Milestone 3 — Gemini safety boundary and 91-test regression
LT Tender Trace now has a tested, credential-safe two-model Gemini server boundary.
Completed
- Added the official
@google/genai2.12.0 SDK as an exact dependency. - Fixed triage routing to
gemini-3.1-flash-liteand decision routing togemini-3.5-flash. - Added provider JSON response schemas plus independent Zod validation.
- Made every customer decision impossible at the triage stage.
- Bound decision citations to the supplied evidence identifier, label, HTTPS URL, and access date.
- Rejected malformed JSON, invented citations, invented requirement identifiers, model-created deterministic exclusions, incomplete evidence, contradictory evidence, and unreviewed Bid outputs.
- Added an accessible agent-run panel for queued, triaging, deciding, completed, and needs-review states.
- Verified lint, TypeScript checking, 91 automated tests across 18 files, and the Next.js production build.
Current evidence
- TED v3 remains live-validated.
- Supabase immutable notice versions and durable amendment events are live.
- Supabase security advisor remains clear with zero outstanding findings.
Still pending
A live deployed Gemini call requires the server API credential. SAM.gov live validation separately requires its API key. Google and Microsoft sign-in still require provider-console configuration and clean-browser verification. These items are not represented as complete.
Next milestone
Run a live TED notice through both Gemini roles, persist the immutable agent run, validate every citation, present the advisory decision for human review, and begin the expert-labeled US/EU golden-set evaluation.

Log in or sign up for Devpost to join the conversation.