We do not ship trust as a promise. We ship it as a test.
26 criteria, each with a binary answer. 4 are green with an automated probe behind them today. 18 have no probe written yet, and 1 cannot pass until something else is built. 3 are failing right now, and we would rather name them: gate 13 (single-reader), gate 14 (cutover-hygiene), gate 22 (recording-absence).
Every one of them, including the red.
This is the full registry rather than a flattering subset. A criterion with no probe is shown as having no probe, because an untested assertion and a passing test are different things and only one of them is evidence. The count in the sentence above is the length of the registry, computed at build time, not a number somebody typed.
the count is len(GATES), not a number in this sentence | reproduce with ledgerctl.py gates | measured 2026-09-02
Blocked is not failing, and it is not passing either.
Two of the criteria above are blocked, which means the probe runs and correctly refuses to go green because the thing it tests does not exist yet. The clearest example is the anchor criterion. Its probe confirms that mutating a stored consent row is detected and named, and that a logged erasure still verifies clean, both of which hold. Then it stops, because the rest of the criterion asks for an RFC 3161 anchor and no signed token is issued or stored anywhere.
So the chain is tamper detectable and it is not tamper proof, and the gate stays amber rather than green until a head digest leaves this machine. A criterion that quietly passed on the half that worked would be worse than no criterion, because it would retire the question.
gate 18 BLOCKED | gate 15 PASS | measured 2026-09-02
A gate that cannot fail is decoration.
The previous version of this website carried a gate count that was correct when it was written and wrong within days, load bearing in the headline the entire time. That is the ordinary way this goes: somebody writes a true number into a page, the product moves, and nothing connects the two again.
So the number is computed, the states are measured, and a build that would publish a green count while something is red does not produce a page at all. The cost of that choice is that you are reading about our failures on our own marketing site. We think that is the cheaper side of the trade.