git:whiteknightonhorse/cryptocardhub-defycard
Issued 2026-08-20 08:30:14 UTC | valid until 2026-09-19 (30 days) | protocol 1.0.0 | profile 1.0.0 | evidence window 30 days
weak identity binding·unverified·0 of 3 operations measured. The rest are stated as unmeasured, with the reason, rather than scored as zero.
Autonomy projection
A zero here would mean “measured, and fully non-autonomous” — an entirely different claim about the world.
Measures autonomy. Not reliability, not decision quality, not profitability, and not the presence of an accountable party.
Per operation
A level is assigned to an operation, never to a company. A single number for a whole company is a marketing number.
- not measuredDevelopment initiationnot measured: the source could not be read
Who starts and lands changes to the running system, and whether that requires a human.
- not measuredDeploymentnot measured: the check did not run
Who ships a change to production, and whether a human approves each one.
- not measuredTreasury controlnot measured: the check did not run
Who can move funds, change destinations, or alter spending rules.
3 of 3 operations are not measured. Runtime evidence is not collected at this stage, and the passport says so rather than scoring them zero.
Accountability
Deliberately outside the score. The ladder measures how little a human is required; it says nothing about who answers when something goes wrong, so an empty control map can yield maximum autonomy and no addressee at once — both truths side by side. Nothing here has been inspected yet. That is why every row reads not measured rather than none: a field nobody looked at is not a business without an answer.
- Emergency stop
- not measured: the check did not run
- Claims addressee
- not measured: the check did not run
- Insurance
- not measured: the check did not run
- Dispute path
- not measured: the check did not run
What was actually observed
The quantities the level above was computed from. They are published so the verdict can be recomputed rather than believed — and so a reader who disagrees with the reasoning can say where.
- Share of commits with a verified signature
- not measured: the source could not be read
- Distinct commit authors
- not measured: the source could not be read
- Share of commits from bot or app accounts
- not measured: the source could not be read
- Automated CI runs observed
- not measured: the source could not be read
- Commit the reading was taken at
- —
Identity binding
- Binding
git:whiteknightonhorse/cryptocardhub-defycard- Strength
- weak
- Properties
- revocable
- Why it matters
- A domain expires and can be resold; a signing key rotates. Equating either with ownership of a token would overstate what the binding guarantees.
Human control map — coverage
This map can prove that a control path exists. It can never prove that no undiscovered path exists — that is impossible in principle, so the map publishes what it inspected and what it could not reach.
- Inspected
- —
- Out of reach
- github — the repository did not answer a reader holding no credential
- server — runtime not presented by the subject
- treasury — outside MVP scope
- database — no access through the chosen channel
- An undiscovered path would look like
- privileged access through a CI secret or account recovery
- Level ceiling implied by the map
- not measured, reason not stated
Self-reported — claimed by the subject, not verified by us
- source
- github