DO NOT TAKE OUR WORD FOR IT
Every number on the benchmark page is either computed in your browser while you
watch, or published as data with its denominator attached. Nothing here needs an
account, a key, or a conversation with us.
WHY THIS MIRROR CARRIES NO FIGURES
The live page renders its measurements from a machine-readable file rather than
from copy, so the numbers cannot drift out of step with the registry. This mirror
deliberately does not restate them. Read them at the source instead:
https://bidda.com/api/v1/proof-dossier.json
That file publishes every measurement together with its denominator and its
method, alongside the known defect counts described below.
EVERY MEASUREMENT, WITH ITS DENOMINATOR
The proof dossier reports strengths and defects in the same file. The defect
counts it carries include:
- nodes below the declared structural floor
- framework identifiers that resolve to nothing in the issuing authority's
published catalog
- source URLs that now return 404
- metadata fields present on only a subset of nodes
An unresolved identifier is a control or technique id in a crosswalk that
resolves to nothing in the issuing authority's published catalog. It is a
mapping error, not a change to the regulatory text or the source citation.
FOUR CHECKS THAT DO NOT INVOLVE US
1. Recompute the registry root.
Fetch https://bidda.com/api/v1/integrity-manifest.json, build an RFC 6962
Merkle tree over the published leaf format, and compare the root to
https://bidda.com/api/v1/registry-checkpoint.json
2. Check a framework identifier at the source.
Take any control id from a node crosswalk and look it up in NIST's own OSCAL
catalog or the MITRE ATT&CK matrix. The resolution figures on the page are
that check, run across every identifier in the registry.
https://bidda.com/api/v1/proof-dossier.json
3. Verify a single node against its regulator.
Fetch https://bidda.com/api/v1/verify/{node_id}.json for the source URL, the
content hash and the fingerprint time, then open the instrument and read it.
https://bidda.com/verify
4. Watch for decay.
A deterministic sample is re-verified on a schedule and the failure count is
published whether it is zero or not.
https://bidda.com/api/v1/regression-health.json
ON SELF-REPORTING
These figures are produced by our own scripts against our own registry. They are
not independently audited, and the dossier says so on its face. What makes them
checkable is that the method for each is published, and the third-party catalogs
used (MITRE ATT&CK, NIST OSCAL) can be queried directly, so a reader can repeat
the measurement against the authority rather than against us.
RELATED
Methodology .................. https://bidda.com/methodology
Trust and proof surfaces ..... https://bidda.com/trust
Transparency log ............. https://bidda.com/transparency
Registry health .............. https://bidda.com/api/v1/registry-health.json
Research and method .......... https://bidda.com/research