The infrastructure predates the law
On May 26, 2026, an investigative writer who publishes as The Drey Dossier filed a piece arguing that the White House National Design Studio is quietly rebuilding the parts of the federal government that touch you most β your prescriptions, your passport, your voter registration, your federal login β on infrastructure the White House itself owns. Three days later we sat down to check it.
What follows is a verification pass against primary public sources: the CISA dotgov registry, certificate transparency logs, the Federal Register, the actual JavaScript shipped by the studio, the actual privacy policy of the actual website. Every URL we hit was fetched and hashed with SHA-256. Every claim below has a receipt at the bottom of its paragraph — the hash printed there pins the exact bytes the assertion was built against.
Most of Drey's specific factual claims came back exact. Some, to the line number. Some, to the UTC minute. None came back contradicted.
But the verification also turned up four things the original article didn't say. The most important one rewrites the timeline of the story by seven months.
1. The vote-gov preview existed seven months before the executive order that authorizes it
Drey writes that a working preview of vote.gov appeared inside the studio's staging environment, gated behind a Cloudflare login. She gives a specific date: "The certificate appeared on April 10, 2026." She frames this as conspicuous because, weeks earlier, the administration had signed an executive order requiring DHS, the Social Security Administration, and the SAVE program to construct a federal citizenship-verified voter list, with a deadline of ninety days from signing.
The April 10 certificate exists. We confirmed both of its entries in the certificate transparency log. But it isn't the first certificate for that hostname. The first certificate for vote-gov.previews.ndstudio.gov was issued on September 8, 2025 β six months and twenty-three days before the executive order was signed.
Strip the ambiguity off and the structure of what happened is this: the White House National Design Studio started building a federal voter-registration website in September 2025. The President of the United States signed an executive order authorizing federal voter-list construction in March 2026. The thing being authorized had been running for half a year before the authorization existed.
That isn't infrastructure responding to an executive order. It's an executive order providing legal cover for infrastructure already in place.
Receipts: claim 12 β vote-gov preview cert timeline Β· claim 39 β EO signing vs. cert timeline Β· claim 33 β EO 14399 metadata Β· crt.sh source Β· sha2566fab65fe3462β¦
2. The deadline that matters is September 4, 2026 β not June 29
The article rightly emphasizes EO 14399's ninety-day deadline from signing. We confirmed it verbatim. From section 4(c):
"The Secretary of Homeland Security shall, within 90 days of the date of this order, establish the infrastructure necessary to compile, maintain, and transmit the State Citizenship List described in section 2(a) of this order."
The EO was signed March 31, 2026. Ninety days lands on June 29, 2026. The article correctly says "that deadline is weeks away."
But the same EO has a second clock β and the second clock is the one that triggers actual list transmission to the states. Section 2(a):
"The State Citizenship List shall be updated and transmitted to State election officials no fewer than 60 days before each regularly scheduled Federal election."
The 2026 midterm general election is November 3. Sixty days before that is September 4, 2026. That is the date by which the list β derived from federal citizenship records, SSA records, SAVE data, and other relevant federal databases β must be in the hands of state election officials.
June 29 is when DHS must finish the plumbing. September 4 is when the plumbing starts moving water. If anyone is going to argue, in court or in Congress, that the federal government cannot inject its own citizenship list into state voter rolls weeks before a federal election, September 4 is the date they're arguing about.
Receipts: claim 34 β 90-day infrastructure deadline (verbatim Β§4(c)) Β· claim 36 β 60-day transmission rule (verbatim Β§2(a)) Β· EO 14399 full text3. The construction is accelerating, not slowing
Drey's article hit on May 26. Most reporting that surfaces this kind of infrastructure causes a quiet pause β projects go dark for a beat, lawyers wake up, things stop moving. That did not happen here.
When we queried the certificate transparency log on May 29, three days after publication, the studio had issued eighteen new certificates we hadn't seen before. One specific set is worth flagging:
This is a small data point, but it speaks. The studio did not pause after national attention. It shipped chat infrastructure the next day.
