BitEvo is the public product and evidence surface for authority-first AI-agent engineering. The site separates what source exists, what was built, what a provider deployed, what was read back, and what external effects were actually authorized.
SOURCE != BUILD != DEPLOYMENT != READBACK != EXTERNAL EFFECT
/— product overview and trust boundary./agent-authority-audit— canonical Authority & Evidence Audit offer./mapperand/workspace— bounded public workflow tools./proofand/dogfood-self-audit— evidence and internal dogfood boundaries./buildand/version— inspectable build/source receipts./universe— evidence-bound ecosystem navigator; public URL existence is not runtime-health proof./ru/*— paired Russian product layer.
This is a static Astro site. Build metadata is generated before compilation, then the built output is postprocessed and verified. Provider-specific policy checks run after provider-neutral core verification.
The release path is intentionally fail-closed:
- source revision is identified;
- build metadata records provider, ref and provenance class;
- Astro renders the static site;
- postprocessing adds paired locale/build receipts;
- deterministic quality, trust, accessibility, budget, CSP and build-receipt gates run;
- provider policy verifies that the receipt is bound to the expected provider/ref and reviewed CSP hashes;
- deployment readiness remains distinct from protected/public HTTP readback and from production promotion.
npm install
npm run dev
npm run build:core
npm run build
npm run build:cloudflare
npm run previewnpm run build:core is provider-neutral. It may produce a LOCAL_GIT receipt when executed in a local Git checkout.
npm run build is the Vercel release path and requires a PROVIDER_BOUND Vercel Git SHA/ref. npm run build:cloudflare requires a PROVIDER_BOUND Cloudflare commit SHA/branch. Provider verification must fail rather than silently treating an unknown or empty provider/ref as release-grade evidence.
/version— human-readable source/build identity./version.json— machine-readable receipt.src/generated/build-meta.json— generated source-side receipt used by the build.
A valid provider release receipt contains an exact 40-character Git SHA, a non-empty provider ref/branch and provenanceClass=PROVIDER_BOUND. A local Git build is explicitly LOCAL_GIT; unknown or malformed identity is UNKNOWN_INVALID and is never release-grade.
The public site is self-hosted. CSP is defined in both vercel.json and public/_headers and contains no unsafe-inline or unsafe-eval. Astro still emits a finite set of immutable inline style/script blocks. Those blocks are authorized only by exact SHA-256 hashes recorded in scripts/csp-inline-allowlist.json. scripts/verify-inline-csp.mjs fails closed on any new, removed or unreviewed hash and forbids inline style attributes. Inert JSON-LD is also hash-bound. The locale switch stylesheet is served from /locale-switch.css rather than injected inline.
Vercel and Cloudflare are separate provider paths. A successful build on one provider is not evidence that the other provider, DNS/canonical origin, private runtime or production promotion is healthy or authorized.
No credentials, private hosts or secret-bearing runtime configuration belong in this repository or public build metadata.
This public site does not grant trading, wallet, exchange, runtime-control or capital authority. Production promotion, DNS changes, credential mutation and consequential external effects require separate explicit authorization.
can_trade=false
capital_permission=DENY