The product
Fixed-price services on one codebase. Each takes a URL or a document, runs a checker whose limits are declared up front, and produces a record: a document that names its subject, hashes what it read, states every finding in the W3C ACT Rules vocabulary, and lists the criteria no machine can decide. The records are served publicly, because a published record found through a search is the entire acquisition channel — there is no outreach.
A checker that cannot say how much it measured is not a checker. Every service here reports its own coverage, and reports zero coverage as a failure rather than as silence.
20 gates behind one command
Read out of this repository's own runner. A partial pass is a fail — the runner exits nonzero if any single gate does, and a gate whose tooling is missing counts as a failure rather than a skip.
| # | Gate | What it catches |
|---|---|---|
| 1 | publication | no personal contact detail anywhere — PUBLICATION.md |
| 2 | types + build | a type error is a defect that has not happened yet |
| 3 | selftest | the paid path produces a record, and HALTS when a verifier is unavailable |
| 4 | verify_design | duplicate images, missing mark, bare pages, placeholder copy |
| 5 | visual baselines | any unintended pixel change, page-level and element-level |
| 6 | lighthouse | the ten numeric bars in QUALITY_BAR §1, re-derived rather than quoted |
| 7 | scrim contrast | AA for text over photography, which axe cannot see and therefore never fails |
| 8 | record integrity | every published record can say what it examined — bytes, hash, subject, method |
| 9 | rendered text | source syntax leaked into prose — the one defect a frozen baseline certifies |
| 10 | links | every internal link resolves, and og:image, robots.txt and the sitemap name THIS site |
| 11 | discoverable | QUALITY_BAR §7 D1–D8, asserted against the served bytes rather than a source literal |
| 12 | deliverability | nothing can be paid for that has no producer, renderer and checker on disk |
| 13 | figures | no number in a published document that nothing on disk counted |
| 14 | honest | every gate's exit code agrees with the verdict it just printed |
| 15 | mutation | the other gates can actually fail, proven by breaking the code on purpose |
| 16 | stripe | what Stripe shows a customer matches what this repo says |
| 17 | complete | a stranger can find it, understand it, buy it, and receive it — provably |
| 18 | pipeline registries | every registry exists and has a station that reads it |
| 19 | pipeline sync | the enforcers that ran are the enforcers under review |
| 20 | ci coverage | every gate here is assigned a CI job, and every gate script on disk is accounted for |
7 of 7 document stations ran
| Station | Output file | Produced | Lines |
|---|---|---|---|
| PickService | SERVICE_PICK.md | yes | 173 |
| SeedDocument | claim-audit-seed.md | yes | 302 |
| PRDDocument | PRD.md | yes | 1601 |
| DesignPackage | DESIGN_PACKAGE.md | yes | 140 |
| TDDDocument | TDD.md | yes | 2100 |
| BuildAgentFile | build_agent.md | yes | 1451 |
| LaunchRunbook | launch_runbook.md | yes | 760 |
6527 lines of documents and 58 evidence records, each verbatim-matched against a hash-pinned source before it could be cited.
18 defects that shipped
scripts/mutate.mjsBoth live repositories published a 100% mutation score. Both were manufactured. Mutation testing breaks the code on purpose and records a mutant as killed the moment any gate exits nonzero — but it never checked whether that gate was ALREADY failing on unmutated code. In business #1 three of seven gates in the oracle were red before a single line was broken; one of them, check-complete.mjs, is red because the domain and the founder interviews are outstanding, which no mutation can change. In this repository two of seven read sibling checkouts that do not exist inside a mutation sandbox. Every mutant was "killed" by a gate that would have said exactly the same thing about untouched source. The honest scores are 7% and 12.5%.
Now caught by: scripts/mutate.mjs runs every oracle gate against an unmutated sandbox first and HALTS on any red, and the parent now reads each shard exit code and aborts the run with its output shown. Gates that cannot be honest oracles were removed from the oracle with the reason written beside them — they still run in npm run verify, where their red is the correct answer. The formal-methods name for this is a vacuous pass: Beer, Ben-David, Eisner and Rodeh, 2001.
scripts/check-figures.mjs“1,392 claims examined, 108 false” was written into a fact sheet intended for a stranger, and stated three times across three documents. It had never been produced by anything — no record, no script, no log. Beside it: “11 registries” when there were 8, and “3 published records” when there were 2.
Now caught by: scripts/check-figures.mjs, which fails any number bound to a countable noun that METRICS.md cannot confirm — and fails harder on a noun nothing counts at all, because that is the case this was.
scripts/check-figures.mjs“spent the last year” appeared in a document about a repository that was days old.
Now caught by: The same figures gate carries a separate rule for elapsed-time narrative, on the grounds that it is unfalsifiable rather than merely wrong.
scripts/gates.config.mjsThe gate runner printed “ALL 8 GATES PASS” having run seven. When verify_design.py was absent it printed “– not installed”, excluded it from the failure list, and reported green.