Receipts: claim 9 β 18 new certs in 3 days Β· claim 14 β chat infrastructure shipped 2026-05-274. The "second vote.gov" is actually two β and there's a paired singular/plural pattern
The piece's headline is about a second vote.gov. The certificate logs show there are actually two parallel vote-registration hostnames running inside the studio's staging environment, not one:
vote-gov.previews.ndstudio.govβ first cert 2025-09-08, twenty cert events through 2026-05-13vote-gov-ndstudio.previews.ndstudio.govβ first cert 2025-11-17, fifteen cert events through 2026-05-13
Both are gated behind loveisaskill.cloudflareaccess.com, the personal-named Cloudflare account Drey identifies. The plural existence is curious. A staging environment typically has one preview hostname per project; having two suggests either parallel implementations or β more likely β production / staging twins. Either way, the studio is treating vote.gov work as a major, multi-track project, not an experiment.
The same pairing shows up on passports. We confirmed in the CISA dotgov registry that both passport.gov (singular) and passports.gov (plural) are registered to the Executive Office of the President. The plural is staging actively β passport.staging.ndstudio.gov, passports.staging.ndstudio.gov, auth.passports.gov, api.passports.gov, and nine separate *.photo.passports.gov certificates issued in a single hour on May 26. The singular is registered but does not respond to direct requests. It's a held domain.
Singular + plural domain pairs are a pattern we hadn't seen called out anywhere. Worth tracking the next time it shows up.
Receipts: claim 7 β passport.gov registered Β· claim 15 β passport / passports staging pair Β· claim 23 β 9 photo certs in 1 hour Β· claim 30 β program-domain probe results5. The dotgov registrations match the executive-order program names
EO 14338 β the order that creates the National Design Studio β uses a specific name for the studio's mission: the "America by Design initiative." The CISA registry shows that americabydesign.gov is registered to the Executive Office of the President, White House Office.
This isn't damning by itself; vanity domain registrations follow program announcements all the time. What's useful is the predictive value. Going forward, when a new EOP-owned vanity .gov shows up in the CISA registry, the matching executive order or program is probably real. We can watch the registry as a leading indicator.
The registry currently holds dozens of EOP-owned domains worth knowing about β including nasaforce.gov (whose subdomain we found in NDS staging), techforce.gov, trumpcard.gov, trumpira.gov, merrychristmas.gov, freedom.gov, live.gov, launch.gov, and crypto.gov, among others. The full table is on the domain roster page.
6. The technical specifics check out
Three of Drey's narrowest, most technical claims could be tested against the running website directly. All three were exact.
The AutoMonitor script
Drey describes "five hundred and forty lines of custom JavaScript with a name embedded directly in the code: AutoMonitor." She says it generates a session ID on line 7 and posts telemetry to a private backend on line 8.
We fetched the file at https://cdn.infra.ndstudio.gov/internal-analytics/script.js. It is 540 lines. Line 4 begins:
class AutoMonitor {
Line 7 reads, verbatim:
this.sessionId = this.generateId();
And line 8:
this.endpoint = "https://analytics.infra.ndstudio.gov/metrics";
The script is loaded on ndstudio.gov itself via a <script src="https://cdn.infra.ndstudio.gov/internal-analytics/script.js"> tag β visible in page source on the studio's own homepage. It posts telemetry to a hostname the studio controls. The endpoint did not respond when we probed it directly, which is what a well-behaved tracker endpoint does.
cb4da9fc1565β¦
The TrumpRx privacy policy contradiction
Drey notes that TrumpRx's privacy policy explicitly says PostHog records user activity and then, "two paragraphs later," states the site does not collect medical information. We confirmed this verbatim. PostHog is named under "Service Providers." Several paragraphs down, under "Information We Do Not Collect," the list includes "Health or medical information" and "Prescription details or medication history."
The contradiction is direct. PostHog's default configuration records full session replays, including page URLs and click targets. TrumpRx exists for the purpose of looking up medication pricing. The URLs and click targets on a medication-pricing website are medication information.
