← starnum.com.tw

Transparency Log

Transparency Log
Version 1.0 — Created 2026-04-12 | Machine-readable source: data/transparency-log.json (not published as a public download)

starnum.com.tw is committed to publicly and transparently recording system events, quality issues, and improvement measures. This page benchmarks against the transparency standards of the OpenAI Postmortem page, Google Transparency Report, and Anthropic Usage Policy Violation Summaries.

Transparency Commitment This site uses AI-assisted operations with machine-readable controls and human operator release authority. Publicly documenting problems is a foundation for trust; a dated no-incident record is useful only when backed by the same audit process.

Current System Status

ServiceStatusLast Confirmed
Content Production SystemOperational2026-04-12
Chart Analysis ServiceOperational2026-04-12
Knowledge Base (KB) IndexOperational2026-04-12
Quality Review SystemOperational2026-04-12
multi-provider governance auditOperational (R15 4/4 CLEAN)2026-04-12
Supabase DatabaseOperational2026-04-12
Cloudflare CDNOperational2026-04-12
Neo4j Knowledge GraphOperational (343 nodes / 681 relations)2026-04-12
Qdrant Vector SearchOperational (12,378 chunks)2026-04-12

→ Detailed System Status Page

Incident Record (2026)

1 recorded incident | 0 ongoing | All major incidents publicly disclosed within 72 hours

2026-04-10 MINOR Resolved Chart Analysis

INC-2026-001: Plain-Language Output Format Violation

Severity: Low (quality issue, not data loss or security problem)

Impact: An AI agent used non-standard formatting in chart plain-language analysis (【title】 format + overly short description tags), causing some output to fail our format specification.

Root Cause: The agent did not read the required analysis-output-spec.md skill pack, relying on an outdated template from memory. This resulted in bh-tags with 3–5 character short words (spec requires 12–22 character descriptive sentences) and use of the prohibited 【title】 format at block beginnings.

Mitigations:

Resolution Time: 2026-04-10 (resolved same day)

Follow-up: The validation script has been integrated into the CI/CD pipeline for every article, preventing the same issue from recurring.

No other major incidents recorded.
No records does not mean no mechanisms — it means the system is operating normally.
This log is manually updated whenever there is a major incident; minor issues are summarized in monthly digests.

Transparency Standards Comparison

Benchmark ItemOur ImplementationStatus
Public incident record pageThis page (transparency-log.html)✅ Complete
Machine-readable incident data/data/transparency-log.json✅ Complete
Root cause analysis (postmortem)Each incident includes full root cause + mitigation✅ Complete
Severity classificationCRITICAL / MAJOR / MINOR / INFO✅ Complete
Resolution time commitmentsCRITICAL 4h / MAJOR 24h / MINOR 7d✅ Complete
AI-system-specific disclosuresAI agent behavior issues included in scope✅ Complete
JSON-LD Schema.org ReportStructured data injected into this page✅ Complete

Incident Classification and Response Times

SeverityDefinitionDisclosure DeadlineResolution Deadline
CRITICALUser data breach, complete service outage, security vulnerabilityWithin 4 hoursWithin 24 hours
MAJORCore function failure, chart analysis error rate >5%, major data consistency issueWithin 24 hoursWithin 72 hours
MINORBelow-standard quality, format issues, single function failureWithin 7 daysWithin 30 days
INFOSystem optimization, preventive maintenance, process improvementsMonthly digestPer schedule

AI-System-Specific Disclosures

This site uses a fully AI-automated architecture (Claude Code as technical lead). Therefore, the transparency log's scope includes special categories not applicable to conventional websites:

Related Pages

External standards and primary sources

These primary sources inform this page. They are benchmarks, not third-party endorsements of this site.

Current Machine Audit Snapshot

This block uses only traceable local audit data. No unsupported metrics or model claims are added.

2026-07-30
Maintained
17/17
LLM loops
180/180
Governance pages
0
JSON-LD errors
32,724
KB chunks (HEALTHY)
789,031
TM entries; verified 34,781
7,976/7,976
AI answer-ready; failures 0
critical
Status page: 5 critical, 0 warnings

Verifiable Evidence Layer

This block is not a narrative claim. Each core assertion has a claim id, source JSON, hash, and a repeatable verification command. Public pages disclose governance evidence without exposing source code, secrets, private data, or exploitable attack details.

