The Operating Standard
Every visit, a certificate.
Every certificate, a proof.
The architecture below is what runs underneath every SFMG visit. The certificate that follows is a real attendance — by today's house in rotation. Photographs and coordinates are abstracted for public display; the operational signals are not.
Today's record · 30 July 2026
A live attendance, witnessed.
Service
routine maintenance
GPS verified at location
12 of 14
Photographic record
Cells anonymized for public display. Real boutique photographs remain private to the client. Each cell's verification stamp is the same stamp the client receives on the live certificate.
Provenance ledger · sample
#01
25.813, -80.192
Captured 1:14 PM · 4m from check-in
Verified#02
25.813, -80.192
Captured 1:18 PM · 5m from check-in
Verified#03
25.813, -80.192
Captured 1:21 PM · 3m from check-in
VerifiedArchitecture
What you would expect from a discretionary supplier — formalized.
Photographic provenance
Every completion photograph carries the device's embedded GPS coordinate and capture timestamp. On upload, the platform extracts the EXIF metadata, computes the distance to the partner's on-site check-in coordinate, and verifies the photograph at the location only when both fall within 100 meters. Every photograph also carries a SHA-256 image hash; the same image cannot certify two visits.
- EXIF GPS extraction · server-side at upload
- Haversine verification · 100-meter radius
- Image hash · SHA-256, cross-job dedup
Cryptographic audit log
Every action — every command issued, every reply returned, every tool invoked — is written to an append-only log signed with a workspace HMAC key. The log is tamper-evident: any post-hoc modification breaks the signature chain and is detected on read. Retention is indefinite. The record of any conversation, any commitment, any decision is recoverable on demand with cryptographic verification.
- Append-only · per-actor JSONL stream
- HMAC-SHA-256 signature · per record
- Indefinite retention · queryable
Partner verification scoring
Each service partner is scored continuously across attendance verification rate, completion timeliness, and visual standard adherence. Partners drift below 95% verified attendance enter a watch band; below 85% enter at-risk and are reviewed for cause. The score is computed daily; changes are alerted before they reach the client.
- Trusted ≥ 95% · Watch 85–95% · At-risk < 85%
- Reviewed daily · 90-day trailing window
- Alerts trigger before client impact
Kill switch
A single command halts every automated action across the platform. Every consequential action requires founder approval. There is no autonomous spending, no autonomous communication, no autonomous infrastructure change. The platform is built to do significantly more than it ever does without explicit authorization.
- Founder-controlled · single command halt
- Per-day spend cap · auto-engages on breach
- No autonomous client communication
Cross-system reconciliation
Every night, the platform reconciles itself. Completed visits are matched against issued invoices. Issued invoices are matched against accounting records. Partner compliance documents are checked against expiration. Locations without recent service are flagged. Discrepancies are surfaced before they reach the client or accounting team.
- Nightly · seven cross-system checks
- Surfaces drift · before operational impact
- Read-only · raises, does not auto-resolve
Practice
Operating since 2020. By private arrangement only. A small number of luxury houses across the United States, under continuous attendance.