Receipts: claim 27 β privacy-policy contradiction Β· live policy Β· sha256cbbd70efcb44β¦
The Cloudflare access wall
Drey reports that the studio's preview subdomains all gate behind a Cloudflare login screen at loveisaskill.cloudflareaccess.com, named after a phrase the studio's lead has used publicly. We probed four of the specific subdomains she named β vote-gov, fbi-kirk-tipline, trump-accounts-splashpage, and war.previews. All four responded with redirects to the loveisaskill SSO portal. The personal-account framing is correct.
7. What's missing β the procedural absence the article gets right
Drey's argument hinges on a specific procedural claim: that the federal government's required privacy disclosures β System of Records Notices, Privacy Impact Assessments β were not filed for any of the twelve National Design Studio programs.
We searched the Federal Register's API for "National Design Studio." The query returns exactly two documents, both of which are presidential documents: EO 14338 (the order that created the studio) and EO 14359 (Trump Accounts).
There are no System of Records Notices. There are no Privacy Impact Assessments. The legally required notices that Congress mandated after Watergate, intended to make sure the federal government cannot run secret data-collection programs on its own citizens, are not on file.
For a federal office that ships JavaScript trackers, runs voter-registration previews, sets up passport-photo upload endpoints, and registers domain names corresponding to half a dozen unannounced programs, that absence is the underlying compliance story. The infrastructure exists. The disclosures that the infrastructure is supposed to generate do not.
Receipts: claim 17 β Federal Register zero SORN/PIA filings Β· live search Β· sha256a4d6bf087864β¦
What we couldn't verify β and what would unblock it
Six specific claims from the article we could not verify in this session, all because the primary source is behind a paywall, an API key, or simply not indexed publicly. We list them here so they're not pretending to be confirmed when they aren't.
- Joe Gebbia as NDS Chief Design Officer. EO 14338 creates the title but does not name him. Reuters reports his appointment, but the Reuters URL returns HTTP 401. Wayback Machine timed out. A subscription or alternative archive would settle it. claim 40
- Greg Hogan promoted to run Login.gov. No Federal Register doc; no published GSA press release we could find. Needs direct Login.gov staff page or congressional record. claim 41
- Akash Bobba's October 2025 recorded call with state election directors. The recording is not in any public index we could find. Likely a FOIA-able or interview-sourced item. claim 42
- DOJ told a federal court the agencies hadn't begun preparation. CourtListener's anonymous API returns 403; we need an API key (free) plus the case caption. claim 43
- DOGE OPM injunction with Hogan exception. Same β needs CourtListener access and a case name. claim 44
- AFT v. Bessent. Same. claim 45
None of these unverified items contradicts the article. They're identity confirmations for specific individuals or specific court findings. The structural argument β about offices, infrastructure, statutes, deadlines, and the absence of required disclosures β does not depend on them.
Update: what changed in the week after the article ran
A change-detection pass on 2026-06-01 caught one substantive new development and confirmed five points of stability.
What did NOT change in the same window:
- The AutoMonitor source is byte-identical to the snapshot we took on 2026-05-29 (sha256
cb4da9fcβ¦unchanged). The studio did not modify the script in response to the technical analysis. - ndstudio.gov homepage is unchanged.
- TrumpRx privacy policy is unchanged β the two-paragraph contradiction described in the report is still present verbatim.
- The CISA dotgov registry has no new EOP-registered domains.
- Federal Register search for "National Design Studio" still returns zero SORN and zero PIA filings. The procedural gap the article identified remains open.
One operational footnote: crt.sh's JSON API returned HTTP 503 on the ndstudio.gov query during this diff. crt.sh has had availability issues since well before the article; this is not new. The HTML form still served the same data, and Certspotter is a partial backup (covers about half of crt.sh's name set). Ongoing monitoring should use both.
Receipts: claim 59 β api2.passports.gov rollout Β· claim 60 β crt.sh outage / Certspotter coverage Β· claim 61 β five unchanged sourcesUpdate: Will Hold cross-check β 2026-06-03
On 2026-05-31, an independent investigation by the substack This Will Hold reached aligned conclusions about the National Design Studio. We treated each novel claim as a verification target. The piece adds substantively to the record on six points, and refines our reading on a seventh.
