Conformance reporting
A conformance report says which controls a project exercised and what their evidence returned. It is self-attested by whoever runs it. It is not an audit, it produces no mark, and it is worth exactly as much as the evidence behind it.
How a report is produced
Four things make a row, and a row without all four is not reported as enforced.
The control
One sentence about behaviour, tied to the principle it belongs to. Not a policy and not an intention: something that is either true of the running system or not.
The evidence
What decides the row. For an enforced control that is an automated check; for a manual one it is a named person performing a written procedure.
The run
One identified execution. A row is enforced only on the strength of what happened in that run, never on the strength of what usually happens.
The status
Enforced, manual or gap. Nothing else, and no shading between them.
The three statuses
- Enforced
- An automated check carries the rule, and it ran in the identified run and passed.
- Manual
- The control holds through a procedure a named person performs. Real, not automated, and reported as what it is.
- Gap
- Nothing enforces it today. Named, with what closing it would take, rather than omitted.
The anti-theatre rule
A control is never reported as enforced unless its evidence ran in the identified run and passed. A previous success, a skipped check or a selection that ran no tests at all is not current verification. A report that calls a control enforced because somebody remembers it passing is a report about memory, and running a report successfully is not a certificate that anything is implemented.
What this report is, and is not
It is a self-attested internal assessment with a limited public evidence summary. It cannot be reproduced from this page: the evidence runs against a repository that is not public, so no command here is offered as one a reader could run. It is not an audit, not a certification and not a conformity assessment, and no authority has assessed, audited or endorsed it.
This project's own assessment
The rows below are a reviewed public projection of an internal assessment of this repository. They are a SUBSET, chosen because each row can be stated publicly without naming what a guard protects. The internal assessment is larger and is not published.
Which assessment this is
- Framework version:
- 2.2
- Assessed on:
- 7 September 2026
- Run:
- 34152270255
- Produced by:
- the COADF system work, not the site work. The site did not re-execute the evidence; it projects it, and names whose it is.
The same set of controls, run on a workstation rather than in continuous integration, was red for two controls that need a database the workstation does not have. Both executed and passed in the run named above. Both runs are recorded internally; neither is hidden to improve the look of this page.
Disclosed scope
16 of 57 controls in the internal assessment. Totals on this page are over the disclosed scope only and are not the totals of the internal assessment. The controls left out are left out because their statements name protected subject matter, not because of their result.
12 enforced, 2 manual, 2 gap, over 16 disclosed controls.
| Control | Principle | What it requires | How it is enforced | Status |
|---|---|---|---|---|
| F-03 | P-1 | Values derived by a language model always carry the method they were extracted by and never reach a published output without human verification. | Automated check, on every change | Enforced |
| F-04 | P-2 | A required attribute with no evidence is never fabricated and never defaulted. | Automated check, on every change | Enforced |
| F-05 | P-6 | No real personal or company documents in code, fixtures, tests or commits.Scope: The guard covers export-document access keys and issuer data. It does not cover every identifier shape, and the residue is carried internally as its own gap. | Automated check, on every change | Enforced |
| F-08 | P-2 | A passport carrying a low-confidence or missing required attribute is never published; the publication gate is code, not a habit. | Automated check, on every change | Enforced |
| F-09 | P-6 | No database schema change without a migration and a working downgrade. | Automated job, on every change | Enforced |
| F-13 | P-4 | The tenant and trace identifiers travel with every request and every stored row.Scope: The request-path half is tested. The stored-row half is not asserted column by column, and is carried internally as its own gap. | Automated check, on every change | Enforced |
| F-14 | P-6 | Code and identifiers in English; reader-facing copy in five locales, with every key present in every one. | Automated check, on every change | Enforced |
| F-16 | P-6 | Interface copy never asserts legal conformity or an unverified fact; an attestation renders as an attestation and never as a verification. | Automated check, on every change | Enforced |
| F-18 | P-4 | A trace identifier on every console interface response, errors included; an incoming one is honoured rather than reminted. | Automated check, on every change | Enforced |
| F-22 | Candidate · Claim discipline | Every factual claim on a public surface resolves to a primary source or to a named test. | Automated check, on every change | Enforced |
| F-23 | P-6 | The running site loads only same-origin resources and sets exactly one cookie, for language. | Automated check, on every change | Enforced |
| F-37 | P-6 | Every crawled public page meets WCAG 2.2 AA in a real browser. | Automated job, on every change | Enforced |
| F-02 | P-6 | No new infrastructure service beyond the agreed set, and no new dependency without a named section in the change request. | Named person, at merge | Manual |
| F-10 | P-6 | No merge with failing checks. | Named person, at merge | Manual |
| P-4-not-null-columns | P-4 | Every stored row carries the tenant and trace identifiers as required columns.What closing it would take: A test over the data model rather than over a running database, asserting the requirement column by column. | Nothing today | Gap |
| P-5-disclosure-rendered | P-5 | A published output whose attributes include a machine-extracted one always renders the disclosure line.What closing it would take: A render test over an output carrying a machine-extracted attribute, with its own proof of teeth. The rendering exists; nothing fails when it is removed, so the control is a habit rather than a rail. | Nothing today | Gap |
Disclaimer
COADF is a publicly documented development framework. It is not a certification, not an audit standard and not a conformity assessment scheme. No authority has assessed, audited or endorsed it. A conformance report is self-attested by whoever runs it, and describes which controls were exercised and what their evidence returned. The name describes the orientation of the development method toward regulatory requirements; it never asserts that any system, output or shipment is compliant.
Public feedback
Disagree with an assumption, found a source issue, or applied this in practice? Contributions are reviewed before publication and stay linked to this version.
