Two businesses · one process · every figure counted

Software thatreports what itdid not check.

I build service businesses end to end — research, product, design, code, gates, deployment. This site documents two of them, and every number on it is re-derived from the repositories it describes rather than typed by hand.

The most useful section is the one listing what shipped broken.

Read the defect log The process
A steel dial caliper resting on a sheet of white paper, jaws slightly open.
Derrick Treadwell / Unsplash
The thesis

A verification step whose absence is indistinguishable from its success.

That sentence describes almost every defect in the log below. A contrast checker that sampled zero pixels. A gate runner that announced all eight gates passing having run seven. A published record carrying the SHA-256 of empty input, reporting six criteria passed on a file it never opened. In each case the tool ran, printed something reassuring, and measured nothing.

The response was not more tests. It was a rule, applied everywhere: every checker states how much it measured, and fails if that is zero. A tool that finds nothing because it looked at nothing now stops the build, because finding nothing is precisely what a clean bill of health looks like.

The same rule governs this page. Every figure on it is read at build time from METRICS.md, which was generated by counting files on disk. There is no number written into this component — asking for one that nothing counted fails the build.

The work

Two businesses, built end to end

2 businesses. 1 is deployed and takes money; the other is finished on disk and deliberately does not. Both run the same gates.

The line

7 stations, then 20 gates

An idea becomes a business through 7 document stations, each enforced by a program that can refuse to emit its output. What the stations produce is then defended by 20 automated gates and 12 standards registries.

All 7 stations and every gate
The defect log

Everything that shipped broken

18 defects, each transcribed from a comment block committed in one of the two repositories at the time it was fixed. A gate opens every one of those files and fails the build if the citation is not there — a defect log is the one artifact on a portfolio with an obvious incentive to embellish.

12
Found by reading
4
Found by an adversarial audit
1
Found by a gate
1
Found by a mutant

The first column is the largest, and that is the finding. Most of these were caught by a person reading carefully, hours later — not by any of the machinery built to catch them. Every gate in the list on the line exists because something in this log got past everything that came before it.

01
Found by an adversarial auditclaim-audit/app/scripts/mutate.mjs

Both live repositories published a 100% mutation score. Both were manufactured. Mutation testing breaks the code on purpose and records a mutant as killed the moment any gate exits nonzero — but it never checked whether that gate was ALREADY failing on unmutated code. In business #1 three of seven gates in the oracle were red before a single line was broken; one of them, check-complete.mjs, is red because the domain and the founder interviews are outstanding, which no mutation can change. In this repository two of seven read sibling checkouts that do not exist inside a mutation sandbox. Every mutant was "killed" by a gate that would have said exactly the same thing about untouched source. The honest scores are 7% and 12.5%.

Why nothing caught it. The tool whose entire job is to prove the other gates can fail had no check that it could itself fail. Worse, when the guard was finally written it did not work either: shards were spawned with stdio ignored and their exit codes never read, so the guard halted its shard, printed its explanation to a discarded stream, and the parent collected the shards that survived and reported a score. A halt nobody hears is not a halt.

What catches it now. scripts/mutate.mjs runs every oracle gate against an unmutated sandbox first and HALTS on any red, and the parent now reads each shard exit code and aborts the run with its output shown. Gates that cannot be honest oracles were removed from the oracle with the reason written beside them — they still run in npm run verify, where their red is the correct answer. The formal-methods name for this is a vacuous pass: Beer, Ben-David, Eisner and Rodeh, 2001.

02
Found by readingclaim-audit/app/scripts/check-figures.mjs

“1,392 claims examined, 108 false” was written into a fact sheet intended for a stranger, and stated three times across three documents. It had never been produced by anything — no record, no script, no log. Beside it: “11 registries” when there were 8, and “3 published records” when there were 2.

Why nothing caught it. Every gate on the project examined code or the running site. These were sentences about the project, written somewhere else. The documents most likely to be read by someone who mattered were the only artifacts with no verifier at all.

What catches it now. scripts/check-figures.mjs, which fails any number bound to a countable noun that METRICS.md cannot confirm — and fails harder on a noun nothing counts at all, because that is the case this was.

03
Found by readingclaim-audit/app/scripts/check-figures.mjs

“spent the last year” appeared in a document about a repository that was days old.

Why nothing caught it. Nothing on disk records elapsed effort. Git records commit dates and nothing else, so there was no source that could have disagreed.

