AIAME · PORTFOLIOFR
Thorough audit on 2026-08-26, in-depth re-verification on 2026-09-08, targeted update on 2026-09-24 — measured state, not declared; a repository created since only appears once audited

What runs, what is tested, what isn't — without rounding.

Every repository audited here, in the aiame-fr organization, is classed as prod, pre-prod or dev from verifiable evidence — CI status (gh api), live domain checks, code reading — never from a README taken at face value.

E2E sandbox certification

Verdict: ABSENT — across every repository audited here.

None of the repositories audited here has an end-to-end certification harness. Almost all CI measures doctrine (garde-fous.yml script: no frontier provider at runtime, no secret tracked by git, no Elzéard credential) — not the product. A green garde-fous badge says nothing about whether the code compiles, runs, or serves real traffic — and a red badge today doesn't say more either (see "CI status" below, reviewed in depth on 2026-09-08: the 08/26 billing cause is resolved, but per-repository reactivation isn't).

11
prod
17
pre-prod
9
dev
37
audited

What an e2e certification would actually require

"ABSENT" isn't a checkbox — it's the absence of a mechanism that would combine four properties at once:

AutomaticTriggered without a human remembering to run a command — CI, cron, or deployment lock.
Real pathExercises the actually deployed instance — the running container, not an in-memory TestClient or a mock.
Full journeyCovers the end-to-end user journey (click → payment → webhook → confirmed order), not an isolated function.
Has authorityA failure blocks or alerts — otherwise it's a one-off measurement, not a certification.

The closest thing to an e2e certification (aiame-fin, aiame-red) remains fragmented across these four properties — see this page's history for the detail, mechanism by mechanism. What has changed since the last audit (2026-08-13/17): CI itself is no longer a reliable signal today, org-wide — see below.

CI status — billing is resolved, reactivation isn't

Regression found on 2026-09-24: the only complete reactivation this page has ever documented has since been re-disabled. The billing block observed on 2026-08-26 remains resolved at the org level (gh api orgs/aiame-fr/actions/permissions still confirms enabled_repositories: all today) — but aiame-miroir, reactivated and green on 2026-09-02 (PR#16, 4 jobs on real runners), shows enabled: false live today, despite a real, green run as recent as 2026-09-22 (run 35692425622). Someone or something switched off Actions for this repository between the 22nd and the 24th — not a new billing outage (the org remains open), a repo-local regression, cause unidentified. There is therefore no longer any verified example of a complete reactivation that held over time in this org.

The rest of the fleet never caught up either. Re-verified repository by repository on 2026-09-24 (gh api repos/aiame-fr/<repo>/actions/permissions, org grown from 36 to 40 repositories since the last pass): 37 of the 38 non-archived, non-fork repositories in the org have Actions disabled at the repository level (36 confirmed on 09-08, the proportion hasn't moved) — a switch left OFF since 08/27 for most, not a new outage. The only verified exception today is aiame-knowledge, whose scheduled workflow (knowledge-refresh.yml) justifies Actions deliberately staying active there. No run (not even workflow_dispatch) has been able to execute on the disabled repositories since 08/26 or 27, regardless of how many commits/PRs have merged since. Enforcement shifted, repository by repository, to a local git hook (.githooks/pre-push) introduced the same week — but that hook is not versioned as active: every clone/worktree must run git config core.hooksPath .githooks itself, without which no check exists at all (the hook's own comment on aiame-store says it in black and white: "NOT ACTIVE on a fresh clone/worktree").

Edge case found on 09-08, not re-verified since: aiame-ledger did retry two runs on 06-09 (workflow_dispatch, not the silence the previous version of this page claimed) — but both remain stuck in queued, never assigned to a runner, more than 2 days later. A distinct problem from the org-wide billing issue (see "CI status"), never resolved or even retried.

