Tracepoint

E.00 Measured, on the shipping code

We measured it to the millisecond.

Every number here comes from running the product's own parser, engine, and package builder on fixed-seed synthetic data, on one laptop, on the filming build. The runs are reproducible from two commands.

7.5s10,000 findings to a 50-artifact package, one laptop, on each of three runs

MeasuredResultCondition
10,000 findings to a 50-artifact package7.5 sOne laptop, each of three runs; 10,000 of 10,000 rows created
10,000-line property book, import preview0.44 sFile fingerprinted, every conversion and gap listed before anything is created
Today screen on the full corpus1.0 sEvery screen inside its render budget
One finding, import to Reviewer Package export15 clicksPlus 3 file choices and one typed step name
Package restoreVerifiedA Full Export Package restores into a cleared workspace, checked against its TraceSeal manifest

What the numbers mean

Ten thousand findings is three times the 3,322 findings GAO reported open across the Department at the end of FY2023, processed to a fifty-artifact package in 7.5 seconds on each of three runs (GAO-24-106890 for the FY2023 count). Every one of the 10,000 rows that should have become a finding did.

The same runs inside a browser produce the same package at the same sizes. The scriptable harness and the in-browser harness are both in the repository.

How it was measured

One laptop; the product makes no network calls. Synthetic data generated from a fixed seed, with the expected results written down before each run. The datasets and both harnesses ship in the repository, so any organization can repeat the runs on its own hardware.

The full benchmark report with the method

E.01 Measured on a realistic corpus

What a battalion's audit season looks like inside the product.

The results below are measured on a realistic corpus built one to one with what an auditor delivers: the emails, the attachments, the sample selections, and the registers, measured by the pack harness at the mounted build, so anyone with the pack can reproduce them. Tracepoint's first agency deployment will add outcomes at an agency to these figures.

A battalion's audit sample support

The corpus includes the package an aide receives for an FY26 sample: an email, 36 attachments, a 45-item existence sample, and a 25-item completeness sample. The product imports the auditor's sample selection directly, pre-fills the count with the sampled lines, attaches each key supporting document to the specific line it supports, and produces a package with item-by-item support for every sampled item. All 45 sampled items are keyed to a book line, 48 documents are attached with 43 line links, and the package covers 55 records with 66 line-support rows. The harness run records 124 records and 221 trail rows, and the verified walkthrough is 50 kilobytes of steps that a first-time user follows from the email to the hand-off.

Carrying findings across fiscal years

From a 334-item FY26 NFR register, a 105-item FY25 rollforward, a 266-row CAP tracker, and three monthly scans, the product found 90 repeat events across 170 of 913 findings and wrote 574 control links on 465 findings, 323 of them from a proposal by the linker or the crosswalk, each link confirmed by a person and written to the trail. The ODCFO export carries 18 rows, and the eMASS export 18 rows with 22 warnings stated. That is the reconciliation work an audit response office does by hand across spreadsheets today.

Speed at scale

With a thousand open corrective actions, the findings view computes in 86 milliseconds, measured on the view model in Node, and every screen stays within a 100 millisecond budget on the full corpus.

Fewer rejected submissions

An eMASS or OSCAL file that would be rejected on import is refused before it is written, with the row and the rule, and the person is warned on the case before they reach the export.

E.02 The handling test

Five hundred planted broken rows, and the expected handling written down first.

A tool that quietly cleans up bad data hides it from the reviewer. Every expectation was met exactly.

Condition in the fileRowsWhat Tracepoint did
No title and no condition23Refused the row and named the reason
Fiscal year missing28Left blank and flagged as not provided
Classification not recognised37Defaulted, and disclosed as defaulted
Source ID repeated in the file33Flagged each repeat and offered to skip

Every conversion the importer made is retained in the export package next to the original source value, and the refused rows leave as a list a person can download.

E.03 Every build

The benchmark runs on every build.

Four behaviours the benchmark holds to, release after release.

eMASS output is checked column by column

The export emits all 21 columns of the eMASS RMF POA&M template in template order with exact header text, and the validator checks every row against the field matrix before the file is written.

Large imports commit in one batch

A 10,000-row register is created at 10,617 findings per second in the browser, and the screen updates once when the batch lands.

Duplicates are caught in both places

Duplicate source identifiers are detected against the existing workspace and inside the incoming file, and the preview says which kind it found.

2,213 automated checks before every commit

The check suites run before every commit, and the date-handling checks set the process clock to America/Los_Angeles, UTC, Pacific/Kiritimati, and Pacific/Pago_Pago in turn, so a printed day is exercised the way a deployed workstation will exercise it.

Every build is checked under its own security headers

The production build is served under the shipped Content-Security-Policy before release, with an integrity manifest that fails the build if the policy pin no longer matches.

E.04 Exports

Exports are checked before they are allowed to exist.

OSCAL, against the NIST schema

The OSCAL POA&M export is validated against the vendored NIST OSCAL schema before it saves, and a refusal lists every schema violation with a CSV download. Where the product deviates from the schema's intent, the deviation is written into the file itself.

eMASS, against the 21-column template

Exact header text in template order. POA&M Item ID is left empty because eMASS generates it. The RMF risk columns are left empty and reported, because they must never be derived from a financial-statement finding classification.

Known-exploited vulnerabilities, with the date

Scanner findings that match CISA's Known Exploited Vulnerabilities catalog are marked, and the catalog date is shown so a reviewer knows how current the marker is.

E.05 Next step

Run it yourself.

The demo runs the same engine on the worked example, and the benchmark harness that produced these figures ships in the repository.