A state-by-state navigator for legal name and gender-marker changes. It turns the bureaucratic maze (vital records, courts, DMV, SSA, passport) into a personalized, ordered checklist, links the exact official form for each step, and explains everything in plain language with a citation and a last-checked date. Information, never legal advice. Built privacy-first, for users who may be in hostile jurisdictions.
npm install # install the pinned development and test tooling
make verify # the full 25-gate pipeline (CI parity)
make dev # http://localhost:8080 → intake → checklist → official form links
make eval # regenerates docs/audits/eval-report.{md,json}Requires Node ≥ 22.6 (TypeScript runs via native type-stripping; no build step). The server is plain node:http; the current reference build has zero production package dependencies.
Operations runbook: docs/OPERATIONS.md. Build log and status: docs/STATUS.md. Audit artifacts (DPIA, eval reports, accessibility audit, residual-risk register) live in docs/audits/.
Status: in build (M6). All 50 states, the District of Columbia, and federal records (SSA, passport), in English and Spanish. All 25 automated merge gates pass (make verify): gate-count (self-description drift), lint, typecheck, tests with coverage, security scan, content validation, forms, citation coverage, source fidelity, privacy, freshness, disclosure, readability, i18n (UTF-8, BCP-47, EN/ES key parity, logical-CSS, no-hardcoded-accessible-name-strings, pseudolocale overflow), accessibility, SEO, eval, an in-process p95-latency guard, SLO-definition/burn-alert validation, and a machine-derived launch-gate status check. CI additionally runs a real-browser accessibility gate, Lighthouse CI, Semgrep/CodeQL SAST, gitleaks + scheduled TruffleHog secret scanning, a container CVE scan, and zizmor over the workflows themselves. The remaining launch gates need human judgment, not code. Their status is derived from the repository's artifacts on every make verify run (make launch-gates), not written by hand — see the table below; keeping them open is a decision, not a gap.
Supported versions: main only — there are no maintained release lines yet (see SECURITY.md for the vulnerability-reporting process and current pre-1.0 scope).
Launch readiness: 8 of 8 review gates are OPEN. Every status below is derived from the
repository's own artifacts on each make verify run — none of it is hand-written, and none of it
can be cleared by editing this table. No record in this corpus has been verified by a named human.
| Launch gate | Status | Machine-derived evidence | Derived from |
|---|---|---|---|
| Named-human verification of every record | 🔴 OPEN | 0 of 1000 records verified by a named human. 1000 carry the Pilot Seed Reviewer placeholder. |
corpus/ + forms/registry.json × corpus/VERIFIERS.json |
| Every record's claims backed by its own cited source | 🔴 OPEN | 1039 assertion(s) located in their cited source, 0 unsupported (merge-blocking), 532 UNCHECKABLE. Separately, 2632 of 3223 prose sentences carry no checkable literal and no gate vouches for them. | make fidelity (scripts/source-fidelity.ts) |
| Every cited source actually under drift watch | 🔴 OPEN | 75 cited source(s) are UNWATCHABLE — no baseline can be taken or compared, so drift there is undetectable and last_verified is a human's assertion rather than a checked fact: https://billstatus.ls.state.ms.us/documents/2026/pdf/SB/2100-2199/SB2126SG.pdf (no reviewed drift baseline), https://courts.delaware.gov/forms/download.aspx?id=16858 (no reviewed drift baseline), https://courts.ms.gov/images/Opinions/CO182514.pdf (no reviewed drift baseline), https://dhss.delaware.gov/wp-content/uploads/sites/12/dph/pdf/GenderReassignment.pdf (no reviewed drift baseline), https://dhss.delaware.gov/wp-content/uploads/sites/12/dph/pdf/RequesterAffidavitSexChange.pdf (no reviewed drift baseline), https://dmv.de.gov/DriverServices/drivers_license/pdfs/gender_designation_change_procedure.pdf (no reviewed drift baseline), https://dmv.de.gov/forms/driver_serv_forms/pdfs/gender_change_request_form.pdf (no reviewed drift baseline), https://doa.alaska.gov/dmv/akol/namchg.htm (403 to our declared user-agent; we do not spoof one), https://doa.alaska.gov/dmv/forms/pdfs/427.pdf (no reviewed drift baseline), https://doh.wa.gov/sites/default/files/legacy/Documents/Pubs/422-144-SexDesignationChangeMinor.pdf (no reviewed drift baseline), https://dph.georgia.gov/document/document/affidavit-amendment-form-3977-revisedpdf/download (no reviewed drift baseline), https://dphhs.mt.gov/assets/Statistics/VitalStats/MTGenderDesignationForm.pdf (no reviewed drift baseline), https://dphhs.mt.gov/assets/Statistics/VitalStats/affidavitcorr.pdf (no reviewed drift baseline), https://eforms.alacourt.gov/media/jtzbncuw/request-to-change-name.pdf (no reviewed drift baseline), https://health.mo.gov/sites/health/files/media/pdf/2026/04/Aff_for_Correction.pdf (no reviewed drift baseline), https://health.wyo.gov/wp-content/uploads/2026/07/WDH-VRS-Correction-Form-2026.pdf (no reviewed drift baseline), https://indianalegalhelp.org/wp-content/uploads/2024/09/Adult-Name-Change-Packet-INSTRUCTIONS-202409-Update.pdf (no reviewed drift baseline), https://juddocumentservice.mt.gov/getDocByCTrackId?DocId=564241 (no reviewed drift baseline), https://ldh.la.gov/vital-records/amendments-to-birth-records (403 to our declared user-agent; we do not spoof one), https://msdh.ms.gov/phs/VR_rules_2023_new_format.pdf (no reviewed drift baseline), https://ndlegis.gov/cencode/t23c02-1.pdf (no reviewed drift baseline), https://odh.ohio.gov/know-our-programs/vital-statistics/changing-correcting-birth-record (403 to our declared user-agent; we do not spoof one), https://portal.ct.gov/-/media/DMV/20/29/B-385.pdf (no reviewed drift baseline), https://public.courts.alaska.gov/web/forms/docs/civ-699.pdf (no reviewed drift baseline), https://public.courts.alaska.gov/web/forms/docs/civ-700.pdf (no reviewed drift baseline), https://public.powerdms.com/ladpsc/documents/368304 (no reviewed drift baseline), https://publicdocuments.dhw.idaho.gov/WebLink/ElectronicFile.aspx?docid=1294&dbid=0&repo=PUBLIC-DOCUMENTS (no reviewed drift baseline), https://realfile.tax.newmexico.gov/mvd10237.pdf (no reviewed drift baseline), https://superiorcourt.maricopa.gov/media/emucljue/name-gender-change-eng-spa.pdf (no reviewed drift baseline), https://travel.state.gov/content/travel/en/passports/have-passport/change-correct.html (403 to our declared user-agent; we do not spoof one), https://travel.state.gov/en/passports/apply/unique-needs/sex-markers.html (403 to our declared user-agent; we do not spoof one), https://travel.state.gov/es/pasaportes/renovar-o-reemplazar/cambiar-o-corregir.html (403 to our declared user-agent; we do not spoof one), https://vitalrecords.nc.gov/documents/NCOVR-BirthModificationsApplicationFinal-07072022v6.pdf (no reviewed drift baseline), https://vitalrecords.utah.gov/wp-content/uploads/902-Affidavit-to-Amend-by-Court-Order.pdf (no reviewed drift baseline), https://www.azdhs.gov/documents/vital-records/manuals/correction-affidavit-correct-amend-birth.pdf?v=20260409 (no reviewed drift baseline), https://www.capitol.tn.gov/Bills/113/Bill/SB1440.pdf (no reviewed drift baseline), https://www.courts.mo.gov/page.jsp?id=3834 (403 to our declared user-agent; we do not spoof one), https://www.courts.nh.gov/sites/g/files/ehbemt471/files/documents/2021-06/filing_fees.pdf (403 to our declared user-agent; we do not spoof one), https://www.dccourts.gov/sites/default/files/2024-01/Name_Change_Application_Full_Fillable.pdf (403 to our declared user-agent; we do not spoof