Each relevant card below reports its own live-verified state — some date from 09-08, others from 09-24 (see each card). aiame-graine was never affected (Actions triggers on push/PR, checks green on HEAD). This section is dated today; like the rest of the page, it goes stale.

Method

Three classes, defined by evidence, never by the ambition declared in a repository's own README:

ProdAlive and live-verified (a real HTTP request on the day of the audit), or a canonical text other repositories depend on that is corrected by a new version, never by editing in place.
Pre-prodBuilt, with real tests that pass in CI (not only doctrine) — but with no proof of serving in production from this repository, or deployed but with an unresolved doubt about what is actually served.
DevWork in progress, broken build, tests written but never called by CI, or no proof of deployment.

Fully redone on 2026-08-26: the 30 repositories declared in repos.json were re-read one by one — CI (gh api, job logs, not just the badge), real code, a live HTTP request on every plausible URL. 11 repositories had never appeared on this page before (see "Inventory gaps" below); 7 changed tier since the last audit (2026-08-13/17) in light of new evidence, not a new scoring policy.

Prod — 11 repositories

aiame-angel e2e certif. absent

"Aiame Angel" — nurse scheduling (CP-SAT roster + deterministic VRPTW round, offline), public on angel.services.aiame.fr behind aiame-auth; split from aiame-optaplanner on 08/27, which remains the solver engine consumed as a library (see its pre-prod card).

  • angel.services.aiame.fr → 200 (real Next.js app) and /api/v1/health → 200; /api/v1/nurses → 401 MISSING_TOKEN — the aiame-auth lock is actually active in prod, not just the code's default (whose default value is auth_required=False)
  • Real persistence (Postgres + Alembic migrations on storage-01); zero business commits since the split — but the deployment still runs under the old aiame-optaplanner-backend/-frontend containers, the deployment path switchover itself remains an open task (documented in this repository and in repos.json)

aiame-auth e2e certif. absent

Cross-cutting AIAME authentication service — short-lived EdDSA tokens, rotating refresh, multi-tenant product+org.

  • /v1/auth/public-key responds live with a real Ed25519 PEM key (not a static stub); aiame-angel (storage-01) is configured in prod with AUTH_REQUIRED=true and actually verifies against this key — corrected on 09-08: it is aiame-angel that carries this consumer since the 08/27 split, not aiame-optaplanner (now a library, see its pre-prod card)
  • 66 tests pass locally, replayed live — GitHub CI disabled for this repository since 08/27 (billing, reactivation not done), enforcement shifted to a local pre-push hook

aiame-doctrine e2e certif. absent

Canonical ethical texts (Constitution, charters, axioms, White Paper) + generators for the legal pages.

  • sov.services.aiame.fr/mentions-legales.html live contains the comment "GÉNÉRÉ par aiame-doctrine/legal/build_legal_sov.py" — this repository's generator is indeed what serves the real page, not a claim
  • verifier-copies.sh replayed live on 09-08: 1/25 vendored copy up to date (aiame-fin only), not 2/25 as this page claimed two days ago — the canonical has moved twice more since (09-06), drift is worsening faster than it resolves

aiame-eu e2e certif. absent

apod.services.aiame.fr — open services for European citizens (APOD). The former name eu.aiame.fr has not resolved since 2026-09-13.

  • Live-re-verified on 09-08: /api/apod still responds, 66/66 tests replayed locally (identical to the 793-line last CI run)
  • GitHub CI disabled since 08/27 (billing, not reactivated) — last real run on 08-19, 2 PRs merged since with no GitHub check at all

aiame-fin e2e certif. absent

Cross-cutting AIAME checkout/entitlements/delivery (catalog, Stripe/SumUp/SEPA PSP) — billing itself remains "planned".

  • /health live returns the real state of the adapters (all in mode:mock, no real payment goes through) — cross-checked against the code, not quoted from the README
  • GitHub CI disabled since 08/27 (billing, not reactivated here): 9 commits merged since with no check at all, including a real P0 fix (SEPA was wrongly reporting "sandbox"). Suite replayed locally on 09-08: 108 passed (up from 87 as of the same drift date)

aiame-fr.github.io e2e certif. absent

Static public showcase — GitHub Pages mirror; real source of www.aiame.fr.

