The six classes
Ordered S ≤ A < B < C. The A variants are flavours of A, not grades.
Placement follows the class
Nothing that sees gets placed where nobody is accountable for seeing.
Hosts rank by who controls the box. A workload runs only where the host is trusted enough for its class: C never lands on a shared pool; A can go anywhere, because there's nothing on it to see.
The class belongs to a workload, not a product. An E2EE app with an automation sidecar is two answers: the app is A, the sidecar is B, and each is placed on its own terms.
A declaration names the workload, its class, every plaintext surface, and where the keys live. Then the CARLOS test: publish the database and see what leaks. A leaks its declared residue and nothing more. B's cold copy leaks nothing. C leaks the data, and said so up front.
Examples show classes, not adoption. Nothing is certified against an external standard yet. What auditors get is a declaration they can test, not a paragraph they have to believe.
Licensing is the other axis
A trust class says what a host can see. A licence class says what a customer can do with the code. CARLOS doesn't dictate: you choose.
The two axes are independent. An L5 app can be class A; an L1 app can be class C. A gallery entry names both, or says which has not been published yet.
Remixability is the third
Trust says what a host can see. Licence says what a customer may do. Remixability says what an agent, or a person with a fork, can actually do today. Three flags, each yes or no.
All three are possible for every app in the family, because every app has the same shape. The gallery records which ones have done it, not which ones could.
See who declares what
Every app in the gallery carries its class, or admits it hasn't published one.