What catches it now. The same figures gate carries a separate rule for elapsed-time narrative, on the grounds that it is unfalsifiable rather than merely wrong.

04
Found by readingclaim-audit/app/scripts/gates.config.mjs

The gate runner printed “ALL 8 GATES PASS” having run seven. When verify_design.py was absent it printed “– not installed”, excluded it from the failure list, and reported green.

Why nothing caught it. The strongest gate lived at an absolute path into a home directory. On any machine without it — a CI runner, a fresh clone, a collaborator — it silently stopped existing, and its absence was indistinguishable from its success.

What catches it now. A gate whose tooling is missing is now a named FAILURE, and the pipeline is vendored into the repo so the enforcers that ran are the enforcers under review.

05
Found by readingclaim-audit/app/scripts/verify-all.mjs

Three gates fetched localhost:3000 and were marked `needsServer: true`. Nothing read that flag. It looked like a guarantee that a server would be running and guaranteed nothing.

Why nothing caught it. A checker pointed at a dead origin finds zero problems, and zero problems is exactly what a clean bill of health looks like.

What catches it now. The runner starts a server when any gate declares it needs one, waits for it, and refuses to continue if it never comes up.

06
Found by readingclaim-audit/app/scripts/gates.config.mjs

A published record for an IRS W-9 shipped with `bytes: 0` and the SHA-256 of empty input, reporting six criteria passed on a file it had never read.

Why nothing caught it. Every gate photographed, measured or parsed the site. A false hash renders exactly as beautifully as a true one.

What catches it now. scripts/check-records.mjs — every published record must be able to state what it examined: bytes, hash, subject, method.

07
Found by an adversarial auditclaim-audit/app/scripts/gates.config.mjs

Two services were marked live, with resolving Stripe links, and no producer script anywhere on disk. A buyer could have paid $500 for a record no code could build.

Why nothing caught it. Every gate asked whether the site was correct. None asked whether the business behind it could honour a sale.

What catches it now. scripts/check-deliverable.mjs — nothing may take money without a producer, a renderer and a checker present on disk.

08
Found by an adversarial auditclaim-audit/app/scripts/gates.config.mjs

Two registries governing human-only work and money spend each printed “Enforced by: check_pipeline.py” at the top. check_pipeline.py ran nowhere — not in a gate, not in CI, not in a station.

Why nothing caught it. The sentence asserting the enforcement was the least verified claim in the repository, and it was load-bearing for two documents about spending money.

What catches it now. check_pipeline.py is now a gate in the runner. Its own honest limit is published with it: several of its rules still only warn.

09
Found by readingclaim-audit/app/app/globals.css

`var(--mono)` was read in seven files — the brand board, every record renderer, two tools — and declared in none. Every SHA-256, record token, outcome label and byte count rendered in the body sans, on records whose entire argument is that you can compare a hash character by character.

Why nothing caught it. An unresolved custom property silently falls back to the inherited value, so a font-family that never applied looks exactly like one that did. A visual baseline had frozen the wrong font as correct; axe and Lighthouse do not grade typeface choice.

What catches it now. The token is declared, and the var() form and the utility-class form now resolve to the same stack so they cannot disagree.

10
Found by readingclaim-audit/app/app/globals.css

The bespoke `.btn` class had no focus state. Not a weak one — none. The entire stylesheet contained a single `:focus` rule, so every button and link on a site that sells accessibility records relied on whatever the browser drew by default, frequently nothing legible over a dark fill.

Why nothing caught it. Automated accessibility checking grades contrast and names and roles. It did not fail a missing focus ring on a custom class.

What catches it now. A `:focus-visible` rule over every interactive element, with two rings so it survives both the light and the dark ground. Inherited into this repository unchanged.

11
Found by readingclaim-audit/app/lib/brand.ts

The brand board's parser matched one declaration per line. The stylesheet pairs verdict tokens two to a line, so every `-bg` token was silently missed and the board reported four colour pairs as BELOW AA when all four cleared it. The palette was fine; the parser was broken.

Why nothing caught it. The board was a generated artifact nobody re-checked, and a wrong FAIL is as corrosive as a wrong PASS — it teaches people to distrust the tool.

What catches it now. It scans declarations rather than lines. It survived only because an uncomputable ratio is treated as a failure rather than skipped; had it skipped what it could not measure, the board would have printed “all pairs clear AA” while checking two thirds of them.

