Standard v1.0 · Public consultation

Is your application truly ready?

Platphorm Ready tests the complete application surface—from DNS and source provenance to contracts, policies, accessibility, agents, and human support.

184

versioned controls

8

evidence domains

90d

certificate validity

Public attestation

CERTIFICATE

A

Platphorm Assured
184 controls
Continuous evidence
SIGNED
VERIFIABLE

The standard

One gate. The whole application.

Every result links to reproducible evidence. Public status stays simple; sensitive findings remain private to verified owners.

01 / 18 checks

Protocols & transport

TLS, HTTP behavior, DNS, redirects, compression, caching, cookies.

02 / 24 checks

Pages & crawl surface

Routes, sitemaps, robots, canonicals, hreflang, feeds, broken paths.

03 / 31 checks

OWASP & vulnerability

Headers, exposure, dependencies, DAST, secrets, supply-chain integrity.

04 / 16 checks

Trust & well-known

security.txt, change-password, policies, ownership, disclosures, contacts.

05 / 22 checks

APIs & contracts

OpenAPI, schemas, compatibility, errors, idempotency, rate limits, webhooks.

06 / 19 checks

Legibility & access

WCAG, semantics, contrast, language, keyboard, responsive rendering.

07 / 14 checks

Agents & discovery

MCP, llms.txt, structured data, agent permissions, human escalation.

08 / 40 checks

Operations & evidence

CI, provenance, SBOM, observability, incident readiness, retention.

Assessment pipeline

Evidence, not checkboxes.

Observe

Crawl the public surface and map protocols, routes, contracts, policies, metadata, and dependencies.

Verify

Connect GitHub and Vercel to prove provenance, CI, deployments, ownership, and operational controls.

Challenge

Run consented, scoped active tests with strict budgets, SSRF defenses, audit logs, and emergency stop.

Attest

Issue a signed, expiring certificate with a public verification payload and private evidence bundle.

Certification levels

01

Observed

0–59

Inventory and evidence captured

02

Ready

60–79

Mandatory public controls pass

03

Verified

80–94

Supply chain and ownership verified

04

Assured

95–100

Active testing and reviewer attestation

Built for every reader

Human-readable. Machine-verifiable.

API

/api/v1 + OpenAPI

Agents

MCP + llms.txt

Network

Graph + events + RSS

Standards and provenance

Platphorm Ready preserves the distinction between declared capability, observed behavior, and independently verified evidence.