telemetry-leak-lab
What can survive log and trace redaction, and how to check without losing useful signals.
Explore case and demo ↗IX / ENGINEERING LAB
Small tools for important questions. I explore how to demonstrate that a system responds correctly, especially when something goes wrong.
01 / FALSE-GREEN
Public alpha · verified locallyOne checkout. Five deliberate faults. Two ways to verify the same journey. The report shows why passing a test is not enough to trust what it checks.
SUPPLIED REPORT / 18 SEP 2026
Two repetitions per phase, with clean controls before and after. Reported results, not a new execution on this website.
| Injected fault | Weak suite | Behavior suite |
|---|---|---|
| Checkout button does nothing | Not detected | Detected |
| Product image cannot decode | Not detected | Detected |
| Shipping information is invisible | Not detected | Detected |
| Confirmation copy is corrupted | Not detected | Detected |
| Explicit accessible label is removed | Not detected | Detected |
The result describes sensitivity to five configured faults. The report’s combined 50% mixes two deliberately different suites; it is not a product quality or coverage score. A fault that never applies is neither detected nor survived.
The alpha was recovered and verified on September 19, 2026: clean installation, 71 unit, 18 offline browser and 20 HTTP tests passed on Windows with Node 24.15.0, Playwright Core 1.56.1 and Chromium 141.0.7390.37. The demo reproduced the displayed contrast. Local validation is not universal compatibility or an independent security audit. See the repository for the separate CI status.
02 / HEALTH-INTEROP-LAB
A clinical interoperability lab already documented in the portfolio. The repository now includes a reproducible Angular → HTTP → gRPC journey, using synthetic data and explicit unavailable states.
Read the existing case ↗PUBLIC TOOLS / SYNTHETIC SECURITY EXPERIMENTS
What can survive log and trace redaction, and how to check without losing useful signals.
Explore case and demo ↗A business question made testable: can one organization read another’s records?
Explore case and demo ↗03 / RESEARCH AGENDA
Six proposals to build and validate. Working names; these are not available products or delivery commitments.
Contracts that distinguish facts, estimates and hypotheses before publication.
Adversarial synthetic scenarios for health integrations.
Explainable decision comparisons across rule versions.
Compare declared routes, links and observed journeys by role.
Idempotency, totals and rounding properties using fictional money.
Agent tool errors and retries without real-world effects.
PUBLICATION STANDARD
Readable code, reproducible installation, synthetic examples and clear limits. Each tool will have its repository when it is ready to be tested.
My GitHub profile ↗FROM EXPERIMENT TO DECISION
The technical and strategic diagnostic turns a scoped question into a system map, prioritized findings and an actionable roadmap. Scope and access are agreed before any work.
Prepare my diagnostic ↗