Company access isolation
Strict authenticated portfolio-company tests passed 36 of 36 checked surfaces, with no failed or inconclusive surface and no rows returned from another company.
Procurement and technical review
A dated index of checked-in product controls and production evidence for buyer and procurement review. It is not continuous monitoring, an external audit, a penetration test or a certification.
Review as of 2026-09-03
Schema 2.0 | release evidence deployment:dpl_AiaLsuHbGUVH3tQDVFyDBpJVLMfy
Product controls
Each statement is bounded to a dated source file below. "Verified" means the named checked-in test passed; it does not mean independently certified.
Strict authenticated portfolio-company tests passed 36 of 36 checked surfaces, with no failed or inconclusive surface and no rows returned from another company.
The adversarial campaign passed 34 of 34 journeys across five investment and operating personas. The P1/P2 release then passed the expanded desktop, mobile, accessibility and runtime production route set.
The break campaign calculated eight supported cases and refused eight unsupported cases without adoption or source mutation. The loss-making and optimistic-assumption mutation journeys also passed on the P1/P2 production release.
Lint, typecheck and the production build passed with 925 deterministic tests and one intentional opt-in live skip. Production presentation, reporting and P1/P2 journeys passed; all 19 registered presentation formats passed desktop, mobile and accessibility checks.
The production recovery snapshot covers 87 tables, 293,061 rows, 38 Auth identities and 217 checksum-verified evidence objects, with no unavailable table.
Verification evidence
Use these repository files and checksums to confirm the evidence recorded for this review.
36/36 surfaces passed; 0 failed; 0 inconclusive
Authenticated Portfolio CEO and Portfolio CFO access for separate sample companies was checked across 36 named database surfaces with internal control comparisons.
test-evidence/company-isolation-2026-09-03.json
SHA256 94FFE5FA29E5F4F08DEFD5E788D32DA5F8A1E4A8FFC95BA620CA667F3B6050F4
34/34 production browser journeys passed across five personas
Fund Leadership / IC, Deal Lead, Operating Partner, Fund Finance and Portfolio CFO, including ten adversarial Lighthouse challenges and a targeted Operating Partner judgement rerun.
docs/reviews/adversarial-persona-uat-2026-08-28.md
SHA256 8D29D1FAAF4DA870664154C0E56A37E465058C4AE93F343EF15D136678D576E2
8 supported cases calculated; 8 unsupported cases refused
Four production sample companies, deterministic and boundary cases, refusal before persistence where required, no adoption, cleanup and source-fingerprint comparison.
test-evidence/scenario-break-campaign-2026-08-26.md
SHA256 1EB385EC749AAB8C431DDD8E38ADE01DC03A92CA0AA226CC3E1684521EAAF0DB
925 deterministic tests passed; production P1/P2, full UAT, reporting and 19/19 presentation checks passed
Release evidence for concise presentation planning, flagship decisions, data states, working notes, talent, origination, exit evidence, retention holds, recovery and three paid grounded Lighthouse runs below the 45-second SLO.
docs/reviews/p1-p2-completion-2026-09-03.md
SHA256 C19E2E665DAA709453DBFEE7A88ABD9B18BB26FB4A48A602CEE05C30AEABBC65
87 tables; 293,061 rows; 38 Auth identities; 217 evidence objects; 0 unavailable tables
Privately retained production recovery archive. The repository contains a hash-pinned metadata receipt only; a separate release verifier checks the retained archive bytes and counts. Restoration still requires an isolated drill environment.
test-evidence/pe-recovery-snapshot-2026-09-03.json.gz
SHA256 E7F0783490CD8AAF8D3FC5C294AA09195D8C1B3AB1E83DE628AEE6A0A28469E0
Limitations and open items
Procurement evidence is useful only when its boundary is stated. These items remain part of buyer diligence.
These artifacts report specific runs dated 26 August to 3 September 2026. They establish the recorded release state, not continuous compliance or a later deployment.
This dossier makes no SOC 2, ISO 27001, regulatory-compliance, penetration-test or independent-audit claim. Contractual and regulatory requirements require separate buyer review.
The persona, scenario and presentation campaigns used the fictional product sample. A buyer should repeat material controls with its agreed roles, records and pilot configuration.
The five-second conclusion and 30-second basis/evidence study harness is complete, but no synthetic result is represented as human evidence. Acceptance requires the recorded real-practitioner trials.
Sub-processors and data handling
| Provider | Purpose | Data handling | Region / boundary |
|---|---|---|---|
| Vercel | Application hosting and delivery | Receives application requests and serves the deployed Lighthouse PE application. Buyer review should confirm the applicable hosting agreement and deployment configuration. | Deployment configuration subject to buyer review |
| Supabase | Postgres, authentication and private evidence-file storage | Stores application records, identities, audit history and private evidence objects under application and forced database access controls. | Sydney for the documented Lighthouse PE project |
| Anthropic | Model calls for Lighthouse | Receives the prompt and scoped record excerpts supplied for a Lighthouse request. Commercial terms, retention and buyer-specific restrictions require contractual review. | Provider processing location subject to contractual review |
Product access is authenticated and organisation/company scoped. The dated isolation artifact directly tests 36 database surfaces across two company-side roles.
Evidence downloads remain private and scoped. Issued LP-report versions cannot be changed, and active retention holds block disposal without changing the issued record.
Lighthouse sends scoped prompt context to Anthropic and persists the answer and citations. Audience-scoped working analysis is excluded from Lighthouse by default unless it is recorded as an eligible record.
The public sample and evidence campaigns named here use fictional sample entities; they do not contain buyer records.
Run the checks
Check the source files and their checksums, then arrange environment-dependent tests against an agreed review environment.
Review deployment dpl_AiaLsuHbGUVH3tQDVFyDBpJVLMfy and retain this dossier with every named source artifact. The health source commit is contextual metadata, not a substitute for the deployment identity.
Calculate SHA-256 over the raw bytes of each sourcePath and compare with verificationEvidence[].sha256. The recovery archive is private: deterministic tests check its receipt, while the release verifier requires the retained archive and checks its original digest and contents.
npm run pe:verify-trust-recoveryRead each source artifact rather than relying on its headline. Confirm environment, sample identities, failures, skipped cases, cleanup and stated limitations.
In an isolated review checkout, run the repository release checks. A new run is new evidence and must be dated separately from this dossier.
npm run lint && npm run typecheck && npm test && npm run buildArrange a working session to rerun company isolation, persona journeys, scenario boundaries and recovery restoration against the agreed review environment.
Working-session review
Bring the buyer's DDQ, role model and pilot constraints. Open items remain open until they are contractually or technically resolved.