  • GitHub Pages active and actually serving (status: built), aiame.fr/www.aiame.fr verified 200 live — the Pages pipeline is independent of the Actions billing issue below, it never stopped deploying
  • GitHub CI (garde-fous) disabled since 08/27 for this repository (not reactivated): 9 commits with no GitHub check, including the ones that wrote these very lines; enforcement local only since then
  • What www.aiame.fr actually serves after a human operator runs make play-vitrine from aiame-infra — no automatic sync between the two

aiame-infra e2e certif. absent

Terraform (Hetzner) + Ansible + Traefik v3 — infrastructure pillar; deploys everything else.

  • Actually applies aiame.fr and the *.services.aiame.fr/*.dev.aiame.fr family (sov, svcmgr, fin, angel, auth, price, miroir, apod) — active Let's Encrypt certificate, live-verified
  • Its own CI proves only doctrine (garde-fous) — the prod verdict comes exclusively from live HTTP checks on the services it deploys, not from its own badge

aiame-sov e2e certif. absent

France Sov — decision assistant for the SME/SMB manager (FastAPI + SQLModel, RAG, territorial monitoring).

  • sov.services.aiame.fr responds live, /api/v1/version confirms environment:"production"; the sov.dev.aiame.fr replica is also live ("staging")
  • Corrected on 09-08: the README still claims an open authorization flaw on the Territoire module, but issue #73 documenting it was closed on 09-01 — the real hole (routes without require_role) was already fixed the very day it was found (6/6 dedicated tests pass, 401 live-verified on /api/v1/regional/entities); the lack of multi-tenant isolation remains true but is reclassed as a deliberate architecture decision (single-tenant per instance until 2028), not a bug

aiame-services e2e certif. absent

SVCMGR — service activation console and license tiers, real-time WebSocket. Repository renamed services-manager → aiame-services on 09/17; this card still carried the old name since then, corrected on 09/24.

  • svcmgr.services.aiame.fr live; auth migrated on 08/21 to aiame-auth token verification (ADR-AA-001)
  • GitHub CI disabled since 08/27 (billing, not reactivated): 16 real backend tests (up from 12) still never replayed by CI, only locally; frontend has no tests at all

aiame-rag-core e2e certif. absent

Canonical AIAME RAG engine (pipeline stages, retrieval scorers, security guardrail registry, opt-in research mode) — not a service on its own, vendored with checksum in aiame-rag/aiame-sov/aiame-one, replaces aiame-sov-kernel.

  • Found missing from this page on 09/24 (created on 09/13) — this is the "canonical text other repositories depend on, corrected by a new version, never in place" pattern applied to code: vendoring live-verified (sha256sum -c app/vendored/aiame_rag_core/CANONICAL.sha256 passes in all three consuming repositories), and actually imported/executed — aiame-sov/backend/app/services/{rag_service,learning_service,eip_service}.py import its modules directly — not dead code, in a repository that is itself verified prod (sov.services.aiame.fr)
  • 98 local tests pass (09/24) — but the repository's README (09/13, never updated since) still claims "not yet functional — initial scaffold", although two features (research mode, claim verification) were merged after that date

aiame-voice e2e certif. absent

Voice → UI action routing (embeddings, closed action registry, zero LLM) — cross-cutting AIAME service, first intended consumer: Elzéard cockpit.

  • Found missing from this page on 09/24 (created on 09/17) — its health probe answered 200 {"status":"ok"} on 09/24, on the organisation's private network (not reachable from the internet) since 09/17 (PR#2), 18 local tests pass
  • Alive doesn't mean used: no product has yet synchronized an action registry — /route returns 404 for every product_id tested, integration on the Elzéard side hasn't started

Pre-prod — 17 repositories

aiame-core e2e certif. absent

Rust — asymmetry mathematics (Kabsch, Laplacian, spectral), aimed at WASM for a frontend.

