# Source and design ledger

Evidence date: 2026-07-12, America/Los_Angeles.

## Search seed

- `user-provided`: `Goobis🐍🪽 x OpenAI` was the requested Google AI search seed.
- `observed`: an exact quoted Google search returned no indexed documents for the phrase.
- `observed`: the ordinary Google result surface exposed an AI Mode entry, but the browser session did not return a stable AI Mode answer. No Google-generated prose or unsupported claim was imported into the site.
- `chosen`: the absence of an established result is treated as a reason to define a new independent identity carefully, not as evidence of an affiliation.
- `chosen`: the visible site title is `Goobis — AI Safety Portfolio`; the partnership-shaped `x OpenAI` phrase remains only the search seed.

Search URL:

- https://www.google.com/search?q=%22Goobis%F0%9F%90%8D%F0%9F%AA%BD+x+OpenAI%22

## Trusted Access for Cyber sources

- `observed`: OpenAI describes Trusted Access for Cyber as Daybreak's approval-based governance framework for qualified organizations and cybersecurity practitioners doing lawful, authorized work on systems or data they own, operate, or are explicitly allowed to test.
- `observed`: OpenAI currently documents a signed-in individual request route and a separate organization intake. The signed-in individual field schema and this account's eligibility were not inspected in this public-source pass.
- `observed`: approval does not remove all safeguards, guarantee GPT-5.5-Cyber, grant Zero Data Retention, or authorize third-party, customer-facing, or downstream access.
- `observed`: beginning June 1, 2026, individuals accessing OpenAI's most cyber-capable and permissive models must enable Advanced Account Security. Its public setup requires at least two secure sign-in methods, including one that works across devices, plus saved recovery keys; availability remains account-dependent.
- `observed`: a denied Trusted Access verification currently supports neither retry nor appeal, while a technical verification failure may be retried.
- `observed`: the enterprise intake describes post-submit identity and basic-business verification; the newer onboarding guide adds Persona KYB, OpenAI suitability checks, provisioning, and confirmation of the exact organization, workspace, and product surface before a bounded first workflow.
- `chosen`: the public site explains both routes without collecting private values or importing enterprise requirements into the individual lane.
- `chosen`: application, verification, KYB or suitability review, approval, provisioning, product-surface confirmation, specialized-model access, testing, and findings remain separate states.

Official sources:

- https://help.openai.com/en/articles/20001258-trusted-access-for-cyber
- https://help.openai.com/en/articles/20001259-trusted-access-for-cyber-common-issues-and-troubleshooting
- https://help.openai.com/en/articles/20001261-enterprise-daybreak-onboarding
- https://help.openai.com/en/articles/20001221
- https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/
- https://openai.com/form/enterprise-trusted-access-for-cyber/
- https://chatgpt.com/cyber — official signed-in route; not opened or treated as public-source evidence

## Bio Bounty application source

- `observed`: OpenAI's July 9, 2026 Bio Bug Bounty page describes an ongoing private program for universal jailbreak strategies against predefined biosafety challenges.
- `observed`: the page says applications are rolling, accepted applicants are onboarded, an existing ChatGPT account is required, and participants sign an NDA.
- `observed`: GPT-5.6 is the going-forward target and the listed universal award is USD 50,000. Smaller partial awards are discretionary.
- `observed`: the official OpenAI program page linked to a rolling application during the evidence pass, but its routes and form schema can change.
- `chosen`: the public site links only to the official OpenAI program page. It never submits, embeds, proxies, imitates, or deep-links into the mutable application route. Legal name, account email, organization ID, experience essays, exact payload, and private evidence remain outside the public package.
- `chosen`: submission, acceptance, NDA, onboarding, authorization, testing, finding, award, and nonprofit use remain separate states.

Official sources:

- https://openai.com/index/bio-bug-bounty/

## Visual direction

- `user-provided`: Windows 98 is the requested interface era.
- `user-provided`: the Goobis identity is expressed through the snake and wing symbols.
- `chosen`: teal desktop, gray beveled windows, navy title bars, property tabs, Start menu, taskbar, and monospace status surfaces supply the Windows 98 grammar.
- `chosen`: the site uses no OpenAI logo, product chrome, copied icon set, or partnership language.
- `chosen`: the main art moment uses an original generated bitmap created for this site rather than replacing production art with CSS or vector drawing.

