{
  "standard": "Bounded Systems Web-Build Conformance Standard",
  "version": "1.0.0",
  "results": [
    {
      "id": "html.dom-author-requirements",
      "area": "html",
      "label": "HTML author requirements",
      "standard": "HTML Living Standard",
      "target": "DOM subtree meets HTML author requirements (valid semantics & structure).",
      "level": "author conformance",
      "evidence": "lone",
      "required": true,
      "loneCodes": [
        "LONE_SEMANTIC_"
      ],
      "status": "met",
      "detail": "lone static checks clean (no findings)",
      "findings": []
    },
    {
      "id": "html.validator-clean",
      "area": "html",
      "label": "Nu HTML Checker errors",
      "standard": "Nu Html Checker",
      "target": "Zero HTML validator (Nu) errors over the rendered page.",
      "level": "zero errors",
      "evidence": "external",
      "required": true,
      "status": "met",
      "detail": "0 validator errors"
    },
    {
      "id": "a11y.aria-author",
      "area": "accessibility",
      "label": "WAI-ARIA author requirements",
      "standard": "WAI-ARIA 1.2",
      "target": "Valid roles/states/properties/relationships; prefer native HTML semantics.",
      "level": "author conformance",
      "evidence": "lone",
      "required": true,
      "loneCodes": [
        "LONE_ARIA_"
      ],
      "status": "met",
      "detail": "lone static checks clean (no findings)",
      "findings": []
    },
    {
      "id": "a11y.wcag22-aa-auto",
      "area": "accessibility",
      "label": "WCAG 2.2 AA (automated subset)",
      "standard": "WCAG 2.2",
      "target": "Automatable WCAG 2.2 AA checks pass (names, text alternatives, contrast, keyboard, SR content).",
      "level": "AA (automated subset)",
      "evidence": "lone",
      "required": true,
      "loneCodes": [
        "LONE_NAME_",
        "LONE_TEXT_",
        "LONE_SR_",
        "LONE_KEYBOARD_",
        "LONE_COLOR_",
        "LONE_READER_"
      ],
      "status": "met",
      "detail": "lone static checks clean (no findings)",
      "findings": []
    },
    {
      "id": "a11y.axe-serious-critical",
      "area": "accessibility",
      "label": "axe serious/critical violations",
      "standard": "axe-core",
      "target": "Zero serious/critical accessibility violations on the rendered page.",
      "level": "serious/critical",
      "evidence": "external",
      "required": true,
      "status": "met",
      "detail": "0 serious/critical violations"
    },
    {
      "id": "a11y.wcag22-aa-manual",
      "area": "accessibility",
      "label": "WCAG 2.2 AA (manual audit)",
      "standard": "WCAG 2.2",
      "target": "Complete-flow manual audit incl. keyboard + screen-reader testing of critical flows.",
      "level": "AA (manual)",
      "evidence": "external",
      "required": true,
      "status": "not-assessed",
      "detail": "no manual WCAG 2.2 AA audit supplied"
    },
    {
      "id": "a11y.wcag22-aaa-selected",
      "area": "accessibility",
      "label": "WCAG 2.2 AAA (selected)",
      "standard": "WCAG 2.2",
      "target": "Selected AAA success criteria met.",
      "level": "AAA (selected)",
      "evidence": "external",
      "required": false,
      "status": "not-assessed",
      "detail": "no AAA attestation supplied (optional)"
    },
    {
      "id": "a11y.agent-heuristic-review",
      "area": "accessibility",
      "label": "Agent heuristic accessibility review",
      "standard": "ARIA/WCAG (machine heuristic)",
      "target": "Machine AT pass: ARIA landmarks, interactive names, heading hierarchy, image alts, skip-nav, tabindex sanity, inline focus-ring removal, invalid ARIA roles; [playwright runner] accessibility tree snapshot + axe corroboration. AGENT/STATIC HEURISTIC — NOT AT-user testing. a11y.wcag22-aa-manual stays not-assessed.",
      "level": "agent heuristic (recommended)",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "met",
      "detail": "agent heuristic pass clean — 7 page(s), 0 warning(s). AGENT/STATIC HEURISTIC — NOT AT-user testing; a11y.wcag22-aa-manual stays not-assessed."
