BETWEEN ISSUES · MAY 2026 · THE VERIFIED BASELINE

The dated v0.4 baseline.

By this May–June 2026 baseline, the engine had gained a per-spec discriminator that addressed the Gatsby-SPA-catchall false-positive class. The engine reported ed25519 signature verification for eleven dogfooded kineticgain.com documents at that time. The linked May 28 crawl artifact covered 1,007 domains; the separate editorial universe count was 2,005 by June 1, without a linked full crawl of that expanded set. This page records the intended baseline for Issue #5; that issue is not published here.

Editorial note, October 2026: “Verified” on this historical page refers to the reported signature check, not schema validity. A separate September 12 estate audit found 0 of 11 sampled documents valid against their own schemas. This page has not rechecked the current documents.

The baseline numbers, locked in

The locked 899-domain crawl is in procurement-pulse-engine/data/issue-4-v04-full.json. The numbers below come from the later baseline-2026-05-28.json crawl of 1,007 domains. Both are dated engine readings, not a present-day measurement.

1,007
domains in May 28 crawl artifact
1
domains publishing (real)
0.10%
aggregate publication rate
11 / 11
May 2026 KG signature checks reported (ed25519)
100
May presence score, not schema validity
0
false positives (was: 1 in Issue #4)
Why the editorial universe count moved. Issue #4 published with 834 domains. The later universe list was at 2,005 domains across 30+ verticals as of 2026-06-01 — an editorial expansion, not a corresponding published full crawl: Forbes AI 50 net-new (28), hand-picked HealthTech AI (18), hand-picked K-12 EdTech (12), every .kineticgain.com operator-surface CNAME the portfolio deployed (then 60+), a CISO procurement pack (64 domains across AI security, GRC, vendor risk, DevSecOps, IAM, OT/IoT, SecOps, MLOps), and the post-2026-05-28 additions: Climate/ESG · Supply Chain · FinOps · Observability · Identity (+18) plus DevOps/PlatformEng/ChaosEng (+50). The "every deploy enters universe" rule was a v2 strategy invariant — measured properties grew with the portfolio, not behind it.
Two baseline artifacts, two purposes. The locked-in baseline for the planned Issue #5 drift report was data/issue-4-v04-full.json (899 domains, same publisher set). The latest snapshot at data/baseline-2026-05-28.json (1,007 domains at crawl time) reported one publishing domain and a 0.10% publication rate. The June 1 editorial universe list had 2,005 domains, but this page links no full crawl of that expanded set and therefore establishes no publication rate for it. The intended later comparison was against the locked 899-domain baseline; this page does not establish that the August run occurred.

The discriminator — what the false positive looks like, after the fix

Issue #4 flagged corporate.charter.com as a 82/100 publisher. It wasn't — the site is built with Gatsby, and its catch-all returns the 404 page-context payload as application/json for any /.well-known/* path. Engine v0.4 (commit 5892d88) then required each of the eleven probed paths to carry its canonical *_version field — the minimal Suite-spec shape, not just "valid JSON". Re-probed live, corporate.charter.com dropped 82 → 0; kineticgain.com held 100/100 on that presence/discriminator score, which was not a schema-conformance score. The instrument then distinguished a Suite document from a SPA's internal page-rendering context.

SpecPathDiscriminator (v0.4)
AEO/.well-known/aeo.jsonaeo_version
Agent Card/.well-known/agents/index.jsonagent_card_version
Prompt Provenance/.well-known/prompts/index.jsonprovenance_version
Evidence Bundle/.well-known/evidence/index.jsonevidence_version
MCP Tool Card/.well-known/tool-cards/index.jsontool_card_version
Tutor Card/.well-known/tutor-cards/index.jsontutor_card_version
Student-AI Disclosure/.well-known/student-ai-disclosure.jsondisclosure_version
Classroom AUP/.well-known/classroom-aup.jsonaup_version
Clinical AI Card/.well-known/clinical-ai-cards/index.jsonclinical_ai_card_version
Incident Card/.well-known/incident-cards/index.jsonincident_card_version
Decision Card/.well-known/decision-cards/index.jsondecision_card_version
What this catches. Gatsby/Next.js/CRA catch-alls, generic 404-page JSON, CDN error pages dressed as application/json, and any "valid JSON of the wrong shape" response. What this still doesn't catch: a vendor that hand-crafts a JSON file with the right discriminator field but otherwise empty payload. That would be intentional misrepresentation, not a SPA artifact — a different problem, and the publishable evidence already includes the full document for inspection.

The first reported signature-verified row

The May 2026 engine run reported closing the Issue #1 signature-check commitment. It reported that kineticgain.com's eleven dogfooded /.well-known/ documents were signed against a public key published at kineticgain.com/.well-known/pulse-signing.json. The dated engine probe reported { verified: 11, unsigned: 0, invalid: 0 } on the dogfood row. That field describes signatures, not schema conformance.

May 2026 signature result · kineticgain.com

The eleven probed documents under kineticgain.com/.well-known/ were reported signed with the same ed25519 keypair. The signature covered the canonical serialization of each document with the signature block recursively removed and remaining keys sorted.

By default the engine trusts the embedded public_key (tamper-evident). With --verify-key-fetch it instead fetches the key from signing_key_url (provenance). Both checks passed on the dated dogfood row. The probe pattern mirrors hash-attestation-rs.

For any future vendor that signs their Suite docs and publishes a key, the engine will roll the verification state up into signatures.verifiedRate on a later issue dataset. This page does not establish that the planned August read was published.

Archived plan for Issue #5 (August 2026)

The following was the original comparison plan, preserved as a historical record. Issue #5 is not published on this site, so these are intended checks rather than results.

The August quarterly delta is the first time the Pulse runs against a calibrated instrument. Issue #1 was the zero-baseline calibration; Issues #2 and #3 expanded and stress-tested it; Issue #4 published the first universe-scale finding alongside the false-positive that shaped the v0.4 fix. Issue #5 has nothing left to calibrate — its only job is to measure the field's movement (or lack of it) across three months of buyer pressure and vendor reaction.

  • Same universe, recrawled. No editorial pivots between now and August. Numbers move because vendors move, not because the lens did.
  • The publication rate — the locked 899-domain crawl reported 1 / 899 (0.11%); the May 28 1,007-domain crawl reported 1 / 1,007 (0.10%). A 2,005-domain publication rate cannot be inferred without a crawl of that expanded universe.
  • The verification rate is reported separately. If even one new domain joins kineticgain.com in the verified column, that's a structural shift, not noise.
  • The drift artifact (data/issue-5-drift.json) will surface every per-domain change: newly publishing, stopped publishing, score and per-spec changes. Reproducible, not editorial.

Archived pre-registration plan for August 2026

These were the planned constraints. This page does not verify that the August crawl ran:

  • Crawl date: the first weekday on or after 2026-08-15.
  • Universe: whatever universe.csv contains at crawl time on the main branch of procurement-pulse-engine. The "every deploy enters universe" rule keeps this honest — surfaces are added when they ship, not chosen to flatter the numbers.
  • Engine: v0.4 or whatever main carries — any further engine changes between now and August will be disclosed in the issue itself, alongside the v0.4 baseline for comparison.
  • Drift report: generated against data/issue-4-v04-full.json (this baseline). The drift JSON ships in the issue folder.
Why pre-register? A buyer-readable governance instrument loses its credibility the first time it's seen to move its goalposts mid-quarter. The Pulse is a public-edition measurement — there is no internal version. What ships in August is exactly what was promised in May.