Release acceptance / read-only evidence

Production convergence without manufactured certainty.

Repository proof, live-host proof, device proof, accessibility review, security review, and performance measurement remain separate gates. A passing simulation cannot compensate for a missing production or human-review record.

repository integrity

Repository and deterministic package

PACKAGE_EVIDENCE_AVAILABLE
Package evidence
  • deterministic archive
  • source/archive byte parity
  • runtime-integrity manifest
  • release-identity proof
production host

cPanel Python, Flask, MySQL, Alembic, and Passenger

MIXED_RELEASE_DEPLOYMENT_OBSERVED
Package evidence
  • bounded public health and rendered-page observation
Still requires
  • Python 3.13.14 cPanel host
  • MySQL/Alembic
  • cPanel-owned Passenger wrapper
  • complete-root candidate cutover
Qualification
  • candidate is not deployed
  • private host cause not established
route reliability

Live route, redirect, asset, and API reliability

REPOSITORY_ROUTE_CONTRACT_AVAILABLE_LIVE_FULL_PROBE_REQUIRED
Package evidence
  • 407 route probes
  • 100 same-origin assets
  • read-only full-probe tooling
Still requires
  • deployed candidate
  • HTTPS full-route probe
  • single immutable release header across responses
Qualification
  • selected public pages respond but expose mixed generations
liquid layout

Global liquid layout and responsive reflow

BROWSER_HARNESS_EVIDENCE_AVAILABLE
Package evidence
  • intrinsic CSS contract
  • Explorer viewport harness
  • no page-wide overflow in exercised Chromium harnesses
Still requires
  • representative browser and physical-device review
Qualification
  • single-engine automation is not cross-browser acceptance
browser device

Representative browsers and physical devices

REPRESENTATIVE_ENVIRONMENT_REQUIRED
Still requires
  • Chrome
  • Edge
  • Firefox
  • Safari/WebKit
  • Android
  • iOS
Qualification
  • not established by static analysis or one browser harness
graphics xr

Physical WebGPU, WebGL, context-loss, and WebXR

HARDWARE_EVIDENCE_REQUIRED
Package evidence
  • renderer non-authority contract
  • WebGPU/WebGL/semantic fallback architecture
Still requires
  • physical GPU/device classes
  • context-loss exercise
  • representative XR headset/controllers
Qualification
  • API presence is not hardware acceptance
accessibility

Human assistive-technology task acceptance

HUMAN_REVIEW_REQUIRED
Package evidence
  • semantic HTML
  • keyboard contracts
  • reduced-motion and reflow support
Still requires
  • NVDA
  • JAWS
  • VoiceOver
  • TalkBack
  • switch control
  • voice control
  • qualified-human task review
Qualification
  • automation cannot replace human assistive-technology review
security privacy

Production security and privacy

DYNAMIC_REVIEW_REQUIRED
Package evidence
  • strict public schemas
  • public non-persistence
  • protected-memory separation
  • secret-leakage scans
Still requires
  • authorized DAST
  • authorization/CSRF/rate-limit review
  • dependency/SBOM review
  • production log and privacy review
Qualification
  • repository checks do not establish production security
performance

Measured production performance and resource cleanup

MEASUREMENT_REQUIRED
Package evidence
  • static budgets
  • progressive replay delivery
  • bounded response-size contracts
Still requires
  • LCP/INP/CLS
  • API latency
  • first analytical state
  • first 3D frame
  • FPS/memory/GPU cleanup
  • repeated-run leakage
Qualification
  • unmeasured production performance cannot pass
protected memory

Protected-customer information isolation

PACKAGE_EVIDENCE_AVAILABLE
Package evidence
  • private/public memory separation
  • no public protected routes
  • sanitized export exclusion
  • protected source-title scan
Still requires
  • authorized private-environment validation
Qualification
  • public demonstration does not validate a customer deployment
independent claims

Independent legal, certification, procurement, and customer validation

NOT_ESTABLISHED
Still requires
  • competent independent reviewers
  • applicable customer and legal evidence
Qualification
  • first-party publication and simulation are not independent validation
Python

3.13.14

Exact production interpreter contract.

Application root

evulgare.com

Mounted at the domain root with a blank URL path.

Passenger

cpanel_app.py → application

cPanel owns the generated Passenger wrapper.

Public boundary

SYNTHETIC_NULL_SINK

Synthetic, non-operational, and non-persistent.

Immutable candidate identity

COHERENT

Release
2.0.0-rc.57-WIP
Build ID
EVULGARE-2.0.0-RC57-WIP
Build digest
e83dca0e9a6bab977ba61d0da69c707df70fe8739105fcef1514b7419f35978b
Identity proof
21 conditions / PASS

A stale environment value cannot redefine the package. Every live HTML and API response should expose the same immutable release headers.

Repository-derived route contract

407 public probes

Declared routes
459
Dynamic templates
38
Static assets
100
Contract proof
17 conditions / PASS

The route inventory is a pre-deployment contract. Status, redirects, headers, compression, cache behavior, and response sizes require the read-only actual-host probe.

Deterministic honesty proof

24 / 24 conditions pass

ConditionStateStatement
production_candidate_is_wipPASSUnfinished external acceptance remains visibly WIP.
candidate_identity_coherentPASSAll active repository release-identity sources agree.
mixed_live_identity_preservedPASSMixed public release markers are preserved rather than normalized away.
candidate_not_claimed_deployedPASSThe candidate is not represented as deployed.
route_inventory_substantialPASSThe public route contract covers the complete major public surface.
route_inventory_not_live_probePASSRepository route inventory does not impersonate an actual-host probe.
python_exactPASSThe cPanel interpreter contract is exact.
startup_contractPASSThe startup module avoids recursive Passenger wrapping.
entry_contractPASSThe WSGI callable is application.
blank_pathPASSThe application is mounted at the domain root.
no_automatic_cutoverPASSRepository code cannot activate production.
no_automatic_migrationPASSRepository code cannot migrate production automatically.
no_automatic_restartPASSRepository code cannot restart Passenger automatically.
no_automatic_promotionPASSEvidence never promotes the release automatically.
independent_gatesPASSAcceptance dimensions cannot compensate for one another.
no_composite_scorePASSNo universal readiness score exists.
actual_host_not_inferredPASSPublic mixed-release evidence does not impersonate host acceptance.
hardware_not_inferredPASSBrowser API support does not impersonate physical hardware acceptance.
human_at_review_requiredPASSAutomated accessibility checks do not impersonate human review.
security_not_inferredPASSStatic checks do not impersonate production security acceptance.
performance_not_inferredPASSUnmeasured production performance cannot pass.
synthetic_boundaryPASSPublic convergence evidence remains synthetic and non-operational.
no_operational_interfacesPASSNo live force-application path is introduced.
terminal_statePASSEvery derived public action terminates at the synthetic null sink.

MISSION-FIRST · EVIDENCE-LOCKED · MACHINE-SPEED

DETECT → VERIFY → DENY → CONTAIN → RECOVER → PROVE

Command integrity. Decision superiority. Compartment security. Attested reconstitution.