# Consent Gap Record — technical dossier

**Built, not deployed** · https://consent-gap.vercel.app

A single audit that loads a site in four consent states, records every third-party host and storage key written in each, and reports which recipients the site's own privacy policy never names.

---

## How to read this document

Every figure below was counted on **2026-08-21** by opening files in the
`consent-gap` checkout. Nothing is transcribed. The third column of each table names the file
and the pattern the number came from, so any of them can be re-derived rather than trusted.

This file is generated from the same objects as the web page it came from — the same metric rows,
the same gate list read out of the runner, the same defect log. It cannot go stale relative to that
page, because there is no second copy of the content.

Generator: `npm run metrics` then `GET /work/consent-gap/dossier`.
Derived data snapshot: 2026-08-21T00:39:47.211Z

---

## The product

One service, built end to end and deliberately not for sale. It visits a site untouched, after Accept, after Decline, and under a Global Privacy Control signal; logs every third-party host contacted and every storage key written in each state; then fetches the site's published privacy policy and reports which of those recipients it never names. Both passages are quoted verbatim and every document is SHA-256 hashed as it arrives. Before any finding, the record prints the questions it refuses to decide.

**What the build argues.** The second build tested whether the process transfers. It does — the same gates, the same registries and the same refusal to ship an uncounted number were reused without modification. What did not transfer is the mutation score, and that gap is the most useful thing on this site.

---

## Measured

| value | what it is | how it was derived |
|---:|---|---|
| 20 | automated gates, reused unmodified | names in the GATES array of consent-gap/app/scripts/gates.config.mjs |
| 29.7 | % mutation score — the honest gap | score in consent-gap/app/quality/mutants.json |
| 1014 | surviving mutants, each one a blind spot | survivors[].length in consent-gap/app/quality/mutants.json |
| 235 | test declarations across its spec files | static count over 5 *.spec.ts / *.test.ts files in consent-gap/app — NOT the runner's total, which multiplies by project and parameter |
| 0 | services live — it does not take money | status: "live" entries in consent-gap/app/lib/services.ts |

---

## Verification — 20 gates

One command runs all of them and a partial pass is a fail. A gate whose tooling is missing counts
as a failure rather than a skip, because a check that cannot run has not passed.

| # | gate | what it catches |
|---:|---|---|
| 1 | `publication` | no personal contact detail anywhere — PUBLICATION.md |
| 2 | `kit` | the shared safeguards are byte-identical to seed/kit, name no product, and are called here |
| 3 | `types + build` | a type error is a defect that has not happened yet |
| 4 | `selftest` | the paid path produces a record, and HALTS when a verifier is unavailable |
| 5 | `verify_design` | duplicate images, missing mark, bare pages, placeholder copy |
| 6 | `visual baselines` | any unintended pixel change, page-level and element-level |
| 7 | `lighthouse` | the ten numeric bars in QUALITY_BAR §1, re-derived rather than quoted |
| 8 | `scrim contrast` | AA for text over photography, which axe cannot see and therefore never fails |
| 9 | `record integrity` | every published record can say what it examined — bytes, hash, subject, method |
| 10 | `rendered text` | source syntax leaked into prose — the one defect a frozen baseline certifies |
| 11 | `links` | every internal link resolves, and og:image, robots.txt and the sitemap name THIS site |
| 12 | `deliverability` | nothing can be paid for that has no producer, renderer and checker on disk |
| 13 | `figures` | no number in a published document that nothing on disk counted |
| 14 | `honest` | every gate's exit code agrees with the verdict it just printed |
| 15 | `mutation` | the other gates can actually fail, proven by breaking the code on purpose |
| 16 | `stripe` | what Stripe shows a customer matches what this repo says |
| 17 | `complete` | a stranger can find it, understand it, buy it, and receive it — provably |
| 18 | `ci coverage` | every gate script on disk is in the gate list, and every gate is in a CI job |
| 19 | `pipeline registries` | every registry exists and has a station that reads it |
| 20 | `pipeline sync` | the enforcers that ran are the enforcers under review |

---

## Provenance — the seven document stations

Presence is measured by checking for the station's output filename on disk.

| station | output file | produced | lines |
|---|---|---|---:|
| PickService | `SERVICE_PICK.md` | **never ran** | — |
| SeedDocument | `*-seed.md` | **never ran** | — |
| PRDDocument | `PRD.md` | **never ran** | — |
| DesignPackage | `DESIGN_PACKAGE.md` | **never ran** | — |
| TDDDocument | `TDD.md` | **never ran** | — |
| BuildAgentFile | `build_agent.md` | **never ran** | — |
| LaunchRunbook | `launch_runbook.md` | **never ran** | — |

---

## The defect log for this repository

_No defect-log entries cite this repository._

---

## What is missing

- It sells nothing, and that is the design rather than an omission. It is deployed and readable; there is no Stripe product and no payment link behind it.
- It takes no money. No Stripe product, no payment link, and the service registry says status “building” so every gate agrees with the page.
- Its mutation score is low. The number is published here rather than omitted; see the honest page.

---

## Standing constraints

- **No outreach, ever.** Discovery is organic search and published work only. No cold email, no
  sequences, no scraped lists.
- **No published personal contact details.** A name, a role and a role address. No home address and
  no personal phone number appear anywhere.
- **No figure that nothing counted.** A number may appear in a published document only if a
  generator produced it from disk.

---

Marcos Matthews — sole member, Wryko LLC · Support@wryko.com
