System status

Everything on this page measures Cogvera’s own platform, the one serving this site and the client Hub. It is the standard we hold ourselves to, not a client reference. The CI gates run in a private repository, so their run logs are named here rather than linked — a link you cannot open is not evidence. What is verifiable from outside is the isolation badge below: a row this platform’s CI writes to its own database, and the only claim on this page that does not ask you to take our word for it.

RLS tenant-isolation harness (verifiable)

checking

Quality gate

external

biome · tsc · eslint · knip · unit · RLS · a11y

quality-gate.yml · run log private

Provenance

external

SLSA build provenance + SBOM (signed, verified in-CI) · tagged releases only

provenance.yml · run log private

CodeQL

external

CodeQL SAST

codeql.yml · run log private

Semgrep

external

Semgrep SAST

semgrep.yml · run log private

gitleaks

external

gitleaks secret scan

gitleaks.yml · run log private

Lighthouse

external

Lighthouse performance budgets · pull requests only

lighthouse.yml · run log private