    },
    {
      "id": "design.palette-contrast",
      "area": "design",
      "label": "Palette contrast (design tokens)",
      "standard": "WCAG 2.2 + APCA",
      "target": "Color-token pairings are CVD-safe, meet an APCA Lc baseline, and satisfy non-text contrast.",
      "level": "AA (token-level)",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "met",
      "detail": "color tokens CVD-safe, APCA baseline, non-text contrast ok"
    },
    {
      "id": "design.typography",
      "area": "design",
      "label": "Typography tokens",
      "standard": "WCAG 2.2",
      "target": "Type tokens give body line-height ≥ 1.5, achievable text spacing (1.4.12), a minimum font size, and legible weights.",
      "level": "AA (token-level)",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "met",
      "detail": "type tokens meet line-height, spacing, size, and weight bars"
    },
    {
      "id": "design.target-size",
      "area": "design",
      "label": "Target size (interactive tokens)",
      "standard": "WCAG 2.2",
      "target": "Interactive size tokens meet the SC 2.5.8 minimum target size (AA).",
      "level": "AA (token-level)",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "not-assessed",
      "detail": "no target-size report supplied"
    },
    {
      "id": "design.opacity-contrast",
      "area": "design",
      "label": "Effective contrast under opacity",
      "standard": "WCAG 2.2",
      "target": "Token opacity composited over its backdrop still meets SC 1.4.3/1.4.11 contrast.",
      "level": "AA (token-level)",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "not-assessed",
      "detail": "no opacity-contrast report supplied"
    },
    {
      "id": "design.token-likeness",
      "area": "design",
      "label": "Token likeness hygiene",
      "standard": "Design-system hygiene",
      "target": "Categorical tokens are perceptibly distinct and no near-duplicate (redundant) tokens collapse the system.",
      "level": "recommended",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "met",
      "detail": "categorical tokens distinct; no redundant tokens"
    },
    {
      "id": "security.asvs",
      "area": "security",
      "label": "OWASP ASVS Level 2",
      "standard": "OWASP ASVS 5.0.0",
      "target": "Verified to Level 2 (Level 3 for highly sensitive applications).",
      "level": "L2",
      "evidence": "external",
      "required": true,
      "status": "not-assessed",
      "detail": "no OWASP ASVS attestation supplied"
    },
    {
      "id": "security.no-critical-vulns",
      "area": "security",
      "label": "known critical/high vulns",
      "standard": "OWASP ASVS 5.0.0",
      "target": "Zero known critical/high exploitable vulnerabilities.",
      "level": "zero critical/high",
      "evidence": "external",
      "required": true,
      "status": "met",
      "detail": "0 known critical/high vulns"
    },
    {
      "id": "security.hsts-preload",
      "area": "security",
      "label": "HSTS preload",
      "standard": "RFC 6797 / hstspreload.org",
      "target": "Origin is on the HSTS preload list (HTTPS enforced before first byte).",
      "level": "preloaded",
      "evidence": "external",
      "required": false,
      "status": "not-assessed",
      "detail": "no HSTS preload status supplied"
    },
    {
      "id": "performance.core-web-vitals",
      "area": "performance",
      "label": "Core Web Vitals (p75)",
      "standard": "Core Web Vitals",
      "target": "LCP ≤ 2.5s, INP ≤ 200ms, CLS ≤ 0.1 at p75 on mobile AND desktop (field data).",
      "level": "p75 mobile + desktop",
      "evidence": "external",
      "required": true,
      "status": "not-assessed",
      "detail": "no Core Web Vitals field data supplied"
    },
    {
      "id": "compatibility.baseline",
      "area": "compatibility",
      "label": "Baseline Widely Available",
      "standard": "Baseline",
      "target": "Baseline Widely Available (interoperable ≥30 months), or a tested fallback for newer features.",
      "level": "Widely Available",
      "evidence": "external",
      "required": true,
      "status": "met",
      "detail": "Baseline Widely Available"
    },
    {
      "id": "reliability.runtime",
      "area": "reliability",
      "label": "runtime reliability",
      "standard": "Bounded Systems reliability bar",
