Skip to content
production / main000%
PROOF-01LIVE ENGINEERING PROOFCOLLECTING EVIDENCE

Claims and observations stay separate.

PASS is used only when there is a verifiable chain. An endpoint response is not uptime, a configured verify command is not a successful release, and unavailable external checks are never presented as success.

EVIDENCE COCKPIT / NO SYNTHETIC PASS
CURRENT RESPONSE

RELEASE GATE

No PASS; attestation chain is incomplete.

OSV / SUPPLY CHAIN

External verification unavailable.

MDN HTTP OBSERVATORY

Independent MDN result unavailable.

Release attestation chain

GATE-ATTEST
Verify policyUNKNOWN
Post-gate attestationUNVERIFIED
package.json hashNOT ATTESTED
bun.lock hashNOT ATTESTED
Deployment commit matchNOT ATTESTED

The attestation is written only after the initial production build, TypeScript, ESLint, Bun tests and critical route verification succeed. A second/final Vite build then embeds it into the deploy artifact.

Supply chain

SUPPLY-CHAIN
DIRECT PROD
LOCKED
SBOM
OSV
package.json / pending
bun.lock / pending
CycloneDX 1.6 / pending

The public surface does not disclose dependency names or CVE/OSV identifiers. OSV results are aggregated. This is not a full transitive vulnerability audit or penetration test.

MDN-VERIFYINDEPENDENT HTTP SECURITY

We do not manufacture our own security grade.

When MDN HTTP Observatory is reachable, its own grade/score is displayed. Otherwise the state remains UNKNOWN. Local header heuristics are not blended into the MDN result.

CLAIM-BOUNDARYEVIDENCE BOUNDARY

What this page does not prove is explicit too.

CURRENT RESPONSE is not an uptime percentage or SLA.
OSV direct-dependency checking is not a full transitive security audit.
MDN HTTP-header security is not a penetration test.
An SBOM component count is not a security score by itself.
NEXT / VERIFY / FROM PROOF TO DECISION

You have seen the live proof. Now identify the gap in your own product.

In four questions, identify whether the bottleneck is validation, architecture, implementation, release or operations.

Chat