Release digest
Improved
- AUDIT-SCOPE-READINESS-OFFER (Commercial Surface) — Replaced the generic Security Readiness private-pilot positioning with one commit-bound Audit Scope Readiness Sprint at 750 USDC, 72 business hours, public EVM repositories only, explicit refund terms, deliverables, exclusions, and non-audit limits.
- AUDIT-SCOPE-MANUAL-CONTRACT (Product Contract) — Added the manual
audit_scope_readiness.v1artifact validator with source/timestamp rules and no automated scoring or security verdict. - AUDIT-SCOPE-QUALIFICATION-INTAKE (Pilot Operations) — Added pinned commit,
chain, review target/deadline, recipient, and payment-owner fields plus an
unapplied migration that reasserts the
receivedstatus default. - AUDIT-SCOPE-COMMIT-BOUND-SAMPLE (Buyer Evidence) — Pinned the public PDF, YAML, and JSON sample pack to the synthetic Foundry demo fixture and its exact repository commit so every sample statement can be traced to source.
- AUDIT-SCOPE-LEGACY-CONTACT-BRIDGE (Launch Operations) — Temporarily route public pilot mail through the founder-confirmed legacy Google Workspace alias until the new-domain mailbox is created and tested; move the Permit S gate to before payment acceptance or paid delivery rather than public deployment.
Internal
- Updated the canonical architecture, active sprint, Q3 roadmap, public guide, privacy notice, launch gate, and internal revenue protocol. Legacy pricing and outreach runbooks are explicitly superseded.
- Added contract coverage for manual artifacts, prohibited commercial claims, exact offer terms, commit-bound sample semantics, qualification intake, and production-migration gating.
- Kept the domain-migration guard strict while allowlisting only the exact test assertion for the temporary legacy Workspace contact route.