The July 4, 2026 date isn't a hidden feature flag β it's written into the EO. A grep of our existing GovInfo snapshot of EO 14338 turned up the literal sentence in Β§3: "Heads of agencies shall consult with the Chief Design Officer to implement the America by Design initiative at their respective agencies and shall produce initial results by July 4, 2026." The certificate-creation timeline the article documented (passports.gov 2026-05-05, vote.gov 2026-04-10) is the runway to that statutory milestone. Will Hold's reading that this date may mark a wholesale switch from agency-owned sites to White House-owned copies is consistent with the order's text β the order does not direct agencies to replicate, but it does set July 4, 2026 as the date by which agency implementation must begin to show. Receipts: claim 62
EO 14399 is real, and the timeline contradiction is sharp. Signed 2026-03-31 and published 2026-04-03 (Federal Register doc 2026-06601). Β§4(c) requires the Secretary of Homeland Security to "establish the infrastructure necessary to compile, maintain, and transmit the State Citizenship List" within 90 days. The EO does not explicitly name the National Design Studio, Login.gov, or the Election Assistance Commission β those identifications are structural inferences about who would actually do the building. The vote.gov staging certificate is dated 2026-04-10 β seven days after EO 14399 was published. That timing is itself a fact. Will Hold further claims the Department of Justice told a federal court the named agencies "had not yet begun preparations and were still in the deliberative phase"; we were unable to surface that filing through public search and have logged it as the highest-leverage remaining open thread. Receipts: claim 63 Β· claim 70 (unverified)
Akash Bobba's USADF security contact is directly visible in the federal authority. Line 1163 of the CISA dotgov-data CSV β the authoritative federal registry of .gov domains β reads: usadf.gov,Federal - Executive,United States African Development Foundation,African Development Foundation,Washington,DC,akash@ndstudio.gov. The security contact is a White House mailbox in the ndstudio.gov namespace, not an USADF mailbox. The older sibling domain adf.gov (line 1162) still lists a usadf.gov mailbox; the transfer is real and unilateral. A staffer reporting to the Chief Design Officer (and through him to the Chief of Staff) now sees who at USADF applies for grants, who gets approved, and the agency's security configuration. Receipts: claim 64 Β· people roster
Five named NDS staff, all with documented DOGE pipelines. Joe Gebbia (Chief Design Officer, ex-Airbnb, ex-DOGE) reports directly to White House Chief of Staff Susie Wiles. Greg Hogan, former OPM CIO, was one of three DOGE-affiliated individuals granted an exception to the 2025 federal court order blocking DOGE from accessing OPM personnel records (American Federation of Teachers v. Bessent, 8:25-cv-00430, D. Md.) and now runs Login.gov from inside NDS. Edward "Big Balls" Coristine β the self-nicknamed DOGE engineer whose Tesla.Sexy LLC owns Russian-registered domains and who is, per Newsweek, descended from a KGB defector β has moved to NDS. Kaitlyn Koller (former Senate Foreign Relations Committee aide) and Zachary Terrell (former DOGE roles at HHS and NSF) round out the visible cohort. The People Roster collects each entry with sources. Receipts: claim 65 Β· claim 66 Β· claim 67 Β· people roster
The March 24, 2025 SSA "Voter Data Agreement" is independently confirmed. Democracy Forward's April 2026 court filings, supported by Democracy Docket and FedScoop reporting, establish that a DOGE team member at the Social Security Administration signed a Voter Data Agreement with a political advocacy group (widely suspected to be True the Vote); the agreement bypassed SSA's internal data-exchange safeguards; SSA discovered it only in November 2025 during an unrelated review. Receipts: claim 68
Two federal challenges to EO 14399 are now in the dockets. League of Women Voters of Massachusetts v. Trump, 1:26-cv-11549, D. Mass., filed 2026-04-02. Common Cause v. DOJ, 1:26-cv-01352, D.D.C., filed 2026-04-21, alleging a "Voter Registration Nationalization Policy." Receipts: claim 69
Net read of the cross-check: the Drey Dossier and Will Hold reach the same structural conclusion through different evidence paths β Drey through certificate transparency and code-side telemetry; Will Hold through Federal Register dates, the SSA / DOGE litigation record, and named DOGE-to-NDS movements. Convergent investigation, not redundant; each side adds the part the other could not see.
