Drey / NDS verification

Generated 2026-09-15T09:49:07Z

Claims

Filter by category or status; type to search the statements and notes. Click a claim headline to copy a permanent link.

ownership

9 claim(s)
confirmed ownership

[1] ndstudio.gov is registered to the Executive Office of the President (White House Office)

primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-05-29 19:32:04
confirmed ownership

[2] passports.gov is registered to the Executive Office of the President (White House Office), security contact blank

primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-05-29 19:32:04
confirmed ownership

[3] realfood.gov is registered to the Executive Office of the President (White House Office)

primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-05-29 19:32:04
confirmed ownership

[4] trumprx.gov is registered to the Executive Office of the President (White House Office)

primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-05-29 19:32:04
confirmed ownership

[5] vote.gov is registered to the Election Assistance Commission (still EAC, not White House)

Article correctly states vote.gov is currently EAC-owned. The 'second vote.gov' the article refers to is the preview subdomain vote-gov.previews.ndstudio.gov — verified separately via crt.sh.
primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-05-29 19:32:05
confirmed ownership

[6] usadf.gov (US African Development Foundation) lists akash@ndstudio.gov as its official security contact

An independent federal agency's cybersecurity point of contact is a personal-named mailbox at the White House design shop. Confirmed verbatim in the CISA registry.
primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-05-29 19:32:05
confirmed ownership

[7] passport.gov (singular) is also registered to the Executive Office of the President, alongside passports.gov

NEW finding not mentioned in the Drey article: the singular form is held by the White House too. Worth flagging — likely same preparation pattern.
primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-05-29 19:32:05
confirmed ownership

[8] nds.gov (shorter form) is also registered to the Executive Office of the President

NEW finding: a shorter nds.gov vanity domain is held by EOP alongside the publicly-known ndstudio.gov.
primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-05-29 19:32:05
confirmed ownership

[31] americabydesign.gov is EOP-owned and corresponds to the 'America by Design initiative' that EO 14338 establishes NDS to advance — vanity-domain match to the EO program name

Two-source connection: EO 14338 names 'America by Design initiative' as the program; CISA dotgov-data shows americabydesign.gov registered to EOP/WH Office.
primary:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
supporting:
  https://www.govinfo.gov/content/pkg/FR-2025-08-26/html/2025-16396.htm
    fetched 2026-05-29 22:21:11 · sha256 77c63cfddf3efa77…
updated 2026-05-30 01:44:48

procedural

14 claim(s)
confirmed procedural

[17] Federal Register full-text search for 'National Design Studio' returns only 2 documents, BOTH presidential documents — zero SORNs, zero PIAs filed for any NDS program

The two results are EO 14338 (Aug 2025, NDS founding) and the Nov 2025 'Fostering the Future for American Children and Families' EO (Trump Accounts). No SORNs, no PIAs. Article's central procedural claim verified.
primary:
  https://www.federalregister.gov/api/v1/documents.json?conditions[term]=%22National+Design+Studio%22
    fetched 2026-09-15 09:49:04 · sha256 a4d6bf0878649407…
updated 2026-05-30 01:44:48
confirmed procedural

[18] EO 14338 'Improving Our Nation Through Better Design': signed 2025-08-21, published 2025-08-26, citation 90 FR 41759, document number 2025-16396

Article gives 'August 2025' as creation date. Exact: signed Aug 21, published Aug 26. EO number 14338 verified.
primary:
  https://www.federalregister.gov/api/v1/documents/2025-16396.json
    fetched 2026-05-29 22:19:22 · sha256 0061fbba2780f129…
supporting:
  https://www.govinfo.gov/content/pkg/FR-2025-08-26/html/2025-16396.htm
    fetched 2026-05-29 22:21:11 · sha256 77c63cfddf3efa77…
updated 2026-05-30 01:44:48
confirmed procedural

[19] EO 14338 establishes NDS within the White House Office of the EOP and creates the Chief Design Officer position; the NDS Administrator reports to the Office of the White House Chief of Staff

EO Sec 2(b) verbatim: 'there is established within the White House Office of the Executive Office of the President the National Design Studio (NDS) and, within the NDS, a new position entitled the Chief Design Officer. The NDS shall be led by an Administrator, who shall report to the Office of the White House Chief of Staff.' Structural reporting claim confirmed; the EO does not name Susie Wiles by name.
primary:
  https://www.govinfo.gov/content/pkg/FR-2025-08-26/html/2025-16396.htm
    fetched 2026-05-29 22:21:11 · sha256 77c63cfddf3efa77…
updated 2026-05-30 01:44:48
confirmed procedural

[20] EO 14338 invokes Section 3161 of Title 5 USC to create a temporary organization terminating 3 years from signing

EO verbatim: 'in accordance with section 3161 of title 5, United States Code, a temporary organization headed by the NDS Administrator and dedicated to helping advance the America by Design initiative. The temporary organization shall terminate 3 years from the date of this order.' Confirmed verbatim.
primary:
  https://www.govinfo.gov/content/pkg/FR-2025-08-26/html/2025-16396.htm
    fetched 2026-05-29 22:21:11 · sha256 77c63cfddf3efa77…
updated 2026-05-30 01:44:48
confirmed procedural

