52 claims
Everything this store says, and how it knows.
Every chip on every page in this design round links to a row below. A claim that cannot be pointed at something is not a claim this site makes — it is either marked as absent or it is not on a page.
Ten states, and only exists and runs is fully earned. The rest say what kind of thing stands behind a sentence: read from a published source, measured on a named workload, arithmetic with the workings shown, a specification for something not built, or a person’s time.
The state of each thing on the offer list
Fifteen Agent Behaviour Policy template shapes are published, free and public, with published read keys, at riskmandate.ai. The pack for any of them is what the £10 level sends: built, and it runs today. The templates being free is not a problem for this store — what is priced is the template with the mandate corrected, a name on the licence and no public key.
How we know: data/abp-catalogue.json, promoted from riskmandate.ai/abp-vaults.html with its content hash
abp-templates-existA template shape is built into a vault by one command. The £50 level is that build, licensed to you, with the public key off it — a vault you hold the keys to, with its own app, its own history and a read key you can hand to anybody who asks how you govern the agent. Built, and it runs today.
How we know: riskmandate.ai/abp-vaults.html: every tile is a shape built into a vault by one command
abp-vault-build-existsThe £500 level is a named security professional's work, and that work has been done many times. The generator and the correction exist, the vaults are built from them, and six vaults of exactly this are published with read keys anybody can open. What is bought at this level is that person's time turned on your situation rather than a template's — which is why its delivery estimate is one to three days from your reply and depends on a calendar rather than on a queue.
How we know: data/offers.yml, t3
Said on: home, try, booking, compare, investors, startups, next, next/policies, offers
abp-correction-by-a-personThe £1,500 level is two sessions with a named security professional, who reviews the work and signs it off. That is not the company issuing a signed opinion as a formal instrument — that wording does not exist on this site — and the delivery page keeps the two apart, because the difference is the whole of what a buyer is and is not getting.
How we know: data/offers.yml, t4, read against the signed-opinion add-on
Said on: home, booking, compare, investors, startups, next, offers
abp-sessions-by-a-personThe catalogue on this site is promoted from riskmandate.ai at build time, with the source URL, the retrieval time and a sha256 of the page it was read from, because no page here that sells anything opens a network connection. A shape added upstream appears at the next build; one that arrives without a product code stops the build rather than rendering a tile whose buttons produce a code nobody can fill.
How we know: tools/promote_abp.py and data/abp-catalogue.json
Said on: home, boundary, next/policies, what-is-in-one
abp-catalogue-promotedThe multi-format add-on's generator exists. The check that every variant renders the same fact set — the diff that must be empty — does not exist, and hard rule 6 forbids printing the guarantee before the check is built. So the guarantee is not printed.
How we know: 02__THE-HARD-RULES.md, rule 6
fact-diff-absentThe signed-opinion add-on's wording does not exist, and it must before a first signature. The offer is listed and cannot be bought: there is no code behind it.
How we know: 01__WHAT-TO-BUILD.md, the add-on rows
opinion-wording-absentThe corrected vault is estimated at one to three days from the buyer's reply — from the reply rather than from the payment, because until the details arrive there is nothing to correct against. It is an estimate rather than a measurement and is labelled as one; the constraint behind it is one person's calendar. The 24 hours is riskmandate.ai's commitment to follow up and is theirs to keep. The gap this closes was found by walking the store as a founder with six weeks to a term sheet, who left without buying and named the missing date as the reason.
How we know: data/offers.yml t3, and the synthetic-user run 2026-09-15-startups-01
Said on: paying
t3-delivery-time-estimatedThe offer line replaced on 15 September 2026
The application that would compute tier 1's delta was built in August and has not been located. Until it is, tier 1 is a questions page, and this site says so on the offer, on the delivery page and here.
How we know: 01__WHAT-TO-BUILD.md, the tier table
Said on: agents
t1-app-not-locatedTier 2 was specified on 28 July. The graph it selects from exists at 1,523 nodes with amendments applied. The pipeline that turns a situation into a vault does not exist.
How we know: 01__WHAT-TO-BUILD.md, the tier table
Said on: not cited on any page
t2-pipeline-absentTier 3 is a booking, and it overlaps the signed-opinion add-on. The overlap is recorded and unresolved, so the two are sold separately and neither page implies the other.
