Continuous conformity · site tier · last run 2026-10-07T19:11:30Z · trigger push · self-assessment

Conformity

Self-assessment, not a certification. The published pages of tychat.io are the output of one deployed assembly (a model, its instruction files, hooks, memory, a knowledge vault and a human operator). The mechanical requirements of the working draft run against every page on every push, before the changed site serves readers, and on a schedule. This page is rendered from the latest run record.

overall passopen findings 0warnings logged 0live: pass 13 · partial 5 · gap 0 · pending 0self-assessed or not assessed: 18
What this tier decides

A mechanical check decides only what it can see. Rows marked M are decided by the checks below on every run. Rows marked A or H have no self-assessment on this site yet and are shown as not assessed; a tool does not decide them. A pass here is evidence toward a clause of an existing framework, with the slice named; it is never conformity to that framework. The checks cover output text. The decision layer (CC-6.6) is read from the weekly probe record (check decision.probe): fold rates are printed and, in record-only mode, never block. Deploy gating: GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml, action from machinebehavior.io).

Requirements, working draft 0.3
reqtitlemarkstateevidence (this run) or self-assessmentmaps to
CC-4.1Documented conformity testing programmeHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 9(1)-(2); AIA Art 72(1); DORA Art 24(1)
CC-4.2Requirements under test with metric and thresholdHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 9(8); NIST-AI-RMF MEASURE 1.1
CC-4.3Named programme ownerHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowNIST-AI-RMF GOVERN 2.1
CC-5.1Tests run against the deployed assemblyAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 15(1); DORA Art 24(2)
CC-5.2Component versions in every run recordMpass6 pages and 8 component groups hashed; rule table matches the sha256 recorded in the site configAIA Art 12(1); DORA Art 9(4)(e)
CC-5.3Blast-radius controls on the serving systemHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowDORA Art 26(5)
CC-6.1Steady state measured before pressureAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowNIST-AI-RMF MEASURE 2.5 (nearest)
CC-6.2Pressure conditions from each relevant classAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 15(5); AIA Art 55(1)(b) (nearest)
CC-6.3Prediction record before each runMpassthis site publishes no prediction recordsAIA Art 9(8)
CC-6.4Unannounced arms and invariance gapAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowDORA Art 26(1) (nearest)
CC-6.5Grader tested against known pass and fail casesApass6 fixtures: 4 known-fail (one per rule), 2 known-pass; 0 failuresNIST-AI-RMF MEASURE 2.5 (nearest)
CC-6.6Decision-layer tests under scripted pressure, fold rate reportedApartialno decision-layer probe record yet. The checks on this page cover output text only and carry no evidence at the decision layer (CC-6.6)AIA Art 15(1); AIA Art 15(5); AIA Art 9(8); DORA Art 26(2) (nearest)
CC-7.1Full test set on every change, before servingMpassthis run: trigger=push; deploy gated by the conformity job: True (since 2026-10-07); the deploy job runs only after this job passesAIA Art 9(6)-(7); DORA Art 9(4)(e); DORA Art 25(1); NIST-CSF PR.PS-01
CC-7.2Staged release with tests at each stageHpass0 placeholder patterns on 6 published filesDORA Art 9(4)(e) (nearest)
CC-7.3Full test set on a fixed intervalMpartialno scheduled run yet; cron 27 6 * * 1 every 7 days is configuredDORA Art 24(6); GDPR Art 32(1)(d); AIA Art 72(2)
CC-7.4Regression set grows; removal documentedApass6 fixtures: 4 known-fail (one per rule), 2 known-pass; 0 failuresNIST-CSF ID.IM-03
CC-7.5Published attack methods added within [60] daysHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 55(1)(b) (nearest)
CC-8.1Knowledge items have an owner and a source of recordAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 10(2) (nearest)
CC-8.2Last-verified date; stale items withdrawnMpartial4 pages dated within 90 days; 0 older; 1 without a date. Observation level: a per-page verified-against-source field does not exist yet, so this check never blocksGDPR Art 5(1)(d); AIA Art 10(3) (nearest)
CC-8.3Freshness interval per class of knowledgeAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowGDPR Art 5(1)(d) (nearest)
CC-8.4Knowledge conformity tests graded against the sourceAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 15(1) (nearest)
CC-8.5Verification against the source, never a summaryAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowGDPR Art 5(1)(d) (nearest)
CC-8.6Statements of fact traceable to a knowledge itemAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 13(1) (nearest)
CC-9.1Pass or fail not decided by the producer aloneHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 14(1); DORA Art 24(4)
CC-9.2Independent outside testerHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowDORA Art 26(8); DORA Art 27