one), https://www.dfa.arkansas.gov/wp-content/uploads/Affidavit_of_Legal_Name_Change_2019.pdf (no reviewed drift baseline), https://www.dfa.arkansas.gov/wp-content/uploads/DS_GenderApplication.pdf (no reviewed drift baseline), https://www.dmv.nh.gov/drivers-licensenon-driver-ids/update-personal-information (403 to our declared user-agent; we do not spoof one), https://www.dpbh.nv.gov/siteassets/programs/birthdeath/dta/forms/Court_Ordered_Change_ONLY.pdf (no reviewed drift baseline), https://www.dpbh.nv.gov/siteassets/programs/pco/Changing_Your_Gender_In_Nevada_Guide_08.24.2018_1.pdf (no reviewed drift baseline), https://www.dpbh.nv.gov/uploadedFiles/dpbh.nv.gov/content/Programs/BirthDeath/dta/Forms/Corrections%20-%20Birth.pdf (no reviewed drift baseline), https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd0149.pdf (no reviewed drift baseline), https://www.health.ny.gov/vital_records/gender_designation_corrections.htm (403 to our declared user-agent; we do not spoof one), https://www.healthvermont.gov/sites/default/files/document/hsi-vr-gender-affidavit.pdf (no reviewed drift baseline), https://www.healthvermont.gov/sites/default/files/documents/pdf/HS_VR_BC_Correct_Amend.pdf (no reviewed drift baseline), https://www.hhs.nd.gov/sites/www/files/documents/DOH%20Legacy/Vital/SFN%2060183%20-%20Birth%20Amendment%20Changes.pdf (no reviewed drift baseline), https://www.legis.iowa.gov/docs/code/2026/144.23.pdf (no reviewed drift baseline), https://www.legis.iowa.gov/docs/code/2026/674.pdf (no reviewed drift baseline), https://www.maine.gov/dhhs/mecdc/sites/maine.gov.dhhs.mecdc/files/Application%20to%20Correct%20a%20Vital%20Record%20in%20Maine%20%28VS-7%29.pdf (no reviewed drift baseline), https://www.maine.gov/sos/sites/maine.gov.sos/files/inline-files/GENDER%20DESIGNATION%20FORM2019.pdf (no reviewed drift baseline), https://www.maine.gov/sos/sites/maine.gov.sos/files/inline-files/Guidance%20about%20Gender%20Designations%20on%20Maine%20Drivers%20Licenses_1.pdf (no reviewed drift baseline), https://www.michigan.gov/mdhhs/doing-business/vitalrecords/correct-change-a-vital-record-and-legal-name-change (403 to our declared user-agent; we do not spoof one), https://www.michigan.gov/sos/all-services/license-or-id-name-correction (403 to our declared user-agent; we do not spoof one), https://www.michigan.gov/sos/all-services/license-or-id-sex-designation-correction (403 to our declared user-agent; we do not spoof one), https://www.ncdot.gov/dmv/downloads/Documents/DL-300.pdf (no reviewed drift baseline), https://www.nj.gov/health/forms/reg-l2_1.pdf (no reviewed drift baseline), https://www.njcourts.gov/sites/default/files/forms/10551_namechg_adult.pdf (no reviewed drift baseline), https://www.nmhealth.org/publication/view/form/5429/ (no reviewed drift baseline), https://www.nycourts.gov/courthelp/Family/nameChange.shtml (403 to our declared user-agent; we do not spoof one), https://www.nycourts.gov/courthelp/NameChange/childNameChange.shtml (403 to our declared user-agent; we do not spoof one), https://www.opm.gov/policy-data-oversight/data-analysis-documentation/personnel-documentation/processing-personnel-actions/guide_to_processing_personnel_actions.pdf (no reviewed drift baseline), https://www.opn.ca6.uscourts.gov/opinions.pdf/24a0151p-06.pdf (no reviewed drift baseline), https://www.sos.mo.gov/cmsimages/adrules/csr/current/19csr/19c10-10.pdf (no reviewed drift baseline), https://www.ssa.gov/forms/ss-5.pdf (no reviewed drift baseline), https://www.tn.gov/content/dam/tn/health/documents/vital-records/PH-1186-Application-to-Amend-A-Tennessee-Birth-Record.pdf (no reviewed drift baseline), https://www.uscis.gov/sites/default/files/document/forms/i-765.pdf (no reviewed drift baseline), https://www.uscis.gov/sites/default/files/document/forms/i-90.pdf (no reviewed drift baseline), https://www.uscis.gov/sites/default/files/document/forms/i-90instr.pdf (no reviewed drift baseline), https://www.uscis.gov/sites/default/files/document/forms/n-565.pdf (no reviewed drift baseline), https://www.vdh.virginia.gov/content/uploads/sites/93/2020/07/VS42_Gender-Designation-Form.pdf (no reviewed drift baseline), https://www4.honolulu.gov/docushare/dsweb/Get/Document-325980/State%20of%20Hawaii%20Driver_s%20License%20Application.pdf (no reviewed drift baseline) |
