Quality & evidence

Better software.
A standard we have to earn.

Our ambition is to build systems that outperform human-developed software in correctness, security and maintainability. We are starting with Syndical itself, and making the evidence visible.

The current record

Measured on our own repositories

Download scorecards

Each result describes the checks that actually ran. A passing check covers its stated scope; it does not establish the quality of the whole system.

Commands and policy are provided. Rerunning source checks requires access to the measured repositories.

Syndical

Quality

70/100

Maintainability

93/100

Static security checks

High severity

0 critical · 1 high · 0 medium · 0 low
5 qualified rules · findings require review

529 / 749 files without configured warnings or errors.

11332 / 12145 recognized functions within every limit. 1.53% of tokens duplicated.

Measured 3 October 2026 · b18c880cbbff

Coverage & evidence

749 selected production files. csharp: 544 · javascript: 7 · typescript: 198.

  • Native checks: 749 / 749 files analyzed
  • Function analysis: 749 / 749 files analyzed
  • Duplication: 749 / 749 files analyzed
  • Security checks: 749 / 749 files analyzed

Function limits: complexity ≤ 15, lines ≤ 80, parameters ≤ 5. Maintainability takes the lower of 93% function compliance and 98% duplication-free tokens. Function parsing limitations are recorded below.

Duplication: at least 5 lines and 50 tokens, mild mode.

Qualified security checks

  • HttpClientHandler certificate callbacks that explicitly accept every certificate. (high; csharp).
  • Explicit rejectUnauthorized:false settings and NODE_TLS_REJECT_UNAUTHORIZED=0 assignments. (high; javascript, typescript).
  • BrowserWindow object literals explicitly disabling context isolation. (high; javascript, typescript).
  • BrowserWindow object literals explicitly enabling renderer Node integration. (medium; javascript, typescript).
  • Direct console arguments named password, token, key or client secret; this is not a dataflow rule. (high; javascript, typescript).

Included roots: apps/, libs/. Extensions: .cs, .ts, .tsx, .js, .jsx, .mjs.

Excluded paths and suffixes: test, tests, fixtures, bin, obj, node_modules, out, dist, resources, .test.ts, .test.tsx, .spec.ts, .spec.tsx, .d.ts, .g.cs, .generated.cs.

Gate: passed. Accepted existing findings still count in these scores.

Findings beyond the accepted baseline: 0.

Policy: syndical-oss-quality-v1

  • Scores measure compliance with this named profile; profiles can differ between languages and repositories.
  • Quality measures configured native warnings and errors, not functional correctness or test effectiveness.
  • C#, Swift and Python functions are recognized heuristically by Lizard; their detection is not compiler-proven complete. JavaScript/TypeScript uses the TypeScript syntax tree.
  • Security covers only the named qualified rules. Dependencies, secrets, runtime behavior and broader dataflow are not assessed here.
  • No overall quality or human-superiority claim is supported by this scorecard.
Download full scorecard

Report SHA-256 b2cff48d9f15b6ee656d4f5f4b51fd6d5c80ab3d6f79d28e403237c535533f35

Syndical.mobile

Quality

71/100

Maintainability

94/100

Static security checks

No findings

0 critical · 0 high · 0 medium · 0 low
4 qualified rules · findings require review

32 / 45 files without configured warnings or errors.

369 / 390 recognized functions within every limit. 1.03% of tokens duplicated.

Measured 3 October 2026 · cde32592f7ec

Coverage & evidence

45 selected production files. swift: 45.

  • Native checks: 45 / 45 files analyzed
  • Function analysis: 45 / 45 files analyzed
  • Duplication: 45 / 45 files analyzed
  • Security checks: 45 / 45 files analyzed

Function limits: complexity ≤ 15, lines ≤ 80, parameters ≤ 5. Maintainability takes the lower of 94% function compliance and 98% duplication-free tokens. Function parsing limitations are recorded below.

Duplication: at least 5 lines and 50 tokens, mild mode.

Qualified security checks

  • Direct MD5/SHA-1 calls require a non-security rationale or a modern cryptographic algorithm. (high; swift).
  • Direct UserDefaults.standard writes with explicit credential key names. (high; swift).
  • Enabling universal network access from WebView file URLs. (high; swift).
  • Passing copied trust exceptions straight back into TLS trust evaluation. (high; swift).