[21] EO 14338 directs the Administrator of General Services to consult with the Chief Design Officer; it does NOT delegate website-building authority to NDS away from GSA

Subtle but legally significant: the EO casts NDS as consulting/coordinating, not as the agency of record for federal websites. The article's framing that NDS is rebuilding federal infrastructure outside its proper agencies is therefore a factual claim about execution, not authority.
primary:
  https://www.govinfo.gov/content/pkg/FR-2025-08-26/html/2025-16396.htm
    fetched 2026-05-29 22:21:11 · sha256 77c63cfddf3efa77…
updated 2026-05-30 01:44:48
confirmed procedural

[33] EO 14399 'Ensuring Citizenship Verification and Integrity in Federal Elections' signed 2026-03-31, published 2026-04-03 — the article's voter-EO claim verified to the document

Article: 'Weeks before that certificate appeared [Apr 10], this administration signed an executive order requiring DHS, the Social Security Administration, and the SAVE program to construct a federal citizenship-verified voter list.' The article describes EO 14399 verbatim. EO signed 10 days before the April 10 cert (close to 'weeks').
primary:
  https://www.federalregister.gov/api/v1/documents/2026-06601.json
    fetched 2026-09-15 09:49:04 · sha256 ac6eb58e1d7a674d…
supporting:
  https://www.govinfo.gov/content/pkg/FR-2026-04-03/html/2026-06601.htm
    fetched 2026-09-15 09:49:04 · sha256 aa45807ac5756d53…
updated 2026-05-30 04:55:09
confirmed procedural

[34] EO 14399 Section 4(c) verbatim: 'The Secretary of Homeland Security shall, within 90 days of the date of this order, establish the infrastructure necessary to compile, maintain, and transmit the State Citizenship List'

Article: 'with a deadline of ninety days from signing. That deadline is weeks away.' Confirmed verbatim. EO signed 2026-03-31, 90-day deadline = 2026-06-29. Article published 2026-05-26 — about a month before the deadline. Article's 'weeks away' framing exact.
primary:
  https://www.govinfo.gov/content/pkg/FR-2026-04-03/html/2026-06601.htm
    fetched 2026-09-15 09:49:04 · sha256 aa45807ac5756d53…
updated 2026-05-30 04:55:09
confirmed procedural

[35] EO 14399 names DHS, SSA, and the SAVE program (Systematic Alien Verification for Entitlements, 42 USC 1320b-7) as the data sources for the State Citizenship List

EO §2(a) verbatim: 'The State Citizenship List shall be derived from Federal citizenship and naturalization records, SSA records, SAVE data, and other relevant Federal databases.' All three sources the article names — DHS, SSA, SAVE — are explicitly invoked.
primary:
  https://www.govinfo.gov/content/pkg/FR-2026-04-03/html/2026-06601.htm
    fetched 2026-09-15 09:49:04 · sha256 aa45807ac5756d53…
updated 2026-05-30 04:55:09
confirmed procedural

[36] EO 14399 creates a federal 'State Citizenship List' that is transmitted to state election officials at least 60 days before each Federal election

EO §2(a) creates the State Citizenship List with the requirement: 'The State Citizenship List shall be updated and transmitted to State election officials no fewer than 60 days before each regularly scheduled Federal election.' Article's framing — that voter registration is being rebuilt on White House infrastructure — is structurally supported here: the EO assigns the list-building to DHS, which is an executive-branch entity reporting to the White House, NOT the independent Election Assistance Commission that currently owns vote.gov.
primary:
  https://www.govinfo.gov/content/pkg/FR-2026-04-03/html/2026-06601.htm
    fetched 2026-09-15 09:49:04 · sha256 aa45807ac5756d53…
updated 2026-05-30 04:55:09
confirmed procedural

[37] EO 14248 'Preserving and Protecting the Integrity of American Elections' is the March 25, 2025 predecessor elections EO

Signed 2025-03-25, published 2025-03-28. Likely the order the article refers to as the one previously challenged in federal court before EO 14399 expanded its citizenship-list provisions.
primary:
  https://www.federalregister.gov/api/v1/documents/2025-05523.json
    fetched 2026-05-30 04:50:14 · sha256 c41f065dfeecabb1…
updated 2026-05-30 04:55:09
confirmed procedural

[38] Trump Accounts EO confirmed: EO 14359 'Fostering the Future for American Children and Families' signed 2025-11-13, published 2025-11-19

Document number 2025-20406. The second NDS-mentioning Federal Register doc (along with EO 14338 founding).
primary:
  https://www.federalregister.gov/api/v1/documents/2025-20406.json
    fetched 2026-05-30 04:49:37 · sha256 80c204c9562a0445…
updated 2026-05-30 04:55:09
unverified procedural

[43] DOJ told a federal court the named agencies had not yet begun preparation and were still in the deliberation phase (article claim about an EO 14399 court challenge)

CourtListener API returned HTTP 403 to anonymous requests; public CourtListener search pages also blocked. To verify: register for a free CourtListener API key, OR look up the specific lawsuit name from secondary reporting on the EO 14399 challenge. The contradiction the article highlights (DOJ saying 'no infrastructure exists' vs. an April 10 cert) is structurally significant and well-framed but the underlying court filing needs to be located.
updated 2026-05-30 04:55:09
unverified procedural

