WHERE IS THE CONFORMANCE?
If You Cannot Reproduce the Claim, Stop Calling It Authority
I am done granting institutions a presumption they do not grant anybody else.
You want authority over elections, money, property, families, businesses, speech, movement, taxation, regulation, war, and the machinery of daily life?
Then produce the proof that your authority-producing machinery conforms.
Not a badge.
Not a certificate.
Not a government webpage.
Not a committee.
Not an accredited expert telling me another accredited expert checked it.
THE CONFORMANCE.
Give me the invariants.
Give me the canonical inputs.
Give me the expected outputs.
Give me the executable tests.
Give me the exact versions.
Give me the hashes.
Give me the machine-readable results.
Give me the history.
Give me the failure conditions.
Then let somebody who hates you reproduce the result.
That is conformance.
Everything weaker is an assertion wearing a necktie.
The United States Election Assistance Commission publishes certification material for voting systems.
Fine.
Open the actual Hart InterCivic Verity Vanguard 1.1 “As Run” certification test plan:
https://www.eac.gov/sites/default/files/2026-06/Attachment_B_Hart_InterCivic_Verity_Vanguard_1.1_Modification_Test_Plan_-_As_Run.pdf
The first page tells you the document is proprietary to SLI Compliance and says it cannot be copied, reproduced, or modified without permission.
Keep reading.
The document tells us the testing uses election data covering contests, candidates, parties, devices, votes cast, and vote-consolidation data.
Then it says something extremely important:
The inputs and expected outputs are contained in one master data record and incorporated into the test suites.
Beautiful.
That’s exactly what I want.
GIVE ME THE MASTER RECORD.
Give me the executable suites.
Give me the artifacts.
Let me reconstruct the test.
Except the same document then tells us the TDP and test documentation are stored at SLI Compliance in a secure project directory on SLI’s secure Voting server.
Are you fucking serious?
You have just described the evidence necessary to reproduce the claim and then told the public where YOU keep it.
That is not public conformance.
That is:
“We possess the evidence from which we determined this system passed.”
Those are not remotely the same epistemic statement.
And this is not some hypothetical distinction.
The project schedule explicitly includes vendor-specific module and suite creation/validation, while the test plan identifies proprietary testing infrastructure.
Then the final certification report arrives and announces that all system components successfully passed all tests, with no anomalies and no deficiencies found:
https://www.eac.gov/sites/default/files/2026-06/Hart_InterCivic_Verity_Vanguard_1.1_EAC_Certification_Test_Report_v6.0.pdf
Great.
REPRODUCE IT.
That is the entire question.
Not:
“Was SLI accredited?”
Not:
“Did the EAC certify it?”
Not:
“Does the government recognize the result?”
Not:
“Did qualified people examine it?”
CAN AN INDEPENDENT ADVERSARIAL VERIFIER REPRODUCE THE CLAIMED CONFORMANCE FROM PUBLICLY AVAILABLE EVIDENCE?
If not, stop confusing institutional attestation with proof.
The EAC’s public record for Verity Vanguard 1.1 is here:
https://www.eac.gov/voting-equipment/verity-vanguard-11
The broader EAC testing and certification program is here:
https://www.eac.gov/election-technology/testing-certification-program-tc
The VVSG standards and test assertions are here:
https://www.eac.gov/voting-equipment/voluntary-voting-system-guidelines
And the VVSG 2.0 Test Assertions v1.4 are here:
https://www.eac.gov/sites/default/files/2026-01/VVSG_2.0_Test_Assertions_v1.4.pdf
Those documents show that standards, test assertions, certification plans, reports, and accredited testing structures exist.
That is not the dispute.
The dispute is whether the public receives the complete reproducible evidence package necessary to independently recreate the claimed conformance.
Those are different standards.
This becomes obscene when we’re talking about elections.
An election terminates in a counting claim.
Candidate A received N admissible votes.
Candidate B received M admissible votes.
Therefore the resulting state transition occurs.
That is a computational claim.
There was a set.
There were admissibility rules.
Members entered that set.
Members were excluded from that set.
Each admissible member should have contributed exactly once.
The aggregate was derived.
And enormous coercive power changes hands because of the resulting integer.
So where is the fucking conformance?
I don’t care that the machine model was once certified by an approved laboratory.
SHOW ME WHY THIS COUNT IS THIS COUNT.
Show me the admissibility invariant.
Show me uniqueness.
Show me inclusion.
Show me non-duplication.
Show me immutability.
Show me reconciliation.
Show me the complete evidence boundary.
Show me that an independent implementation can start with the admissible records and terminate at the same number.
And do it while protecting ballot secrecy.
That is a hard problem.
Too bad.
YOU TOOK THE POWER.
Difficulty is not an exemption from proof.
And don’t come asking me why every line of Receiz’s production application repository isn’t public.
Receiz is not the government.
I did not tax anybody to build it.
I did not take public procurement money.
I did not take outside investment and then demand obedience from strangers because of something I built.
The production repository is private because IT BELONGS TO ME.