Included roots: SyndicalApp/Sources/, SyndicalApp/App/. Extensions: .swift.

Excluded paths and suffixes: tests, uitests, fixtures, .build, build, deriveddata, desktopviews, assets.xcassets, resources, Fixtures.swift, ConnectionUITestFixture.swift.

Gate: passed. Accepted existing findings still count in these scores.

Findings beyond the accepted baseline: 0.

Policy: syndical-mobile-quality-v1

  • Scores measure compliance with this named profile; profiles can differ between languages and repositories.
  • Quality measures configured native warnings and errors, not functional correctness or test effectiveness.
  • C#, Swift and Python functions are recognized heuristically by Lizard; their detection is not compiler-proven complete. JavaScript/TypeScript uses the TypeScript syntax tree.
  • Security covers only the named qualified rules. Dependencies, secrets, runtime behavior and broader dataflow are not assessed here.
  • No overall quality or human-superiority claim is supported by this scorecard.
Download full scorecard

Report SHA-256 513da646fe86e25998e089b1a56148f7a4ccc610360ef32bd3723bd9359b1a9b

Syndical.site

Quality

100/100

Maintainability

100/100

Static security checks

No findings

0 critical · 0 high · 0 medium · 0 low
2 qualified rules · findings require review

67 / 67 files without configured warnings or errors.

303 / 303 recognized functions within every limit. 0.00% of tokens duplicated.

Measured 3 October 2026 · 013f14f35db5

Coverage & evidence

67 selected production files. javascript: 5 · python: 8 · typescript: 54.

  • Native checks: 67 / 67 files analyzed
  • Function analysis: 67 / 67 files analyzed
  • Duplication: 67 / 67 files analyzed
  • Security checks: 67 / 67 files analyzed

Function limits: complexity ≤ 15, lines ≤ 80, parameters ≤ 5. Maintainability takes the lower of 100% function compliance and 100% duplication-free tokens. Function parsing limitations are recorded below.

Duplication: at least 5 lines and 50 tokens, mild mode.

Qualified security checks

  • Credential-shaped values passed directly to browser console methods (high; typescript, javascript).
  • Explicit shell=True subprocess calls require review (medium; python).

Included roots: app/, components/, icons/, illustrations/, lib/, providers/, infra/, next.config.ts, postcss.config.mjs. Extensions: .ts, .tsx, .js, .mjs, .py.

Excluded paths and suffixes: test, tests, fixtures, node_modules, dist, __pycache__, .test.ts, .test.tsx, .test.mjs, .d.ts, infra/test_.

Gate: passed. Accepted existing findings still count in these scores.

Findings beyond the accepted baseline: 0.

Policy: syndical-site-quality-v1

  • Scores measure compliance with this named profile; profiles can differ between languages and repositories.
  • Quality measures configured native warnings and errors, not functional correctness or test effectiveness.
  • C#, Swift and Python functions are recognized heuristically by Lizard; their detection is not compiler-proven complete. JavaScript/TypeScript uses the TypeScript syntax tree.
  • Security covers only the named qualified rules. Dependencies, secrets, runtime behavior and broader dataflow are not assessed here.
  • No overall quality or human-superiority claim is supported by this scorecard.
Download full scorecard

Report SHA-256 4db59e116288327819e1209c22c3565d0b3afe80566d504b601a4d0cc7da5406

How to read these scores

Quality is the percentage of checked production files with no configured native warnings or errors. Build and test outcomes remain separate evidence below.

Maintainability is the lower of recognized function compliance and duplication-free tokens. Scores round down; 100 requires complete compliance with the stated profile.

Security shows the highest flagged severity and findings to review in qualified rules. Missing or incomplete scans say Not measured. No findings does not mean the system is proven safe.

Profiles differ by language and repository. These scores describe their stated scope, not a ranking across projects or evidence of superiority to human development. There is no blended overall score.

Build, test & earlier measurement evidence

Syndical

Open findings

Desktop application and orchestration runtime

  • .NET buildPassed

    The solution build completed with the repository warnings-as-errors policy.