Update: the Borges whistleblower disclosure β 2026-06-03
The Will Hold piece's claim that the private data of 300+ million Americans was copied into an unsecured cloud environment is independently and publicly substantiated. The substantiation is a formal whistleblower disclosure filed 2025-08-26 by Charles 'Chuck' Borges, the Social Security Administration's Chief Data Officer, through the Government Accountability Project β to the U.S. Office of Special Counsel and the four Congressional committees with jurisdiction. The disclosure is 18 pages and is public on whistleblower.org. We have read it in full.
Borges is a career civil servant: 22 years U.S. Navy (Air Medal with Combat Distinguishing Device, Operation Iraqi Freedom), prior CDO at NAVAIR, civil-service stops at GSA, OMB, CDC (during COVID), and as a White House Presidential Innovation Fellow. He began his SSA CDO role on 2025-01-27, six days after the administration took office. By statute his role requires full visibility into data access, data exchange, and cloud-based environments used for SSA production systems.
The disclosure names four DOGE personnel inside SSA β Edward Coristine, Aram Moghaddassi, John Solly, and Michael Russo β plus Akash Bobba and Payton Rehling as further participants. The narrative tracks a precise sequence with primary-source exhibits.
Phase 1: bypassed access (March 2025). On 2025-03-14, DOGE members Payton Rehling and Aram Moghaddassi obtained access to the Enterprise Data Warehouse PSNAP and SNAP MI databases through a process that bypassed SSA's Systems Access Management (SAM) approval system. The profiles granted included 'equipment pin access' (which makes user actions untraceable to specific people) and 'write access' (the ability to edit data). The EDW team discovered the unauthorized access three days later, on 2025-03-17. Receipts: claim 73
Phase 2: TRO circumvention (March 20β24, 2025). On 2025-03-20, a federal court Temporary Restraining Order in AFSCME v. SSA, 1:25-cv-00596 (D. Md.), prohibited DOGE and its affiliates from accessing SSA's PII. Within 24 hours, per the disclosure, DOGE officials had restored access for two DOGE employees with 42 different new and expanded user profiles, including 'specifically identified privileges that should not have been granted.' Four days later, on 2025-03-24, SSA Defendants certified compliance with the TRO under oath. Borges' disclosure flags the simultaneity as the core of the allegation, and lists potential statutory violations: 18 U.S.C. Β§ 1030 (Computer Fraud and Abuse Act), 5 U.S.C. Β§ 552a (Privacy Act), 44 U.S.C. Β§ 3551 et seq. (FISMA), 5 U.S.C. Appendix (Inspector General Act), and 18 U.S.C. Β§ 371 (Conspiracy to circumvent a federal court order). Receipts: claim 74
Phase 3: NUMIDENT in an unsecured cloud (JuneβJuly 2025). On 2025-06-06, the Supreme Court stayed the AFSCME preliminary injunction, allowing DOGE access pending appeal. Four days later, John Solly initiated a request for a Virtual Private Cloud within SSA's AWS Agency Cloud Infrastructure to host NUMIDENT β the database containing the SS-5 application data for every U.S. Social Security card ever issued, including names, dates and places of birth, citizenship, race, parents' names and parents' SSNs. The internal SSA "Risk Acceptance Request Form" issued 2025-06-12 by a career OCIO official labeled the project 'very high risk' (estimated risk score 15), with the explicit warning that 'unauthorized access to the NUMIDENT would be considered catastrophic impact to SSA beneficiaries and SSA programs.' Three mitigations were stipulated: no production data, DIS involvement to enforce agency policy, and a FISMA ATO. None of the three were met. On 2025-06-25, Michael Russo β by then a 'special advisor' rather than CIO β approved the transfer of live NUMIDENT data to the DOGE-controlled cloud in a single-word email reply: 'Approvedβ¦.' On 2025-07-15, Aram Moghaddassi (the actual SSA CIO at that point) signed a 'Provisional Authorization to Operate' for the environment, stating in writing: 'I have determined the business need is higher than the security risk associated with this implementation and I accept all risks associated with this implementation and operation.' Per Borges, by late June 2025 no verified audit or oversight mechanisms existed over the cloud environment, and no one outside the former DOGE group had insight into code being executed against the live data. Receipts: claim 75
Phase 4: response to the CDO. When Borges raised concerns internally starting 2025-08-06 and emailed information requests to Coristine, Solly, and the OCIO Executive Officer Mickie Tyquiengco on 2025-08-11, he received no response. The SSA Office of General Counsel reportedly advised employees not to respond to his inquiries. By statute, the CDO requires that information to perform the role. Receipts: claim 76
The Will Hold piece's exact phrasing was 'whistleblowers have alleged that DOGE affiliates improperly copied the private data of over 300 million Americans into the private cloud server, with claims that some retained highly sensitive access to SSA systems.' That sentence β generic-sounding when first read β turns out to be a near-verbatim restatement of the Borges disclosure's central technical claim. The cloud is AWS-ACI (an Amazon environment) rather than Cloudflare specifically, though earlier Cloudflare-mediated data sharing by DOGE-SSA personnel between 2025-03-07 and 2025-03-17 is separately attested by Democracy Forward.
