What is built, what is written down,
and what has never been run
Every other page on this site describes a capability. This is the page where each one is checked against what has actually been counted. It is kept the way a maintenance log is kept: three states, a figure beside each item, the date it was read, and the one thing that would move it to the next state. When a figure is bad it is here anyway.
Read this before believing anything else here
This page exists because without it the rest of the site would be a brochure. A product whose whole claim is that it refuses to guess has to publish its count, including the one where the refusal failed. Everything below comes from the engineering record or was measured off the running system on 12 September 2026; each row says which.
How to read it
three states · three gradesBuilt means the thing exists in code and has been run; the figure beside it is what the run showed. Built items that fell short carry Short or Failed in their own table. Specified means the need is written down and counted, and the thing that would meet it does not exist yet or has not been pointed at it. Never run means no measurement exists, and the honest answer to "how well" is "not known".
Every figure carries a grade. counted was read off the running system on 12 September 2026. record comes from the engineering record, written by the pass that did the work. derived is arithmetic on the other two.
Built
and what the run showed| Item | State | What the record shows | What would close it |
|---|---|---|---|
| Conversion run | Built | 56,687 files in; 53,776 readable documents out; 98% clean; 2 quarantined for a person to look at. record | Closed. Reopens if an intake leaves a file without a status. |
| Per-file isolation | Built | One subprocess per file with a hard timeout. Throughput went from about 3 unique files a minute to about 2,250, with zero false quarantines. record | Closed. |
Legacy .doc conversion | Built | Timeouts fell from about 578 to about 3 when a single-shot converter replaced the daemon. record | Closed for what it reads; the 787 with no reader are under Specified. |
| Counting | Built | A retry loop once made a manifest 3.6 times its unique file count — 15,800 rows for about 4,400 files. Unique files are counted now, never rows. record | Closed. The lesson is a test now, not a memory. |
| Provenance repair | Built | 1,097,899 dead source paths repaired to zero. record | Closed. Reopens if a later walk finds a dead path. |
| Hardening pass | Built | 40 findings raised; the 30 rated P0 or P1 verified; 0 refuted. record — SA-REC-RPT-002 | The 10 below P1 are not in the verified set; verify or refute each. derived: 40 − 30 |
| Index | Built | 92,114 documents and 8,363,533 chunks across four corpora; 21.7 GB of stores. All of it the founder's own records. counted | Closed as a count. Open as coverage — see the intake row under Never run. |
| Extractive answer | Built | At most 3 verbatim lines and at most 2 citations, each with a document id and a line
locator. MAX_ANSWER_LINES = 3, MAX_CITATIONS = 2.
counted |
Closed. The cap is the promise. |
| On-device embedder | Built | The health endpoint reports fastembed:BAAI/bge-small-en-v1.5 and
degraded: false. counted |
Closed. |
| Perimeter | Built | Loopback bind; per-key authentication with constant-time comparison; 120 requests per 60 seconds per key; append-only audit log; an off-device provider refused at startup. record — perimeter.py | Closed as built; what is not hardened is on the security page. |
| Tenant wall | Built | tenant_id required on every store read and write; a call without it raises
rather than defaults. record — store.py |
Closed. |
| Arithmetic | Built | Deterministic code, never the model. The estimator reproduces its anchor exactly: 376 m at $834.95 a metre, from the founder's own historic job file. record — ledger.py | Closed. |
| Engine | Built | 5,639 lines across 23 modules. No language model inside it; the only model loaded is the embedder. counted | Closed. Small enough to read end to end. |
Built, and found short
the rows that count against us| Item | State | What the record shows | What would close it |
|---|---|---|---|
| Retrieval quality | Short | The old evaluation reported 100%. It was survivorship: phrasings that failed had been excluded, and a hashing stub with no semantic signal also scored 100% against it. Honest re-measurement put retrieval at roughly 30–60%. record | A fresh evaluation on a held-out set with the failing phrasings kept in, published here with its method before its number. Until then no other page carries a hit-rate. |
| Abstention | Failed | Measured once across three corpora: 45 unsafe answers — questions it should have declined. The embedder fix moved retrieval and left this unchanged, so the fault is in the gate, not the search. record | A re-measurement on the same three corpora after the gate is reworked, published whether it moves or not. |
| Conformal gate | Short | Fitted on one corpus. Its honest guarantee there: about one unanswerable question in seven is still answered — and the cases it was fitted on are the cases it was scored on. record — SA-REC-RPT-007 R0.2 | Calibration on held-out cases; the guarantee restated on them; then the other three corpora. |
| Citation locator | Short | A span stitched from non-adjacent lines is reported as one contiguous range. The quoted text is right; the range is not. record — dossier finding Q3 | Each contiguous run as its own locator, or the span marked as stitched; a test that fails now and passes on the fix. |
Specified
written and counted, not yet met| Item | State | What the record shows | What would close it |
|---|---|---|---|
| The agent bench | Specified | The agents folder holds a charter, one template, one registry and one agent partway through preparation. No seat is configured; no evaluation has been run. The bench is a specification, not a running thing. counted | One seat configured and one evaluation run against it, with the result here. |
Legacy .doc / .xls reader | Specified | 787 legacy files are present, counted, and have no reader. record | A reader for the two formats, run over the 787, each resolving to a status. |
| Photographs of documents | Specified | Held as media-only: present, provenance-carrying, not searchable.
record |
OCR routed to them, per-page confidence recorded, and a count of how many became searchable. |
Never run
no measurement exists| Item | State | What the record shows | What would close it |
|---|---|---|---|
| OCR over the SIG scan queue | Never run | 0 of 883 candidates. The OCR is built and has run elsewhere in the archive — 7,996 documents, 35,633 pages, local-only, zero egress — not over these. record | The 883 through the same local OCR, page count and zero egress stated again. |
| Files present in name only | Never run | 962 files the storage layer lists but does not hold on disk. Reported, not skipped. record | The bytes brought down and the walk re-run; each of the 962 resolving to a status. |
| Intake since 22 July 2026 | Never run | Nothing filed after 2026-07-22 is in any corpus. counted | An intake run over everything filed since, and this date replaced. |
Two rows are here because they are good
The hardening pass — 40 raised, 30 verified, none refuted — and the provenance repair — 1,097,899 dead paths to zero — sit in the same tables as the 45 unsafe answers, graded the same way. That is the only reason to trust either kind. A page of good rows is a brochure; a page of bad rows is a confession. This is the count.
What this page cannot tell you
Every figure above was counted on the founder's own records — four corpora of his own companies' paper — and on no one else's. There are no customers yet. A row closes by changing, on the date it changes. The two accuracy figures here are the only two on the site; the record carries them with their caveats, and a fresh evaluation will replace them.
Where this leads
three doorsWhat we stand behind
The scope of the claim, as narrowly as a contract states it.
Read the scope ▸ The engineWhen it abstains
The refusal as a designed state, and the measurement above in full.
The refusal ▸ Your filing cabinetWhat it cannot read
The scans, photographs and old files that are counted, held, and not yet searchable.
What is not read ▸