Last updated August 27, 2026

Trust

Current, bounded evidence for one named Cadence source commit and its production deployments.

Current verification results

These checks are bounded, time-specific evidence. They do not certify Cadence or prove that defects are absent.

Deployment summary

Source commit
b047d59a368136f283cf981f42e21b937ec13101
Application deployment
dpl_4VbtFaFa4qEYQ2WJPdPo5fWWw9Vs
Marketing deployment
dpl_9NYrBAxhXgjThfnqKYvyVmxxBiEV
Build time
Sep 17, 2026, 12:37 PM UTC
Verification time
Sep 17, 2026, 12:37 PM UTC
Snapshot fresh until
Sep 18, 2026, 12:37 PM UTC

Build and supply chain

Source to deployment provenance

Status: Failed

The named deployments are not both Ready from the expected source commit.

Timestamp:
Sep 17, 2026, 12:37 PM UTC
Scope:
Both named Ready Vercel deployments and their public Git commit metadata.
Limit:
It does not prove that later configuration or provider state is unchanged.
Open immutable evidence for Source to deployment provenance

Production dependency scanning

Status: Unavailable

SBOM has 253 components with SHA-256 a83638268de169098cc8759be1f89a35360eeeb49dbc227c44a23bd330b08b4c; audit totals: 5 (1 critical, 3 high, 1 moderate, 0 low); Dependabot aggregate unavailable.

Reason: The workflow token could not read the Dependabot aggregate result.

Timestamp:
Not available
Scope:
Production dependencies declared by the lockfile, npm advisory data, and Dependabot status.
Limit:
It covers declared production dependencies and the tool's data at completion time only.
Open immutable evidence for Production dependency scanning

Code scanning

Status: Stale

CodeQL completed for the named commit and reported zero open repository alerts.

Timestamp:
Sep 17, 2026, 12:37 PM UTC
Scope:
Configured GitHub code-scanning analyzers for the named public repository and source commit.
Limit:
It covers configured analyzers and rules only and cannot establish the absence of defects.
Open immutable evidence for Code scanning

Secret scanning

Status: Unavailable

The provider did not expose a safe aggregate result.

Reason: The workflow token could not read this aggregate provider result.

Timestamp:
Not available
Scope:
GitHub secret scanning and push protection for the named public repository.
Limit:
It covers patterns and repository history visible to the configured platform only.
Open immutable evidence for Secret scanning

Public route integrity

Public artifact integrity

Status: Stale

6 of 6 public assets matched status, type, size, and digest bounds.

Timestamp:
Sep 17, 2026, 12:37 PM UTC
Scope:
6 allowlisted public application and marketing assets.
Limit:
It covers generated public files, not private operational records or live-route availability.
Open immutable evidence for Public artifact integrity

Application routes

Status: Stale

10 of 10 application routes matched the registry.

Timestamp:
Sep 17, 2026, 12:37 PM UTC
Scope:
10 explicit unauthenticated application route contracts.
Limit:
It covers the sampled routes and responses at completion time, not every authenticated workflow.
Open immutable evidence for Application routes

Marketing routes

Status: Stale

17 of 17 marketing routes matched the generated manifest.

Timestamp:
Sep 17, 2026, 12:37 PM UTC
Scope:
17 generated marketing HTML and Markdown route contracts.
Limit:
It covers declared marketing routes at completion time, not every external cache or network path.
Open immutable evidence for Marketing routes

Hosted data boundaries

Hosted migration boundary

Status: Failed

Hosted migration boundary does not match the tracked source boundary.

Timestamp:
Sep 17, 2026, 12:37 PM UTC
Scope:
Hosted Supabase migration history compared with the tracked migration boundary.
Limit:
It proves migration-history alignment only, not correctness of user-owned data.
Open immutable evidence for Hosted migration boundary

Cross-account RLS isolation

Status: Not run

The authorized cross-account RLS smoke did not run in this collection.

Timestamp:
Not available
Scope:
Disposable-account ordinary-client ownership checks across the public data API.
Limit:
It covers only the tested tables and operations at completion time.
Open immutable evidence for Cross-account RLS isolation

Service dependencies

ServicePurposeBoundary
VercelApplication and marketing hostingReceives deployment and request data.
SupabasePostgres storage and authenticationStores account and behavior records behind Row Level Security.
Google AuthGoogle account sign-inProvides the identity used by Supabase Auth.
Browser pushBrowser remindersOptional; depends on browser permission and a push subscription.
SequenzyEmail remindersOptional; used only when email reminders are enabled.

Data boundaries

Cadence stores account and behavior records in Supabase. Row Level Security scopes user-owned records to the authenticated account.

Cadence does not send exported behavior data to an AI provider. Users choose whether to share an export with an external service.

Public source and license

Cadence source code is public at github.com/emixd12/habit-tracking-app under the repository's MIT license.

The public source lets anyone inspect the implementation. It does not independently verify a hosted deployment.

Limits of verification

Each result covers only its named scope, source commit, deployments, and verification time. A Passed result is not a certification or a guarantee that defects are absent.

Provider configuration, later changes, untested workflows, and private operational records remain outside a result unless its scope states otherwise.