Availability proof
A public 200 response proves only that a route served content at the time and method checked.
These are the public quality gates to work toward. A checked HTTP endpoint is not a complete functional application test, and documented plans are not deployed software.
| Gate | Pass standard | Current evidence or gap |
|---|---|---|
| Entrances | Every approved sitemap/catalog URL returns expected HTTPS content. | Timestamped HEAD audit ↗ |
| Routing security | Unauthorized privileged paths denied, no secret/API leakage. | Selected denial probes ↗ · Independent penetration testing not certified |
| Chat inference | Each provider-specific workflow gives a real response from verified backend, logs fallback accurately. | Published local model receipts ↗ · Official third-party backends not connected |
| Browser UX | Real controls, keyboard/touch, responsive layout and no JS page exceptions. | 12-UI browser evidence ↗ · Physical iPhone and Android certification pending |
| Games and models | All stages solvable, honest physics limits, no real physical controls. | Public simulation rules ↗ · Full AAA fidelity not certified |
| Factory builds | Deterministic candidates, source integrity, tests, owner approval, rollback. | Factory release evidence ↗ · General autonomous code improvement not certified |
| Continuity | Verified backups, restore procedures and outage detection. | Running audit and backup jobs ↗ · Independent offsite full restore not certified |
| Commercial readiness | Security, user privacy, capacity, abuse prevention, support, regulatory review, recovery. | NOT UNIVERSALLY CERTIFIED Each product must pass its own release criteria. |
A public 200 response proves only that a route served content at the time and method checked.
A browser action plus a witnessed state transition proves that tested interaction. It does not certify everything else.
Received outputs must identify assigned model, actual runtime and any fallback. A vendor-themed UI is not proof of vendor APIs.
Negative path probes are useful, but vulnerability and penetration testing must still be done separately.