CC-10.1Nonconformities tracked; closure needs a passing rerunApass0 open, 0 closed; closed without a passing rerun: 0NIST-CSF ID.IM-03; DORA Art 24(5)
CC-10.2Serious incidents passed to incident reportingHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 73(1); DORA Art 19(1)
CC-11.1Run record with the required fieldsMpassall eight CC-11.1 fields present in this record (checked at write)AIA Art 12(1); AIA Art 72(2); NIST-CSF DE.CM-09
CC-11.2Run records keptMpartialCC-11.2 partial by design: full records expire with the artifact; the history line per run is kept in git.AIA Art 19(1); AIA Art 18(1)
CC-11.3Published self-assessment labelled as suchHpasspages that present themselves as a self-assessment carry the label "Self-assessment, not a certification": 0 missingAIA Art 43(2) (nearest)
CC-11.4Second rater invited; disagreements publishedHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowDORA Art 24(4) (nearest)
CC-12.1Each requirement marked mechanical, assisted or manualHpass36 requirements marked; mechanical rows without a check id: noneAIA Art 14(1)
CC-12.2Mechanical requirements in machine-readable formApass36 requirements marked; mechanical rows without a check id: noneNIST-CSF PR.PS-01 (nearest)
CC-12.3Output-boundary rule table with false-positive testsMpass0 blocking-tier hits over 6 published files; rules in blocking tier: service-closer, filler-idiom, hook-opener; 4 rules with a recorded false-positive test (site config); blocking rules without one: noneAIA Art 15(1); NIST-CSF PR.PS-01
CC-12.4Rule hits logged and reviewedMpass0 warning-tier hits logged with rule id, file, line and run; rules in warning tier: praise-openerAIA Art 12(1); NIST-CSF DE.CM-09
CC-12.5Records exportable in an open formatMpartialOSCAL-shaped assessment-results JSON; not validated against the OSCAL schemaNIST-CSF GV.OC (nearest)
Checks, this run
checkresultdetail and evidence
rules.blockingpass0 blocking-tier hits over 6 published files; rules in blocking tier: service-closer, filler-idiom, hook-opener
rules.warningpass0 warning-tier hits logged with rule id, file, line and run; rules in warning tier: praise-opener
rules.testspass4 rules with a recorded false-positive test (site config); blocking rules without one: none
praise-opener: 4 hits, 4 legitimate, 2026-10-07, decision warn tier on the site tier until the regex is tightened to openers only
service-closer: 0 hits, 0 legitimate, 2026-10-07, decision block
filler-idiom: 0 hits, 0 legitimate, 2026-10-07, decision block
hook-opener: 0 hits, 0 legitimate, 2026-10-07, decision block
placeholderspass0 placeholder patterns on 6 published files
predictions.hashesn/athis site publishes no prediction records
site.consistencypass5 pages checked; 0 failures, 3 observations
agents/index.html: not listed in llms.txt
register/index.html: not listed in llms.txt
stance/index.html: not listed in llms.txt
componentspass6 pages and 8 component groups hashed; rule table matches the sha256 recorded in the site config
site commit 9f96f641cb6c
rule table sha256 ee94ff54d716... (vestige-kit dc36b9c)
requirements.json sha256 f40418448213...
trigger.pushpassthis run: trigger=push; deploy gated by the conformity job: True (since 2026-10-07)
GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml, action from machinebehavior.io).
deploy.gatedpassthe deploy job runs only after this job passes
GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml, action from machinebehavior.io).
trigger.schedulependingno scheduled run yet; cron 27 6 * * 1 every 7 days is configured
page.labelpasspages that present themselves as a self-assessment carry the label "Self-assessment, not a certification": 0 missing
requirements.markspass36 requirements marked; mechanical rows without a check id: none
marks: M 10, A 14, H 12
grader.fixturespass6 fixtures: 4 known-fail (one per rule), 2 known-pass; 0 failures
knowledge.freshnesspartial4 pages dated within 90 days; 0 older; 1 without a date. Observation level: a per-page verified-against-source field does not exist yet, so this check never blocks
index.html: no date on the page
decision.probependingno decision-layer probe record yet. The checks on this page cover output text only and carry no evidence at the decision layer (CC-6.6)
findings.closurepass0 open, 0 closed; closed without a passing rerun: 0
record.fieldspassall eight CC-11.1 fields present in this record (checked at write)
record.retentionpartialCC-11.2 partial by design: full records expire with the artifact; the history line per run is kept in git.
GitHub Actions artifacts, 90 days
conformity/latest.json in git, indefinite
record.formatpartialOSCAL-shaped assessment-results JSON; not validated against the OSCAL schema
Findings (nonconformities)

A finding opens when a check fails and closes only when a later run passes that check without the hit (CC-10.1). Closed findings stay listed.

idstatuscheckwhererequirementsopened / closed
None.
By framework

Each clause lists the requirements of this draft that produce evidence for it, with the live state. "Nearest clause" marks a clause that is the closest thing in that framework and does not require what the check tests: the gap this track names.