How we know: 01__WHAT-TO-BUILD.md, the tier table
Said on: not cited on any page
t3-collision-openTier 4 is a booking with a deposit: two sessions with a named security professional, whose time the deposit reserves. The seven-role team described in the pack is a specification rather than something staffed — what is delivered is one person's work, and the page says which before the conversation rather than after it.
How we know: 01__WHAT-TO-BUILD.md, the tier table
Said on: not cited on any page
t4-is-a-booking-with-a-personTier 4's deposit is £500, and it is payable by link. The fee argument that put tier 4 on the invoice rail was always about the £10,000 and never about the deposit: at £10,000 a card costs up to about £250, and on the same rate £500 costs about £12. So the deposit is a payment link and the balance is not — two amounts, two rails, one offer. Arithmetic, not an invoice.
How we know: 01__WHAT-TO-BUILD.md, the price paragraph, applied to the deposit the same document already describes
Said on: not cited on any page
t4-deposit-below-thresholdWhat happens to a deposit against an engagement that cannot be scheduled is not written down. Until it is, the deposit follows the conversation and a written scope and is never taken before one — which is a change to the flow rather than a promise on a page, because a promise about somebody's money that nobody has agreed is worse than an admission that the wording does not exist.
How we know: data/offers.yml, the t4 deposit record, and the same rule that holds the signed-opinion add-on off sale
Said on: not cited on any page
t4-deposit-terms-absentWho each offer was built for
For a team assessing an agent they already run, the market anchors between eight and one hundred and fifty thousand dollars, and nothing sits underneath it. The choice today is a five-figure engagement or nothing, and that gap is what tiers 1 and 2 are pointed at.
How we know: The audiences brief, in the pack at /dev-packs/store/
agent-market-gapNo productised, affordable, signed investor review exists at any price, and every component of one is already written. It is the emptiest quadrant on this site, and tiers 3 and 4 are what point at it — but the signature itself is a separate add-on whose wording does not exist.
How we know: The audiences brief, in the pack at /dev-packs/store/
investor-review-absentFor a founder, two funded incumbents and a free tier beneath them already publish the answer. Selling a startup a posture document is selling into a commoditised tier, so no offer here does. The unoccupied direction is the reverse one: what diligence will find, before it runs.
How we know: The audiences brief, in the pack at /dev-packs/store/
founder-tier-commoditisedNothing on the offer list was built pointing at a startup. The startup group is assembled entirely from tiers built for somebody else, run in the opposite direction — it is a framing of tiers 3, 4 and 2, not a seventh thing on the price list. The reverse-direction offer does not exist as a separate purchase and is not sold as one.
How we know: data/buyers.yml, where the startup group's primary list is empty and the gate checks that it is
startup-offer-is-reverse-onlyThe lab, and what it is not
The five pages at /lab/ are prototypes of a purchase flow, not a purchase flow. Nothing on them can be bought, no brief reaches us, no payment link sits behind anything on them, and which of the five (if any) becomes the real one is not decided. A build check fails the release if any of them stops saying so.
How we know: build.py, LAB_VIEWS and check_lab_is_marked in tools/check_site.py
Said on: lab, agent-canvas, agent-sequence, board, delta, interview, ladder, product, scenario
lab-is-a-prototypeThe mapping and policy work these briefs configure is done by a named security professional. Nothing in it is automated today, the seven-role team these prototypes describe is a specification rather than something staffed, and which parts could later be done without people is a decision nobody has taken. A brief is the thing a first call would otherwise be spent assembling — it is not a delivery.
How we know: 01__WHAT-TO-BUILD.md, the tier 4 row, read against what /lab/ configures
lab-fulfilment-is-peopleThe configurator does not compute a price. Weighted selections add up, the total lands in one of four bands, and each band names one of the four tiers that already exist and its price. A configurator that emitted a number would be inventing a price, which is the first thing the pack says may not be invented — so the build fails if a band names an offer that is not on the list.
How we know: data/brief.yml, the bands table, and check_lab_bands in tools/check_site.py
Said on: lab
lab-price-is-a-bandThe five prebaked scenarios are shapes somebody might arrive in, not counted frequencies. Nobody has measured how common any of them is. Each brief records which scenario it started from, so that what was assumed stays separable from what was answered — which is the only thing that makes starting from a guess safe.
