QUALITY / VERIFIED VS. UNVERIFIED

Release quality.

Release confidence comes from reproducible checks and explicit limits, not a label saying “production-ready.”

What is checked

CheckEvidence methodWhat it proves
Page and asset deliveryHTTPS HEAD and GET for approved public pathsRoutes serve the expected HTTP response and MIME type
Catalog safetySchema check, allowlisted internal URLs, unique pathsDirectory cannot point to arbitrary external addresses
Public/private boundaryNegative route probesSelected internal endpoints deny unauthenticated access
Browser behaviorKeyboard, search, filter, link and viewport checksUsable experience under sampled conditions; requires manual browser verification
Backend disclosurePublic inference metadataBackend identity is stated accurately at time of check
Release reversibilityBackup of the modified router and explicit undo procedureThe platform route can be disabled without moving existing apps

What is not certified

A successful HTTP 200 does not prove every feature is working. There is no claim here of full penetration testing, formal accessibility conformance, load testing at production scale, paid provider integration, multi-region failover, or a security certification. Those require dedicated evidence.

Production acceptance gates

  1. All advertised public links respond; MIME types match; unexpected traversal, private files and admin URLs return denial.
  2. Local-model UI passes a real bounded prompt test within its allowance; external provider status remains unverified without signed receipts.
  3. Search/filter and navigation pass keyboard and mobile-browser checks at 320, 390, 768 and 1280 CSS pixels.
  4. Rate limiting, resource quotas and access logs are evaluated without leaking personal content or keys.
  5. Backup, restore, process health, automated restart and rollback are exercised on the deployed code.
  6. Performance, traffic, abuse resistance and uptime objectives are defined and load-tested before a commercial-service guarantee.

Maintainer procedure

Serve static assets from the dedicated /platform/ allowlist in the existing public router. Run python3 test_platform.py from the platform directory for the public release checks. Record execution date, results, build files and any exceptions. Do not change the root hub or private services as part of this isolated feature without their own release review.

Release facts and tests remain documented even when the chat history is deleted; they live on the VPS.

← Return to platform