12
Found by readingclaim-audit/app/scripts/verify-all.mjs

A nav button on a paid page read “Get a record — $500” — the literal escape sequence, visible, for days.

Why nothing caught it. The visual baseline froze the broken text as the reference. A regression test cannot tell you that what it captured was already wrong. Lighthouse and axe passed: an em-dash entity is valid, legible, high-contrast text. TypeScript passed: both forms are valid JSX.

What catches it now. scripts/check-rendered-text.mjs reads the rendered DOM for source syntax that leaked into prose — the one defect class a frozen baseline actively defends.

13
Found by a gateclaim-audit/app/scripts/verify-all.mjs

Text over a photographic band measured 1.36:1 — an eyebrow whose box ran roughly 950px past its last glyph, into the light end of the scrim gradient.

Why nothing caught it. axe computes contrast from a CSS background colour. Behind this text was a canvas, so it returned nothing at all, and nothing looks exactly like a pass. Every visual baseline passed too: the band looked precisely as intended, and was still an AA failure.

What catches it now. scripts/check-scrim.mjs rasterises the real composite and measures the brightest pixel under every letter.

14
Found by readingclaim-audit/app/scripts/check-figures.mjs

The figures gate's own extraction pattern used a lazy quantifier and tested only the final word, so “8 automated gates” matched with zero intervening words, tested “automated”, found no noun, and moved on. It reported “4 figures examined” on documents containing far more.

Why nothing caught it. Four is not zero, so the measurement guard that fails on zero did not fire either. The checker written to notice absence had a quiet absence of its own.

What catches it now. A greedy window of up to four words, with every word tested. The count of figures examined is printed on every run so the number itself is reviewable.

15
Found by readingclaim-audit/app/scripts/check-figures.mjs

A rendered PDF sat four hours behind the HTML it came from, carrying superseded figures, under the filename somebody would actually attach to an email. Twice in one day.

Why nothing caught it. The figures gate reads the HTML, so it certified the source as clean while the artifact derived from it disagreed. The check and the thing that reaches a human were different objects.

What catches it now. The gate compares mtimes and fails when a rendered artifact is older than its source.

16
Found by a mutantclaim-audit/app/scripts/gates.config.mjs

The completion gate could print “NOT COMPLETE — 3 of 10 criteria unmet” and then exit 0. The runner reads the exit code, not the prose, so a business would have been declared finished while its own gate said in plain English that it was not.

Why nothing caught it. Nothing found this by reading. It was found by a mutation run — 2,022 mutants, of which two survived, both in that file. Every other gate is watched by something; the last one was watched by nobody, and its answer matters most.

What catches it now. scripts/check-gates-honest.mjs asserts that every gate's exit code agrees with the verdict it just printed.

17
Found by an adversarial auditclaim-audit/app/scripts/gates.config.mjs

Thirteen gates, and not one of them read the account that takes the money. A live $500 checkout session for an undeliverable service sat payable while the deliverability gate printed ALL CLEAR, and the business profile described a retired product on every receipt for weeks.

Why nothing caught it. `grep -rn "api.stripe.com" scripts/` returned nothing. The repository was thoroughly checked against itself and never against the system that customers actually touch.

What catches it now. scripts/check-stripe.mjs reconciles what Stripe shows a customer against what the repo claims, and halts rather than passing when the credential is absent.

18
Found by readingclaim-audit/app/components/RecordShell.tsx

Every published record page shipped with no nav, no mark and no link home. Someone arriving at a record — the exact person the entire acquisition strategy is built to reach — could read the proof and had no way to find out who made it or how to buy one.

Why nothing caught it. The design gate checks that a nav carries a real mark, and a page with no nav has no nav to check. Lighthouse does not grade whether a page links anywhere. The visual baselines had frozen the navless layout as correct.

What catches it now. One RecordShell component wraps every record, replacing three hand-written footers that had already begun to differ. It is in this repository too, wrapping the dossiers.

What is not true here

No customer has ever paid for any of this.

Zero revenue. Zero customers. One of the two businesses is not deployed, and it ran none of the 7 document stations that the first one ran. The second build's mutation score is 29.7%, meaning 1014 deliberately broken versions of its code got past the 7 gates a mutant is actually shown — not all 20 it runs, which is what this sentence claimed until an audit caught it.

All of that is on the honest page in full, with the counts and where they came from. It is linked from the nav rather than from a footer, because a portfolio that hides its limitations is making a claim it has not checked.

The honest page