How we know: data/brief.yml, the scenarios list
Said on: lab
lab-scenarios-are-hypothesesA brief is written to the browser's own local storage and reaches nothing else. There is no form, input, textarea or select anywhere in this site's output and no page here that sells anything opens a network connection — both held by build checks — so exporting a brief hands the file to the reader rather than to us.
How we know: check_no_forms and check_no_network in tools/check_site.py
lab-brief-stays-localHow paying works, and why it works that way
A United Kingdom card account cannot tap in Portugal: the provider declines the transaction on detecting a different country, and says so in those words. A payment link is an online payment, so no cross-border rule applies to it. The conclusion the pack draws: no card reader should be bought.
How we know: The payment-rail brief, in the pack at /dev-packs/store/
Said on: paying
card-reader-refusedThe entry price has moved three times and every move is kept. £10 on 10 September, because at £5 the fixed card fee alone is about four per cent of the transaction. £5 on 15 September, by ruling, with the arithmetic unchanged and the judgement changed. £10 again on 16 September — and this time the number is not what moved. Two reviewers, one human and one invented, independently said £5 read as a commodity price for something sophisticated; the answer ruled was not a larger number for the same thing but a commercial licence over material that is public under CC BY, which is a different product rather than a dearer one. Every step stays on the page, because a price that moves quietly is a price nobody can argue with.
How we know: 01__WHAT-TO-BUILD.md, the price paragraph, and the pricing ruling of 15 September 2026
Said on: offers
card-fee-floorPrices are in pounds. Pricing in euros while settling in pounds adds about two per cent.
How we know: 01__WHAT-TO-BUILD.md, the price paragraph
Said on: offers
pricing-in-poundsThe cloud marketplace's seller terms state that a seller is not permitted to collect customer payment information at any time. The two rails are therefore strictly separated: the marketplace is not a second button beside the card button, it is a different conversation with a different threshold.
How we know: The marketplace brief, in the pack at /dev-packs/store/
marketplace-no-customer-paymentThe marketplace listing fee is 0.5 per cent, and falls to zero inside a qualifying multi-product solution. The pitch is procurement, not discount: the buyer already holds the marketplace's legal terms, so there is no master agreement, no vendor onboarding and no new purchase order.
How we know: The marketplace brief, in the pack at /dev-packs/store/
Said on: paying
marketplace-feeProfessional services listings do not draw down committed spend on the cloud provider. Three independent sources state the exclusion. An earlier version of this claim said the opposite; the correction is recorded here rather than quietly dropped, and the old version appears on no page of this site.
How we know: The marketplace brief, correction carried in brief 2 of the pack
no-committed-spendMarketplace registration is the long pole: four to eight weeks. The listing is therefore a November surface, not an event surface, and nothing on this site depends on it.
How we know: 01__WHAT-TO-BUILD.md, the surface table
marketplace-registrationNo payment link has been created for any offer on this site. Every offer carries a checkout_url in data/offers.yml and every one of them is empty, so each offer shows its code and its delivery page rather than a button. Issuing a checkout is one pasted line; the gate holds whatever lands there to buy.stripe.com or checkout.stripe.com over HTTPS, so a checkout cannot quietly become a redirect through somewhere else.
How we know: data/offers.yml, and check_checkout_links in tools/check_site.py
Said on: home, admin, rails, next/cart, next/pay, offers, paying
checkout-links-not-issuedA standing payment link carries one price, and three of the six offers do not have one. Tier 2 and tier 3 are bands and tier 4 is a conversation, so only tier 1 can ever have a standing link; the banded tiers take a link issued once the band is fixed for the case. That is a property of a fixed-price link, not a policy, and it is why the checkout is not simply four buttons.
How we know: 01__WHAT-TO-BUILD.md, the price paragraph, read against how a fixed-price payment link works
checkout-bands-have-no-standing-linkA discount code is recognised by the page, not by a rail. What ships is sha256 of the code and never the code, checked on every release against every byte of the built site — but a short code can be ground out of a hash, and that is said rather than dressed up. The thing that stops a stranger paying nothing is that a browser does not take money: a code changes the amount a payment link is issued for, and the rail decides what is charged. No rail exists yet, so today a code at a hundred per cent is how the whole flow gets walked without money.
