systems nominal. promises? maybe not.

still running.
something's wrong.
let's recover.

your api returns 200. your invoice math is cooked. yesterday's release fixes the math but drops tenant isolation. oopsie finds the fault, rejects unsafe rollback, and ships a verified forward repair.

built for the weird outages that stay green///own your demo. see every receipt.
oops report / inv_a / livefault 0x01
01GET /invoices/inv_a 200 ok
02expected 1299 minor units · observed 129900
03× legacy rollback: tenant boundary missing
04× prior rollback: retired schema field
05✓ forward repair: current floor, five checks passing
06✓ live gateway switched · public probes passing

recovery with receipts.

01 / watch

catch the silent break

watchpoints check customer promises, not just uptime. a reachable api can still return the wrong money.

02 / investigate

replay today's rules

an agent checks old releases against the current tenant boundary and schema. rejected candidates show their failed checks.

03 / recover

ship the safe path

a constrained patch runs in an isolated container. the gateway changes only after the same artifact passes the unchanged floor.

the receipt is the product.

each oops keeps the counterexample, approved policy source, candidate matrix, scanner findings, artifact hash, deployment action, and fresh public verification. the demo uses synthetic invoices and your own isolated service.

see it break. watch it recover. ↗
200http status, still wrong3+recovery candidates compared5current watchpoints enforced