  • 22/22 real tests replayed locally on 09-08, unchanged — GitHub CI disabled since 08/27 (billing, not reactivated), last real run on 08-19; the local pre-push hook that took over doesn't cover cargo test, only garde-fous doctrine
  • CI never builds the real WASM target (only native); dead code exists in the tree (src/analysis/, never wired up)

aiame-graine e2e certif. absent

"Aiame Graine" POC — coreless engine + "You are owed" card scored by TinyML (payment drift), Rust→WASM inference identical in browser/server.

  • 38/38 tests replayed live, including a mutation-tested kill-test (TinyML AUC gain vs. naive rule: 19.7 points, kill threshold at 10); cargo test 5/5 (Python↔Rust numeric parity < 1e-4)
  • One of the few repositories not hit by the Actions block: CI triggers on push/PR (not dispatch-only), 3 green checks on HEAD including a dedicated job that actually compiles the wasm32 target (84 KB, < 2 MB)
  • No deployment surface (the README itself lists 13 ABSENT lines: frontend, persistence, LLM) — hence pre-prod, not prod

aiame-knowledge e2e certif. absent

Document extraction and synthesis for the aiame-fr org.

  • CI passed today itself under workflow_dispatch alone (PR#9) following the Actions billing block — no more automatic push/PR trigger; the README still claims the opposite
  • A real pytest suite exists and was passing before the trigger change

aiame-ledger e2e certif. absent

Manual CLI that builds the cost/revenue ledger for the 5 E3 services with mandatory traceability ("Law of Evidence").

  • Corrected on 09-08: it isn't "nothing since 08/22" — two new workflow_dispatch runs were indeed retried on 06-09, but both remain stuck in queued, never assigned to a runner, more than 2 days later. A distinct problem from the org-wide Actions billing issue (see "CI status"), never resolved or retried since

aiame-mcp e2e certif. absent

Stdio-only MCP server exposing 6 AIAME services (auth, RAG, embeddings/blob, knowledge, angel, one) as 9 tools — a subprocess, not a hosted network service.

  • 91 real tests replayed live on 09-08 (up from 89), ruff clean — no possible URL by design (stdio), so no "live" proof applies
  • GitHub CI disabled since 08/27 (billing, not reactivated): the last 4 commits, including the one that grew the suite to 91, never ran on GitHub — only replayed locally

aiame-miroir e2e certif. absent

B2H instrument: face + hand in a single geometric frame, 100% local (browser WASM).

  • miroir.dev.aiame.fr live, live-verified — four distinct CI jobs (cargo-test 72 tests, frontend, zero-leak egress)
  • Regression found on 09-24: Actions was reactivated and green since 09-02 (PR#16, 4 jobs on real runners, last green run on 09-22) — but shows enabled: false today, disabled again between 09-22 and 09-24 with no visible commit or PR to explain it. See "CI status": so this was not a reactivation that held over time

aiame-one e2e certif. absent

Multi-format/voice ingestion → RAG → ERP draft (single-operator spike).

  • 74 backend tests replayed live on 09-08 (up from 70 on 08-26; README still at 66/66, gap now 8) — GitHub CI disabled since 08/27 (billing, not reactivated), the last 2 merged PRs (including the one that produced this HEAD) had no GitHub check at all
  • The frontend (TypeScript, vitest) is never exercised by CI, only the backend is — a gap acknowledged in the ci.yml comment itself

aiame-optaplanner e2e certif. absent

Cross-cutting AIAME solver engine — CP-SAT (roster) and heuristic VRPTW (round); a pure library with no business domain or API, consumed in-process by aiame-angel since their 08/27 split.

