About ScreenPath
An open-source experiment exploring whether external operational failure signals can become useful inputs into financial-services control assurance.
The thesis
Learn from failures outside your walls before reproducing them inside your own.
Module 1 converts governed external discovery into evidence-grounded FailureShapes and themes. Future modules connect those patterns to enforcement, policy change, internal controls and deterministic non-production assurance.
This is a public preview. It serves a captured, read-only snapshot of investigations that really ran against live sources. Starting new investigations and scheduled monitoring are disabled here so that anonymous visitors cannot spend search, regulator-API or model budget — both run in a self-hosted deployment.
Truth model
ScreenPath keeps these four states apart on purpose. Collapsing them is how an intelligence product starts claiming things it has not established.
- DISCOVERED
- A source says this exists. ScreenPath holds the metadata — title, URL, domain, rank — and nothing more.
- OBSERVED
- ScreenPath was permitted to acquire the content, and holds it with its provenance.
- INFERRED
- An interpretation drawn from observed evidence. Always attributed, never presented as proof.
- PROVEN
- A deterministic assertion engine executed a test and recorded the outcome. Module 1 never claims this.
A model interprets evidence. A model never determines PASS, FAIL or compliance. Every model assessment must validate against a canonical schema, agree with its own extracted features, and quote the evidence verbatim — or it is discarded. Deterministic proof belongs to a later module and is not claimed anywhere in Module 1.
Roadmap
Known limitations
- Public search providers frequently do not expose a trustworthy publication date. Undated evidence is deliberately excluded from current-period incident claims rather than assumed recent.
- Investigations are anchored to an approved institution registry. Source applicability, alias matching and CFPB coverage are reference data, not runtime guesses.
- A local model host is supported for private self-hosted use, but is never part of the hosted runtime.
- Modules 2–8 are not built. Nothing in this product proves a control passes or fails.
Built in public
Fork it, test the assumptions, open an issue, propose a failure family, improve a provider, or contribute a module.
View on GitHub ↗