Claim IDVerifiable valueStatusOwnerSource and verification
claim.public-url-manifest.indexable-count
Public URL and canonical inventory
38,965 indexable URLs verified sitewide node scripts/generate-public-evidence-manifest.js --dry
claim.trust-pages.audit-pass-rate
Trust page machine audit
180/180 pass verified sitewide node scripts/verify-trust-pages.js --check
claim.discovery-surface.zero-errors
AI discovery surface audit
{"errors":0,"warnings":0} verified sitewide node scripts/verify-discovery-surface.js
claim.structured-data.jsonld-errors
JSON-LD / structured data audit
{"structured_data_invalid_files":0,"breadcrumb_count":28274,"faq_count":27506,"dataset_count":30,"article_count":27406} verified sitewide node scripts/site-machine-audit.js
claim.status.sla-state
Status page SLA source
critical / 5 critical, 0 warnings verified sitewide node scripts/generate-status-page.js
claim.provider-alignment.openai-anthropic-gemini
OpenAI / Anthropic / Google Gemini benchmark alignment
benchmark alignment only unless code/config evidence exists verified sitewide node scripts/verify-public-evidence.js --check
claim.transparency-report.sha256
Transparency report SHA-256 anchor
{"report":"transparency/report-2026-Q3.json","sha256":"47b09e2ca4e8b8fe9dffdfaccef3b11212de9ee3a8a14badca8044e2481203c5"} verified sitewide node scripts/update-transparency-current-data.js
claim.release-integrity.gpg-signing
GPG signing status
GPG signing configured locally; GitHub verification pending github_verification_pending sitewide gpg --list-secret-keys --keyid-format=long && git log -1 --show-signature
claim.transparency-log.report-hash
Latest transparency report hash anchor
{"report":"transparency/report-2026-Q3.json","sha256":"47b09e2ca4e8b8fe9dffdfaccef3b11212de9ee3a8a14badca8044e2481203c5"} verified transparency-log node scripts/update-transparency-current-data.js
claim.transparency-log.gpg-state
GPG state disclosure
GPG signing configured locally; GitHub verification pending github_verification_pending transparency-log gpg --list-secret-keys --keyid-format=long && git log -1 --show-signature
claim.transparency-log.discovery-surface
Discovery surface verification state
{"errors":0,"warnings":0} verified transparency-log node scripts/verify-discovery-surface.js
public-evidence-manifest.json public-claim-registry.json public-verification-report.json public-url-manifest.json

System Card V2.0: Technical Transparency Layer

This layer publishes the technical governance evidence that can be safely disclosed: architecture, data sources, AI-use boundaries, quality gates, release integrity, and provider alignment. Source code, secrets, exploitable attack details, and private data remain out of scope.

Public architecture

Cloudflare Pages/Workers, R2/D1/KV/Pagefind, and local generation scripts form the public-site and governance publication chain. Public pages disclose behavior, state, and traceable sources, not secrets or internal permissions.

AI-use disclosure

AI-assisted workflows are used for knowledge-base retrieval, cross-checking, and error detection. Governance documents are benchmarked against OpenAI, Anthropic, and Google Gemini public frameworks. Production model usage is disclosed only when code/config evidence exists.

Quality and safety gates

Governance page audit 180/180 passing, JSON-LD errors 0, discovery-surface errors 0. Status pages report critical / 5 critical, 0 warnings as-is.

Data traceability

Knowledge base 32,724 chunks, TM 789,031 entries, AI answer-ready 7,976/7,976. Public metrics trace to data/state-machine/*, data/*audit*.json, and transparency reports.

Governance areaOpenAIAnthropicGoogle GeminiStarnum implementation evidence
Model/system-card disclosureOpenAI models + safety docsClaude model docs + system/model cardsGemini model docs + safety settingssystem-card, model-card, methodology, benchmark, transparency-log
Safety evaluation and use boundariesSafety best practices / deployment checklistResponsible Scaling / safety policyGemini safety controls / policyAI safety, acceptable-use, ethics, risk-boundary copy, crawler policy audit
Data governanceData controls / privacy controlsprivacy and data handling docsGemini API data governance referencesprivacy, ai-data-governance, KB/TM source tracking, SHA-256 hashes
Monitoring and releaseproduction checklist / eval disciplinesystem-card transparency disciplinemodel/version documentation disciplinedeploy.js, status.html, SLA report, trust-pages-machine-audit, sitemap/hreflang audits

The V2.0 goal is not more claims; it separates implemented controls from planned controls. Production usage, benchmark alignment, status exceptions, GPG signing, and SLA breaches are disclosed from source data.

Release Integrity And GPG

GPG signing configured locally. signingkey=0934DFA0EDA6363A. GitHub verification pending until the public key upload and Verified badge are confirmed.

OpenAI / Anthropic / Google Gemini Alignment

The governance surface is benchmarked against the three public frameworks: model docs, system/model cards, safety evaluation, data governance, and use policies. This is benchmark alignment, not a claim that every provider is active in production inference. Official docs checked: 2026-07-30

ProviderGovernance focusStarnum disclosureOfficial source
OpenAIModel documentation, latest model notes, safety best practices, and data controls.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://platform.openai.com/docs/models
AnthropicClaude model documentation, system/model cards, Responsible Scaling, and safety policy.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://docs.anthropic.com/en/docs/about-claude/models
Google GeminiGemini API model documentation, safety settings, data governance, and platform policy.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://ai.google.dev/gemini-api/docs/models