  • git ls-files backend/app empty (verified 09-08): no more API route or business domain versioned here — only backend/aiame_optaplanner/{rostering,routing} remains, the README says so explicitly
  • 30/30 tests green + ruff clean, replayed live on 09-08; honest-by-construction design: a dishonest OPTIMAL/FEASIBLE result is a ValueError at construction, not just a convention. Only CI = garde-fous doctrine (disabled since 08/27, not reactivated); only consumer found org-wide = aiame-angel (local path import, no proper deployment)

aiame-pouls e2e certif. absent

"Le Pouls" POC — C1 "You are owed" / C3 "It's coming" cards, provenance registry.

  • Suite replayed live: green, 80 tests — corrected on 09-08: the README still cited 65/65 two days ago, but PR#10 (06-09) resynced all 3 mentions to 80/80, no gap left today. Note for next time: the local clone used for this review was itself 2 commits behind (git fetch alone isn't enough), corrected before verifying

aiame-price e2e certif. absent

Third-party price monitoring (backend + dashboard), BTP/construction scope via a Würth adapter.

  • price.dev.aiame.fr responds 200 today (/api/v1/health ok) — explicitly a pre-production host, not prod, by the org's own DNS convention
  • Switched to workflow_dispatch the same day (08/26 commit), same cause as aiame-knowledge — identical code tree to an earlier green run, verified by hash

aiame-rag e2e certif. absent

Full-stack arXiv RAG (Qdrant, Celery/Redis, LangGraph agent) — active work on auto-calibration.

  • A real test Qdrant container (not a mock) and a real pytest job, replayed live on 09-08: 14/14 green — GitHub CI disabled since 08/27 (billing, not reactivated), 27 commits merged since with no GitHub check at all, only local
  • No live route found (rag.aiame.fr/rag.services.aiame.fr/rag.dev.aiame.fr: all three NXDOMAIN, verified 09-08); repos.json describes it as "functional" with no caveat — the infra itself documents this route as "not yet wired"

aiame-red e2e certif. absent

Deterministic AI-drift red-team audit engine, sold as an offer (aiame.fr) and self-applied in CI against 5 other repositories.

  • 28/28 tests replayed live on 09-08, engine re-run against specs/BASELINE.json: zero drift — the red-selfaudit.yml logic (--baseline) holds, but this workflow hasn't actually run on GitHub since 08/22 (CI disabled since 08/27, billing, not reactivated): 9 commits/PRs merged since with no check at all, despite the repository's own "self-applied in CI" pitch
  • No proper deployment surface (CLI/library) — no direct HTTP verification possible

aiame-scheduler e2e certif. absent

Vendored micro-library (a single file) providing an APScheduler wrapper wired to the FastAPI lifespan — fixes a bug class (scheduler dying silently).

  • CI genuinely green at creation (08/24, 3 runs), but disabled since 08/27 (billing, not reactivated): 2 PRs merged since (08/27, 08/29) had no GitHub check at all, only the local hook. No deployment surface by design (vendored library, never served)
  • The bug it fixes hasn't yet been retrofitted into aiame-agri-gers, the repository that motivated it

aiame-sov-kernel e2e certif. absent

Vendored Python kernel (2 files, checksum) — deterministic provenance scoring + FD-01 mitigations, vendored in aiame-sov and aiame-one.

  • The kernel itself (safety.py/critique_service.py) is identical to PR#2, green before the block — but 4 more PRs have merged since (garde-fous, hooks), so the whole tree is no longer an empty diff as this page claimed
  • Actions remains disabled at the repository level, no run retried since 08-26 — and the comparison to aiame-miroir this card claimed no longer makes sense: miroir was itself disabled again as of 09-24 (see its card and "CI status"), so there is no longer a "one-click fix already applied elsewhere" to point to as an example

aiame-store e2e certif. absent

Three vendorable storage mechanisms (S3/Garage blob, Postgres provisioning) plus one real microservice, embedding-compute.

