E.00 Measured, on the shipping code
We measured it to the millisecond.
Every number here comes from running the product's own parser, engine, and package builder on fixed-seed synthetic data, on one laptop, on the filming build. The runs are reproducible from two commands.
7.5s10,000 findings to a 50-artifact package, one laptop, on each of three runs
| Measured | Result | Condition |
|---|---|---|
| 10,000 findings to a 50-artifact package | 7.5 s | One laptop, each of three runs; 10,000 of 10,000 rows created |
| 10,000-line property book, import preview | 0.44 s | File fingerprinted, every conversion and gap listed before anything is created |
| Today screen on the full corpus | 1.0 s | Every screen inside its render budget |
| One finding, import to Reviewer Package export | 15 clicks | Plus 3 file choices and one typed step name |
| Package restore | Verified | A Full Export Package restores into a cleared workspace, checked against its TraceSeal manifest |
What the numbers mean
Ten thousand findings is three times the 3,322 findings GAO reported open across the Department at the end of FY2023, processed to a fifty-artifact package in 7.5 seconds on each of three runs (GAO-24-106890 for the FY2023 count). Every one of the 10,000 rows that should have become a finding did.
The same runs inside a browser produce the same package at the same sizes. The scriptable harness and the in-browser harness are both in the repository.
How it was measured
One laptop; the product makes no network calls. Synthetic data generated from a fixed seed, with the expected results written down before each run. The datasets and both harnesses ship in the repository, so any organization can repeat the runs on its own hardware.
E.01 Measured on a realistic corpus
What a battalion's audit season looks like inside the product.
The results below are measured on a realistic corpus built one to one with what an auditor delivers: the emails, the attachments, the sample selections, and the registers, measured by the pack harness at the mounted build, so anyone with the pack can reproduce them. Tracepoint's first agency deployment will add outcomes at an agency to these figures.
A battalion's audit sample support
The corpus includes the package an aide receives for an FY26 sample: an email, 36 attachments, a 45-item existence sample, and a 25-item completeness sample. The product imports the auditor's sample selection directly, pre-fills the count with the sampled lines, attaches each key supporting document to the specific line it supports, and produces a package with item-by-item support for every sampled item. All 45 sampled items are keyed to a book line, 48 documents are attached with 43 line links, and the package covers 55 records with 66 line-support rows. The harness run records 124 records and 221 trail rows, and the verified walkthrough is 50 kilobytes of steps that a first-time user follows from the email to the hand-off.
Carrying findings across fiscal years
From a 334-item FY26 NFR register, a 105-item FY25 rollforward, a 266-row CAP tracker, and three monthly scans, the product found 90 repeat events across 170 of 913 findings and wrote 574 control links on 465 findings, 323 of them from a proposal by the linker or the crosswalk, each link confirmed by a person and written to the trail. The ODCFO export carries 18 rows, and the eMASS export 18 rows with 22 warnings stated. That is the reconciliation work an audit response office does by hand across spreadsheets today.
Speed at scale
With a thousand open corrective actions, the findings view computes in 86 milliseconds, measured on the view model in Node, and every screen stays within a 100 millisecond budget on the full corpus.
Fewer rejected submissions
An eMASS or OSCAL file that would be rejected on import is refused before it is written, with the row and the rule, and the person is warned on the case before they reach the export.
E.02 The handling test
Five hundred planted broken rows, and the expected handling written down first.
A tool that quietly cleans up bad data hides it from the reviewer. Every expectation was met exactly.
| Condition in the file | Rows | What Tracepoint did |
|---|---|---|
| No title and no condition | 23 | Refused the row and named the reason |
| Fiscal year missing | 28 | Left blank and flagged as not provided |
| Classification not recognised | 37 | Defaulted, and disclosed as defaulted |
| Source ID repeated in the file | 33 | Flagged each repeat and offered to skip |
Every conversion the importer made is retained in the export package next to the original source value, and the refused rows leave as a list a person can download.
E.03 Every build
The benchmark runs on every build.
Four behaviours the benchmark holds to, release after release.
The export emits all 21 columns of the eMASS RMF POA&M template in template order with exact header text, and the validator checks every row against the field matrix before the file is written.
A 10,000-row register is created at 10,617 findings per second in the browser, and the screen updates once when the batch lands.
Duplicate source identifiers are detected against the existing workspace and inside the incoming file, and the preview says which kind it found.
The check suites run before every commit, and the date-handling checks set the process clock to America/Los_Angeles, UTC, Pacific/Kiritimati, and Pacific/Pago_Pago in turn, so a printed day is exercised the way a deployed workstation will exercise it.
The production build is served under the shipped Content-Security-Policy before release, with an integrity manifest that fails the build if the policy pin no longer matches.
E.04 Exports
Exports are checked before they are allowed to exist.
OSCAL, against the NIST schema
The OSCAL POA&M export is validated against the vendored NIST OSCAL schema before it saves, and a refusal lists every schema violation with a CSV download. Where the product deviates from the schema's intent, the deviation is written into the file itself.
eMASS, against the 21-column template
Exact header text in template order. POA&M Item ID is left empty because eMASS generates it. The RMF risk columns are left empty and reported, because they must never be derived from a financial-statement finding classification.
Known-exploited vulnerabilities, with the date
Scanner findings that match CISA's Known Exploited Vulnerabilities catalog are marked, and the catalog date is shown so a reviewer knows how current the marker is.
E.05 Next step
Run it yourself.
The demo runs the same engine on the worked example, and the benchmark harness that produced these figures ships in the repository.