[44] DOGE OPM injunction with Hogan exception (article claim — federal judge blocked DOGE access to OPM records but granted three people exceptions)

CourtListener blocked. Specific case name not in article. Search NDLA / EFF / OPM lawsuits 2025 to find docket. Then the specific motion granting Hogan an exception.
updated 2026-05-30 04:55:09
unverified procedural

[45] AFT v. Bessent (American Federation of Teachers lawsuit challenging DOGE access to Treasury / IRS systems)

CourtListener API blocked. The case was widely reported in 2025; specific filings showing the systems DOGE was granted read/write access to would need direct PACER access or a journalist-grade legal database.
updated 2026-05-30 04:55:09

surveillance

10 claim(s)
confirmed surveillance

[27] TrumpRx privacy policy contains the two-paragraph contradiction the article describes: explicitly names PostHog for usage analytics, then a few paragraphs later lists 'Health or medical information' and 'Prescription details or medication history' under 'We Do Not Collect'

Verbatim from /privacy-policy: 'PostHog Provides anonymous usage analytics to help us improve our service.' Then under 'Information We Do Not Collect': 'Health or medical information / Prescription details or medication history'. PostHog session replays by default include page URLs and click targets, which on a medication-pricing site IS medication information.
primary:
  https://trumprx.gov/privacy-policy
    fetched 2026-09-15 09:49:03 · sha256 488c19fc04f82ac4…
updated 2026-05-30 01:44:48
confirmed surveillance

[47] AutoMonitor captures button clicks with element text (up to 100 chars), id, className, href, and click X/Y coordinates — on top of full pathname and form action

From AutoMonitor.getClickData() lines 222-249. Every <button>, <a>, [role=button], [onclick], or [data-track] click on a page running this script is reported with enough detail to reconstruct what the user did and where they clicked on the page.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 22:03:00
confirmed surveillance

[48] AutoMonitor captures JavaScript errors with full stack traces, user-agent string, source filename, line and column numbers — and additionally instruments console.error/console.warn to report the same

Lines 274-334. Stack-traced error data + UA + console messages give the receiver detailed insight into the application's internals and the user's environment.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 22:03:00
confirmed surveillance

[49] AutoMonitor's transport is navigator.sendBeacon (line 440), the fire-and-forget W3C API specifically designed to survive page unload; fallback is fetch with keepalive:true — both choices that prioritize delivery over user-cancellable behavior

sendBeacon was designed exactly for telemetry-on-unload. It's the correct API for the use case AND the API that gives the user the least opportunity to interrupt data leaving the browser.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 22:03:00
confirmed surveillance

[50] AutoMonitor has zero consent UI, zero opt-out, zero respect for the browser Do Not Track header, no SORN filing, and no public privacy policy for the receiving collector

Review of all 540 lines. No reference to consent, DNT, opt-out, or any privacy disclosure. Combined with the Federal Register zero-SORN finding, this is a federal tracker shipped without any of the legally-prescribed disclosure mechanisms.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 22:03:00
confirmed surveillance

[51] NEW: nasaforce.gov ships PostHog analytics — second NDS-built site found running PostHog beyond TrumpRx

Direct fetch of nasaforce.gov homepage; HTML source contains 'posthog' references. The article's PostHog finding (about TrumpRx) generalizes to at least one additional NDS site we could verify by direct fetch.
primary:
  https://nasaforce.gov/
    fetched 2026-05-30 21:59:43 · sha256 b3d20e65b237ec97…
updated 2026-05-30 22:03:00
confirmed surveillance

[52] NEW: genesis.energy.gov (DOE/Oracle AI Initiative) ships BOTH AutoMonitor AND Google Analytics — two telemetry channels reporting to two different parties simultaneously

Direct fetch of genesis.energy.gov; HTML contains both the AutoMonitor script tag (cdn.infra.ndstudio.gov/internal-analytics/script.js) and Google's gtag/googletagmanager markers. So the federal AI initiative reports user behavior simultaneously to a White House endpoint and to Google.
primary:
  https://genesis.energy.gov/
    fetched 2026-05-30 21:59:48 · sha256 70baba9fc9dbfb0b…
supporting:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 22:03:00
partial surveillance

[57] PostHog SDK on nasaforce.gov ships with defaults: disable_session_recording=false, mask_all_text=false, mask_personal_data_properties=false, capture_pageleave='if_capture_pageview' — these are SDK defaults that would only be reconfigured via a posthog.init() override

Read directly from the nasaforce PostHog SDK source. Without seeing the actual posthog.init() call (located in a separate inline script), we can't confirm whether nasaforce overrides these defaults. If they don't override, session replay (full keystroke/mouse/page capture) is ON. Worth following up by capturing the page in a headless browser and inspecting the running config.
primary:
  https://nasaforce.gov/_astro/posthog.astro_astro_type_script_index_0_lang.HSTy8Lgu.js
    fetched 2026-05-31 18:48:09 · sha256 30a473818e59ca04…
updated 2026-05-31 18:51:16
confirmed surveillance

[98] Between 2026-06-01 and 2026-06-22, ndstudio.gov's homepage removed the AutoMonitor analytics script reference (cdn.infra.ndstudio.gov/internal-analytics/script.js); the script file at that CDN was itself unchanged over the same period.

