gadirlabs.Fictional illustrative sample
Asterpath · Revision 4

Reader coverage guide

Know what each assessment area covers.

Follow authentication, backend behaviour, database quality and the operational questions a founder may not know to ask. Keep the evidence limits visible as you read.

Fictional, not a scanner result. FICTIONAL ILLUSTRATIVE SAMPLE. Asterpath, its product, evidence, findings and measurements are invented. No Asterpath application was inspected and no scanner was executed. These are original GadirLabs illustrations, not native vendor exports.

This guide points to the same I01–I13 fictional packets and F01–F08 findings already used in the report. More visible coverage does not mean additional checks were completed.

Find a chapter

What the expanded areas do—and do not—establish

Authentication, accounts and permissions

Can customers regain access safely, and can each account reach only its own information?

The same fictional source, selected sign-in/session records and sampled isolation scenarios support this chapter.

Not verified: A complete account-lifecycle and role matrix is not represented. Applicable OAuth, recovery, account-linking and invitation variants need their own scoped evidence; unsupported features may be marked Not applicable.

Related existing evidence: I01, I03. No new finding or check is asserted.

Authentication, accounts and permissions · page 16

Backend, APIs and background processing

Does the work behind the interface finish correctly after an interruption or retry?

Selected source boundaries and the existing payment, generation and alert sequences are reused. F01 remains the same single payment finding.

Not verified: All API routes, edge functions, background jobs, concurrent operations and provider failure combinations have not been demonstrated.

Related existing evidence: I01, I04, I05, I08. No new finding or check is asserted.

Backend, APIs and background processing · page 33 · Payments & entitlements · page 22

Database design and data integrity

Will information stay correct and useful as records accumulate and requests overlap?

The system/data-boundary snapshot, interrupted entitlement write and recovery documentation provide context. They are not a complete schema or query-plan review.

Not verified: Complete relationship/constraint design, justified duplication, transaction behaviour, representative query plans and successful restore evidence remain unverified.

Related existing evidence: I01, I04, I12. No new finding or check is asserted.

Database design and data integrity · page 36 · Release & recovery · page 61

Critical email and notifications

Can customers actually receive the messages they need to sign in, recover access or confirm an action?

Selected session records and the existing rejected operator-alert example are related context. F07 is an operator-alert failure, not a proven password-reset delivery defect.

Not verified: End-to-end transactional email delivery, domain configuration, bounce handling and mailbox receipt are not evidenced.

Related existing evidence: I03, I08. No new finding or check is asserted.

Authentication, accounts and permissions · page 16 · Observability & support · page 42

Business-rule correctness

Do access, balances and limits remain correct when events arrive twice or out of order?

The existing interrupted paid-access sequence and single aligned cost period show two bounded problems.

Not verified: All entitlement transitions, quota boundaries, rounding/time-zone rules and simultaneous updates are not covered by those records.

Related existing evidence: I04, I09. No new finding or check is asserted.

Payments & entitlements · page 22 · Backend, APIs and background processing · page 33 · Database design and data integrity · page 36 · Testing & change safety · page 46

Capacity and operating limits

What is likely to slow down, fail or become unexpectedly expensive as usage grows?

Source/configuration context, one timeout sequence, lab page speed and one invoice period remain separate kinds of evidence.

Not verified: These records do not establish a concurrency ceiling, sustained load capacity, database connection headroom or production demand forecast.

Related existing evidence: I01, I05, I07, I09. No new finding or check is asserted.

Speed & performance · page 30 · Backend, APIs and background processing · page 33 · Database design and data integrity · page 36 · External services & operating costs · page 50

Safe support and administration

Can an authorised person resolve customer problems without making uncontrolled changes to live information?

Source ownership, sampled identity/isolation and instruction/handbook records identify relevant boundaries.

Not verified: A complete support-role matrix, privileged-action audit trail and end-to-end safe customer-repair exercise are not evidenced.

Related existing evidence: I01, I03, I11. No new finding or check is asserted.

Authentication, accounts and permissions · page 16 · Observability & support · page 42 · Codebase, documentation & ownership · page 11

Business continuity and ownership

Could another competent person operate and recover the service if the original builder were unavailable?

Ownership and instructions, a staging release record and documented rollback are represented in the fiction.

Not verified: Successful full restore, usable business-data export and an independent complete operating handover remain unverified.

Related existing evidence: I01, I11, I12. No new finding or check is asserted.

Codebase, documentation & ownership · page 11 · Database design and data integrity · page 36 · Release & recovery · page 61

AI output quality and control

Are generated plans useful and correctable, and are any AI-triggered actions appropriately limited?

Synthetic generation, timeout recovery and cost reconciliation show selected operational behaviour.

Not verified: Representative output-quality evaluation, adversarial inputs and the safety of any autonomous actions are not established by a successful generation or dry-run.

Related existing evidence: I05, I09, I11. No new finding or check is asserted.

External services & operating costs · page 50 · UX, interface & visual consistency · page 25 · Testing & change safety · page 46

Open structured coverage map (JSON)