How we know: data/discounts.yml and tools/check_site.py, check_discount_codes_are_not_printed
discount-code-is-in-the-browserThere is no <form>, <input> or <select> anywhere in this site's output, and the reason boxes on /review/ are the only place on this domain that can be typed into. The rule was absolute until v0.1.15 and moved by ruling, to make room for a page that answers a partner's review — asking somebody to answer a critique with no way to answer it would have been the joke version of this site's whole argument. What stayed absolute: no <form>, which is the element that submits; no <input> and no <select>, which is where a card number or an address gets typed; no network connection on any page, which is the check that makes all of it a fact rather than a sentence; and no name attribute on the boxes, because a name is what a field is called when it is submitted and these are never submitted. What a reader types stays in their browser until they copy it out.
How we know: tools/check_site.py, check_no_forms and check_the_typing_surface_is_inert
review-is-the-one-typing-surfaceThe entry level is a licence, not a download. The same files are published free under CC BY, which obliges anybody using them to attribute; what £10 buys is a commercial licence to the buyer over the same material, so it can go into client work, into a product or into a document for a regulator without carrying our name into it. It is grantable for one reason — the copyright in the pack is ours, because everything in it was written here — and that makes it a constraint on what may go into a pack from now on. The wording is not drafted. A grant to an unnamed holder has to read as a grant and not as a public re-licence of the same bytes, and until that is written this claim says what is intended rather than what is signed.
How we know: The project lead, 16 September 2026, and data/offers.yml
entry-level-dual-licenceWhat a finding is worth, and what may be promised
Recall-optimised agents run at 0.388 precision — about three findings in five are wrong. This is the reason the product is triage and never raw findings, and the reason every finding that reaches a buyer has been reproduced rather than reviewed.
How we know: The disclaimer brief, in the pack at /dev-packs/store/
Said on: home, audiences, booking, add-formats, add-opinion, t1, t2, t3, t4, disclosures, agents, investors, startups
precision-0388The transparency article has applied since 2 August 2026 and reaches a third-country party whose output is used in the Union. Outputs here are model generated and are marked as such on the face of the artefact, not only in a footer.
How we know: The disclaimer brief, in the pack at /dev-packs/store/
Said on: home, booking, disclosures, versions
transparency-articleThe regulation graph exists at 1,523 nodes, with amendments applied. It is the launch catalogue because the European regulation is expressly reusable commercially, including adaptation.
How we know: 01__WHAT-TO-BUILD.md and hard rule 10
Said on: disclosures
graph-nodesThe international management standards are not adapted, translated, resold as a derivative, or fed to a model here — prohibited twice over, once as a derivative and once as a model input. The same prohibition covers the payment card standard and the centre's controls. Nothing on this site is derived from any of them.
How we know: 02__THE-HARD-RULES.md, rule 10
Said on: disclosures
standards-not-adaptableThe words this site uses, and the words it does not
Tamper evident, given a witness — never the absolute form of that claim, which is false. A rewritten hash chain verifies against itself; tampering is detectable only when another party already holds an older hash. The witness is a second clone, which makes handing somebody a read key the act that makes the claim true. Append-only is stated as a policy, not a property.
How we know: 02__THE-HARD-RULES.md, rule 14
Said on: disclosures, versions
tamper-evident-witnessThe sentence a reader expects from an encryption product — the one about what its operator can and cannot see — is not printed on this site in any form, because six questions about what leaks (filenames, directory structure, object sizes, commit timing, recovery or escrow, support access) have not been answered. In November 2020 a regulator acted against a company for claiming end-to-end encryption while its servers held the keys; the settlement imposed twenty years of third-party assessments.
How we know: 02__THE-HARD-RULES.md, rule 13
Said on: home, catalogue, disclosures, versions
cannot-read-unansweredLicence to operate — a permission granted by an authority, ruled 3 September — collides with a second phrase in the same vocabulary, written 17 July, which describes exposure already carried. They mean opposite things and both are in use. The collision was recorded on 8 September and is still open, so the second phrase appears on no page of this site and a build check keeps it off.
How we know: 03__THE-NAMES.md, the open collision
Said on: disclosures, versions
naming-collision-openThree contested terms — one for encryption, one for recall, one for autonomy — do not appear anywhere on this site. What is used instead: end-to-end encrypted as the primary term, client-side encryption as the mechanical one, and durable for the property that resumes losslessly. The build fails if any of the three reaches a page. Each is described on the disclosures page.
