Skip to main contentSkip to navigation
Claim boundaries
Inspectable assurance

Trust should be a table, not a halo.

Every public control below has a status, evidence, a scope, an owner, and a limitation. Repository evidence is not the same thing as production assurance—and this page does not pretend otherwise.

Canonical capability registry

The public claim must survive inspection.

Each status names its evidence, owner, scope, and limitation. A status is not a certification.

Capability / controlStatusEvidence packageScopeOwnerBoundary / next proof
Governed answer contractWorkingRepositorypackages/core/src_pkg/services/answer.tsTests / evaluationpackages/core/src_pkg/test/answer-governance.unit.test.tsProductionNone claimedVerified2026-09-07Authenticated core and synthetic public proofProduct engineeringLimitationThe current synthesis path is deterministic. No external language model is invoked.Next proofRun the contract over a permissioned real-world evidence slice and review every unsupported or conflicting answer.
Tenant- and workspace-scoped retrievalWorkingRepositorypackages/core/src_pkg/services/permissions.tsTests / evaluationpackages/core/src_pkg/test/mcp-permission.unit.test.tsProductionNone claimedVerified2026-09-07Repository-backed application queriesPlatform engineeringLimitationUpstream source-system ACL fidelity must still be verified connector by connector.Next proofValidate inherited ACL behavior against one bounded source connector and adversarial cross-tenant cases.
Conflict and non-controlling evidence disclosureWorkingRepositorypackages/core/src_pkg/services/answer-governance.tsTests / evaluationpackages/core/src_pkg/test/answer-governance.unit.test.tsProductionNone claimedVerified2026-09-07Governed answersProduct engineeringLimitationDisclosure depends on the records admitted into the permitted evidence set.Next proofScore conflict detection and disclosure on a blinded set of contradictory operational records.
Named human review boundaryWorkingRepositorypackages/core/src_pkg/services/actions.tsTests / evaluationpackages/core/src_pkg/test/actions-integrity.unit.test.tsProductionNone claimedVerified2026-09-07Governed action proposalsProduct engineeringLimitationOnly repository-supported actions are executable. Unsupported external writes remain blocked.Next proofExercise maker-checker approval, rejection, expiry, and replay behavior in a monitored pilot workflow.
Deterministic work-package readiness verdictSyntheticRepositoryapps/web/src/lib/shipbuilding/readiness.tsTests / evaluationapps/web/src/lib/shipbuilding/__tests__/readiness.test.tsProductionNone claimedVerified2026-09-07Synthetic VS-001 proof (WP-019)Product engineeringLimitationComputes Ready / Not ready / Cannot establish from six gates on synthetic data. No live model, no shipyard connector; a named human releases the work.Next proofCompare live bounded work-package verdicts with authorized releases and audit false-ready, false-blocked, and unknown cases.
Synthetic Build Graph and vessel-state modelSyntheticRepositoryapps/web/src/lib/shipbuilding/build-graph.tsapps/web/src/lib/shipbuilding/work-packages.tsTests / evaluationapps/web/src/lib/shipbuilding/__tests__/build-graph-traversal.test.tsProductionNone claimedVerified2026-09-07Synthetic vessel VS-001 and work package WP-019Product and designLimitationThe graph, vessel, records, and outcomes are hand-authored. It is not naval architecture, a customer record, or a production deployment.Next proofMap a bounded real program slice and measure identity, relationship, provenance, and authority completeness.
Actor-attributed audit eventsBuildingRepositorypackages/core/src_pkg/services/audit.tspackages/prisma/prisma/schema.prismaTests / evaluationpackages/core/src_pkg/test/actions-integrity.unit.test.tsProductionNone claimedVerified2026-09-07Selected authenticated workflowsPlatform engineeringLimitationRetention, export, backup, and recovery evidence remain deployment-specific.Next proofDemonstrate immutable actor attribution, export, retention, backup, and recovery in a deployment environment.
Enterprise identity and lifecycleBuildingRepositoryapps/web/src/app/api/auth/oidc/status/route.tspackages/core/src_pkg/services/oidc.tsTests / evaluationNone claimedProductionNone claimedVerified2026-09-07Hosted accessPlatform engineeringLimitationPassword sessions exist. OIDC exchange, provisioning, MFA policy, and directory lifecycle are not complete.Next proofComplete and test an enterprise identity lifecycle with MFA policy, revocation, and provisioning evidence.
Bounded document ingestionBuildingRepositoryapps/web/src/app/api/ingest/_lib/upload-policy.tspackages/core/src_pkg/services/parsers.tsTests / evaluationapps/web/src/app/api/ingest/_lib/__tests__/upload-policy.test.tsProductionNone claimedVerified2026-09-07Uploaded CSV, PDF, DOCX, and XLSX recordsPlatform engineeringLimitationFiles are treated as untrusted. No malware-scanning service is currently claimed.Next proofAdd and validate malware scanning, quarantine, parser isolation, and failure telemetry in a monitored environment.
Live enterprise connectorsTargetRepositorydocs/PRODUCT_TRUTH.mdTests / evaluationNone claimedProductionNone claimedVerified2026-09-07Customer environmentsProduct engineeringLimitationNo production connector fleet or inherited-ACL claim is made.Next proofBuild one bounded connector and verify identity, authority, freshness, provenance, failure, and inherited permissions.
External security assuranceNot claimedRepositorydocs/PUBLIC_CLAIMS_REGISTER.mdTests / evaluationNone claimedProductionNone claimedVerified2026-09-07CompanyCompanyLimitationNo SOC 2, ISO 27001, HIPAA, FedRAMP, or formal penetration-test claim is made.Next proofDefine the assurance scope, operate the controls, and obtain independent evidence before making any certification claim.
Three boundaries

