Scroll horizontally for more navigation links.

Capability status

Truth, not a green light.

Application availability and production capability are disclosed separately.

Application available

Mode

demo

Data

Live registry aggregate + Demo detail

Database

connected verified

Bundle evidence

2026-07-29T00:47:26.000Z

Declared capabilities

Read-only demo access

Sanitized local portfolio evidence can be inspected without credentials.

Available

Audited operator workflows

Implemented in this repository: tenant-scoped reads, permission-checked and CSRF-protected writes, single-use approval evidence, exactly-once idempotency, optimistic concurrency, and a hash-chained audit entry written in the same transaction as each change.

Available

Control-plane mutations available now

Requires operator sign-in to be configured on this deployment. Without a verified session there is no principal to authorize a write, so every mutation fails closed regardless of role.

Available

Verified production database

Available only after the server completes and validates the aggregate-only registry RPC.

Available

Production provider integrations

Registrar, deployment, repository, analytics, email, and payment providers are snapshot-only or unavailable. Their adapters, capability discovery, approval classes, and operation state machine are implemented and tested.

Not live

Provider operation execution

No provider transport is installed in this build, so a proposed operation stops before the network even when its variables are configured, its owner gate is on, and its approval has been granted. Installing a transport is a separate reviewed change.

Not live

Public sponsorship intake

The /advertise request form. In demo it validates and acknowledges without storing anything; in production it requires a configured durable writer and the explicit intake gate, and fails closed otherwise.

Available

Durable sponsorship persistence

Available only when the server-only narrow writer boundary is configured in production. No inquiry is ever acknowledged in production without being stored.

Not live

Stripe hosted checkout

Requires production mode, the durable writer, the exact Stripe secret and webhook signing variables, commerce signing material, and the owner-confirmed account/entity gate. Reaching the success page never marks an order paid; only the signed webhook does.

Not live

Paid campaign delivery

Paid decisioning, approval gating, and scope targeting are implemented and tested, but no durable approved-campaign reader is installed, so production serves no paid inventory. Demo returns deterministic house decisions only.

Not live

Event-token validation

Available only when valid server-only signing material of at least 32 bytes is configured.

Available

Durable event ingestion

Validated demo events are acknowledged and discarded. In production, a configured writer stores replay-checked aggregate impression and click counts only — never an address, agent, or visitor value.

Not live

The JSON form is available at /api/health. Database status becomes connected only after a successful, schema-validated aggregate RPC. Detailed rows remain demo data.

A separate read-only operator authentication foundation is available at /operator/sign-in. Its adapter can verify sessions and memberships, but Google identity and email delivery are independently off unless explicitly enabled. Google is identity-only with exactly openid email profile scopes. Gate or environment presence does not prove provider/client configuration, login, or membership, and health does not claim a globally exercised login.