Generated by receipts cards. Do not edit by hand.
The data path exists to compute funder-report aggregates with reproducible receipts and to test that the grounding gate blocks invented numeric spans.
Inputs are organization-provided CSV exports and author-controlled TOML specs. The deterministic engine processes source rows locally and emits scalar figures with query, row-count, and slice-hash receipts. The committed benchmark and examples are synthetic. They contain English and Spanish narratives, planted receipt-backed displays, and planted unbound numbers.
Operators provide their own CSV and TOML files locally. The project does not collect, host, scrape, or redistribute those inputs. Synthetic fixtures are authored in this repository and reviewed with the tests that consume them.
CSV rows are validated, loaded into in-memory SQLite, and reduced to scalar figures. The receipt stores the query, row count, canonical slice hash, and timestamp. Source rows do not enter the report renderer or model request.
The deterministic engine uses local inputs to produce receipts and aggregate reports. The optional Bedrock request uses the filled narrative and a scalar display allowlist only. The synthetic benchmark evaluates the fail-closed numeric grounding behavior; it is not representative of real client outcomes.
Synthetic fixtures and the committed eval report ship under Apache-2.0 with the repository. Organization-provided source data is never bundled or redistributed.
The maintainer updates this card, the synthetic fixtures, and the eval report in the same change that alters the data boundary, grounding policy, suppression policy, prompt, or model seam. Release CI fails if generated cards drift.
By default, no data leaves the process. With Bedrock drafting explicitly enabled, the request contains only the filled narrative and scalar display allowlist. It does not contain source rows, client identifiers, receipt hashes, SQL, or data paths. Small aggregate values may appear in the first in-memory drafting pass; organizations must authorize that transfer under their own data policy.
Exports are structurally aggregate-only. Counts from 1 through 10 are redacted under the CMS-modeled default; complementary, delta, and percentage controls reduce arithmetic recovery. HUD does not prescribe this numeric floor, so the applicable local policy remains authoritative. True zeros remain visible.
The application does not create a cloud-side retention policy; Amazon Bedrock account and logging configuration controls provider-side handling. Local source files, outputs, ledgers, and bundles remain under operator control. Receipts show how a number was computed, not whether collection was complete, consensual, or free from structural bias.
Last verified: 2026-07-12 · Recheck: on any data-boundary, retention, or model-seam change.