Homepage snapshots: 2026-06-01 (29,378 b, references cdn.infra...script.js x2) vs 2026-06-22 (29,987 b, 0 references). Nav links Work/History/Dev Index/Apply Now also removed. Remaining byte delta is Next.js rebuild churn. Note: script still served at the CDN, just no longer embedded.
primary:
  https://ndstudio.gov/
    fetched 2026-09-15 09:49:03 · sha256 25fec70aacd73291…
supporting:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-06-22 21:37:16
confirmed surveillance

[99] TrumpRx (trumprx.gov) privacy policy, revised 2026-06-11, deleted its 'Usage Analytics' section that had disclosed PostHog tracking of pages visited and medications viewed.

Before 2026-06-01 (55,304 b, dated Feb 2 2026) vs after 2026-06-22 (50,525 b, dated June 11 2026). Removed: Usage Analytics block (pages/medications viewed, device/browser, referrer, error reports); PostHog vendor naming + 'hosted in the United States' + PostHog policy link; analytics-cookies disclosure; 'Block analytics' opt-out guidance. Caveat: removing the disclosure does not prove tracking stopped.
primary:
  https://trumprx.gov/privacy-policy
    fetched 2026-09-15 09:49:03 · sha256 488c19fc04f82ac4…
updated 2026-06-22 21:37:16

technical

30 claim(s)
confirmed technical

[9] crt.sh shows 997 certificates ending in ndstudio.gov as of 2026-05-29 (article said 979 as of 2026-05-26 — 18 new certs in 3 days, indicating active development)

primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-29 21:20:01
confirmed technical

[10] All 8 of the specific subdomains the article names appear in crt.sh: vote-gov.previews, vote-gov-ndstudio.previews, fbi-kirk-tipline.previews, trump-accounts-splashpage.previews, board-of-peace-assets, war.previews, cdn.infra, analytics.infra (.ndstudio.gov)

Every subdomain the article specifically calls out is present in the certificate transparency log. See notes/01-ndstudio-subdomains.md.
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-29 21:20:02
partial technical

[11] Article: 'The certificate appeared on April 10, 2026' for vote-gov preview

Article is technically correct — there IS a cert on April 10, 2026 for vote-gov.previews.ndstudio.gov. BUT it is one of many renewals, NOT the first appearance. First cert: 2025-09-08, eight months earlier. Vote preview infrastructure has been actively maintained for at least 8 months with ~20 cert events. Article's phrasing risks readers inferring April 10 was when the preview was first built; it wasn't.
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-29 21:20:02
confirmed technical

[12] vote-gov preview infrastructure has been continuously renewed since Sept 8, 2025; most recent cert was 2026-05-02 (just 24 days before the article published)

vote-gov.previews.ndstudio.gov: 20+ cert events Sep 2025 – May 2026. vote-gov-ndstudio.previews.ndstudio.gov: added Nov 17, 2025; renewed through 2026-05-13. This is production-grade upkeep, not an abandoned experiment.
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-29 21:20:02
confirmed technical

[13] Article: 'roughly forty more, unannounced' subdomains under ndstudio.gov

51 non-wildcard subdomains end in ndstudio.gov. About 10 are publicly announced/visible (ndstudio.gov itself, hiring., projects., trumprx.ndstudio.gov etc.). That leaves ~41 unannounced — consistent with the article's 'roughly forty' framing.
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-29 21:20:02
confirmed technical

[14] NEW: chat staging infrastructure (chat.staging.ndstudio.gov, chat-embed.staging.ndstudio.gov) appeared 2026-05-27 — one day AFTER the Drey article published

Studio shipped new staging infrastructure the day after the article ran. Chat embeds suggest some kind of conversational or assistive UI is being added to one of the existing properties.
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-29 21:20:02
confirmed technical

[15] NEW: passport.staging.ndstudio.gov AND passports.staging.ndstudio.gov both appeared 2026-04-07, paired with the dotgov registration of passport.gov + passports.gov

Singular and plural were registered as dotgov domains AND set up as staging hostnames on the same day. Strong signal these are paired production endpoints, not redundant placeholders.
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-29 21:20:02
partial technical

[16] NEW: subdomains hint at programs not named in the article: nasaforce.staging, cms[.api/.sandbox], hstf, dga, cio, boardofpeace, forestandrangelands, merry, freedom, america, upload, onboarding (all under ndstudio.gov)

Open follow-up — confirm what each program is. 'upload.ndstudio.gov' (2026-04-30) is plausibly the passport-photo upload endpoint the article warned about. 'nasaforce' aligns with the dotgov registration of nasaforce.gov (EOP-owned, found in our CSV scan). 'hstf' unknown — Health Strike Task Force? Homeland Security Task Force?
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-29 21:20:02
confirmed technical

[22] crt.sh shows exactly 26 certificate entries for passports.gov, first cert issued 2026-05-05 18:27:01 UTC — matches article's 'first certificate was issued May 5'

Total: 26 (article said 26 as of 2026-05-26). First apex+wildcard certs issued at exactly the same minute on May 5.
primary:
  https://crt.sh/?q=passports.gov&output=json
    fetched 2026-09-15 09:49:02 · sha256 2fb2c58522dfbbac…
updated 2026-05-30 01:44:48
confirmed technical