      "target": "No uncaught browser errors; no broken internal links; critical journeys covered by e2e tests.",
      "level": "—",
      "evidence": "external",
      "required": true,
      "status": "not-assessed",
      "detail": "no runtime reliability report supplied"
    },
    {
      "id": "semantic.jsonld-shacl",
      "area": "semantic",
      "label": "JSON-LD 1.1 + SHACL conformance",
      "standard": "JSON-LD 1.1 / SHACL",
      "target": "Structured data parses as JSON-LD 1.1 and conforms to its SHACL shapes (zero violating blocks).",
      "level": "conforms",
      "evidence": "external",
      "required": true,
      "tier": 2,
      "status": "met",
      "detail": "JSON-LD 1.1 conforms to SHACL shapes (0 violating blocks)"
    },
    {
      "id": "seo.technical",
      "area": "seo",
      "label": "Technical SEO",
      "standard": "Search-engine technical guidelines / RFC 9309",
      "target": "Canonical URLs correct, titles unique, robots.txt RFC 9309-valid, sitemap resolves, zero broken internal links.",
      "level": "clean",
      "evidence": "external",
      "required": true,
      "tier": 2,
      "status": "met",
      "detail": "canonical/titles/robots/sitemap clean, 0 broken internal links"
    },
    {
      "id": "semantic.commonmark",
      "area": "semantic",
      "label": "CommonMark conformance",
      "standard": "CommonMark",
      "target": "Authored Markdown parses cleanly under the CommonMark spec.",
      "level": "conforms",
      "evidence": "external",
      "required": true,
      "tier": 2,
      "status": "not-assessed",
      "detail": "no CommonMark report supplied"
    },
    {
      "id": "semantic.ai-readability",
      "area": "semantic",
      "label": "AI-readability",
      "standard": "llms.txt convention",
      "target": "llms.txt present, its links resolve, and HTML pages expose Markdown siblings for machine consumption.",
      "level": "recommended",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "met",
      "detail": "llms.txt present, links resolve, Markdown siblings exposed"
    },
    {
      "id": "semantic.openapi",
      "area": "semantic",
      "label": "OpenAPI 3.2 + JSON Schema 2020-12",
      "standard": "OpenAPI 3.2 / JSON Schema 2020-12",
      "target": "Published OpenAPI document is valid and responses match their declared JSON Schemas. Only applies if an API is published.",
      "level": "conditional",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "not-assessed",
      "detail": "no OpenAPI report supplied (only applies if an API is published)"
    },
    {
      "id": "semantic.feeds",
      "area": "semantic",
      "label": "Atom feed (RFC 4287)",
      "standard": "RFC 4287",
      "target": "Published feed is a valid Atom 1.0 document.",
      "level": "recommended",
      "evidence": "external",
      "required": false,
      "tier": 2,
      "status": "met",
      "detail": "Atom feed valid (RFC 4287)"
    },
    {
      "id": "integrity.slsa-provenance",
      "area": "integrity",
      "label": "SLSA provenance + in-toto",
      "standard": "SLSA / in-toto",
      "target": "Build emits in-toto/SLSA provenance that is present, signed, and verifies against the artifact.",
      "level": "present + signed + verified",
      "evidence": "external",
      "required": true,
      "tier": 3,
      "status": "met",
      "detail": "SLSA/in-toto provenance present, signed, and verified"
    },
    {
      "id": "integrity.reproducible-build",
      "area": "integrity",
      "label": "Reproducible build",
      "standard": "Reproducible Builds",
      "target": "Re-running the build from source yields byte-identical artifacts.",
      "level": "reproducible",
      "evidence": "external",
      "required": true,
      "tier": 3,
      "status": "met",
      "detail": "build is byte-reproducible"
    },
    {
      "id": "integrity.sbom",
      "area": "integrity",
      "label": "SPDX SBOM",
      "standard": "SPDX",
      "target": "An SPDX SBOM is present, valid, complete (covers all components), and signed.",
      "level": "present + valid + complete + signed",
      "evidence": "external",
      "required": true,
      "tier": 3,
      "status": "met",
      "detail": "SPDX SBOM present, valid, complete, and signed"
    },
    {