api/watchability.ts over corpus/source-hashes.json + forms/form-hashes.json + corpus/snapshots/index.json |
| Independently authored expert gold set | 🔴 OPEN | independent_author: false — the gold set was co-authored with the corpus, so accuracy is partly tautological |
eval/gold.provenance.json |
| Counsel review of the disclaimers (UPL) | 🔴 OPEN | no sign-off in docs/signoffs/ — this gate cannot be cleared by editing a doc |
docs/signoffs/*.json (gate: counsel-review) |
| Manual screen-reader / keyboard / 200%-zoom walkthrough | 🔴 OPEN | no sign-off in docs/signoffs/ — this gate cannot be cleared by editing a doc |
docs/signoffs/*.json (gate: accessibility-walkthrough) |
| Real Bedrock-backed eval run | 🔴 OPEN | no sign-off in docs/signoffs/ — this gate cannot be cleared by editing a doc |
docs/signoffs/*.json (gate: bedrock-eval) |
| DPIA + STRIDE threat-model sign-off | 🔴 OPEN | no sign-off in docs/signoffs/ — this gate cannot be cleared by editing a doc |
docs/signoffs/*.json (gate: dpia) |
The rules for changing your name and gender marker differ by state and by document, they change often, and the guidance that exists is scattered across PDFs, court clerks, and forum lore. People pay for incomplete help or give up. A current, cited, accessible navigator is a public good. And correctness here is a safety property: wrong guidance costs people money, time, and sometimes safety.
| Intake | Checklist | Official form, linked |
|---|---|---|
![]() |
![]() |
![]() |
▶ Live demo — runs the real app (every route works, not a static export) on AWS Lambda. It serves machine-compiled seed records, none yet verified by a named human — the interface says so beside every source, and the table below tracks the count. It's a serverless, scale-to-zero deploy chosen as a cost guardrail: no always-on compute, a per-month budget alarm, no paid LLM calls by default. First request after idle takes a few seconds to wake. (AWS setup and cost-guardrail breakdown: docs/DEPLOY-AWS-PREVIEW.md.)
Which commit is that? Nothing here deploys on a push, a tag, or a schedule — the only deploy path is a manual workflow_dispatch of deploy-aws-preview.yml, so the preview can be behind main and no date on this page would tell you. Ask the running service instead: curl -s <demo-url>/version reports the commit the image was built from, when it was built, and the corpus digest it verified at boot. When an image carries no stamp it answers "commit": null, "stamped": false rather than guessing, and the deploy refuses to report success unless the live URL names the exact commit it just shipped. (Runbook: docs/OPERATIONS.md.)
Prefer your own host? One click deploys the same image to Render's free tier:
— see
docs/DEPLOY-PREVIEW.md.
It's a demonstration, not a launched service: the corpus is illustrative seed content with corrected official sources but placeholder verifiers, and every page carries the "information, not legal advice" disclosure. It also runs locally in one command (see Quickstart).
- Asks a short, respectful intake: your state, which documents, your language. There is no account. Private mode skips the optional local resume copy; the server still processes the request fields needed to render the page, as the Privacy Notice explains.
- Produces an ordered, personalized checklist (court order → SSA → DMV → passport → records), with prerequisites, realistic costs, and timelines.
