mend.rest

trust & repair
Status  Development instance. The official benchmark held-out execution is BLOCKED pending independent steward isolation. Nothing on this site is a production claim or an assurance claim, and a deployed instance is still an unclaimed dev instance.

What this is

mend.rest is a declared, hosted trust-and-repair agent system. An orchestrator delegates a unit of work; mend.rest appraises what came back, hands the orchestrator bounded repair when the work falls short, and emits a reproducible report of what it observed — including, explicitly, what it could not observe.

"Declared" is the load-bearing word. Every surface states its own agency, its allowed effects, its budgets, and its non-capabilities up front, and is then held to them. The product is not the verdict. The product is the evidence behind the verdict, in a form you can re-check without trusting this website.

The loop

Four moves, each leaving a receipt. The system's authority to act ends where its evidence ends.

AppraiseA submitted claim of done-ness is graded against the commission's scope, budgets, and prohibited effects. The disposition is one of PASS UNKNOWN REPAIR_REQUIRED BLOCKED.
RepairA shortfall produces a bounded repair node the orchestrator fetches and acknowledges. Attempts are counted against the commission's budget. mend.rest does not perform the work; it names what is missing.
ReportA deterministic projection of report-safe facts — timeline, coverage, named gaps, claims and their evidence, scope and budget, roots and witnesses — reduced to one fact_digest.
GovernExport and deletion are first-class methods with their own receipts. A deletion receipt names its own limitations rather than claiming completeness it cannot deliver.

The honesty colouring

The same three-colour law runs through every surface here. It is the brand, and it is not decorative.

greenReceipt-backed and verified. Used only where a receipt exists and its pin is a real proof pin — never for a PASS that rests on a simulation pin.
amberAttention, unverified, unknown, or absent. Absence is never red — a missing receipt means unobserved, not didn't-happen. An error of observation (a refused credential, a timeout) is also amber: it means we could not learn.
redRefuted, failed, tampered, or BLOCKED. Only ever a verdict about the work — never a verdict about our ability to look at it.
Inherited from the ledger surface in assets/surfaces-ledger/, which renders no verdict it cannot support. This portal keeps that rule and adds one: the distinction between "we looked and it failed" and "we could not look" is never collapsed.

Where to go

ReportsThe receipts river. Bring your own credentials, read your own task reports and verdict receipts in the browser. Nothing is stored on this site.
VerifyHow to check a report offline, against the open verifier, without trusting this site or its API.
APIPOST /rpc — newline-delimited JSON-RPC 2.0, Bearer authorization, 14 mend.* methods. Health at GET /healthz. Credentials are issued out of band; there is no signup here.
What this instance does not claim