How we know: 02__THE-HARD-RULES.md, rule 12
Said on: disclosures, versions
three-banned-wordsThe deadline, and what actually depends on it
The event is 17 and 18 September 2026, in Lisbon. The offer page and the payment codes are the only parts of this with a hard date. The merchandise surface, the catalogue of eight further offers and the marketplace listing do not depend on it.
How we know: 00__START-HERE.md, the deadline
Said on: paying
event-datesA ruling of 10 September placed a storefront under the risk product rather than on the platform domain. The instruction in hand overrode it and named this host. The ruling stands on the record, unedited, in the pack — and the build treats the host as moveable: every internal link is relative, the host appears in no copy, and the offer identifiers are stable.
How we know: 00__START-HERE.md and 03__THE-NAMES.md
domain-ruling-overruledThe handover, and what the two sites owe each other
riskmandate.ai publishes one page per level — paid-t1 to paid-t4 — and since its v1.19.2 the level-one page is the download itself: the zip, its size, its sha256 and a check that hashes the file in the buyer's own browser against the hash that shape publishes. The size and the hash are stamped by their build, not typed, and a stale manifest fails their CI. This store does not copy any of it, because two copies of a hash is one hash that will go stale.
How we know: riskmandate.ai/after-payment.md, the table of four levels
post-sale-pages-existNothing carries a sale from this store to the people who follow up. Their pages promise a person within 24 hours at the three vault levels, and that person needs the level, the order reference, the address paid with and — at £500 — the template chosen. A static site cannot send it: no page here opens a connection except to embed a published vault, and none will ever send anything about a reader. So until a rail exists whose receipt reaches them, the channel is the buyer's own first message from the page they land on. This is the one thing that gates the first paid order at those levels, and it is written here rather than assumed.
How we know: riskmandate.ai/after-payment.md, item 2 of five
sale-notification-absentTheir pages tell the buyer the order reference is on their receipt. No rail has issued a receipt yet, so what a real receipt says — and whether it carries the reference under that name or another — is not known. The store generates SG- plus six characters from an alphabet with no 0/O or 1/I, and hands it to the provider with the amount. What comes back on the receipt is the provider's to decide and has not been seen once.
How we know: riskmandate.ai/after-payment.md, the open list; data/checkout.yml, every url empty
receipt-reference-untestedAt £500 the buyer runs MAP-A-GRANT.md where the agent runs and sends back grant.json, mandate.json and the session record, with no secret in them. That route is email today. A write-only vault the buyer drops the files into is the intended route and does not exist yet; when it does, their level-three page changes and this store's wording changes with it.
How we know: riskmandate.ai/after-payment.md, the open list
Said on: paying
level3-return-by-emailThe four pages name one mailbox, and who owns it past the first orders is settled on neither site. This store names nobody: it links to the page that carries the address, so that when the person or the address changes it is one change on four pages there and none here. A mailbox duplicated onto a fifth page is a mailbox that will one day be wrong on one of them.
How we know: riskmandate.ai/after-payment.md, the open list
Said on: paying
follow-up-owner-unnamedThe opinion add-on is listed here and has no page there. Their brief says: if the store lists it, say so and the page will be built in the same shape as the four. This store lists it — at /d/add-opinion/, marked absent, with the wording for a signed opinion recorded as not existing. The page after payment for it does not exist on either site, and nothing here says otherwise.
How we know: riskmandate.ai/after-payment.md, item 4 of five; data/offers.yml, add-opinion
Said on: paying
opinion-add-on-has-no-page-thereWhat is true of what is sold here
This work has been done, repeatedly, and it is published. Twenty-eight encrypted vaults are published at sgit.ai, each opened by a read key that site publishes on the vault's own page; six of them are this work — an agent's grant, its mandate and the delta between them, simulated end to end; an eleven-step risk-acceptance walk over one evolving register; a fact-to-risk graph explorer; a standard turned into something a position can be measured against; eleven linked threat models presented at a conference in Barcelona; and a regulation parsed into a graph you can cite a row of. What has not happened is a sale through this store. Those are two different sentences, and until this date this site printed only the second one and let a reader draw the first.
How we know: sgit.ai/demos/vaults/llms.txt, retrieved 16 September 2026, and data/evidence.yml
Said on: home
the-work-has-been-done