Trustyu Forge Evidence research
Evidence research v1.7 · cut 2026-07-17T23:24:33Z

Public search
source-bound.

This registry publishes the sanitized artifacts from the run supporting the v1.7 search. External sources were treated as unreliable data; each fetch was limited by policy, linked to snapshot and hashes and discarded after derivation. No raw external content was persisted.

20 / 20 receipts approved 3 / 3 reproducible studies 11 independent groups No model call
423.265bytes received
21HTTP calls
37.675 mssummed fetch time
9 / 9revised claims
0 / 0model calls/tokens
$0direct model cost
Three questions

Supported Conclusions
independent.

Each claim maps to at least two sources and each search uses at least three independent groups. The semantic relationship was reviewed by human; receipts prove acquisition, checks and source binding, not an automatic truth.

R1 Reliable Harness

The system surrounding the model determines reliability

Explicit workflow and workspace, isolation, small changes, observable feedback, orchestration roles, and durable decisions form the public baseline.

R2 · Secure & Auditable

Testing, isolation and provenance are distinct controls

Policy in text is not enough. Auditable delivery separates AI verification, least privilege, sandboxing, provenance, and artifact-independent validation.

R3 · Evals, OTel & FinOps

Quality and cost need a unit of value

Evals combine criteria and observable execution. Non-zero cost comes from official billing; absence of export remains unknown, never an invented zero.

Claim boundary: This pack proves that public intake and multi-source research were successfully exercised for 20 sources reviewed in this cut. It does not prove Operational, Attested, certification, product adoption, customer outcome or global leadership.
Public ledger

20 fonts.
20 verifiable pairs.

The manifest records the request, capabilities and budget. The receipt records result, final URL, snapshot, hashes, checks, retention and measured cost. The files below are byte-by-byte mirrors of the canonical pack merged into trustyu-docs@994bbad7.

Official sourceGroup/focusManifestReceipt
OpenAI Symphony specificationOpenAI · harness/orchestrationJSONJSON
OpenAI Codex Linux sandboxOpenAI · isolation/securityJSONJSON
OpenAI Agents SDK tracingOpenAI · observability/privacyJSONJSON
DORA report 2025Google DORA delivery systemJSONJSON
NIST Dioptra/AI RMF MeasureNIST · AI measurementJSONJSON
SLSA specification 1.2OpenSSF · supply chainJSONJSON
GitHub artifact attestationsGitHub · provenanceJSONJSON
FinOps measure unit costsFinOps Foundation unit economicsJSONJSON
GitHub billing usage reportsGitHub billing APIJSONJSON
AWS ADR processAWS · architecture decisionsJSONJSON
Azure architecture decision recordsMicrosoft · architecture decisionsJSONJSON
Google engineering practices: small CLsGoogle review/deliveryJSONJSON
OpenAI organization costs APIOpenAI provider billingJSONJSON
Google Cloud billing exportGoogle Cloud provider billingJSONJSON
OWASP AISVSOWASP · agentic securityJSONJSON
Anthropic evaluation cookbookAnthropic · evals/qualityJSONJSON
Microsoft AutoGen AgentChatMicrosoft · multi-agentJSONJSON
OpenTelemetry GenAI observabilityOpenTelemetry · traces/costJSONJSON
GitHub billing reportsGitHub reconciliationJSONJSON
Anthropic Usage and Cost APIAnthropic provider billingJSONJSON
Operating Limits

Measured zero does not erase
the unknown.

This acquisition did not call OpenAI, Anthropic, or Gemini; Therefore, the direct cost of this intake model is zero. Future billing is documented but not configured. Without authorized credential/export and reconciliation by project/SKU, product spend remains unknown.

Provider billing

OpenAI Admin Usage Costs API, Anthropic Usage and Cost API and Google Cloud billing export are in the official catalog. State: documented-not-configured.

Fail-closed real

HTTP 403, DLP/prompt-injection and content-hash-mismatch continued to be denied. The execution swapped mutable pages for official immutable snapshots, without bypass.

Origin: gate framework-only from issue Docs #292, executed by policy profile forge.public-evidence-fetch/v1 of trustyu-ai-env@fb43ea3d and accepted in trustyu-docs@994bbad7. Public artifacts do not include retrieved content or secrets.