  • 13 tests replayed live on 09-08, all green — GitHub CI disabled since 08/27 (billing, not reactivated), 3 PRs merged since with no GitHub check at all, only a local hook itself "NOT ACTIVE on a fresh clone/worktree" by its own comment
  • No live route found for embedding-compute to date despite its status as a deployable service

aiame-racines e2e certif. absent

Technical provenance spike — SIRET/SIRENE lookup + BAN geocoding + distance, ahead of any product decision (arising from a regional prospecting study), extends the aiame-pouls engine.

  • Found missing from this page on 09/24 (created on 09/10) — 45/45 real tests replayed locally today, identical to the figure the README states; no GitHub CI (disabled org-wide), enforcement by a local pre-push hook not active by default
  • A deliberate, pre-decision spike by construction: the README itself says "deployment, public exposure: ABSENT" — name, sector, department remain open questions, this is not a product

aiame-guard e2e certif. absent

Verifies that aiame-red stays consistent (TRACEABILITY.yml vs rules.py drift, tests, redaction invariant) — doctrine → red → guard triad.

  • Found missing from this page on 09/24 (created on 09/18) — 29 local tests pass (2 skipped, requiring AIAME_RED_RACINE), actually deployed via a dedicated Ansible role (aiame-infra/ansible/roles/guard-watch, weekly systemd timer), consistent with a real failure/alert/recovery cycle dated 09/19
  • CLI/cron with no HTTP surface at all — no "real HTTP request" is possible by construction (same situation as aiame-mcp, stdio-only), so not prod despite an unusually solid proof of deployment for this type of repository; at-rest encryption of the deployed SMTP secret doesn't exist yet ("named, not built" by the README itself)

Dev — 9 repositories

aiame-agri-gers e2e certif. absent

Coordination POC for seasonal farm workers in the Gers (housing, mobility, job offers) — public interest, not a marketplace.

  • The pytest suite (23 tests) and frontend build actually work locally — replayed this session — but CI never calls them, only garde-fous doctrine
  • No proof of deployment (no infra route, DNS resolves nowhere)

aiame-compliance e2e certif. absent

Cross-cutting EU AI Act logging/risk-signal substrate (art. 12/13/50) for aiame-rag/aiame-sov/aiame-one — vendored (checksum-pinned) in aiame-rag since 09-01.

  • 14/14 tests replayed live, ruff clean — no CI workflow in this repository (only Dependabot exists), the suite is never called automatically
  • Vendoring verified byte for byte (sha256) in aiame-rag, imported at 3 real entry points of the pipeline (not dead code) — but aiame-rag itself has no live route at all (NXDOMAIN on all 3 plausible domains), and its own README still says "not wired into any consumer", stale since the very day of vendoring

aiame-creator e2e certif. absent

Prior-art document — static file.

  • Static document — nothing to build or deploy, by design

aiame-dream e2e certif. absent

Deterministic (zero LLM) CLI that mines the AIAME ecosystem's governed documents (ADR, VISION.md) with mandatory file:line provenance on every fact.

  • A real e2e suite (9 tests) replayed locally, green — GitHub CI disabled since 08/27 (billing, not reactivated), not merely "never wired up for these tests"
  • CLI-only by design (README) — no deployment surface intended at this stage

aiame-ivx e2e certif. absent

Private, docs-only research space: studies a legacy "IVX" system archive and produces syntheses that feed ADRs elsewhere.

  • No application code at all — CI = doctrine only when it runs, but disabled since 08/27 (billing, not reactivated): doctrine itself is no longer verified on GitHub, only locally. No deployment proof sought by design

aiame-memory e2e certif. absent

Persistent Claude Code session memory — context syntheses, no real secrets.

