Verify it yourself
Every material number in this filing comes from one registry, is consumed by one ledger, and is checked by 108 automated tests. All of it is published here.
If a number cannot be traced to the registry below, it should not be trusted — and none exists.
The registry — the single source of truth
- assumptions.yaml — every material figure, each with a unit, an evidence class, and a note on where it came from. The 688 MW planning case includes a 200 MW undemonstrated winter import;
hybrid_capex_gross_bexcludes the cost of securing it.import_20yr_cost_bis open; do not invent a dollar figure. The 675 MW conversion identity is not added to the 600 MW shortfall; a parallel Hydro coincident identity is 288 MW at 6.4 kW. - heat_pump_study.yaml — a separate book for the heat-pump conversion identity. Never mixed into 413 / 688 / 788. Written note: heat-pump-rollout-study.md.
Peer-review register
There are no claimed expert reviews yet, and no completed expert reviews from a licensed witness. The register was empty until 19 August 2026. One external assessment is now logged as disputed on the public claim: the portfolio is worth testing, and it has not been proved as a $1.5–1.8 billion replacement for 750 MW of gas. Read it at external-review-2026-08-19.md. The machine-readable log is reviews.yaml. GIS civic honesty: Winnipeg neighbourhoods.
The code that consumes it
- regulator_paper_assumptions.py — loads the registry and exposes the winter and summer load models.
- system_b_ledger.py — the dual-ledger engine: accreditation scenarios, margins, delivered $/kW, cost bands, and the pass gates.
- heat_pump_study.py — the conversion identity, dual-fuel extra of 0 MW, and the written study note. It does not write into the winter stack.
- scripts/generate_report_v2_figures.py — generates every figure in the filing from the registry.
Verification you can run
With the repository checked out: python3 -m pytest research/ runs the 108 published evidence-base tests. Site-copy and honesty-clock tests live in tests/ at the repo root — run python3 -m pytest tests/. Those are not counted in the 108.
The 108 tests
These are what stop the arithmetic from drifting. Several exist specifically to keep retired figures — the 895 MW composite, the pre-correction 761 / 861 MW headlines — from ever reappearing.
Filing and ledger (54)
Red River basin evidence (54)
The binational water-quality and streamflow base behind the phosphorus arithmetic.
Estimates that still need outside verification
48 figures carry the E class: derived and documented, but not checked by anyone outside this project. The open engineering challenge lists every one with the discipline qualified to settle it, where to find such a person in Manitoba, and what evidence would close it.
Standards we work to
These are applied as method, not certification. Nothing here is audited or certified by a standards body, and we do not claim it is. They are the frameworks the evidence base is organised around, so a reviewer knows what to expect and where to push.
| Standard | What it governs | How it is applied here |
|---|---|---|
| ISO 19115 | Geographic information — metadata | Every spatial dataset in the basin evidence carries provenance: source, retrieval date, extent, and licence. |
| ISO 19157 | Geographic information — data quality | Completeness, logical consistency, and positional accuracy are recorded for the water-quality and streamflow joins rather than assumed. |
| ISO 8000 | Data quality and master data | One registry is the master record; every published figure resolves to it, carries an evidence class, and is regenerated rather than retyped. |
The checklist that tests this is verify_standards_checklist.py — currently 36/36. Its output is published as standards_checklist.md and standards_checklist.json.
Data quality and protection measures
Everything below is in force today and checkable from this page. Where a measure is a limitation rather than a control, it is listed as one.
Quality — how a number earns its place
| Measure | How it is enforced |
|---|---|
| One master record | Every material figure resolves to assumptions.yaml. Nothing is typed twice; if it is not in the registry, it does not exist. (ISO 8000 method.) |
| Evidence class on every figure | O / C / E / A / PD travels with the number into the site, the figures, and the filing, so a reader always knows how strong it is. |
| Generated, never retyped | Figures come from generate_report_v2_figures.py reading the registry, so a chart cannot disagree with the text. |
| Automated tests | 108 tests, all passing — 54 on the filing and ledger, 54 on the basin evidence. Listed below. |
| Standards checklist | verify_standards_checklist.py, currently 36/36, published as markdown and JSON. |
| Retired figures are actively blocked | Tests forbid the retired 895 MW composite and the pre-correction 761 / 861 MW headlines from reappearing anywhere. A regression fails the suite rather than reaching a reader. |
| Provenance on spatial data | Source URL, retrieval date, extent, and licence recorded for every ingested dataset. (ISO 19115 method.) |
| Quality recorded, not assumed | Completeness, logical consistency, and positional accuracy captured for the water-quality and streamflow joins. (ISO 19157 method.) |
| Published falsifiers | The filing states what evidence would break each claim, and the forum has a Change our mind category for people to bring it. |
| Adversarial review, acted on | An independent review found the headline over-claimed. The numbers were corrected downward — 761 → 688 MW reference — and the retired figures are named in public rather than quietly dropped. |
| Stated limitation | E-class figures are not externally verified. The tests check internal consistency, not whether an engineering estimate is right. Confirming them is what the seven orders ask for. |
Protection — how the site and its readers are safeguarded
| Measure | How it is enforced |
|---|---|
| Encryption in transit | HTTPS site-wide with an automatically renewed certificate; plain HTTP redirects, and the apex redirects to the canonical host. |
| No tracking of readers | No analytics, advertising, or tracking pixels anywhere. No cookies at all unless you sign up for the forum. |
| The letter builder never transmits | Names and letter text are assembled in your browser and sent by your own mail app. There is no server to store them and no draft saved. |
| Forum application is out of reach | The app and its database credentials live outside the public directory; only the public folder is exposed. Verified: config.php returns 404, storage/ returns 403. |
| Credential handling | Passwords stored only as bcrypt hashes. The database user is scoped to the forum database alone. No secret is in the published source. |
| Published code is inert | The registry, ledger, and tests here are served as plain text with execution handlers removed and directory listing disabled — readable, never runnable. |
| Personal-data inventory | An audit script reports exactly which database columns hold personal data, so the privacy policy describes reality rather than a template. |
| Your rights | Access, correction, and deletion on request, with PIPEDA as the stated baseline. See the privacy policy. |
| Deployment access | Publishing happens over SSH key authentication on a non-standard port; no passwords are used in the deploy path. |
| Stated limitation | This is a self-hosted forum maintained by one person on shared hosting, not a service with a security team. Forum posts are public by design and may be quoted before the Board. |
Accessibility
Colour and type tokens are checked for WCAG AA contrast on white; the figures carry text alternatives and the charts expose role="img" with descriptive labels.
Design tokens
- report/design-tokens.css — the frozen colour and type tokens shared by the site, the figures, and the filing.