[23] 9 certificates for *.photo.passports.gov and *.photos.passports.gov were issued in a single hour on 2026-05-26 (between 03:29 and 04:21 UTC) — matches article verbatim

Article said 'nine new certs for photo.passports.gov and photos.passports.gov issued in a single hour on May 26.' Counted nine such certs in our snapshot, all within 03:29 to 04:21 UTC (52 minutes). Confirmed exactly.
primary:
  https://crt.sh/?q=passports.gov&output=json
    fetched 2026-09-15 09:49:02 · sha256 2fb2c58522dfbbac…
updated 2026-05-30 01:44:48
confirmed technical

[24] passports.gov subdomain rollout timeline: staging (May 21), photo.staging (May 22 — 4 days before article), auth + api (May 22), production photo/photos (May 26)

Production-quality rollout: apex → staging → auth/api → photo staging → production photo. New context not in article: staging photo was up by May 22, days before the production sprint on May 26.
primary:
  https://crt.sh/?q=passports.gov&output=json
    fetched 2026-09-15 09:49:02 · sha256 2fb2c58522dfbbac…
updated 2026-05-30 01:44:48
confirmed technical

[25] AutoMonitor script verified: 540 lines (article said 539 — trailing newline accounts), defines class AutoMonitor (line 4), generates sessionId on line 7, sets endpoint to https://analytics.infra.ndstudio.gov/metrics on line 8

Direct quote from line 8: this.endpoint = "https://analytics.infra.ndstudio.gov/metrics". Exact endpoint URL. Article's specific code-level claims confirmed to the line.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 01:44:48
confirmed technical

[26] ndstudio.gov homepage loads the AutoMonitor script directly via <script src='https://cdn.infra.ndstudio.gov/internal-analytics/script.js'>

Found verbatim in ndstudio.gov HTML source. The script ships AutoMonitor and runs on every page load on the studio's own homepage.
primary:
  https://ndstudio.gov/
    fetched 2026-09-15 09:49:03 · sha256 25fec70aacd73291…
supporting:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 01:44:48
confirmed technical

[28] trumprx.gov homepage footer contains the link 'Designed and Engineered in D.C. by [National Design Studio]' with href=https://ndstudio.gov — the article's opening hook verified

Federal government website with a designer byline, confirmed verbatim in source HTML.
primary:
  https://trumprx.gov/
    fetched 2026-05-29 22:17:25 · sha256 70491281cdc1411c…
updated 2026-05-30 01:44:48
confirmed technical

[29] All 4 probed preview subdomains (vote-gov, fbi-kirk-tipline, trump-accounts-splashpage, war.previews .ndstudio.gov) redirect to loveisaskill.cloudflareaccess.com — the personal Cloudflare account from the article

Direct HTTPS probe of each subdomain returns the loveisaskill SSO portal. Confirms article's claim that one personal-named Cloudflare account fronts 40+ federal preview sites.
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-30 01:44:48
confirmed technical

[30] Program-domain live status probe (2026-05-29): trumprx.gov, realfood.gov, nasaforce.gov, americabydesign.gov, genesis.energy.gov, retire.opm.gov all return HTTP 200; trumpaccounts.gov returns 403 (gated); passport.gov (singular) is dark (no response)

trumpaccounts.gov 403 is notable — article mentions it as an active program but it's not publicly browsable. passport.gov (singular) being registered-but-dark while passports.gov (plural) is actively staged suggests one is the production target and the other a hold.
updated 2026-05-30 01:44:48
partial technical

[32] analytics.infra.ndstudio.gov (the AutoMonitor metrics endpoint) does not respond to direct GET or POST probes — returns no response (000) from outside the embedded JS context

Endpoint URL is verified in code, but direct curl probes get no response. Either it filters by origin, requires the session-id contract, or rejects non-browser clients. Consistent with a tracker built to ingest only from embedded contexts.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 01:44:48
partial technical

[39] Timeline: EO 14399 signed 2026-03-31; vote-gov.previews.ndstudio.gov cert issued 2026-04-10 (10 days later); article's 'weeks before' framing is approximately correct

Strict numbers: EO + 10 days = first April cert; EO + 90 days = 2026-06-29 deadline; article published 2026-05-26 = day 56 of the 90-day window. The vote-gov preview existed continuously since 2025-09-08 — but the April 10 cert renewal lines up with the EO signing in a way that strongly supports the article's central correlation between EO and infrastructure work.
primary:
  https://www.govinfo.gov/content/pkg/FR-2026-04-03/html/2026-06601.htm
    fetched 2026-09-15 09:49:04 · sha256 aa45807ac5756d53…
supporting:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-05-30 04:55:09
confirmed technical

[46] AutoMonitor monkey-patches three browser primitives unconditionally: window.fetch (line 109), XMLHttpRequest.prototype.open/.send (lines 140-160), and console.error/console.warn (lines 306-334) — replaces them with wrappers that report to analytics.infra.ndstudio.gov before passing through

This is the technique used by application performance monitoring tools, but normally opt-in with a published privacy policy. Here it ships unconditionally to every visitor with no documentation.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 22:03:00
confirmed technical

