",
      "transaction_id": "PAY_50ecfa8849a822ce54d1f6557a28b221",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944721933-156483b1b9c7",
      "received_at": "2026-08-05T15:45:21.933Z",
      "service": "virtual_account",
      "reference_id": "qaj-2b813a1eed-va-06",
      "transaction_id": "PAY_cf60f21d1e7b4b281fbffa8baf2cbd6a",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944721842-f844175ee39d",
      "received_at": "2026-08-05T15:45:21.842Z",
      "service": "virtual_account",
      "reference_id": "qaj-6188f7bcaf-va-07",
      "transaction_id": "PAY_35c59cbde4b1c60914a3a969b0a3a9fc",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944721329-4c8eeb554c3c",
      "received_at": "2026-08-05T15:45:21.329Z",
      "service": "virtual_account",
      "reference_id": "qaj-d9f711400a-va-10",
      "transaction_id": "PAY_1036af0f458a5174e715b1b61397fac3",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944720988-6f9dfdb382e7",
      "received_at": "2026-08-05T15:45:20.988Z",
      "service": "virtual_account",
      "reference_id": "qaj-0779596246-va-02",
      "transaction_id": "PAY_b2a2ff1b133d5b70c3d9b50da2173479",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944720922-631d6ed81a38",
      "received_at": "2026-08-05T15:45:20.922Z",
      "service": "virtual_account",
      "reference_id": "qaj-7aea1a6e58-va-08",
      "transaction_id": "PAY_05132f88e3fa238d23dbe8365a7032b7",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944720840-0815bf58bf22",
      "received_at": "2026-08-05T15:45:20.840Z",
      "service": "virtual_account",
      "reference_id": "qaj-5941149c6f-va-07",
      "transaction_id": "PAY_2993b2141ac850c5c58a27fb174595f5",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944720335-acb2aacf5624",
      "received_at": "2026-08-05T15:45:20.335Z",
      "service": "virtual_account",
      "reference_id": "qaj-d9f711400a-va-08",
      "transaction_id": "PAY_59219c7da593f98a737ee7c59b5d9989",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944720143-bf4f0acec7fc",
      "received_at": "2026-08-05T15:45:20.143Z",
      "service": "virtual_account",
      "reference_id": "qaj-7aea1a6e58-va-05",
      "transaction_id": "PAY_93ad01a4cd9bae853c17ee2d8a7f22be",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944720089-316eeb57e7fa",
      "received_at": "2026-08-05T15:45:20.089Z",
      "service": "virtual_account",
      "reference_id": "qaj-5bf9e875ee-va-03",
      "transaction_id": "PAY_29ff23b506707d37ead83cb8fb9cb54e",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944720019-6bb58d0c8d9f",
      "received_at": "2026-08-05T15:45:20.019Z",
      "service": "virtual_account",
      "reference_id": "qaj-d9f711400a-va-05",
      "transaction_id": "PAY_70e48a5872b6d314030bb06a71acd5a1",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944719882-e0e8ce719af5",
      "received_at": "2026-08-05T15:45:19.882Z",
      "service": "virtual_account",
      "reference_id": "qaj-bc4120a68f-va-08",
      "transaction_id": "PAY_43276491d8c33d2873dafabb8ab3c1fc",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944719755-aee5eb8805dd",
      "received_at": "2026-08-05T15:45:19.755Z",
      "service": "virtual_account",
      "reference_id": "qaj-9ca2d8a7da-va-01",
      "transaction_id": "PAY_f81953bfb6d43942e27ac2d07cfc28ea",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944719211-594bf6cbbbcb",
      "received_at": "2026-08-05T15:45:19.211Z",
      "service": "virtual_account",
      "reference_id": "qaj-6188f7bcaf-va-04",
      "transaction_id": "PAY_f23a7d4d7613a6316dd284a664067d3e",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944718790-f25253ec55ef",
      "received_at": "2026-08-05T15:45:18.790Z",
      "service": "virtual_account",
      "reference_id": "qaj-0779596246-va-07",
      "transaction_id": "PAY_bd1011900b8c1970fa676ea28a59a7eb",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944718520-f4b796bdecfa",
      "received_at": "2026-08-05T15:45:18.520Z",
      "service": "virtual_account",
      "reference_id": "qaj-5bf9e875ee-va-02",
      "transaction_id": "PAY_22f9344a6bb720ddbe9b76a13761e288",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944717778-ae598695ab68",
      "received_at": "2026-08-05T15:45:17.777Z",
      "service": "virtual_account",
      "reference_id": "qaj-0779596246-va-08",
      "transaction_id": "PAY_18128c4bb9942b334f35f09dcbd12cbb",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [
        {
          "layer": 1,
          "key": "strict_payload_reference",
          "required": false,
          "status": "pass",
          "detail": "Request body is parsable and carries a traceable reference_id-like value."
        },
        {
          "layer": 2,
          "key": "signature_timestamp",
          "required": false,
          "status": "observed",
          "detail": "Signature header is present and paired with a fresh timestamp header."
        },
        {
          "layer": 3,
          "key": "replay_tamper_guard",
          "required": false,
          "status": "pass",
          "detail": "Explicit replay/tamper test modes and duplicate references are rejected for three-layer probes."
        }
      ],
      "replay_status": "not_detected",
      "validation_ok": true,
      "validation_errors": [],
      "validation_warnings": [
        "No callback signature header was detected. This is fine for plain Test URL, but signed callbacks should include signature headers."
      ]
    },
    {
      "id": "1785944717703-36010a6f1e85",
      "received_at": "2026-08-05T15:45:17.703Z",
      "service": "virtual_account",
      "reference_id": "qaj-2b813a1eed-va-02",
      "transaction_id": "PAY_89f49bd8219bb63d7b161ad68d786612",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944717402-6322eb55b919",
      "received_at": "2026-08-05T15:45:17.402Z",
      "service": "virtual_account",
      "reference_id": "qaj-bc4120a68f-va-10",
      "transaction_id": "PAY_c15da2f4d08a4ddf650c69895c7952a7",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    },
    {
      "id": "1785944717145-a41fcd3af7d4",
      "received_at": "2026-08-05T15:45:17.145Z",
      "service": "virtual_account",
      "reference_id": "qaj-5941149c6f-va-05",
      "transaction_id": "PAY_a3c76cbfd03852e20884ad505b0dab56",
      "signature_status": "missing",
      "timestamp_status": "missing",
      "security_mode": "observed_callback",
      "security_profile": "standard",
      "security_layers": [],
      "replay_status": "not_detected",
      "validation_ok": null,
      "validation_errors": [],
      "validation_warnings": []
    }
  ]
}