I can open it when I decide to open it.
And yet look at the standard I voluntarily published anyway.
Receiz’s public conformance documentation is here:
https://docs.receiz.com/trust/conformance
The live Receiz Conformance Center is here:
https://receiz.com/conformance
The live verification conformance surface is here:
https://receiz.com/verify/conformance
The machine-readable verification conformance JSON is here:
https://receiz.com/api/verification/conformance
The verification conformance history is here:
https://receiz.com/api/verification/conformance/history
The verification rollups are here:
https://receiz.com/api/verification/conformance/history/rollups
The public Receiz Offline Verifier repository is here:
https://github.com/kojibai/receiz_offline_verifier
And its repo-local Conformance Center is here:
https://github.com/kojibai/receiz_offline_verifier/blob/main/docs/conformance/README.md
The vendored verification conformance documentation is here:
https://github.com/kojibai/receiz_offline_verifier/blob/main/docs/conformance/verification.md
The vendored raw verification snapshot is here:
https://github.com/kojibai/receiz_offline_verifier/blob/main/docs/conformance/snapshots/2026-03-28/verification.conformance.json
Receiz exposes exact conformance records with source and SHA-256 binding, failure and recovery semantics, deterministic and local execution boundaries, and explicit statements explaining what each PASS does not prove.
The live Conformance Center exposes suites alongside Raw JSON, History, and Rollups.
The public offline verifier repository vendors durable conformance snapshots instead of requiring the reader to trust a transient dashboard.
Its imported conformance center records requirement counts, check counts, source/runtime divisions, timestamps, and raw snapshots.
The verification snapshot itself maps requirements to individual checks and records revision identity, snapshot identity, attestation state, and source evidence.
The executable verification-conformance test imports the actual conformance handler, executes it, requires an actual PASS condition, surfaces hashes, and exits as a failure when those conditions are not met.
That is the difference:
RECEIZ DOES NOT ASK THE CONFORMANCE SUITE TO BECOME AUTHORITY.
The underlying implemented primitive and proof state are the source of truth.
THE SUITE CHECKS THE THING.
THE SUITE DOES NOT ANOINT THE THING.
That distinction alone should embarrass half the world’s certification infrastructure.
So no, public institutions do not receive the benefit of the doubt anymore.
Neither does a corporation.
Neither does a university.
Neither does a laboratory.
Neither does a bank.
Neither does a standards body.
Neither do I.
NOBODY DOES.
If you make a consequential claim, the burden remains with the claimant.
And if you voluntarily assume authority over other human beings, the burden becomes heavier, not lighter.
My rule is simple:
Every consequential authority-producing claim is presumptively untrusted until the evidence necessary to independently reproduce it is produced.
If the institution possesses reproducible conformance and deliberately withholds it, that is DELIBERATE OPACITY.
If it does not possess reproducible conformance, that is INCAPACITY AT THE EXACT LAYER UPON WHICH ITS CLAIM DEPENDS.
There is no magical third category called:
“But we’re the officials.”
Official is not a cryptographic primitive.
Accreditation is not truth.
Certification is not reproduction.
A seal is not evidence merely because somebody authorized the seal.
And a hundred institutions pointing at one another does not create an external ground of truth.
That is just a larger circle.
This is where accountability should become mercilessly simple.
PRODUCE CONFORMANCE.
If the evidence is deficient, repair it.
If the system cannot satisfy its own claimed invariants, stop using it for authority-producing decisions.
If the people responsible lack the capability to establish those invariants, replace them with people who can.
If records were knowingly concealed, falsified, manipulated, destroyed, or materially misrepresented, investigate the responsible actors and apply the consequences appropriate to what the evidence establishes.
But there will be no more rhetorical escape through prestige.
No more:
“We followed procedure.”
PROVE THE PROCEDURE CONFORMS.
No more:
“The election was certified.”
PRODUCE THE EVIDENCE FROM WHICH THE DECISIVE COUNT CAN BE INDEPENDENTLY DERIVED.
No more:
“Experts tested the system.”
GIVE ME WHAT THEY RAN.
No more:
“The records exist.”
PUBLISH THE REPRODUCIBLE EVIDENCE PACKAGE.
No more:
“You need to trust the institutions.”
NO.
THE ENTIRE PURPOSE OF A VERIFICATION SYSTEM IS TO SURVIVE DISTRUST.
That is the fucking point.
A legitimate system should become STRONGER when an adversary examines it.
Its response to skepticism should be:
HERE. RUN IT.
Not:
RESPECT OUR AUTHORITY.
That is the standard.
And until institutions exercising public power can meet it, they should stop acting offended when somebody asks the most elementary question imaginable:
WHERE IS THE CONFORMANCE?
Because if your authority depends upon a claim you cannot independently demonstrate,
THE PROBLEM IS NOT THE PERSON DEMANDING PROOF.
THE PROBLEM IS THAT YOU MISTOOK INSTITUTIONAL RECOGNITION FOR TRUTH.