- Plans a move to another state (
/move): a destination delta over the same cited corpus. Given an origin, a destination, and the documents you already hold, it says what carries over, what the new state re-issues on its own terms, in what order — and which routes close the day you stop being a resident of the state you're leaving (Texas's petition is filed "in the county where you live"; that door shuts when you move). Cost is the #1 reported barrier to relocation, so the cost model is a floor built only from fees the sources actually state, explicit about every step it cannot price, and it surfaces fee waivers. It never guesses, and it never claims the new state honors a document the old one issued — no source says so. Seedocs/RELOCATION.md. - Answers the inverse question, "which state?" (
/compare): a table of every covered state against the documents/changes you pick, each cell showing exactly one of four facts — a documented path, a documented path that needs reverification, a source that documents no path (a fact about the source, not a guess about the state), or not yet checked. It ranks nothing: no score, no "safest"/"friendliest" label, default sort is alphabetical, and the one optional sort is a literal count ("number of documented paths"). Every cell links to the record(s) it came from. - Links the exact official form for each step, at its government source, for you to download and file yourself. (It does not auto-fill: these are XFA/LiveCycle PDFs that browser tooling can't fill, and a mis-filled legal form is a real harm — better the authoritative form.)
- Answers questions with inline citations to the governing source and a last-verified date, and says plainly when it doesn't know.
- Offers a per-jurisdiction change-alert feed (
/feeds, RSS 2.0): subscribe to "Washington: records updated" with no account and no email, and the feed itself is never tracked (it is XML and loads no analytics) — a subscriber in a hostile state can watch their own state's requirements without handing over any identity. Every entry reports that OUR RECORDS changed, on the date a named reviewer (re)checked them — never a claim that the law itself changed. Seeapi/feed.ts. - Builds a portable, single-file edition (
make portable): one self-contained HTML file carrying the whole corpus, the official-forms registry, both language bundles, and the same checklist, relocation and comparison engines the server runs. It answers fromfile://with the network disabled — no server, no origin, no request to anything — so it can be handed over on a USB stick, over AirDrop, or copied between people who cannot afford to appear in a log. ItsContent-Security-Policyforbids every outbound directive, so the guarantee is enforced rather than promised; its freshness is evaluated against the reader's own device clock, so a copy carried past its records' re-check dates says so and stops presenting them as current — while still handing over the official-source links, which is the one thing a degraded copy must never withhold. The artifact is not a second edition of the engine:tests/portable.test.tsasserts itshandleRouteis byte-identical to the server's across the entire eval gold set, so drift fails the build. It does not update itself and never phones home; a newer copy is a newer download. Build-only for now:make portablebuilds the file, but nothing publishes it or attaches it to a release, and there is no public distribution until counsel and community review.
Four properties are enforced by merge-blocking CI gates, not by convention:
- No claim without a citation — and no citation without a matching source. Every substantive statement renders with a source and a last-verified date, or it does not render. This applies to model-generated text too: output passes through the same post-generation enforcement, so a hallucinated sentence cannot reach a user. That was only half the chain, though: it proved an answer cited a record, never that the record matched the source it cites. A record could assert a fee, a form, or a deadline its own cited page never stated and every gate stayed green — which is exactly how the corpus came to name a retired DMV form and a $0 fee that page never mentioned, with an unchanged source hash, so the drift watcher saw nothing either.
make fidelitycloses that: it re-reads every record against a committed offline snapshot of its cited source and blocks any load-bearing claim — fee, timeline, form id, hard requirement — that isn't locatable there. It is also honest about its limits: it does not attempt semantic entailment, so what it cannot vouch for is counted and published indocs/audits/source-fidelity.mdrather than passed in silence. - Information, not legal advice. Every page carries the disclosure, persistently and in both languages. The service makes no representations about individual legal outcomes.
- Privacy is a safety property. The service has no account or identity-profile database, and the form helper keeps names on-device. Checklist selections and an optional question are sent in the request URL so the server can render a response. Raw question text bypasses the application cache and is excluded from application logs and responses; selection-only renders may use a bounded in-memory cache, and allowlisted request metadata is retained for a limited period. The optional save-progress blob is encrypted with a passphrase and remains on the user's device. In a hostile-jurisdiction threat model, this is deliberate minimization—not a claim that no server, browser-history, or infrastructure record can exist. Google Analytics 4 counts page views on the hosted preview only (ADR 0007): it receives the page path without the query string (so no selection or question), never loads on a page carrying a question or on the relocation planner, and never loads under Global Privacy Control, Do Not Track, or the footer opt-out.