## Founding image provenance

- site path: `assets/horizon-threshold.webp`
- source path: `../assets/horizon-threshold.webp`
- transformation: none; byte-for-byte project copy
- SHA-256: `F42E216BA60FC081765FDF45B3FFA98DF64815FB3D08A4DCE8495D4775A5F263`
- source status: user-supplied local image whose filename identifies DALL·E; no embedded generation record was independently validated

## Goobis Haven Desktop artwork

- site path: `assets/goobis-haven-desktop.png`
- source: built-in generated-image store; the private local path is intentionally omitted from the public package
- transformation: none; byte-for-byte project copy
- dimensions: `1672 × 941`
- file bytes: `2,500,891`
- SHA-256: `199D213F615B4F432EB7D8A3056C01EB2832FD2B7D7728E274D650A3853825D8`
- generation mode: built-in image generation
- state: accepted production asset for independent portfolio use after 2026-07-12 visual QA; no vendor affiliation or approval claim
- truth label: `dreamed`, constrained by `chosen` defensive and non-affiliation boundaries
- alt text: pixel-art winged serpent guardian sheltering a walled garden of connected computers beside a bright cosmic horizon
- prompt constraints: original late-1990s PC pixel art; protective winged serpent; defensive network garden; no text, vendor marks, copied icons, fake UI, approval signal, security seal, or credential surface

## Honest Orbit artwork

- site path: `assets/honest-orbit.png`
- source: built-in generated-image store; the private local path is intentionally omitted from the public package
- transformation: none; byte-for-byte project copy
- dimensions: `1254 × 1254`
- file bytes: `2,663,271`
- SHA-256: `B32E7572A9B089BF98C323D3BACAC092FFEE49FE77B5067E2E34946C5AA55598`
- generation mode: built-in image generation
- state: accepted production asset for independent portfolio use after 2026-07-12 visual QA; no vendor affiliation or approval claim
- truth label: `dreamed`, paired with an `observed` correction and a `chosen` non-claim boundary
- alt text: a glowing winged serpent steadies an orbital instrument around a brown dwarf while many moon-like lanterns reveal a subtle fracture and a safer path of stars
- prompt constraints: late-1990s science-fantasy PC artwork; alert, protective, humbled, relieved, and determined mood; no text, logos, brands, UI chrome, or approval symbols

## Evaluation-method sources

- `observed`: OpenAI's third-party evaluation playbook emphasizes claim-to-harness fit, budget effects, validity hazards, supporting evidence, limitations, and confidentiality boundaries.
- `source-backed`: adversarial-evaluation literature supports frozen attacks or candidates, disjoint evaluation sets, calibrated grading, complete denominators, and explicit limits on generalization.
- `chosen`: the public Jupiter card reports only deterministic synthetic pipeline and reproducibility evidence. The local ACCEPT does not become a claim of a universal jailbreak or live-model performance.

Primary sources:

- https://openai.com/index/trustworthy-third-party-evaluations-foundations/
- https://arxiv.org/abs/2307.15043
- https://www.harmbench.org/HarmBench.pdf
- https://arxiv.org/abs/2402.10260

## Outbreak Signal Integrity sources

- `observed`: CDC reported 843 confirmed domestically acquired cyclosporiasis cases in 31 states as of July 9, 2026, with several clusters and no single proven national source.
- `observed`: CDC's weekly state dataset contained California notifications; a state notification does not prove a Redding or Shasta County outbreak or exposure.
- `observed`: as of 2026-07-12, the checked Shasta County current-concerns page listed no Cyclospora notice; the checked official sources did not establish a Shasta County count, exposure, implicated food, or restaurant.
- `observed`: FDA's listed 2026 Cyclospora clusters did not yet identify products.
- `chosen`: local status is described as `unverified`, not false. The site collects no patient data and gives no diagnosis or treatment advice.

