FunctionFoundry keeps the contract, test evidence, security posture, artifact digest, commercial rights, entitlement, and audit history connected to one immutable capability version—and labels build-cost estimates separately from recorded facts.
ARTIFACT 0ecdb1c0…b93aa
download → verify entitlement → stream digest-pinned artifact → audit
The evidence bundle is useful because its records agree on capability, version, artifact, organization, and rights. A hidden download URL is never treated as authorization.
Build-versus-buy only earns trust when every number carries its source. FunctionFoundry separates stored events, seller declarations, planning assumptions, and external data the prototype does not possess.
Evaluations, wallet transactions, purchases, issued licenses, entitlements, downloads, and audit records stored by FunctionFoundry.
Integration hours, supported runtimes, deployment targets, test claims, and evidence attached to a capability manifest.
Token, agent-runtime, CI-cycle, review-hour, engineering-effort, and cost ranges derived from visible planning assumptions.
Model-provider bills, coding-agent traces, CI invoices, human time systems, and a counterfactual completed internal build.
This prototype demonstrates credible boundaries without representing a fixture scan, local object store, or simulated payment as production assurance.
Today, evaluations use deterministic fixtures. The repository also defines a disabled future isolated-job path, but it remains gated until a reproducibly built runtime and disposable-node conformance report exist.
The concise threat model covers malicious sellers, artifact replacement, license bypass, cross-tenant access, duplicate purchases, manipulated economic estimates, agent overspending, runner escape, and provenance tampering. A favorable model never bypasses purchase policy.
Resolve resources through the authenticated organization, return scoped not-found responses, and test negative access paths.
Require explicit confirmation, per-transaction and daily limits, idempotency, server-side authorization, and auditable policy decisions.
Pin version and SHA-256 digest in provenance, receipt, entitlement, and download records; surface revocation without deleting history.
Keep the fixture runner as default and require isolated ephemeral workers, default-deny egress, resource bounds, and conformance before enabling code execution.
Events record actor type and identifier, organization, target resource, request ID, timestamp, and structured metadata for admin review.
Compatibility 94 · fixture result retained
Demo wallet policy approved $799.00
Commercial source · version 1.1.0
Organization entitlement verified
Open a real seeded listing to inspect its contract, evidence, license terms, raw manifest, artifact checksum, and explicit prototype disclosures.
Ready for review