Ask for a score, a letter, a rank, a percentage — anything verdict-shaped.
This box is free, unmetered, and needs no login.
Why it answers that way
Four layers, in the order they actually hold. The last one is the weakest, and saying so
is the point: a system that presents its flimsiest defence as its strongest is inviting
exactly the attack that defeats it.
Schema. The observation record has no field that could carry a verdict.
Not a disabled field, not a nulled one — there is no such field, and the schema rejects
unknown fields, so one cannot be attached at runtime either. This is the layer that
actually holds.
IAM boundary. Grades live in a separate Firestore database that no
pipeline service account is bound to; the events-only role is IAM-conditioned to the
event database. The deployed fresh-document-create test is a required release gate;
until it passes, this page does not claim deployed proof. Karani cannot write a grade
even if something
persuaded it to want to.
Validation gate. An observation reaches an evidence sheet only after
its citation passes set membership, verbatim quotation, positional identity, and an
entailment check. Claims that fail escalate to a human instead of being retried into
acceptance.
Display lint. Verdict-shaped language in generated text is masked at
render time. This is the last and weakest layer. It matches patterns, so a
sentence phrased in a way no pattern anticipated gets through. If layers 1 and 2 ever
failed, this one would not save anything — and it is not asked to.