This page is the product's spine made public: every defect we know about, every claim we make with its verified status, every mistake we've made with its root cause — and the exact scope of what our guarantees bind. Figures frozen 2026-08-16 13:55 UTC for this launch snapshot; production will render them live from the register.
Status across all 120: 101 OPEN · 8 CLOSED · 6 INFO (positives) · 3 WITHDRAWN · 1 PARTIAL · 1 QUALIFIED. Withdrawn findings stay visible — a register you can silently prune is a register you can't trust.
The register's working definitions — so "serious" can't quietly mean something mild.
Foundational / framing — findings about how the estate itself is read and governed.
Serious. Wrong money, wrong records, unearned claims, or security exposure. Fix before launch.
Material. Real defects with bounded blast radius or a known workaround.
Minor. Inconsistencies and gaps that mislead but don't yet damage.
Informational, including recorded positives — things that work and must be preserved.
Every sentence our marketing makes is a row here, checked against production. A claim that can't survive its query doesn't ship. Current: 7 FALSE · 3 PARTIAL · 2 UNDERSTATED · 1 TRUE-NARROW · 8 TRUE — launch is defined as FALSE = 0, and yes, we're publishing the sevens.
| ID | Claim | Status |
|---|---|---|
| C1 | Dashboard: "6 MONITORED" | FALSE |
| C2 | Projects page: "0 active of 0 total" | FALSE |
| C4 | Audit page: "a read-only record of what the system has actually done" | FALSE |
| C6 | Sign out ends your session | FALSE |
| C11 | Enable build alerts — real-time notifications | FALSE |
| C17 | Marketing: "Live deliberation engine — 16 open-reasoning rounds on record" | FALSE |
| C18 | FAQ: "Structured deliberation is live today" | FALSE |
| C10 | A non-superadmin cannot read the audit log | PARTIAL |
| C13 | Serving-check detects a stale-serving domain | PARTIAL — crash-test scheduled |
| C20 | Homepage: "Bring your own keys. Every call audited." | PARTIAL |
| C15 | Marketing: "39/39 tables RLS-enforced" | UNDERSTATED (40/40) |
| C16 | Marketing receipts: 612 findings / 124 scans / 5,878 audit entries / 16,919 pings | UNDERSTATED — all stale low |
| C9 | Merge queue enforces diff-read-required | TRUE-NARROW |
| C3 | "RLS 100%" / "RLS Coverage 25/25" | TRUE |
| C5 | "Only emails listed here can complete sign-in" | TRUE |
| C7 | Coverage measures whether each active project has completed a health check | TRUE |
| C8 | Hiding routine activity never conceals warnings | TRUE |
| C12 | Security Score 74/100 grade C | TRUE |
| C14 | Marketing: "7 isolated projects, own Supabase each" | TRUE |
| C19 | FAQ: "Deeper scenario tooling is on the roadmap, not yet shipped. We would rather say so." | TRUE |
| C21 | The product can route to a model and record the result | TRUE |
Every time our own analysis was wrong, what we claimed, and why it was wrong — root cause included, never deleted. Three of these correct the same finding three times; the sequence is preserved because it teaches more than the conclusion.
What binds today: database constraints make deliberation records write-once against every application path, every API route, and every non-superuser role. No panellist can see a peer before committing. Nothing is "verified" without a named verifier and a timestamp. An application bug and a hurried admin hit the same wall.
What does not bind yet: us, as the database operator. A superuser could disable the trigger or restore an altered backup. Independent anchoring — a published hash chain and customer-side verification, so the evidence checks out without trusting ZASIS — is on the roadmap, and until it ships you will not find the words "immutable" or "not even us" anywhere on this site.
Register refs: D114 (the constraint chain), D117 (the scope), D115 (first public record — in verification).