The dated v0.4 baseline.
By this May–June 2026 baseline, the engine had gained a
per-spec discriminator that addressed the Gatsby-SPA-catchall false-positive class.
The engine reported ed25519 signature verification for eleven dogfooded
kineticgain.com documents at that time. The linked May 28 crawl artifact
covered 1,007 domains; the separate editorial universe count was 2,005 by
June 1, without a linked full crawl of that expanded set. This page records the intended
baseline for Issue #5; that issue is not published here.
Editorial note, October 2026: “Verified” on this historical page refers to the reported signature check, not schema validity. A separate September 12 estate audit found 0 of 11 sampled documents valid against their own schemas. This page has not rechecked the current documents.
The baseline numbers, locked in
The locked 899-domain crawl is in procurement-pulse-engine/data/issue-4-v04-full.json.
The numbers below come from the later baseline-2026-05-28.json crawl of 1,007
domains. Both are dated engine readings, not a present-day measurement.
.kineticgain.com operator-surface CNAME the portfolio deployed (then 60+), a CISO procurement pack
(64 domains across AI security, GRC, vendor risk, DevSecOps, IAM, OT/IoT, SecOps, MLOps), and the post-2026-05-28
additions: Climate/ESG · Supply Chain · FinOps · Observability · Identity (+18) plus DevOps/PlatformEng/ChaosEng
(+50). The "every deploy enters universe" rule was a v2 strategy invariant — measured properties grew with
the portfolio, not behind it.
data/issue-4-v04-full.json
(899 domains, same publisher set). The latest snapshot at
data/baseline-2026-05-28.json
(1,007 domains at crawl time) reported one publishing domain and a 0.10% publication rate.
The June 1 editorial universe list had 2,005 domains, but this page links no full crawl
of that expanded set and therefore establishes no publication rate for it. The intended
later comparison was against the locked 899-domain baseline; this page does not establish
that the August run occurred.
The discriminator — what the false positive looks like, after the fix
Issue #4 flagged corporate.charter.com as a 82/100 publisher. It wasn't — the site is
built with Gatsby, and its catch-all returns the 404 page-context payload as application/json
for any /.well-known/* path. Engine v0.4 (commit
5892d88)
then required each of the eleven probed paths to carry its canonical *_version field —
the minimal Suite-spec shape, not just "valid JSON". Re-probed live, corporate.charter.com
dropped 82 → 0; kineticgain.com held 100/100 on that presence/discriminator score,
which was not a schema-conformance score. The instrument then distinguished a
Suite document from a SPA's internal page-rendering context.
| Spec | Path | Discriminator (v0.4) |
|---|---|---|
| AEO | /.well-known/aeo.json | aeo_version |
| Agent Card | /.well-known/agents/index.json | agent_card_version |
| Prompt Provenance | /.well-known/prompts/index.json | provenance_version |
| Evidence Bundle | /.well-known/evidence/index.json | evidence_version |
| MCP Tool Card | /.well-known/tool-cards/index.json | tool_card_version |
| Tutor Card | /.well-known/tutor-cards/index.json | tutor_card_version |
| Student-AI Disclosure | /.well-known/student-ai-disclosure.json | disclosure_version |
| Classroom AUP | /.well-known/classroom-aup.json | aup_version |
| Clinical AI Card | /.well-known/clinical-ai-cards/index.json | clinical_ai_card_version |
| Incident Card | /.well-known/incident-cards/index.json | incident_card_version |
| Decision Card | /.well-known/decision-cards/index.json | decision_card_version |
application/json, and any "valid JSON of the wrong shape" response.
What this still doesn't catch: a vendor that hand-crafts a JSON file with the right discriminator
field but otherwise empty payload. That would be intentional misrepresentation, not a SPA artifact —
a different problem, and the publishable evidence already includes the full document for inspection.
The first reported signature-verified row
The May 2026 engine run reported closing the Issue #1 signature-check commitment.
It reported that kineticgain.com's eleven dogfooded /.well-known/ documents were signed
against a public key published at
kineticgain.com/.well-known/pulse-signing.json.
The dated engine probe reported { verified: 11, unsigned: 0, invalid: 0 } on the dogfood row.
That field describes signatures, not schema conformance.
The eleven probed documents under kineticgain.com/.well-known/
were reported signed with the same ed25519 keypair. The signature covered the canonical serialization of each
document with the signature block recursively removed and remaining keys sorted.
By default the engine trusts the embedded public_key (tamper-evident).
With --verify-key-fetch it instead fetches the key from signing_key_url
(provenance). Both checks passed on the dated dogfood row. The probe pattern mirrors
hash-attestation-rs.
For any future vendor that signs their Suite docs and publishes a key, the engine will roll the
verification state up into signatures.verifiedRate on a later issue dataset.
This page does not establish that the planned August read was published.
Archived plan for Issue #5 (August 2026)
The following was the original comparison plan, preserved as a historical record. Issue #5 is not published on this site, so these are intended checks rather than results.
The August quarterly delta is the first time the Pulse runs against a calibrated instrument. Issue #1 was the zero-baseline calibration; Issues #2 and #3 expanded and stress-tested it; Issue #4 published the first universe-scale finding alongside the false-positive that shaped the v0.4 fix. Issue #5 has nothing left to calibrate — its only job is to measure the field's movement (or lack of it) across three months of buyer pressure and vendor reaction.
- Same universe, recrawled. No editorial pivots between now and August. Numbers move because vendors move, not because the lens did.
- The publication rate — the locked 899-domain crawl reported
1 / 899 (0.11%); the May 28 1,007-domain crawl reported1 / 1,007 (0.10%). A 2,005-domain publication rate cannot be inferred without a crawl of that expanded universe. - The verification rate is reported separately. If even one new domain joins
kineticgain.comin theverifiedcolumn, that's a structural shift, not noise. - The drift artifact (
data/issue-5-drift.json) will surface every per-domain change: newly publishing, stopped publishing, score and per-spec changes. Reproducible, not editorial.
Archived pre-registration plan for August 2026
These were the planned constraints. This page does not verify that the August crawl ran:
- Crawl date: the first weekday on or after 2026-08-15.
- Universe: whatever
universe.csvcontains at crawl time on themainbranch ofprocurement-pulse-engine. The "every deploy enters universe" rule keeps this honest — surfaces are added when they ship, not chosen to flatter the numbers. - Engine: v0.4 or whatever
maincarries — any further engine changes between now and August will be disclosed in the issue itself, alongside the v0.4 baseline for comparison. - Drift report: generated against
data/issue-4-v04-full.json(this baseline). The drift JSON ships in the issue folder.