  • .NET regression testsFailed

    6,854 of 6,857 tests passed; 3 failed and 0 skipped. 16 of 16 projects measured.

  • TypeScript regression testsPassed

    1,482 of 1,482 tests passed; 0 failed and 0 skipped. 2 of 2 workspaces measured.

  • TypeScript typecheckPassed

    The configured workspace typechecks passed.

  • Desktop production buildPassed

    The desktop production build completed.

  • Production code duplicationMeasured

    1.77% of analyzed source lines were flagged as duplicated (3,270 of 185,124). 738 of 748 selected files measured; advisory finding level.

  • Estimated complexityMeasured

    Token-based file estimates across 738 measured files: median 35, 95th percentile 221. Advisory screening, not verified per-function complexity.

  • npm dependency advisoriesFailed

    12 dependency entries flagged: 10 high, 1 moderate and 1 low severity. Includes production and development dependencies at measurement time.

Measured 3 October 2026 · revision e1c835c958f8

Local macOS run · Node.js 22.15.1 · .NET SDK 9.0.301 · source held stable

Scope, limitations & reproduction

Source content SHA-256558583b61927752a7a4ce71a6a813380d6cee8dbca47cdcc8345687408302437

Read the full measurement report
Measurement methodology and scope

Read the exact scope, reproduction commands, measurement limitations and proposed controlled comparison for this snapshot.

Current measurement policy

The original machine-readable policy used for this measurement.

Initial baseline · 3 October 2026

The initial run, using instrument revision 938ac2978b1a on source c487d771442d, recorded 7 TypeScript test failures and 12 dependency entries flagged (10 high-severity). The .NET measurement was incomplete after an earlier 20-minute instrument limit; its test counts cover only 15 of 16 projects. This snapshot uses earlier instrumentation and is not an equivalent-scope comparison.

Initial baseline measurement policy

The original baseline policy is retained alongside its report.

Intermediate measurement · 3 October 2026

At revision bf73ebf41c8f, 2 TypeScript tests failed and npm flagged 12 dependency entries. The .NET measurement covers 15 of 16 projects, with 2 failures in those completed projects. A nonterminating test fixture required an explicit stop of the orchestration test project; this was an operator intervention, not a configured deadline. Incomplete counts are not full-suite totals.

Full measurement at dc5861d3 · 3 October 2026

All 16 .NET test projects completed: 6,819 of 6,857 tests passed and 38 failed, with no skips. All 1,482 TypeScript tests passed; npm flagged 12 dependency entries. The failed .NET run is retained here as measured. Subsequent fixture corrections belong to a later source snapshot and do not change this report.

Measurement policy used at dc5861d3

The original policy is retained for this completed attempt. Its scanner size setting comes from the immutable source snapshot, and comparability requires the actual measured-file inventory.

  • This is a local snapshot, not evidence that hosted CI or every deployed version passed. Later fixes require their own measurement before being described as verified.
  • OS-vault integration was disabled for this run; the report records the executed test scope and all outcomes.
  • Duplication and complexity are advisory measurements. Very small files below the scanner token threshold are excluded from measured scope and counted in the report.
  • The earlier attempts used different instrumentation, environments or source scope. No equivalent-scope improvement or causal comparison is claimed.
  • npm flags dependency entries, not necessarily distinct vulnerabilities or confirmed production exploitability. SAST, secret detection, .NET dependency scanning and independent security review remain unmeasured.
  • Coverage, hidden-test or mutation effectiveness, independent maintainability, production reliability and controlled human comparison remain unmeasured.