Now caught by: A gate whose tooling is missing is now a named FAILURE, and the pipeline is vendored into the repo so the enforcers that ran are the enforcers under review.
scripts/verify-all.mjsThree gates fetched localhost:3000 and were marked `needsServer: true`. Nothing read that flag. It looked like a guarantee that a server would be running and guaranteed nothing.
Now caught by: The runner starts a server when any gate declares it needs one, waits for it, and refuses to continue if it never comes up.
scripts/gates.config.mjsA published record for an IRS W-9 shipped with `bytes: 0` and the SHA-256 of empty input, reporting six criteria passed on a file it had never read.
Now caught by: scripts/check-records.mjs — every published record must be able to state what it examined: bytes, hash, subject, method.
scripts/gates.config.mjsTwo services were marked live, with resolving Stripe links, and no producer script anywhere on disk. A buyer could have paid $500 for a record no code could build.
Now caught by: scripts/check-deliverable.mjs — nothing may take money without a producer, a renderer and a checker present on disk.
scripts/gates.config.mjsTwo registries governing human-only work and money spend each printed “Enforced by: check_pipeline.py” at the top. check_pipeline.py ran nowhere — not in a gate, not in CI, not in a station.
Now caught by: check_pipeline.py is now a gate in the runner. Its own honest limit is published with it: several of its rules still only warn.
app/globals.css`var(--mono)` was read in seven files — the brand board, every record renderer, two tools — and declared in none. Every SHA-256, record token, outcome label and byte count rendered in the body sans, on records whose entire argument is that you can compare a hash character by character.
Now caught by: The token is declared, and the var() form and the utility-class form now resolve to the same stack so they cannot disagree.
app/globals.cssThe bespoke `.btn` class had no focus state. Not a weak one — none. The entire stylesheet contained a single `:focus` rule, so every button and link on a site that sells accessibility records relied on whatever the browser drew by default, frequently nothing legible over a dark fill.
Now caught by: A `:focus-visible` rule over every interactive element, with two rings so it survives both the light and the dark ground. Inherited into this repository unchanged.
lib/brand.tsThe brand board's parser matched one declaration per line. The stylesheet pairs verdict tokens two to a line, so every `-bg` token was silently missed and the board reported four colour pairs as BELOW AA when all four cleared it. The palette was fine; the parser was broken.
Now caught by: It scans declarations rather than lines. It survived only because an uncomputable ratio is treated as a failure rather than skipped; had it skipped what it could not measure, the board would have printed “all pairs clear AA” while checking two thirds of them.
scripts/verify-all.mjsA nav button on a paid page read “Get a record — $500” — the literal escape sequence, visible, for days.
Now caught by: scripts/check-rendered-text.mjs reads the rendered DOM for source syntax that leaked into prose — the one defect class a frozen baseline actively defends.
scripts/verify-all.mjsText over a photographic band measured 1.36:1 — an eyebrow whose box ran roughly 950px past its last glyph, into the light end of the scrim gradient.
Now caught by: scripts/check-scrim.mjs rasterises the real composite and measures the brightest pixel under every letter.
scripts/check-figures.mjsThe figures gate's own extraction pattern used a lazy quantifier and tested only the final word, so “8 automated gates” matched with zero intervening words, tested “automated”, found no noun, and moved on. It reported “4 figures examined” on documents containing far more.
Now caught by: A greedy window of up to four words, with every word tested. The count of figures examined is printed on every run so the number itself is reviewable.
scripts/check-figures.mjsA rendered PDF sat four hours behind the HTML it came from, carrying superseded figures, under the filename somebody would actually attach to an email. Twice in one day.
Now caught by: The gate compares mtimes and fails when a rendered artifact is older than its source.
scripts/gates.config.mjsThe completion gate could print “NOT COMPLETE — 3 of 10 criteria unmet” and then exit 0. The runner reads the exit code, not the prose, so a business would have been declared finished while its own gate said in plain English that it was not.
Now caught by: scripts/check-gates-honest.mjs asserts that every gate's exit code agrees with the verdict it just printed.
scripts/gates.config.mjsThirteen gates, and not one of them read the account that takes the money. A live $500 checkout session for an undeliverable service sat payable while the deliverability gate printed ALL CLEAR, and the business profile described a retired product on every receipt for weeks.
Now caught by: scripts/check-stripe.mjs reconciles what Stripe shows a customer against what the repo claims, and halts rather than passing when the credential is absent.
components/RecordShell.tsxEvery published record page shipped with no nav, no mark and no link home. Someone arriving at a record — the exact person the entire acquisition strategy is built to reach — could read the proof and had no way to find out who made it or how to buy one.
Now caught by: One RecordShell component wraps every record, replacing three hand-written footers that had already begun to differ. It is in this repository too, wrapping the dossiers.
Stated here, not left as an absence
- No customer has paid for a record. The payment links are live and the delivery chain is complete on disk; nobody has used it.
- Discovery is unproven. The strategy is that a published record ranks and a stranger finds it. Nothing yet demonstrates that it does.