[53] analytics.infra.ndstudio.gov/metrics returns no HTTP response at all (000) to direct GET, POST, OPTIONS, and HEAD probes — even with proper Origin: https://ndstudio.gov header and a valid JSON payload

Endpoint is configured to drop connections that don't match its expected session/origin pattern, returning nothing instead of the normal 401/403/405. Consistent with a collector designed to accept data only from its own embedded JS, and to be opaque to outside researchers.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-30 22:03:00
confirmed technical

[54] MAJOR: analytics.infra.ndstudio.gov has NO public DNS record at all — NXDOMAIN from Cloudflare (1.1.1.1), Google (8.8.8.8), and Quad9 (9.9.9.9) — yet the AutoMonitor script still posts to it

Sister hostname cdn.infra.ndstudio.gov resolves normally (Cloudflare IPs 104.26.12.39, 104.26.13.39, 172.67.70.9). The cert for analytics.infra has existed in transparency logs since 2025-09-10 and was actively renewed for months. Three possibilities: (1) DNS was pulled in response to public scrutiny; (2) split-horizon DNS — endpoint only resolves on internal/VPN networks; (3) endpoint was never live publicly and the cert is preparatory. If (1), it's a meaningful behavioral signal — the operator responded to attention by pulling the data-receiver hostname from public DNS while leaving the script that posts to it.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-05-31 18:51:16
confirmed technical

[55] All NDS-controlled hostnames front through Cloudflare (104.26.x / 172.67.x ranges). No origin server is exposed to public DNS

DNS A record probe of ndstudio.gov, cdn.infra.ndstudio.gov, trumprx.gov, realfood.gov, genesis.energy.gov — every one resolves to Cloudflare addresses.
primary:
  https://ndstudio.gov/
    fetched 2026-09-15 09:49:03 · sha256 25fec70aacd73291…
updated 2026-05-31 18:51:16
confirmed technical

[56] nasaforce.gov is built on Astro framework, not Next.js — different framework than TrumpRx

The site loads PostHog via /_astro/posthog.astro_astro_type_script_index_0_lang.HSTy8Lgu.js, an Astro-framework script bundling pattern. TrumpRx uses Next.js (_next/static/chunks/...). The studio runs at least two different SPA frameworks on its sites.
primary:
  https://nasaforce.gov/
    fetched 2026-05-30 21:59:43 · sha256 b3d20e65b237ec97…
updated 2026-05-31 18:51:16
confirmed technical

[58] PostHog data goes to PostHog's US ingest (us.i.posthog.com) — not self-hosted; data leaves the federal government and goes to a third-party SaaS

The nasaforce PostHog SDK explicitly sets api_host='https://us.i.posthog.com' when app.posthog.com is detected. So whatever telemetry PostHog collects is transmitted off the .gov perimeter to PostHog's US infrastructure.
primary:
  https://nasaforce.gov/_astro/posthog.astro_astro_type_script_index_0_lang.HSTy8Lgu.js
    fetched 2026-05-31 18:48:09 · sha256 30a473818e59ca04…
updated 2026-05-31 18:51:16
confirmed technical

[59] NEW (diff 2026-06-01): api2.passports.gov stood up 2026-05-28 — TWO DAYS after Drey article — while original api.passports.gov shifted from HTTP 302 to HTTP 403 by 2026-06-01

First certs for *.api2.passports.gov issued 2026-05-28 20:55 UTC. By 2026-06-01 direct probes show api2.passports.gov returns HTTP 302 (still serving) while api.passports.gov returns 403. Looks like a deliberate version-bump migration with the prior endpoint locked off. Plausibly a response to scrutiny: someone probably probed api.passports.gov after the article, prompting them to move and lock.
primary:
  https://crt.sh/?q=passports.gov&output=json
    fetched 2026-09-15 09:49:02 · sha256 2fb2c58522dfbbac…
updated 2026-06-01 14:20:09
confirmed technical

[60] NEW (diff 2026-06-01): crt.sh JSON API for ndstudio.gov returned HTTP 503 — service unavailable; HTML form still worked. Certspotter only has 34 of 65 names — confirms crt.sh as primary, Certspotter as partial backup

crt.sh has had availability issues since the article (article itself noted it). Certspotter is incomplete relative to crt.sh because some CAs aren't in its watch set. For monitoring, the recommended fallback is crt.sh HTML form when JSON 503s; do NOT rely on Certspotter alone.
primary:
  https://api.certspotter.com/v1/issuances?domain=ndstudio.gov&include_subdomains=true&expand=dns_names
    fetched 2026-07-14 16:14:49 · sha256 c783dc01bf1326d9…
updated 2026-06-01 14:20:09
confirmed technical

[61] As of 2026-06-01: AutoMonitor source unchanged (sha256 cb4da9fc), ndstudio.gov homepage unchanged, TrumpRx privacy policy unchanged, CISA dotgov registry unchanged, Federal Register still zero NDS SORN/PIA filings

Diff run 2026-06-01 14:17 UTC. Five of seven watched URLs are byte-identical to the prior snapshot. The studio shipped api2.passports.gov but did not modify the AutoMonitor script or publish any privacy disclosure.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
updated 2026-06-01 14:20:09
confirmed technical

[96] The 'NDS sites' (ndstudio.gov, americabydesign.gov, trumprx.gov, realfood.gov, nasaforce.gov, trumpaccounts.gov, and the staging copies of passports.gov / vote.gov / login-equivalent) are a DISTINCT SUBSET of Executive-Office-of-the-President-owned .gov domains. They share a stack signature: Next.js frontend, Cloudflare-fronted, PostHog session-replay analytics, AutoMonitor JS interception layer, and (for staging) gated behind loveisaskill.cloudflareaccess.com. Most other EOP-owned vanity .gov domains — live.gov, crypto.gov, saveamerica.gov — are simple 301 redirects to whitehouse.gov sub-pages. AI.gov is a third category: independent content, but hosted on the commercial Webflow CDN (cdn.prod.website-files.com), not the NDS stack.

