Aperture API

Verified facts

Every statement on this page is backed by a committed, independently checkable artifact. Where a figure has no committed artifact, we publish no figure. That rule is why this page is shorter than most vendor claim pages.

Software-defined calibration — live in production

Digital-twin calibration is live on the production API, including the no-account /public/reconstruct endpoint. In the committed closed-loop proof, the optimizer recovered the true pixel pitch to within 0.0005% from a nominal value that was mis-specified by 6%, and the digital twin replicated the measured field to within the optimizer's convergence tolerance.

This is a closed-loop synthetic validation of optimizer convergence and endpoint plumbing — not a physical-target measurement, and we label it as such. Artifact: calibration/results/sdc_end_to_end_hex_nut.json.

Pixel pitch is the parameter we recover well. Wavelength and propagation distance recover far less precisely, and that is physics rather than a defect we are hiding — the two are degenerate in the underlying model.

Deploy provenance you can query

The live /health endpoint serves a full deploy-identity block, and a hash-chained deploy ledger verifies intact from genesis. Both are registered live checks (deploy-identity, ledger-verify) — ask, and the running system answers with a live run.

Data-retention governance, fail-closed

Retention policy is class-keyed with fail-closed owner routing: unclassified data routes to a named data-integrity owner, never to a default. Legal holds are write-once events with declared release conditions, and clock-basis divergence is provable. Verified by the registered retention-proof check.

Conformity decisions are data, not code

Quality-threshold decisions ship as content-addressed, supersession-chained records with an enforced separation between the business decision owner and the engineering computation. The freeze gate requires at least three independent evidence lineages — a passing verdict cannot be self-manufactured by the vendor.

Benchmark discipline

Every published performance number is stamped with the committed result artifact it came from; capabilities without a committed measurement are listed as not-yet-benchmarked and carry no number. A freshness check (bench-doc) fails the build if the published document drifts from the artifacts.

Regression budget enforced at every release

A quiet-window benchmark-regression gate runs against a committed baseline with a fixed 0.80 performance budget before changes are accepted. The gate result is a registered live check (bench-regression).

What is deliberately absent

No accuracy figure. No agreement-with-ground-truth figure. No throughput or frames-per-second figure. No certification claim. Each of those is missing because we do not hold a committed artifact that would support it, and we would rather publish a short page than an unbackable one.