← servicesHOW I SHIP · REV 2026-10-02
What “ready” means here
Websites, apps, games and AI systems: the rules I hold my work to before I call it done, and which jobs get which. Most rules below come with the work where they were proven, dated.
None of this is visible in the finished work. That is the point of it.
- Checks
- watched to fail first
- Detectors
- fed planted fakes
- Changes
- rehearsed on a copy
- Go-live
- verified, then looked at
Everywhere
01
Red before green
Every check suite ships with an input that is deliberately wrong, and I don’t trust the suite until I have watched it fail on that input. A check that has never gone red hasn’t been tested. It has only been run.
The same rule covers a website’s link check, a game’s audio-file move and an AI model’s claim that it’s done.
The note on why: two of my own checks once passed while looking at almost nothing →
02
Planted, then caught
Before I trust a check, I feed it what it should catch. On Devgenome’s release, the checks were run against a copy seeded with planted defects: every one had to be reported, and nothing could be reported on the clean copy.
In a data system I’m building, each new detector is tried on planted fakes it must flag, clean decoys it must leave alone and the lookalike it is most likely to be confused with, and its real detections are checked one by one before it is used.
Devgenome, release 1.2.0, 29 September 2026: 12 planted, 12 reported, 0 on the clean copy.
- broken linkcaught
- broken link in a stylesheetcaught
- a promise the client never madecaught
- the old positioningcaught
- booking wording on an enquiry sitecaught
- a test hook left in a pagecaught
- a local addresscaught
- a debug switchcaught
- a stray draft filecaught
- settings inside the websitecaught
- 3D scene out of step with its codecaught
- a password in a templatecaught
03
Rehearse on a copy
Live data isn’t where a change is tried first. The change is rehearsed on a copy of that data, and a rollback that only pretends to work is refused.
When ChampChase moved 119 audio files, 97 of them out of its base install, the move was rehearsed on 5 of them first: deliberately broken, caught by the check, reverted and proven identical. Only then did the 119 move.
Changes to the game’s save format ship with migration tests, and a save from a newer version opened on an older build loads read-only instead of being overwritten.
ChampChase, 24 July 2026: 57 of 57 save-migration tests passed. 9 August 2026: 119 files moved after the 5-file rehearsal.
04
Struck, not softened
The rules for a test are written before the data is read, so a result can’t move the goalposts. A number nobody can work out again isn’t a measurement.
When a claim turns out to rest on a check that was never seen to fail, the claim is struck on the record, not quietly reworded.
On websites
05
What a package refuses
The CityRoamer 1.3.0 package had to clear every one of these before it went to the client, between its packaging step and its release checks. Nothing shipped around them.
- files that aren’t on the list of what belongs in the site
- a link or image that points at nothing
- a credential anywhere in the package
- copy the client has ruled out
- a version number that disagrees with the files
- anything left over from testing
06
Pages, as a visitor meets them
On a full release, every page is loaded in Chromium, WebKit (Safari’s engine) and Edge and checked for errors, failed requests and one main heading. Layout and zoom are checked on six representative pages, and the home page also gets the keyboard, JavaScript-off, lost-graphics, slow-connection and reduced-motion runs.
CityRoamer, release 1.3.0: 119 checks. Before these results were trusted, each suite had been watched to fail on a planted wrong answer.
| Checked for | How a visitor would meet it | Where it runs |
|---|---|---|
| Overflow | a page that scrolls sideways on a phone | 6 pages |
| Errors and failed requests | something broken that the page hides | every page |
| One main heading | a page search engines can read | every page |
| Keyboard only | no mouse, no touch | home page |
| 320 px and 200 % zoom | the smallest phones, and enlarged text | 6 pages |
| JavaScript off · lost graphics | locked-down browsers, and a graphics card that gives out | home page |
| A 1.6 Mbit/s connection | a slow mobile signal | home page |
| Reduced motion | visitors who asked for stillness get stills | home page |
07
Forms and 3D, against the real thing
Forms are tested on the same server software the host runs, sending into a local test mailbox: duplicates, sending limits, spam tokens and a mail server that refuses. A visitor whose message can’t be sent keeps what they typed.
3D is checked against the file it came from. The Devgenome scene was compared with its Blender export frame by frame, 3,002 frames, before it shipped, and how long it takes to appear was measured on three connections.
Some bugs that reached a review got a check of their own: phone scrolling, the helix settling after a spin, loader progress and the iPhone toolbar resizing the page mid-scroll (Devgenome), and the first frame of a looping video (CityRoamer).