- Stale law is broken law. Every record has a freshness SLA. Expired data is shown as "needs reverification," never silently served as current.
The privacy controls are checked three ways: a static gate rejects direct identity-field handling in runtime API and log-call code, the application logger drops fields outside a fixed allowlist, and a data-flow test injects sentinel content into every request field and proves it is not reflected into an application log descriptor or response body. Those checks do not claim that request inputs never reach the server; the exact request, cache, log, and provider boundaries are documented in the Privacy Notice and docs/audits/dpia.md.
Retrieval-mandatory generation over a corpus of jurisdiction records, each carrying its own cited source and last-verified date. (Not human-verified: every record currently holds a placeholder verifier — the launch-gate table above is the machine-derived count.) The HTTP layer (api/server.ts) does plumbing only; routing and validation live in unit-tested api/router.ts; the checklist engine, retrieval, and citation enforcement are separate modules under api/. Rendering is server-side, accessible HTML (src/) that works with JavaScript disabled; progress tracking and save/resume progressively enhance. All user-facing strings live in per-language bundles under src/i18n/; adding a language means writing one bundle module and registering it. A deterministic extractive composer is the default generator; a Bedrock-backed generator is the production seam, subject to identical citation enforcement.
English and Spanish ship with full parity, enforced twice: the compiler checks every locale bundle against the same interface, and an end-to-end test suite asserts no English chrome leaks into Spanish pages. Where Spanish coverage is thinner than English for a state, the page says so honestly instead of pretending.
This repo references the portfolio's private engineering standards (/STANDARDS)
rather than restating them; they are fetched read-only at CI time
(.github/workflows/standards.yml, pinned to .standards-version), never committed.
Per-repo values live in docs/ROADMAP.md §7/"Observability" and
docs/RESPONSIBLE-TECH-AUDITS.md. All 11 standards
apply to this repo — none is N/A. No row below claims more than is actually gated;
where a gap is open, it says so and points at where it's tracked.
| Standard | Applies | This repo's posture |
|---|---|---|
| Quality & Metrics | ✅ | make verify (25 stages) = CI parity; in-process p95-latency and SLO-definition/burn-alert checks are merge-blocking. DEFINITION_OF_DONE.md defines done with an honest gate/review/human-gate split; the PR template carries its rollback/observability/ISO-25010 lines. |
| Code Quality | ✅ | TS 6 + tsc --strict plus all 7 beyond-strict flags (noUncheckedIndexedAccess, noImplicitOverride, noFallthroughCasesInSwitch, noImplicitReturns, noUnusedLocals, noUnusedParameters, exactOptionalPropertyTypes); coverage ≥90%/85%/90% (lines/branches/functions) enforced via node --test --test-coverage-lines=90 --test-coverage-branches=85 --test-coverage-functions=90 (scripts/run-tests.ts), merge-blocking — the TS-native equivalent of CQ's coverage-floor gate, exceeding the ≥80% target in CODE-QUALITY-STANDARD.md §3. Python controls N/A — reason: zero Python source in this repo (CODE-QUALITY-STANDARD.md §11): coverage_threshold_set (CQ-08) and single_pyproject (CQ-25) as named by automation/conformance_check.py are Python-specific (they check for pyproject.toml/cov-fail-under) and will always read MISSING here — that checker's is_python heuristic is triggered by the mere presence of a tests/ directory, which §4 of the same standard requires for TS repos too, so the false positive is structural, not a gap in this repo. Adding a pyproject.toml with a fabricated Python coverage floor to satisfy the string-match would be gaming the check, not fixing anything real; the enforced control this repo actually needs (a coverage floor, single root config) is the row you're reading. Single-config-source: one each of package.json, tsconfig.json, stylelint.config.js, playwright.config.ts at repo root, no duplicates/nesting — no eslint.config.mjs/vitest.config.ts since this repo uses neither ESLint nor Vitest (see below), matching the TS half of CQ-25's project-layout rule (§4). Bundler/React controls N/A (zero runtime deps, no build step, no JSX). No ESLint/Prettier — a deliberate dependency-minimal deviation, recorded with its compensating controls in docs/adr/0006; the five build ADRs are migrated to individual files (docs/adr/0001–0005). scripts/lint.ts covers api/+src/ only — extending it over scripts//tests//eval/ (CQ-34/35) is tracked in ADR-0006's consequences. |