      "id": "integrity.content-digests",
      "area": "integrity",
      "label": "Content digests (RFC 9530)",
      "standard": "RFC 9530",
      "target": "Responses carry Repr-Digest (RFC 9530) representation digests.",
      "level": "recommended",
      "evidence": "external",
      "required": false,
      "tier": 3,
      "status": "met",
      "detail": "Repr-Digest headers present (RFC 9530)"
    },
    {
      "id": "integrity.signed-release-manifest",
      "area": "integrity",
      "label": "Signed release manifest",
      "standard": "Bounded Systems release bar",
      "target": "Each release ships a manifest of artifact digests that is present and signed.",
      "level": "present + signed",
      "evidence": "external",
      "required": true,
      "tier": 3,
      "status": "met",
      "detail": "release manifest present and signed"
    },
    {
      "id": "integrity.ipfs-cid",
      "area": "integrity",
      "label": "IPFS CID recorded",
      "standard": "IPFS / CIDv1",
      "target": "The release records a content-addressed IPFS CID for the artifact.",
      "level": "recommended",
      "evidence": "external",
      "required": false,
      "tier": 3,
      "status": "met",
      "detail": "IPFS CID recorded"
    },
    {
      "id": "integrity.http-rfc9110",
      "area": "integrity",
      "label": "HTTP correctness (RFC 9110)",
      "standard": "RFC 9110",
      "target": "Responses are semantically correct per RFC 9110 HTTP semantics.",
      "level": "recommended",
      "evidence": "external",
      "required": false,
      "tier": 3,
      "status": "not-assessed",
      "detail": "no RFC 9110 HTTP report supplied (optional)"
    },
    {
      "id": "integrity.scorecard",
      "area": "integrity",
      "label": "OpenSSF Scorecard",
      "standard": "OpenSSF Scorecard",
      "target": "Repository scores ≥ 7.0 on the OpenSSF Scorecard.",
      "level": "score ≥ 7.0",
      "evidence": "external",
      "required": false,
      "tier": 3,
      "status": "not-assessed",
      "detail": "no OpenSSF Scorecard result supplied"
    },
    {
      "id": "integrity.slsa-level",
      "area": "integrity",
      "label": "SLSA build level",
      "standard": "SLSA",
      "target": "Build achieves the targeted SLSA build level (default L3).",
      "level": "≥ target (default L3)",
      "evidence": "external",
      "required": false,
      "tier": 3,
      "status": "not-assessed",
      "detail": "no SLSA build level supplied"
    },
    {
      "id": "cognitive.complexity-budget",
      "area": "cognitive",
      "label": "Interface-complexity budget (W3C COGA-derived)",
      "standard": "W3C COGA (derived)",
      "target": "Rendered DOM stays within an interface-complexity budget: choice density, primary-action count, heading depth, clear link purpose, interruptions, form/memory burden, motion, progressive disclosure. This is an interface-complexity budget, NOT a cognitive-load measurement.",
      "level": "budget (recommended)",
      "evidence": "lone",
      "required": false,
      "tier": "cognitive",
      "loneCodes": [
        "LONE_COGA_"
      ],
      "status": "met",
      "detail": "lone static checks clean (no findings)",
      "findings": []
    },
    {
      "id": "cognitive.focus-budget",
      "area": "cognitive",
      "label": "COGA Obj-5: Focus budget (attention proxy)",
      "standard": "W3C COGA Making Content Usable — Objective 5",
      "target": "Content within reading-grade ≤ 10 (Coleman-Liau) + sentence ≤ 20 words + jargon ≤ 0.5/100 words + sections ≤ 200 words without subheadings; interaction patterns support sustained attention (no autoplay, no focus-stealing, prefers-reduced-motion gated, one clear primary action per region, aria-current set). AGENT/STATIC PROXY — NOT COGA usability testing with people with cognitive disabilities.",
      "level": "Obj-5 proxy (recommended)",
      "evidence": "external",
      "required": false,
      "tier": "cognitive",
      "status": "unmet",
      "detail": "not-yet-met: readingGrade threshold exceeded, avgSentenceLength threshold exceeded, jargonDensity threshold exceeded. AGENT/STATIC PROXY for COGA Obj-5 — NOT COGA usability testing with cognitive disabilities. Do NOT mass-rewrite content — editorial is the maintainer's call; gate reports honestly."
