bench:frontier-scorecard
All domains signed and current.
The rollup confirms that every benchmark domain is signed, within its validity window, and verifier-current.
Every frontier domain is signed and current.ScorecardSigned · Jun 2026Signed scorecard: KMS/Sigstore signed and re-verifiable, dated Jun 2026.
Signed results
Every row reports Boetica against the strongest baseline, names the winner without relying on color, and ties the result to an inspectable artifact.
| Metric | Boetica | Best baseline | Winner | Artifact |
|---|---|---|---|---|
| Domains signed | 7 / 7 | n/a | Boetica | Rollup manifest |
| Domains within validity | 7 / 7 | n/a | Boetica | Freshness report |
| Verifier-current | 6 / 7 | n/a | Boetica | Verifier report |
Representative end-state figures. Replaced by live signed scorecard data before procurement review.
- Algorithm
- ECDSA P-256 (cosign keyless)
- KMS key
- gcpkms://projects/boetica-prod/locations/global/keyRings/evidence/cryptoKeys/scorecards
- Sigstore bundle
- sigstore-bundle://rekor/boetica/scorecards
- Signer
- boetica-evidence-signer
- Signed at
- 2026-06-24T12:00:00Z
- Digest
- sha256:fb000001
- Rollup manifest
sha256:rollup00 - Domain digests
sha256:domain00 - Signature
sha256:fb000001
Plain-text summary: across 3 measured metrics, Boetica leads its baselines on the bench:frontier-scorecard benchmark, signed ECDSA P-256 (cosign keyless) on 2026-06-24T12:00:00Z and re-verifiable from the hash trail above.
bench:frontier-scorecard · methodology
How this benchmark is run
The rollup is scored on whether every benchmark domain is signed, within its validity window, and verifier-current.
- Fixtures
- The set of all domain scorecards and their signatures, freshness windows, and verifier states.
- Baseline collection
- The rollup has no external baseline; it is an internal integrity attestation over the other domains.
- Statistical method
- Each metric is an N-of-M count over the domain set (signed, within validity, verifier-current).
- Reviewer
- Evidence integrity owner
- Last updated
- 2026-06-24
Inclusion rules
- Every domain scorecard must be present and signed to count.
- Freshness is measured against each domain's own validity window.
- Verifier-current requires a passing verifier re-run.
Exclusion rules
- Domains outside the published benchmark set are excluded from the rollup.
Limitations
- Verifier-current count trails freshness when a domain is mid re-verification.
Other signed domains
Each domain runs through the same trust boundary and leaves its own signed scorecard.
- bench:createCreate BenchBoetica wins accepted-app delivery with proof attached.
- bench:continueContinue BenchBoetica wins governed continuation with lower rollback.
- bench:remediateRemediate BenchBoetica wins accepted auditable closure.
- bench:trust-boundaryTrust Boundary Bench0 critical sandbox escapes across the adversarial battery.
- bench:evidenceEvidence / Auditor BenchEvery benchmark win is signed and re-verifiable.
- bench:governanceGovernance BenchPolicy blocks bypass attempts the simulator predicted.
- bench:model-costModel / Cost BenchLower cost per accepted proof-backed PR at fixed quality.
Run it on your own work
Prove bench:frontier-scorecard on your repo, not ours.
Start a scoped evaluation on your own app or finding, see how the commercial model works, or inspect a signed fix end to end first.