.NET build

npm run quality:check -- --checks dotnet-build --output .syndical-local/quality/reproduce-dotnet-buildDownload evidence

.NET regression tests

npm run quality:check -- --checks dotnet-build,dotnet-tests --output .syndical-local/quality/reproduce-dotnet-testsDownload evidence

TypeScript regression tests

npm run quality:check -- --checks dotnet-build,typescript-tests --output .syndical-local/quality/reproduce-typescript-testsDownload evidence

TypeScript typecheck

npm run quality:check -- --checks typescript --output .syndical-local/quality/reproduce-typescriptDownload evidence

Desktop production build

npm run quality:check -- --checks desktop-build --output .syndical-local/quality/reproduce-desktop-buildDownload evidence

Production code duplication

npm run quality:check -- --checks duplication,complexity --output .syndical-local/quality/reproduce-duplicationDownload evidence

Estimated complexity

npm run quality:check -- --checks duplication,complexity --output .syndical-local/quality/reproduce-complexityDownload evidence

npm dependency advisories

npm run quality:check -- --checks npm-audit --output .syndical-local/quality/reproduce-npm-auditDownload evidence

Syndical.site

3 checks passed

The public website you are reading

  • Production build and typecheckPassed

    The production build completed and generated the public quality page.

  • Delivery helper regression testsPassed

    64 tests executed successfully, including the real production-build marker check.

  • npm dependency advisoriesPassed

    0 dependency entries flagged by npm at measurement time, including production and development dependencies.

Measured 3 October 2026 · revision b4c3e1c700c8

Local macOS run · Node.js 22.15.1 · implementation measured before commit

Scope, limitations & reproduction

Source content SHA-2567f1d55108a57d52c7504fd4ac6c276784b1f1f809d35c245ef63f6665e3068b7

Read the full measurement report
  • Local execution on macOS with Node.js 22; hosted CI and production publication were not measured in this run.
  • Measured before the page implementation was committed; the source digest includes that working tree. Public result exports are excluded to avoid the report hashing itself.
  • Delivery tests include one real production-build integration check; infrastructure API interactions use fixtures and mocks.
  • No application coverage, mutation testing, SAST, secret scan, independent audit or controlled human comparison is established by these checks.

Production build and typecheck

npm run buildDownload evidence

Delivery helper regression tests

python3 -B -m unittest discover -s infra -p 'test_*.py' -vDownload evidence

npm dependency advisories

npm audit --jsonDownload evidence

Still to measure

  • Coverage of changed code
  • Test effectiveness against hidden or seeded defects
  • Security beyond the published static rules and dependency advisories
  • Independent maintainability assessment
  • Complexity and duplication trends
  • Escaped defects and production reliability
  • Controlled comparison with human development

The engineering foundation

Quality is part of the delivery process

These capabilities exist in Syndical today. The checks and review stages used on a particular change depend on its repository policy and squad.

Executable checks

Repositories can define build, test, lint, coverage and security gates. Teams choose which checks must pass before delivery.

Available · configured per repository

Independent review

Separate reviewer roles examine correctness, test quality, security and engineering standards. Their findings can send work back for repair.

Available · depends on the selected squad

Evidence and bounded repair

Verification records what ran against the change. Repair attempts have limits, and the delivery checks reject missing or stale required evidence.

Implemented · scope and configuration matter

An ambition with a test

What would “better” actually mean?

Fewer defects. Stronger security. Code that is easier to change. Improvements that survive independent evaluation and real use.

Human comparison: not yet measured

These checks do not establish that Syndical outperforms human-developed software. A controlled comparison has not been completed.

Our proposed comparison method

01Agree the experiment first

Define representative tasks, acceptance tests and the primary quality measure before seeing results. Record task selection and sample size.

02Keep the conditions comparable

Use the same starting code and requirements. Record developer experience, tools, model versions, time, compute cost and human interventions.

03Assess independently

Evaluate correctness and security with held-out checks. Have reviewers assess maintainability without knowing who produced the change, where practical.

04Report every outcome

Publish failures and exclusions, sample size, variation and uncertainty. Measure escaped defects over time. Limit every conclusion to the tested tasks and conditions.

Our commitment, in public

Read the publishing policy

01

Measure our own software first

Apply the same scrutiny to Syndical and the website that presents these results.

02

Publish the gaps

Show failed, blocked and unmeasured checks alongside successful results.

03

Make claims traceable

Attach the date, revision, commands and limitations to each published measurement.

04

Raise the standard with evidence

Use defects, review findings and maintainability measures to guide the next improvement.

This page presents our own engineering evidence. It does not claim independent certification. These results are our own measurements; they are not an external audit or accreditation.