1sealsemantic last-mile verification

for the agent and for us · one stylesheet, one vocabulary

Receipt

Paper, ink, rules, monospace for evidence, stamps for status. One brand accent. Visual clarity helps inspection; it is not evidence of correctness or trustworthiness.

Source of truth: styles/seal.css. Everything below is a rendering of it. System fonts only (CSP). Light and dark via prefers-color-scheme.

01

Colour

paper--paper · #f6f4ef
page ground

paper-2--paper-2 · #efece5
recessed cells, table heads

ink--ink · #15181a
text, rules, filled buttons

ink-3--ink-3 · #6b7075
kickers, meta, gaps

seal--seal · #0f4c5c
the one accent: links on hover, primary count, PASS, layer 4

crit--crit · #a3261c
critical ≥ 9.0 · FAIL reason · read errors. never brand

high--high · #8a5a00
high 7.0–8.9 only

rule-soft--rule-soft · #cfcbc2
1px inner dividers

Rule. Medium and low severity get no colour — ink and grey. If everything is coloured, nothing is critical.

02

Type

h1The signature is perfect. The payload is wrong. lede · 18px ink-2One paragraph that states the claim and its boundary in the same breath. h2 · 22–26px 800

What a PASS means — and what it does not

body · 16px/1.55Sentence case. One claim per paragraph. Max measure 64ch. kicker · mono 12px upperoffline · deterministic · no llm evidence · monoCVE-2026-33211 · F-TEKTON-001-001 · sha256:9f2c…a1 · v1.9.2

Rule. If it is an identifier, a hash, a version, a score or a code — monospace. If it is a sentence — sans. The reader must be able to tell evidence from prose without reading.

03

Stamps

patchedmergedfixed publiclyfixed before reportaccepted · pendingFAIL · RC.REGISTRY_MISMATCHcvss 8.7CVEUNSIGNED · preview build
.stampdefault — a state upstream confirmed: patched, merged, applied. .stamp.softgrey — kind labels, and states we report but did not receive credit for. .stamp.sealaccent — accepted by a maintainer, publication pending. Excluded from counts. .stamp.crit / .highseverity only. Never for emphasis.

Rule. A stamp is a fact someone else confirmed. Never stamp our own claims — VERIFIED appears only when the verifier returned it.

04

Components

.hd / .nav2px bottom rule, wordmark + small descriptor, lowercase nav, current = 2px ink underline. .doc / .sec / .margDocument grid: numbered sections left (56px gutter for §), 280px margin notes right. Every secondary page is this grid. .hero / .dial / .tick / .ledgerVerdict instrument. The word is a stamp impression — ink at 70% through a noise mask, no frame, no tilt. Reason code in mono grey; red only for the code and the failing ledger row. 40-cell tick bar, 4-row layer ledger. .counts / .count.primaryTotals strip: one dominant number in accent, others equal; 1px inner dividers, 2px top rule. .org-stripBoxed organisation grid: name, proportional bar and record count; six columns on desktop, three on tablet, two on mobile. Informational, with no selected state or filtering action. Expansion only reveals more cells. .distributionMatching informational views for Security areas and Failure mechanisms. Label, count and decorative proportional bar; three columns on desktop, two on tablet, one on mobile. No buttons, hover states or filtering. Areas count records, mechanisms count finding IDs; do not add the views together. Selection belongs in Browse filters. .ws / .rail / .appliedOne Browse records workspace for search and checkbox filters. Apply filters commits the draft selection; applied chips, Clear all and result counts sit beside the list. Mobile collapses the filter panel, not search. .row / .detailRecord row: severity cell 64px, id + kind stamp + repo, one-line summary, status stamp, ▸ evidence. Drawer: dl of facts, decoded CVSS vector, “what this record does not claim”. .rule-table / .patterns / .twocol / .timeline / .calloutDocument blocks for secondary pages. All ruled, no shadows, no radii. .state / .state.errEmpty (dashed) and error (crit left rule). Error withholds the list rather than showing stale data. .sigSignature block. Hash, key id, date, verify button. Stamp reflects the verifier result and nothing else.
5authorization OPA, Cedar4semantics LMV · 1seal3provenance SLSA, in-toto
04b

Data, code and archive

classuserule
.table / .table-wrapany table of factsmono uppercase heads, 1.5px rule under the head, 1px between rows, no zebra, no cell borders. Always wrapped for narrow screens.
pre.codeconfig and payloadsrecessed ground, 2px left rule, comments in <b> grey. Never a fake terminal, never a window chrome.
.steps / .stagesflows and lifecyclesmono counter or mono term in a fixed gutter; collapses to one column under 640px.
.modesthe three ways to read researchone ruled row, current mode inverted. Not tabs — each target is a real anchor.
.hlcurated highlightsscore · id + one sentence · status. The sentence says what the record demonstrates, not how severe it is.
.archive-barsuperseded pagesfirst element inside main, before the h1. Grey, never red — archived is not broken.
.captionunder any table or diagramcarries the limit of what the thing above proves. A diagram without a caption is an unlabelled claim.
archived

This is the archive bar as it appears in place: same header and footer, same stylesheet, unmistakably not current.

degraded_mode:
  container:      fail_open_with_audit   # dev
  container_prod: fail_closed            # prod
05

Rules that are not about pixels

always

Every capability claim has its boundary in the same section.
Every number links to the data it came from.
Missing data reads not recorded — never hidden, never invented.
Empty states say “absence is a filter result, not a claim”.

never

Emoji. Gradients. Rounded corners. Shadows.
Red for brand or emphasis.
Marketing superlatives — the record speaks.
A stamp for something we assert about ourselves.

Accessibility target. Visible 2px accent focus, textual state labels, reduced-motion support and native controls. These design rules are not a claim of a completed WCAG conformance audit.