The DOJ "deliberative phase" filing is real, and the language is verbatim. Will Hold attributes specific phrasing to DOJ in EO 14399 litigation β that the agencies "had not yet begun preparations and were still in the deliberative phase." We tracked it down: it is the Defendants' Combined Memorandum of Law in Support of Their Motions to Dismiss and in Opposition to Plaintiffs' Motions for a Preliminary Injunction, filed 2026-05-01 in DSCC v. Trump, 1:26-cv-01114-CJN (D.D.C.), Document 106-1 β the DOJ's primary brief in the lead consolidated case. Four passages, near-verbatim to Will Hold's paraphrase:
"These three suits were each filed well before any agency had taken any steps to implement the Executive Orderβand before the agency defendants even knew how they might try to implement the President's directions, or on what timeline. Even to this day, none of the possible future agency actions contemplated by the Executive Order have been finalizedβand some have not even started." β DOJ Mem. p.1
"As of this filing, no such lists have been created, nor has any of the 'infrastructure' contemplated by Section 4(c) of the Order." β DOJ Mem. p.2
"Indeed, the relevant agencies themselves are still deliberating regarding the Executive Order's possible future implementation." β DOJ Mem. p.9
"DHS has not yet made any determination that preparing these lists is either 'feasible' or 'consistent with applicable law.'" β DOJ Mem. p.18
The filing is signed by AAG Brett A. Shumate, Deputy AAG Eric J. Hamilton, Asst. Branch Director Joseph E. Borson, Senior Trial Counsel Stephen M. Pezzi, and Trial Attorney Esam K. Al-Shareffi. It is supported by three sworn declarations from DHS (Mayhew), SSA (MacBride), and USPS (Monteith) β each attesting to the lack of implementation progress as of late April 2026. Receipts: claim 85
But the SSA half of that representation is in tension with the Borges record. The DOJ tells the court "DHS has not yet made any determination" about whether using SSA's Privacy-Act-protected data for the State Citizenship List is feasible or lawful. That is true at the SORN level β DHS publishes the relevant SORN, not SSA. But the operative SSA data the State Citizenship List would need β NUMIDENT β was already running as a live copy inside an SSA AWS Virtual Private Cloud under DOGE administrative control as of mid-2025. The configuration was approved 2025-06-25 by Michael Russo with the one-word reply "Approvedβ¦." and the Provisional Authorization to Operate was self-signed 2025-07-15 by Aram Moghaddassi. Both dates pre-date EO 14399. So the relevant infrastructure does exist; it just sits on the wrong side of FISMA, set up under a different pretext, with no independent security oversight. Receipts: claim 86 Β· claim 75
And the runway aligns to the day. The DOJ memo argues plaintiffs' challenges are unripe because agencies have until 2026-06-29 (EO 14399 Β§4(c)'s 90-day deadline) to comply β i.e., until five days before the EO 14338 Β§3 July 4, 2026 "America by Design initial results" deadline. The cert log dates we already had (passports.gov 2026-05-05, vote.gov 2026-04-10) sit on the runway between the EO signing and the Β§4(c) deadline. If the deadlines are met, the cert log timestamps will already have proven the work began before DOJ's May 1 representations to the court. Receipts: claim 87
The broader frame: three independent primary sources describe the same strategy. The narrow story we and Drey began with β White House digital services being rebuilt under EOP ownership β turns out to be one face of a wider DOGE strategy of cross-agency data consolidation. Three independent primary sources describe it:
- Tiffany Flick, then-Acting Chief of Staff to the SSA Acting Commissioner β retired 2025-02-16, filed a sworn declaration in AFSCME v. SSA describing DOGE employees pressuring her and then-Acting Commissioner Michelle King for "immediate access" to all SSA systems, evasive about why. King resigned in February 2025 rather than comply. Flick describes Michael Russo (then SSA CIO; later the "Approvedβ¦." authorizer of the NUMIDENT transfer) as "obsessed with unsubstantiated claims of Social Security fraud rather than with the actual operational needs of the agency."
