The operating discipline
How DreamerOS Ships
Merged is not done. Deployed is not done. Done is when a paying customer can use the capability the way it was promised, with proof on every answer. This page is the inside view of how we get there.
Honest by default
When the loop on a capability is not yet closed end to end, we say "shipping next" on it. We do not call it done until every one of the six rows below is true. This page itself follows that rule: anything you see described here either runs today or is marked shipping next.
The seven stages of a checked answer
Every checked answer on DreamerOS walks this pipeline. If any stage fails, the failure surfaces to you. There is no quiet skip.
- Prompt shapingYour message gets restructured into a precise, surgical question before any model sees it. Original is preserved. The shape is what the engines act on.
- Pre-checksRule-based safety and integrity scans run on the input: injection idioms, ambiguity, sensitive topics, multi-question framing.
- Engine routingThe shaped question is routed to the engine whose published strength matches the intent (build, review, synthesis, signal, research). Sometimes more than one engine, with a synthesis step.
- Live model callThe selected engine generates a response. Streaming when streaming is supported; full-response otherwise.
- Post-checksRule-based and model-assisted audits on the answer: hedging signals, silent-drop heuristics, depth proportionality, citation integrity, contradiction with prior turns.
- Signed receiptEvery answer, on every plan, is signed and timestamped with a public key id. The receipt is the audit trail. You can hand it over and a third party can check it. The free plan gets 25 receipts a day.
- Observable failureAnything that breaks at any stage surfaces to you in plain language, never swallowed in silence. If you do not see a receipt, the gate did not pass.
What done actually means: the six rows
A task is done only when all six are true. If any one is false, we mark it partial, open, or deferred. Never done.
- Code path connectsThe change actually wires up end to end. Imports resolve, the lint passes, the function the caller invokes is the function that runs.
- Deploy is liveThe latest commit is the one running on Railway, Vercel, and Porkbun. The health check is green. The build log shows the SHA you expect.
- Customer can reach it through the intended entrypoint at the intended tierThe right person, at the right plan, can click through to it from where the marketing or directive said they would. No hidden gates.
- Capability delivers the value the directive or marketing promisedWhat it does matches what we said it does. Not a stub. Not a partial. Not a placeholder that returns hardcoded text.
- No mis-selling on site, app, or pricing pageThe copy on this app, on dreameros.app, and on the pricing page matches what runs. If marketing is ahead of code, that is a hard escalation, never a copy edit.
- Failure is observable to the customer or to operationsWhen it breaks, you or our pager hears about it. Never silently swallowed.
What this means for you
Every answer, on every plan, carries a signed receipt with a timestamp and a public key id. The receipt is the proof the seven pipeline stages all passed. You can keep it, hand it over, or hand it to an auditor; the signature stands on its own.
You can browse your receipts at any time on the audit log.
One more time
Anywhere on this app, on dreameros.app, or on a pricing page, we say "shipping next" when the loop on a capability is not yet closed end to end. We say "live today" only when all six rows above are true on that capability. If you ever see a mismatch, tell us. That mismatch is a hard escalation, not a copy edit.
The public record
Every checked event lands on a public log. Anyone can read it. No account needed.
GET /api/v1/intent-log/head - append-only; each entry hash is recomputable from the fields shown