What we measure
- Architecture quality, separation of concerns, technical debt signals
- Security baseline, auth, authorization, secrets, dependency provenance
- Operational maturity, monitoring, alerting, rollback, release governance
- Documentation completeness, runbooks, API contracts
- Testing maturity, coverage signals, test categories, CI integration
- Multi-tenant isolation and tenancy model fitness
- IP / licensing, dependency audit, SPDX provenance
- Code quality, linting, structure, complexity heuristics