  • A notes repository, now 183 .md files (up from ~120), no code to build or deploy
  • Corrected on 09-08: its own copy of the garde-fous script has drifted (hash different from the aiame-doctrine canonical, old GF-5 regex) — and above all, this repository isn't even declared in verifier-copies.sh, the org's own drift-detection tool: its drift is invisible to its own tooling, exactly the failure mode this tool claims to catch

aiame-motion e2e certif. absent

Two unrelated things under the same name: a product concept never built (shared perceptual referent) and the only real code present, an EU-APOD crawler.

  • Major doc/reality gap: the README describes a biometric-analysis product, the real code is an unrelated image scraper — neither has a test or a proof of deployment

aiame-prd e2e certif. absent

Product spec corpus (PRD Aiame v1.3, PRD Elzéard v2 carried over for IP prior art, PRD Le Pouls, MISSION 2027) — not a code repository.

  • No application code, nothing to deploy — classed dev in the sense of "no service", not in the sense of "under construction"

aiame-wrapped e2e certif. absent

"Aiame Wrapped" — visual project retrospective (matplotlib mock-up).

  • Self-declared "mock-up, not a tool" in its own README
  • Qualitative weights hard-coded, nothing computed

Inventory gaps — resolved 2026-08-26, reopened 2026-09-08, reopened again 2026-09-24

11 of 30 repositories existed in repos.json without ever having appeared on this page: aiame-agri-gers, aiame-auth, aiame-dream, aiame-ivx, aiame-ledger, aiame-mcp, aiame-optaplanner, aiame-price, aiame-scheduler, aiame-sov-kernel, aiame-store. Two of them (aiame-auth, aiame-optaplanner/Angel) are public services that had already been in production for several days — the omission wasn't neutral, it left two entire prod repositories outside the audit. The 19 other classifications from the previous audit (2026-08-13/17) were fully re-read rather than carried over as-is; 7 changed tier in light of new evidence (detail in each card above), not 5 as this page once claimed — two changes (aiame-one, aiame-prd) had been applied to the cards without being counted in that sentence, found by re-reading this page afterward, corrected here rather than left as is: aiame-sov and services-manager (dev → prod), aiame-fin (pre-prod → prod), aiame-core, aiame-rag and aiame-one (dev → pre-prod), aiame-prd (pre-prod → dev). aiame-miroir, which only had a provisional "post-audit" section while awaiting proof of deployment, is now a normal pre-prod card.

Reopened on 2026-09-08: the same class of gap reproduced 13 days later. The org has 36 repositories, not 30 — 3 truly deserved a card (aiame-angel, aiame-compliance, aiame-graine, all audited above), bringing the total to 33. Two other names found (aiame-tf, changedetection.io) turned out to be false leads already settled elsewhere — aiame-tf is archived, its content merged into aiame-infra/terraform/dns/; changedetection.io is a public fork of a third-party tool, never deployed by AIAME — both are correctly declared in excluded[] of repos.json on main, only the working copy used for this review was temporarily missing it. repos.json itself therefore needs no correction.

Reopened on 2026-09-24: the same class of gap, a third time in a month. The org has 40 repositories, not 36 — 4 new repositories created since the last pass (aiame-racines, aiame-rag-core, aiame-voice, aiame-guard, all created between 09/10 and 09/18) truly deserved a card, all audited above, bringing the total to 37.

A fifth name found, aiame-workspace (created 08/07 — not new, simply never audited), turned out to be a false lead of the same kind as aiame-tf/changedetection.io: its own README says so explicitly, versioned root tooling, no product code. Excluded from this page for that reason, not a separate omission. aiame-tf and changedetection.io themselves remain correctly excluded, nothing to fix there.

Side effect found during this review, unrelated to the inventory itself: aiame-miroir's CI reactivation documented on 09-08 has since regressed — see "CI status" and its card.

This is exactly the kind of drift ./bootstrap.sh --check exists to catch — this portfolio doesn't replace that verification, it gives a snapshot dated 2026-09-24. Third reopening in a month (08-26, 09-08, 09-24): this portfolio is itself exactly the example it denounces at the top of the page — a snapshot that goes stale, never a continuous mechanism.