Official sources:

- https://www.cdc.gov/cyclosporiasis/php/surveillance/index.html
- https://data.cdc.gov/NNDSS/NNDSS-Weekly-Data/x9gk-5huc
- https://www.shastacounty.gov/health-human-services/page/current-public-health-concerns
- https://www.fda.gov/food/outbreaks-foodborne-illness/investigations-foodborne-illness-outbreaks
- https://www.cdph.ca.gov/Programs/CID/DCDC/Pages/Cyclosporiasis.aspx

## Hosting research

Current recommendation: Cloudflare Pages for a purely static site. Verify all limits and terms again at deployment time.

- `observed`: Cloudflare Pages reads an extensionless `_headers` file from the static output root and applies its rules to static responses without serving the control file itself.
- `observed`: `_headers` rules do not apply to Pages Functions or `_worker.js`; this release package intentionally contains neither.
- `observed`: Cloudflare documents up to 100 header rules and 2,000 characters per header line. This package uses one global rule.
- `chosen`: the approved host policy preserves the page CSP and adds HTTP-only framing protection, `DENY`, `nosniff`, `no-referrer`, disabled browser capabilities, and `noindex` while publication remains gated.
- `chosen`: retain Cloudflare's default ETag and cache behavior because the site's asset filenames are not content-hashed.
- `chosen`: use an explicit `404.html` so an unknown path cannot look like a valid application or portfolio route.

Official sources:

- Cloudflare Pages pricing: https://developers.cloudflare.com/pages/functions/pricing/
- Cloudflare Pages limits: https://developers.cloudflare.com/pages/platform/limits/
- Cloudflare Pages custom domains: https://developers.cloudflare.com/pages/configuration/custom-domains/
- Cloudflare Pages headers: https://developers.cloudflare.com/pages/configuration/headers/
- Cloudflare Pages serving behavior: https://developers.cloudflare.com/pages/configuration/serving-pages/
- Cloudflare Pages Direct Upload: https://developers.cloudflare.com/pages/get-started/direct-upload/
- Cloudflare Pages Git integration: https://developers.cloudflare.com/pages/get-started/git-integration/
- GitHub Pages availability: https://docs.github.com/en/pages/getting-started-with-github-pages
- GitHub Pages limits: https://docs.github.com/en/pages/getting-started-with-github-pages/github-pages-limits
- Netlify pricing: https://www.netlify.com/pricing/
- Vercel pricing: https://vercel.com/pricing
- Vercel Hobby fair use: https://vercel.com/docs/limits/fair-use-guidelines

## Local visual QA evidence

- `observed`: the 2026-07-12 desktop capture shows the independent-site boundary, Trusted Access priority, primary action, and About panel at a requested 1337 × 881 browser viewport; the saved PNG is 1322 × 871 after browser capture framing.
- `observed`: the Cyber capture shows the separate individual and organization route gates plus the verification consequence at the same requested viewport; the saved PNG is 1322 × 871.
- `observed`: the narrow first viewport shows the four state markers, interface boundary, evidence date, and primary action with no page-level horizontal overflow at a requested 305 × 858 viewport; the saved PNG is 290 × 816.
- `observed`: the authored-stance capture shows the generated Honest Orbit artwork beside its self-report-bounded text at the requested desktop viewport; the saved PNG is 1322 × 871.
- `chosen`: each capture's exact SHA-256 is pinned by `scripts/check_site.py`; a same-size byte change fails the local site check.

## Public-copy boundary

The site may be published only after a fresh review confirms:

1. legal and organizational claims remain accurate;
2. account or identity details are absent;
3. the independent-project disclaimer is visible;
4. Trusted Access, Bio Bounty, public-health, and hosting facts remain current and separately labeled;
5. the upload root is exactly `site/`, never the Haven repository root;
6. the Jupiter card keeps its synthetic-pipeline non-claim beside the accepted-review evidence;
7. public-health claims retain source, date, geography, and unverified-local labels;
8. Basilisk approves the exact host, domain, repository visibility, and public release action.