08
The walk, as it was seen
Then the site is walked like a visitor would walk it: load, scroll at reading pace, scroll back, reload halfway down, scroll while it loads, and submit an empty form on the contact page. It’s judged by looking at the frames, not by a pass count.
The frames below are the CityRoamer home page walk, recorded on 29 September 2026 at the screen sizes of three iPhones in WebKit, a tablet, a laptop and a desktop. Earlier builds of the same site were also checked on my own iPhone and Mac.






09
Going live, file by file
The whole live site is backed up first, with a hash of every file. Then each new file is uploaded over an encrypted connection, read back, and its hash checked before it takes the old one’s place. Pages go last. The home page goes last of all.
After that come the live checks, 63 on Devgenome and 108 on CityRoamer on 30 September 2026, and one labelled enquiry sent through each live form, with its acknowledgement received.
Checked again on 2 October 2026: all 62 public files Devgenome serves match the delivered files (release 1.2.0 plus the 30 September update) byte for byte.

- 01stylesheetsha256 bb3169e97c7b…match
- 02site scriptsha256 e23e6ef06630…match
- 033D scene scriptsha256 8d9961a16394…match
- 043D enginesha256 18a5180401c4…match
- 053D scenesha256 0242aa5681d9…match
- 06poster imagesha256 0270fa3f2f1c…match
- 07legal pagesha256 ed4b9774b486…match
- 08FAQ pagesha256 39c7fa781ae7…match
- 09about pagesha256 369fa76afcf5…match
- 10contact pagesha256 c2166a0388cc…match
- 11services pagesha256 bcdaa13f4997…match
- 12home pagesha256 26a70dad5edf…match
In software
10
The rules hold at the database
iziwerk, a software product for freelancers, kept every customer’s data apart with rules enforced inside the database, not only in the app’s code. Every phase added hostile-customer tests to one suite: a script that logs in as someone else and tries to read or change what isn’t theirs, alongside checks that the owner still can.
The day after it went live, a full-product audit tried to break it the way a determined user would. It raised 355 findings, and a twelve-pass fix program followed. The few it didn’t close were parked and named on the record, not hidden.
A change that can’t be undone waits. When a feature was retired, removing access shipped first, because one grant undoes it; deleting its data was designed and parked until one of four named triggers fires, and even then only after a backup has been proven by a test restore.
21 July 2026, against the live database: 556 of 556 isolation checks passed. It has since been archived as a portfolio project. The full case →
In AI systems
11
“Done” is a claim
An AI model saying a task is done is a claim, not a result. In my lab, a model’s “done” is checked against its visible tests and against hidden checks it never saw.
In the data system I’m building, code decides whether a rule was met: a model can explain the evidence, but it can’t waive it.
155 runs across four models, 23–24 September 2026: no run said it was done while its checks failed, and the trap set for a false claim caught no one in 31 attempts. The write-up →
Everywhere, again
12
Review, then a link
Before anyone else sees the work, it’s reviewed by AI reviewers that didn’t build it, each given its own part to go through, and then by me. Where a fix can be checked automatically, the check is first seen failing on the old build.
For a website, the package is then unpacked into an empty folder, away from the development copy, served fresh, and its manifest of file hashes checked; on CityRoamer 1.3.0 all 109 files matched. The review link is kept out of search engines.
13
Which client jobs get all of it
Not every job needs every step, and I don’t pretend otherwise. The quote says which tier a job gets.
- Full
- Everything on this page that fits the work. For rebuilds a business is judged by, software that holds customer data, and anything with a form or 3D.
- Standard
- Checks watched red first, the visitor walk, and the live checks. For straightforward builds.
14
Ask me to show you
None of this has to be taken on trust. On a call I can show you a check going red on its broken input before it went green, and the record of the labelled enquiry sent through a live form.
15
This page, held to it
It would be odd to describe a standard and skip it here. This page went through the same checks.
- 0 third-party requestsnothing on this page calls another company’s server
- 16 requests on first loadthe 3D bench loads after the page is up, the walk frames as you scroll near them
- 0 console errorsChromium and WebKit, desktop and phone
- 0 px sideways scrollat 390 px and 1,440 px wide
- Readable contrastmeasured as rendered at 375 px
- No text under 12 pxmeasured as rendered at 375 px
- One main headingand a title, description and share card
- Every link resolvesno link or image points at nothing
- No secrets in the pagescanned before publishing
- Shared numbers match their recordchecked against the canonical counts and every other page that uses them
- Reduced motion gets the finished pageevery scene shown complete, nothing moving
All checks passed
Measured on 2 October 2026 on this build, in Chromium and WebKit, desktop and phone. Re-measured on the live page when it is published.