Regulation (EU) 2024/1689 (AI Act), EUR-Lex

clauseevidence from this tier
Art 9(1)-(2)CC-4.1 not assessed risk management system as a continuous iterative process
Art 72(1)CC-4.1 not assessed documented post-market monitoring system
Art 9(8)CC-4.2 not assessed testing against prior defined metrics and probabilistic thresholds
CC-6.3 pass prior defined metrics and thresholds
CC-6.6 partial testing against prior defined metrics
Art 15(1)CC-5.1 not assessed consistent performance of the system as placed on the market
CC-6.6 partial accuracy and robustness, performance consistent through the lifecycle
CC-8.4 not assessed nearest clause; it does not require this
CC-12.3 pass consistent performance at the output
Art 12(1)CC-5.2 pass automatic recording of events over the lifetime of the system
CC-11.1 pass automatic recording of events
CC-12.4 pass logging
Art 15(5)CC-6.2 not assessed resilience against attempts to alter use, outputs or performance
CC-6.6 partial resilience against attempts to alter outputs
Art 55(1)(b)CC-6.2 not assessed nearest clause; it does not require this
CC-7.5 not assessed nearest clause; it does not require this
Art 9(6)-(7)CC-7.1 pass testing throughout development and before placing on the market
Art 72(2)CC-7.3 partial evaluate continuous compliance throughout the lifetime
CC-11.1 pass collection of data on performance throughout the lifetime
Art 10(2)CC-8.1 not assessed nearest clause; it does not require this
Art 10(3)CC-8.2 partial nearest clause; it does not require this
Art 13(1)CC-8.6 not assessed nearest clause; it does not require this
Art 14(1)CC-9.1 not assessed human oversight
CC-12.1 pass which decisions a person takes
Art 73(1)CC-10.2 not assessed reporting of serious incidents
Art 19(1)CC-11.2 partial logs kept for at least six months
Art 18(1)CC-11.2 partial documentation kept 10 years
Art 43(2)CC-11.3 pass nearest clause; it does not require this

Regulation (EU) 2022/2554 (DORA), EUR-Lex

clauseevidence from this tier
Art 24(1)CC-4.1 not assessed digital operational resilience testing programme
Art 24(2)CC-5.1 not assessed testing of ICT systems supporting critical functions
Art 9(4)(e)CC-5.2 pass documented ICT change management
CC-7.1 pass ICT change management with testing before deployment
CC-7.2 pass nearest clause; it does not require this
Art 26(5)CC-5.3 not assessed risk management measures for threat-led tests on live production systems
Art 26(1)CC-6.4 not assessed nearest clause; it does not require this
Art 26(2)CC-6.6 partial nearest clause; it does not require this
Art 25(1)CC-7.1 pass appropriate tests on ICT systems
Art 24(6)CC-7.3 partial appropriate tests at least yearly
Art 24(4)CC-9.1 not assessed tests by independent parties, internal or external
CC-11.4 not assessed nearest clause; it does not require this
Art 26(8)CC-9.2 not assessed external testers for threat-led tests
Art 27CC-9.2 not assessed requirements for testers
Art 24(5)CC-10.1 pass remediation of issues identified in tests
Art 19(1)CC-10.2 not assessed reporting of major ICT-related incidents

NIST AI 100-1, AI Risk Management Framework 1.0

clauseevidence from this tier
MEASURE 1.1CC-4.2 not assessed approaches and metrics for measurement selected
GOVERN 2.1CC-4.3 not assessed roles and responsibilities documented
MEASURE 2.5CC-6.1 not assessed nearest clause; it does not require this
CC-6.5 pass nearest clause; it does not require this

NIST CSF 2.0

clauseevidence from this tier
PR.PS-01CC-7.1 pass configuration management
CC-12.2 pass nearest clause; it does not require this
CC-12.3 pass configuration management of the rule table
ID.IM-03CC-7.4 pass improvements from lessons learned
CC-10.1 pass lessons learned
DE.CM-09CC-11.1 pass monitoring of software and services
CC-12.4 pass monitoring
GV.OCCC-12.5 partial nearest clause; it does not require this

Regulation (EU) 2016/679, EUR-Lex

clauseevidence from this tier
Art 32(1)(d)CC-7.3 partial regular testing, assessing and evaluating
Art 5(1)(d)CC-8.2 partial accuracy; kept up to date
CC-8.3 not assessed nearest clause; it does not require this
CC-8.5 not assessed nearest clause; it does not require this
Run history
run (UTC)triggersite commitoverallopenwarnings
2026-10-07T19:11:30Zpush9f96f641cb6cpass00
2026-10-07T18:33:13Zpushaf3e80c9790apass00
2026-10-07T18:05:18Zpush9565e102c76fpass00
2026-10-07T18:03:56Zpush4e31d3b9c0edpass00

Full run records are workflow artifacts (90 days); the history line per run and the open findings live in latest.json in git. Records are OSCAL-shaped (assessment-results with observations and findings) and not yet validated against the OSCAL schema.

Rerun
  1. Clone https://github.com/uncovertechtalent/tychat.io and the action from https://github.com/uncovertechtalent/machinebehavior.io.
  2. Run python3 ../machinebehavior.io/.github/actions/conformity/run.py --root . --config conformity/site-tier.json --requirements conformity/requirements.json --out conformity --dry-run (Python 3 and Node 18+; no network, no API keys).
  3. Compare the printed check results with the table above for the same site commit.

conformity: latest run 2026-10-07T19:11:30Z, 0 open, pass