| Security & Supply-Chain | ✅ | ASVS L2 posture; Semgrep + CodeQL + Trivy (container) all blocking; gitleaks CI (diff/push) + scheduled TruffleHog full-history scan + pre-commit gitleaks hook; HSTS + Permissions-Policy headers; SHA-pinned actions (Renovate, 72h cooldown); Harden-Runner block mode with observed-egress allowlists on 8 of ci.yml's 9 jobs (each allowlist mined from real audit-mode runs, not guessed — see the workflow). container-and-infra and all of release.yml stay in Harden-Runner audit, each with a written, PR-verified reason (a non-deterministic per-pull CDN redirect on the public-ECR pull; a release workflow that has never run) — see their own comments, not silently left behind. OpenSSF Scorecard aggregate is 7.5/10 as of a dated run against main on 2026-09-06 (docs/audits/scorecard-2026-07.md, ## 2026-09-06 section) — up from 5.8/10, after the Token-Permissions fixes landed and the Maintained age heuristic expired. Its CI automation, silently broken for 2 months, is confirmed fixed by a green run on main (34005526933) whose SARIF reached code scanning. |
| CI/CD | ✅ | make verify byte-for-byte in CI; least-privilege job-scoped tokens; concurrency groups on every publish/deploy job; zizmor + CodeQL language: actions cover the workflow YAML itself; .github/CODEOWNERS present. docs/audits/branch-protection-2026-07-05.md for the exact settings and what's missing (this is a repo-settings change, not something a code change can do). Graph Update: pip in /corpus/snapshots, in GitHub's own dynamic/dependabot/update-graph workflow, that has failed all 7 of its runs (2026-07-14 → 2026-09-06) and has never passed. It fails with dependency_file_not_evaluatable / RequirementsFileParseError because it parses three corpus snapshots as pip requirements files — corpus/snapshots/dor-mo-gov-driver-license-issuance-id-requirements-html-3146ecde.txt, corpus/snapshots/dshs-texas-gov-vital-statistics-requirements-requesting-changing-vital-00409814.txt, corpus/snapshots/mass-gov-info-details-eligibility-requirements-for-indigency-waiver-of-bc737a19.txt — whose URL-derived names happen to contain the word "requirements". There is no Python manifest anywhere in this repo and .github/dependabot.yml declares no pip ecosystem; the job is created by GitHub's manifest detection, not by this repository. Checked 2026-09-13: it cannot be excluded. Dependabot graph jobs are documented as requiring only "that the dependency graph is enabled for your repository"; exclude-paths is marked Version updates only and its changelog scopes it to pull requests; and the upstream change that would make graph jobs honor it — dependabot-core PR #15148, "Honor exclude_paths in graph jobs" — is open and conflicted, alongside the open upstream report of this exact false positive (#15141). Declaring pip here would not silence it, only add a second failing job; the only off-switch is disabling the dependency graph for the whole repository, which would also end npm alerts. The snapshots are not renamed, because their names are their provenance. Nothing is left unwatched by this: npm, github-actions and docker updates, Dependabot alerts and every merge-blocking gate above are unaffected. tests/dependabot-pip-graph.test.ts fails if a real Python manifest ever lands, so a genuinely new pip failure cannot hide behind this note. Tracked in #265. |
| Release & Versioning | ✅ | release.yml re-runs the full make verify gate set at the tagged commit, checks tag↔package.json version consistency, publishes to GHCR by immutable digest only (never :latest), keyless-signs with cosign, attests a schema-validated CycloneDX SBOM and SLSA provenance, and independently pulls the published artifact back down to verify it before the release is considered done. CHANGELOG.md (Keep a Changelog) added. The running image now answers GET /version with the commit it was built from, so "released" and "live" are separately checkable. |