Access first. Evidence untrusted. Consequence human.

These are operating constraints, not marketing slogans. Each boundary names what the current software capability will not do for you.

  1. 01

    Scope before retrieval.

    Tenant, active workspace, role, and permission constraints belong in the candidate query—not after an answer exists.

    Boundary: upstream ACL fidelity still depends on each connector.
  2. 02

    Treat content as data.

    Uploaded text, document instructions, and retrieved records cannot grant authority or rewrite system policy.

    Boundary: no malware-scanning service is currently claimed.
  3. 03

    Keep the consequential gate named.

    The system may retrieve, compare, reconstruct, and propose. A person with authority approves, rejects, or requests evidence.

    Boundary: supported execution is limited to the internal task adapter.
Reading the roadmap honestly

Four time horizons. Never blended into one pitch.

Ambition and evidence stay in separate columns. The same discipline governs VeldBuild, the first software and systems layer: in development, with synthetic proof and no deployment claimed.

01

Working now

A deterministic governance foundation: authority, evidence, conflict, refusal, and named human review run in bounded repository workflows. The VeldBuild readiness application of that foundation to VS-001 and WP-019 is synthetic, not a live yard capability.

02

Building now

VeldBuild: the governed Build Graph, authoritative build state, change propagation, readiness, evidence, and the interface architecture connecting current systems to future production state.

03

Evidence still needed

Bounded evaluation against real shipbuilding and industrial problems with yards, fabricators, suppliers, engineers, and production teams. No partner relationship or shipbuilding deployment is claimed today.

04

Long-term direction

Build the software, engineering, production, robotics, industrial-network, and physical capabilities required to take complex vessels from requirement to delivered reality as one controlled industrial system.

Explicit non-claims

Nothing to hide behind a badge.

Planned work stays planned, and deployment claims require deployment evidence.

  • No SOC 2, ISO 27001, HIPAA, FedRAMP, or equivalent certification claim.
  • No claim that public synthetic fixtures represent a customer environment.
  • No claim that OIDC, provisioning, MFA policy, or directory lifecycle is complete.
  • No claim that uploaded files are malware-scanned.
  • No claim that external source-system writes are broadly enabled.
  • No claim that a repository test proves a production deployment is correctly configured.
  • No claim that Veldarium operates a shipyard, holds a vessel contract, or has a shipbuilding customer.
  • No claim that VS-001 is engineered, classed, plan-approved, inspected, certified, or authorized to operate.
  • References to public frameworks or guidance do not imply NIST, CISA, Coast Guard, or classification-society endorsement.
Status key

What each label on this site actually means.

Every narrative page carries a compact status chip. This is the canonical definition of each one. A chip is never colour alone — it always renders a glyph and a word.

Status key
Working
Runs today, with evidence and a named owner on /trust.
Building
Under active development. Partially real, not finished.
Synthetic
Hand-authored demonstration data. Not a customer system, not live.
Concept
A design position about how this could work. Nothing is built yet.
Target
A capability Veldarium intends to earn next. Not started or not proven.
Long-term
Company direction. Years out, and dependent on everything before it.
Not claimed
Veldarium does not have this, and is not implying that it does.

Full definitions, evidence and owners on Trust.

Not claimed

What Veldarium does not claim.

These are the conclusions the site does not support today.

  • A shipyard, a drydock, or any manufacturing facility
  • A vessel under construction, delivered, or under contract
  • A Navy, Department of Defense, or other government contract or program
  • A defense customer, a commercial customer, or disclosed revenue
  • Production robotics, CNC machinery, or automated production lines in operation
  • Certifications, accreditations, or third-party audits
  • An employee count, team size, or disclosed funding round
  • Classified work, cleared facilities, or cleared personnel
  • Shipbuilding customers, design partners under contract, or a backlog
Security contact

Report a concrete issue directly.

Full reporting instructions, what to include, and the boundaries of responsible research are on the security page. Do not send secrets or customer data.

Read the security page
Evaluate the boundary

Describe one operational bottleneck without sending confidential records.

Initial contact is direct email. Any later evidence handling would require a separately agreed scope, access path, and responsible owner.