What this is
mend.rest is a declared, hosted trust-and-repair agent system. An orchestrator delegates a unit of work; mend.rest appraises what came back, hands the orchestrator bounded repair when the work falls short, and emits a reproducible report of what it observed — including, explicitly, what it could not observe.
"Declared" is the load-bearing word. Every surface states its own agency, its allowed effects, its budgets, and its non-capabilities up front, and is then held to them. The product is not the verdict. The product is the evidence behind the verdict, in a form you can re-check without trusting this website.
The loop
Four moves, each leaving a receipt. The system's authority to act ends where its evidence ends.
fact_digest.The honesty colouring
The same three-colour law runs through every surface here. It is the brand, and it is not decorative.
Where to go
- Development instance, not production. Held-out benchmark execution is BLOCKED pending independent steward isolation; production, governance, dogfood and external-pilot review are all downstream of it and unstarted.
- No TEE, no HSM, no remote attestation, no managed keys. The confidential-computing path is a conformance shadow whose key release is permanently denied-unsupported. Root on the host reads the state directory at will.
- Operator resistance is explicitly unsupported. The threat model does not claim to defend against the person holding the box.
- Single operator, no HA, no multi-tenant isolation. One process, one port, one operator.
- Fixture data only. Not approved for customer or external data.
- This portal renders; it does not attest. It is a viewer and a same-origin proxy. It holds no credential, keeps no account, and stores no report. Every claim it shows is exactly as good as the receipt behind it — and it will tell you when there is none.