| Accessibility | ✅ | WCAG 2.2 AA. Real-browser pa11y-ci (axe + HTML_CodeSniffer, 0 violations, 15 URLs incl. the offline-shell page) + Lighthouse CI (a11y ≥0.95, perf ≥0.90, LCP/CLS/TBT budgets) both blocking; mechanical static gate covers 25 page templates. docs/audits/accessibility-2026-05-31.md, dated, explicitly flagged as now covering a wider surface than when it was written — not silently treated as current); no ACR/VPAT yet. |
| Observability | ✅ — Tier A (hosted service) | Declared under ## Observability in docs/ROADMAP.md. The repo ships allowlist structured logs, /livez + fail-closed /readyz, W3C-correlated server/Bedrock spans, bounded-route RED metrics at /metrics, and parsed 30-day availability/latency SLOs with fast/slow burn alerts. Lighthouse CI covers Tier-B lab budgets. RUM is N/A — reason: no client telemetry is sent to a third-party analytics vendor. |
| Internationalization | ✅ — in scope, declared in docs/I18N.md |
EN/ES ship with compiler-enforced key parity, an end-to-end no-leakage test suite, UTF-8 (G1) + BCP-47 (G3) + pseudolocale-overflow (G9) + logical-CSS (G10) gates, and disaggregated eval parity (≤5pp). A dedicated gate (i18n-hardcoded) rejects any aria-label/alt/title/placeholder typed as a literal in a src/ rendering template rather than sourced from the locale bundle (issue #151) — narrower than the full G2 FormatJS ratchet, but it closes the specific hole a mechanical WCAG check and key-parity check both miss: a landmark label can be well-formed and still be in the wrong language. Content-Language is now set on every rendered response. |
| AI Evaluation | ✅ | Retrieval-mandatory generation; no claim renders without a citation, enforced identically for the deterministic composer and the Bedrock seam (api/citation.ts). Groundedness, accuracy, refusal, adversarial behavior, retrieval recall@8, precision@1, and segment parity are merge-blocking. |
| Documentation | ✅ | CITATION.cff, SECURITY.md (private vuln reporting), CHANGELOG.md, .standards-version, currency stamps on every audit artifact, and this table. ADRs live in docs/adr/ (0000 practice record; 0001–0005 migrated from docs/ROADMAP.md §6; 0006 toolchain deviation). |
| Responsible-Tech Framework | ✅ — in full (sensitive population) | docs/RESPONSIBLE-TECH-AUDITS.md instantiates §A–F; request-content non-reflection test, allowlist logger, disclosure gate, and corpus quarantine are all portfolio-reference quality. docs/audits/dpia.md and docs/audits/accessibility-2026-05-31.md; AI risk register / impact assessment / EU AI Act classification drafted 2026-07-17 (docs/audits/ai-risk-register.md, ai-impact-assessment.md, eu-ai-act-classification.md) — all three unreviewed drafts, counsel/human finalization pending. |
No standard above is a bare, unexplained gap: every STANDARDS/README.md's "silent omission" rule).
See CONTRIBUTING.md, GOVERNANCE.md (how decisions get made, and which ones are not up for debate), SUPPORT.md, and CODE_OF_CONDUCT.md. Accessibility barriers are treated as bugs.
The most valuable contribution is verifying a record. Launch gate 1 is "named-human verification of every record", and it currently reads 0 of 1000 — every record carries a Pilot Seed Reviewer placeholder, and the generated launch-gate table above is the number that stays right. That gate is the reason this is a demonstration rather than a service, and it is the one thing no amount of code can close. You do not need to be a lawyer, and you do not need to use your legal name: you need to have read the official source and be willing to be credited for it, under your name, a stable pseudonym, or an organization ID. docs/HELP-WANTED.md has the measured freshness position, what one hour actually buys, the 44 records no script can check, and how crediting works.
Also wanted, and useful without any legal expertise: reporting that a law or page changed, accessibility barriers (especially screen-reader, keyboard and 200%-zoom findings — that walkthrough is itself an open gate, scripted in docs/a11y-walkthrough.md), and Spanish review — EN/ES parity is enforced mechanically, but no native speaker has reviewed the translations.
This project was built AI-assisted (the disclosure on every page says so too) within a portfolio that shares a common quality standard: every project ships with merge-blocking gates for its core safety properties, and audit artifacts are committed to the repo rather than claimed. Related scaffolding (a civic-RAG starter and an eval harness) lives in separate repos of the same portfolio.


