# Verification record

7 October 2026. Scope: this independent synthetic portfolio project. Prior analytics-workflow and portability-candidate test results are not counted here.

## Local executor

The behavioral suite ran 37 tests on Python 3.12.14, Windows: 35 passed, two skipped, zero failures. The skipped cases require creating file and directory symlinks, which this account cannot do. They are not passing verification of those paths. The implementation resolves paths, but those environment-dependent end-to-end checks remain outstanding.

Evidence: `evidence/engine/test-final.txt` and `evidence/engine/test-report.json`. The report binds the tested engine, test code, definition file and data bytes with SHA256. `test-initial-red.txt` retains the initial behavioral failures against a not-implemented seam. `environment-note.md` distinguishes an earlier default-temporary-directory access failure from behavioral test results. No denied content was read or security settings changed.

The suite covers pooled denominators, signed returns, unknown versus zero, duplicate and unmatched customer keys, malformed requests, argument and tool restrictions, missing context, stale inputs, source/definition/result tampering, output boundaries, run collisions, writer ownership and truthful verification fields. Cancellation was checked before CLI work and after a real staging write before commit. Source changes during staging were also checked. These are local executor checks, not tests of an application cancelling a model or native process.

## Actual run

`evidence/engine/inspection-response.json`, `recorded-response.json`, `verification-response.json` and `runs/demo-002/` retain the current inspect, analyze and verify sequence. The original `runs/demo-001/` and `pre-review-*` responses are historical evidence from before a code correction; their engine identity differs from the current runner. They are not current verification.

The output is a conversion numerator/denominator of 91/110 and known revenue subtotal of 140 fictional units across four of five rows. Complete revenue remains unknown; duplicate C2 blocks the customer join. Tool success and integrity verification do not grant analytical release or human approval.

The site build refuses a failing or stale test report and re-verifies the retained run before copying it into the presentation. The browser itself displays a bundled snapshot; it does not inspect the current filesystem or execute the runner.

## Additional review

Final reproduction, site delivery, browser and fresh-reader checks are recorded below. A listed pending check is not a pass.

- Independent arithmetic and relocated execution: passed. `evidence/reproduction-check.json` records a real three-tool sequence from a copy whose path contains spaces, launched from an unrelated working directory. The metrics matched the retained result. The disposable copy was removed after verification.
- Static links, archive contents and checksums: passed. The delivery check resolves local assets and section targets, checks unique IDs, validates every archive member against PACKAGE-SHA256.json and inspects the nested source download. `evidence/static-delivery-check.json` records the scope.
- Downloaded source rebuild: passed in a disposable copy. `evidence/download-check.json` records successful rebuilding and delivery checks. An intentional change to tested code was rejected as stale evidence, and the prior archive remained unchanged.
- Interaction logic: passed for all five scenario transitions, selected-state updates, actual receipt and test-count binding, missing-evidence handling, and clipboard success/fallback. `evidence/site-interaction-check.json` identifies the method as Node VM with a minimal DOM test double. This is not a browser, layout or keyboard test.
- Browser rendering: not verified. The local HTTP readiness check failed with `An attempt was made to access a socket in a way forbidden by its access permissions.` No alternate browser route, permissions change or bypass was attempted. The owned local server was stopped. Responsive layout, visual rendering, keyboard navigation and screen-reader behavior remain unverified in a browser.
- Fresh-reader continuity: passed for purpose, authority, definitions, execution route and verification limits. Review found an output-size inconsistency and a missing-site-source packaging issue, both corrected before final packaging. See `evidence/fresh-review.md`. This was AI-assisted review, not independent human certification.

The output-size correction has an executed failing regression in `evidence/engine/review-cap-red.txt` and a passing case in the final 37-test suite. A permitted 10,000-row input can expand beyond one MiB as JSON; generated artifacts now have a separate four MiB read limit. The original input cap is unchanged. The source archive now includes the editable HTML, CSS and JavaScript needed to rebuild the presentation.

The first package build correctly stopped when its private-path scan mistakenly matched the scanner's own example pattern. The pattern was narrowed, archive inputs are now checked before writing, and output archives are replaced only after a successful write. The subsequent build and delivery checks passed. This was a build defect, not an exposed credential or private-data incident.

## Limits

No real Claude, ChatGPT, Grok or open-weight model execution was performed. No model-quality benchmark, latency comparison, cost saving or universal compatibility is claimed. Python 3.12.14 on Windows is the tested runtime; other versions and operating systems are unverified.

Native Excel/BI acceptance, managed-plugin connectivity, human release approval, accessibility certification, adversarial security review, hostile concurrent filesystem mutation, process-kill recovery, production load and OS isolation are not established. Hashes are integrity checks, not signatures or proof of source truth. The five-row fixture establishes semantics, not production scale.

All implementation changes belong to this independent project. Live analytics records and the sealed portability candidate were not edited. No live-workspace regression pass is claimed. There was no Git, Docker, installation, credential change or remote publication.