- An anonymous whistleblower in April 2025 β disclosed to Rep. Gerry Connolly that DOGE was building a single cross-agency "master database" of sensitive information drawn from the IRS, SSA, HHS, and Treasury. Connolly's letter to the SSA OIG quotes the allegation that "DOGE engineers have tried to create specialized computers for themselves that simultaneously give full access to networks and databases across different agencies" β calling this "an apparent attempt to sidestep network security controls" β and that "Individuals associated with DOGE have assembled backpacks full of laptops, each with access to different agency systems, that DOGE staff is using to combine databases that are currently maintained separately by multiple federal agencies." This whistleblower is separate from Chuck Borges and predates the Borges disclosure by four months.
- Steve Davis, Musk's longtime senior aide β the Washington Post reported 2025-05-07 that Davis told SSA staffers DOGE "would soon start linking various sources of Social Security data for access and analysis." Davis is not part of the 19-22-year-old DOGE engineer cohort; he is the senior operator articulating the master-database doctrine on the record.
The National Design Studio, populated by DOGE alumni inside the Executive Office of the President, is the logical receiving infrastructure for that consolidated data once it has been moved out of the originating agencies and brought under direct White House control. NDS staff are hired under Section 3161; the EOP has no inspector general; the Presidential Records Act seals everything for twelve years after this administration ends. Receipts: claim 88 (Davis) Β· claim 89 (Flick) Β· claim 90 (King) Β· claim 91 (Connolly) Β· claim 92 (synthesizing) Β· people roster
The shape of the story after verification
The Drey Dossier reported, on May 26, 2026, that a White House design office was quietly building federal infrastructure outside the agencies that legally own it. After three days of checking, here is what we can now say is documented from primary sources:
- The office exists by executive order. [claim 19]
- It reports to the White House Chief of Staff, not GSA. [claim 19]
- It hires under Section 3161 as a temporary organization. [claim 20]
- It owns at least thirty domains in the CISA registry under the Executive Office of the President. [roster]
- It runs at least sixty-five subdomains in the certificate transparency logs, of which roughly forty are unannounced. [subdomains]
- It built a working preview of vote.gov in September 2025 β six and a half months before the executive order authorizing a federal citizenship-verified voter list. [claim 12]
- It uses a personal-named Cloudflare account to front federal preview infrastructure. [claim 29]
- It ships a custom JavaScript telemetry script that records page activity and forwards it to a hostname under the studio's own control. [claim 25]
- It contradicts its own privacy policy on the federal medication-pricing website. [claim 27]
- It has filed zero System of Records Notices and zero Privacy Impact Assessments across its programs. [claim 17]
- It continued shipping new staging infrastructure the day after the article ran. [claim 14]
The structural argument is intact. The timeline is older than the article reported. The next dates to watch are June 29, 2026 (DHS infrastructure deadline) and September 4, 2026 (the day the State Citizenship List has to be in state election officials' hands for the midterms).
All claims, sources, and the timeline are browsable from the navigation above. The original Drey Dossier article is available on Substack. Every URL referenced on this site was fetched and hashed with SHA-256 before being cited; the hash appears next to each receipt so the underlying byte content can be independently verified by anyone who fetches the same URL today.