    },
    {
      "id": "cognitive.coga-usability-testing",
      "area": "cognitive",
      "label": "COGA usability testing",
      "standard": "W3C COGA",
      "target": "Usability testing conducted with people with cognitive disabilities; critical tasks pass.",
      "level": "manual (recommended)",
      "evidence": "external",
      "required": false,
      "tier": "cognitive",
      "status": "not-assessed",
      "detail": "no COGA usability testing supplied (optional)"
    }
  ],
  "summary": {
    "met": 22,
    "unmet": 1,
    "notAssessed": 14,
    "total": 37
  },
  "areaSummaries": [
    {
      "area": "html",
      "met": 2,
      "unmet": 0,
      "notAssessed": 0,
      "total": 2,
      "summary": "html: 2/2 met"
    },
    {
      "area": "accessibility",
      "met": 4,
      "unmet": 0,
      "notAssessed": 2,
      "total": 6,
      "summary": "accessibility: 4/6 met (2 not assessed)"
    },
    {
      "area": "design",
      "met": 3,
      "unmet": 0,
      "notAssessed": 2,
      "total": 5,
      "summary": "design: 3/5 met (2 not assessed)"
    },
    {
      "area": "security",
      "met": 1,
      "unmet": 0,
      "notAssessed": 2,
      "total": 3,
      "summary": "security: 1/3 met (2 not assessed)"
    },
    {
      "area": "performance",
      "met": 0,
      "unmet": 0,
      "notAssessed": 1,
      "total": 1,
      "summary": "performance: 0/1 met (1 not assessed)"
    },
    {
      "area": "compatibility",
      "met": 1,
      "unmet": 0,
      "notAssessed": 0,
      "total": 1,
      "summary": "compatibility: 1/1 met"
    },
    {
      "area": "reliability",
      "met": 0,
      "unmet": 0,
      "notAssessed": 1,
      "total": 1,
      "summary": "reliability: 0/1 met (1 not assessed)"
    },
    {
      "area": "semantic",
      "met": 3,
      "unmet": 0,
      "notAssessed": 2,
      "total": 5,
      "summary": "semantic: 3/5 met (2 not assessed)"
    },
    {
      "area": "seo",
      "met": 1,
      "unmet": 0,
      "notAssessed": 0,
      "total": 1,
      "summary": "seo: 1/1 met"
    },
    {
      "area": "integrity",
      "met": 6,
      "unmet": 0,
      "notAssessed": 3,
      "total": 9,
      "summary": "integrity: 6/9 met (3 not assessed)"
    },
    {
      "area": "cognitive",
      "met": 1,
      "unmet": 1,
      "notAssessed": 1,
      "total": 3,
      "summary": "cognitive: 1/3 met (1 unmet, 1 not assessed)"
    }
  ],
  "conformant": false,
  "claim": "Partial conformance: automated DOM checks clean; WCAG 2.2 AA (manual audit) not supplied; OWASP ASVS Level 2 not supplied; Core Web Vitals (p75) not supplied; runtime reliability not supplied."
}