Direct probes 2026-06-03: live.gov → 301 → whitehouse.gov/live; crypto.gov → 302 → whitehouse.gov/crypto; saveamerica.gov → 301 → whitehouse.gov/saveamerica; ai.gov → 200, content served from cdn.prod.website-files.com (Webflow); launch.gov → TLS cert error (invalid certificate, not serving content). This is useful for the dossier because it answers the question 'how do you tell an NDS site from a non-NDS EOP site' with three clear distinguishing features: (a) Next.js / posthog.com fingerprint; (b) Cloudflare account ownership under loveisaskill.cloudflareaccess.com for staging; (c) registered to 'White House Office' suborg with blank security contact in the CISA dotgov CSV. Anything else is conventional whitehouse.gov plumbing or commercial-hosted content.
updated 2026-06-04 13:57:49
confirmed technical

[100] A new subdomain inference.ndstudio.gov appeared in Certificate Transparency logs for ndstudio.gov (present 2026-06-22, absent in the 2026-05-29 snapshot).

crt.sh %.ndstudio.gov: 65 names (2026-05-29) -> 66 names (2026-06-22); the sole addition is inference.ndstudio.gov. The name suggests model-inference/serving infrastructure, but the CT log only confirms a TLS certificate was issued for it. passports.gov crt re-fetch still 503'd.
primary:
  https://crt.sh/?q=%25.ndstudio.gov&output=json
    fetched 2026-09-15 09:49:01 · sha256 2ac8a33f43b2560f…
updated 2026-06-22 21:39:20
confirmed technical

[101] cdn.infra.ndstudio.gov (the CDN serving the AutoMonitor script) stopped resolving on public DNS sometime between 2026-06-02 and 2026-06-26, and remains unresolvable (NOERROR, 0 answers) as of 2026-07-14 across three independent resolvers (Cloudflare 1.1.1.1, Google 8.8.8.8, Quad9 9.9.9.9), while ndstudio.gov's own zone (SOA) and A records are unaffected — only this one subdomain's record was pulled. A Cloudflare-issued TLS certificate for the hostname remains currently valid (issued 2026-05-03, expires 2026-08-02, per Certspotter CT-log data), indicating the Cloudflare zone/hostname configuration has not been deleted, only the public DNS answer withheld.

Last successful fetch of the script itself: 2026-06-01, HTTP 200, byte-identical to the 2026-05-29 snapshot (sha cb4da9fc...) — no content change before it went dark. Sister hostname analytics.infra.ndstudio.gov (the AutoMonitor metrics endpoint, claim referencing its NXDOMAIN-style status) remains similarly unresolvable, unchanged. Narrows the outage window vs. the prior 2026-07-01 note (which only flagged the failure, no window or cert data); still consistent with either a deliberate DNS-record pull or split-horizon/internal-only DNS — the still-valid cert argues against full decommissioning but is not conclusive on its own.
primary:
  https://cdn.infra.ndstudio.gov/internal-analytics/script.js
    fetched 2026-06-01 14:17:57 · sha256 cb4da9fc156568b0…
supporting:
  https://dns.google/resolve?name=cdn.infra.ndstudio.gov&type=A
    fetched 2026-07-14 16:14:39 · sha256 eaab2cbc9004a0be…
  https://dns.google/resolve?name=analytics.infra.ndstudio.gov&type=A
    fetched 2026-07-14 16:14:47 · sha256 21247338789a7411…
  https://api.certspotter.com/v1/issuances?domain=ndstudio.gov&include_subdomains=true&expand=dns_names
    fetched 2026-07-14 16:14:49 · sha256 c783dc01bf1326d9…
updated 2026-07-14 16:15:06

personnel

17 claim(s)
unverified personnel

[40] Joe Gebbia named Chief Design Officer by Reuters (article cites this)

Reuters article URL returns HTTP 401 (paywall). Wayback Machine fetch timed out. EO 14338 creates the Chief Design Officer position but does not name Gebbia. The Reuters reporting that names Gebbia specifically requires a paid Reuters subscription or successful archive.org retrieval. Still UNVERIFIED from a primary public source we have direct access to.
primary:
  https://www.reuters.com/world/us/airbnb-co-founder-gebbia-named-trumps-chief-design-officer-2025-08-21/
    fetched 2026-05-30 04:50:15 · sha256 4c52a2714d74eceb…
updated 2026-05-30 04:55:09
unverified personnel

[41] Greg Hogan promoted to run Login.gov (article claim)

