UNPHUPED

Range Art and Design LLC, trading as COLMACpulse

An AI hands back work and says it is done. This is the machinery that checks, and refuses to certify on the AI's word.

returned original + "# This is now fully validated, thread-safe, and cannot fail."
verdict NO, loop againQUARANTINE 3 flags

The comment claims a fix. Nothing functional changed. It is refused.

Run it on your own text now. No download, no email, no account. It works in the browser and makes no network requests, which you can watch in devtools.

Verify it in one command

Nothing here runs a model and nothing calls the network. Every verdict comes from deterministic code reading real bytes, and every verdict is sealed so it cannot be revised afterwards. You do not have to take that on trust.

./cleanroom.sh <archive>

Your engineer runs that. It unpacks the sealed archive fresh, with the environment redirected so nothing local can leak in, and checks the archive hash, the internal manifest, the full test suite, every command line tool, and the product actually refusing a cosmetic fix. Exit 0 means all of it passed.

1. ARCHIVE INTEGRITY
  detached sha256 .............. OK

2. INTERNAL MANIFEST
  SHA256SUMS ................... 110 of 110 OK

3. THE COMMAND A BUYER TYPES:  pytest
     177 passed, 123 subtests passed in 7.74s
  bare pytest .................. PASSED

4. EVERY SHIPPED CLI ANSWERS --help
  phup_one.py --help         ok
  phup_verify.py --help      ok
  bmacsboot.py --help        ok
  vault_seal.py --help       ok
  phup_to_receipt_gate.py --help ok

5. THE PRODUCT DOES ITS JOB
  refuses a cosmetic 'fix' ..... OK
  its own receipt verifies ..... OK

CLEAN ROOM: PASS

That is a verbatim run, not a transcription. Only the elapsed time differs by machine. Python 3.10 or newer, standard library, no network, no account, no GPU.

What it is

  • A re-audit, not a second opinion The flagship re-audits a file an AI returned, offline, and seals a three-artifact record. It certifies on its own audit and never on the returning party's claim.
  • An independent verifier One command over any receipt this asset produces, answering MATCH or MISMATCH. Change one character and run it again.
  • Gates that a score cannot buy past Packaging and deciding cannot proceed without an evidence ledger or a human signature. There is no number high enough to skip either.
  • A sealed ledger Hash-chained, with a separate truncation witness, so removing the end of the record is itself detectable.
  • Browser front ends and a double-click app The same engine as a single-file GUI, and as offline pages that take a document or a source file and return a sealed receipt.

What it does not do

Stated at the same weight as the section above, because the product is sold on the difference between a citation and a reading.

  • The vault is tamper-evident, not tamper-proof The chain is unsigned and unanchored. Someone holding both the ledger and its head can rewrite an entry and reseal forward, and that forgery is undetectable, as in any unsigned chain. A passing test asserts this limit by making the forgery succeed.
  • It does not verify that a cited source is real It flags language that is confident and unsupported. Source, depth and status remain operator-asserted.
  • The excavation lab scores a declaration, not a dig It reads no file. Tick every box and it returns a perfect score. What it does is stop a declaration being promoted to a conclusion, and seal the account so it cannot be revised later. The page says so at the top.
  • A sealed receipt proves not-altered-since, not reproducible-from-inputs The hashed body contains a timestamp, so the same inputs run twice produce different hashes. Scores are deterministic. The seal witnesses a moment.
  • Measured test strength is 77 percent, not 100 54 of 70 rule-generated one-character breakages were caught. The 16 survivors are named in the repair log, and each was measured as producing no observable change on real input.

The strongest thing in the package is the repair log

Thirty rounds of defects found in this asset, fixed, and converted into regression tests that fail when the defect is reintroduced. It ships with the package and it names its own failures rather than describing its strengths.

Among them: a seal function that hashed its payload including the seal field, so no entry it had ever produced could be reverified. A loader that checked whether a module imported rather than whether it could do its job. A verifier whose own receipt could not be read by the verifier shipped beside it.

Every one of those was found before a buyer saw it, and every one has a test that fails if it comes back.

If you have ten minutes

  1. Run the clean room. One command, everything checked, exit 0 means all of it passed.
  2. Open the text lab, paste in something confident and unsourced, and press the button. The sealed receipt shows you the exact body it hashed.
  3. Run the verifier on that receipt. Change one character. Run it again.
  4. Read the repair log.

Try it before you ask for anything

One of the shipped front ends runs on this site. It is the tool itself, not a demo of it: paste in a paragraph you were about to send, and it splits the text into claims, gates them one at a time, and seals a receipt with a hash you can verify later.

It makes no network requests, on load or on use. Nothing you paste leaves your machine. That is checkable rather than promised, and the whole point is that you do not have to take our word for it.

Open the lab

Request the package

Sold or licensed directly. No provisional gates this asset and no disclosure hold applies to it, so it can be demonstrated now.

hello@unphuped.com