Federal Register search for 'Login.gov' returned 112 results, all older SORN/agency notices — none announce a leadership change. Login.gov's own staff/leadership page is not in Federal Register. Need: direct fetch of login.gov, GSA press releases, or congressional testimony to confirm.
updated 2026-05-30 04:55:09
unverified personnel

[42] Akash Bobba's October 2025 conference call with state election directors (article quotes him saying 'I don't know what they retain and what they are logging')

Recording or transcript would be primary. Article does not link to the recording itself. Likely available via FOIA or to journalists with secondary access; not retrievable from public web in this session.
updated 2026-05-30 04:55:09
confirmed personnel

[64] Akash Bobba (DOGE alumnus, now at the National Design Studio) is listed as the security contact for usadf.gov in CISA's authoritative dotgov-data CSV. The contact email is akash@ndstudio.gov — a White House EOP-controlled mailbox, not a USADF mailbox.

Verified directly in the CISA dotgov-data CSV snapshot (sha 12d89fd59bcb…, fetched 2026-06-01). Line 1163: 'usadf.gov,Federal - Executive,United States African Development Foundation,African Development Foundation,Washington,DC,akash@ndstudio.gov'. By contrast, the older 'adf.gov' domain (line 1162) still lists 'schi@usadf.gov' as security contact. This means the USADF security contact was transferred from a usadf.gov mailbox to an ndstudio.gov mailbox — i.e., a White House staffer now has full visibility into USADF security configuration. Confirms a Will Hold claim directly from the federal authority.
supporting:
  https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv
    fetched 2026-09-15 09:49:02 · sha256 c6a342dcb3684e4c…
updated 2026-06-03 14:31:50
confirmed personnel

[65] Greg Hogan, former Office of Personnel Management Chief Information Officer and one of three DOGE-affiliated individuals granted an exception to a 2025 federal court order blocking DOGE access to OPM personnel records, now runs Login.gov from inside the National Design Studio.

Verified via Nextgov/FCW article 2026-04 ('GSA Taps Greg Hogan As Head of Government's Identity Proofing Service, Login.gov') and Government Executive coverage of his September 2025 OPM departure. The court order (from American Federation of Teachers v Bessent, 8:25-cv-00430 D. Md.) named Hogan as a permitted exception. Login.gov has 150M+ accounts. UPDATED 2026-06-04: The underlying preliminary injunction in AFT v. Bessent (8:25-cv-00430 D. Md.) was VACATED on 2025-08-12 by the Fourth Circuit (No. 25-1282). The Hogan-as-court-ordered-exception framing no longer applies. See claim 97. He remains head of Login.gov inside NDS; that part is unchanged.
updated 2026-06-04 14:03:43
confirmed personnel

[66] Edward 'Big Balls' Coristine, a former DOGE staffer with Russian-registered web domains via his Tesla.Sexy LLC, has joined the National Design Studio team led by Joe Gebbia.

Verified via Daily Beast ('Trump Gives Big Balls Edward Coristine Huge New Job to Undermine US Allies'), Newsweek (reports on his KGB-defector great-grandfather), and Wikipedia. His Tesla.Sexy LLC owns domains for an AI Discord bot operating in the Russian market. The 'Big Balls' nickname was self-given on Fox News (Watters 'Primetime').
updated 2026-06-03 14:31:50
confirmed personnel

[67] Kaitlyn Koller (former Senate Foreign Relations Committee aide) and Zachary Terrell (former DOGE staffer at HHS and the National Science Foundation) joined the National Design Studio team after their DOGE roles.

Koller verified via WIRED reporting cited by NOTUS. Terrell verified via NOTUS, Techdirt, and executive-search news coverage. NOTUS reported that NDS would be 'populated by DOGE operatives affiliated with the General Services Administration' but did not publish a complete staff list. Coverage of Terrell's specific NDS position is less definitive than for Koller.
updated 2026-06-03 14:31:50
confirmed personnel

[77] Aram Moghaddassi — former Neuralink and X engineer, prior DOGE role at the Department of Labor — became Chief Information Officer of the Social Security Administration in June 2025. As CIO he self-authorized the Provisional ATO for the DOGE-controlled NUMIDENT cloud environment on 2025-07-15.

Verified in Borges disclosure footnote 3 (citing DevX, Wired, NYT). Coristine and Moghaddassi were previously granted access to vast sensitive immigration data at USCIS including the cloud-based 'data lake' (FedScoop, April 2025). In April 2025, Moghaddassi sent acting SSA Commissioner Leland Dudek a list of 6,300 immigrants whose parole status was revoked the same day; he claimed the list was only people on 'terrorist watch list' but it included eight minors, including a 13-year-old (NYT).
updated 2026-06-03 23:47:07
confirmed personnel

[78] Michael Russo — appointed Chief Information Officer of the SSA by President Trump on 2025-01-30 despite no government experience (previously a Shift4 payment-processing executive) — approved the transfer of live NUMIDENT data to the DOGE-controlled cloud environment with a single-word reply ('Approved….') on 2025-06-25, by which date he had been moved out of the CIO role to a 'special advisor' position.

Verified in Borges disclosure (p.15 and footnote 3). Russo was replaced as CIO by Scott Coulter in late March 2025 and transitioned to special advisor role focused on 'modernizing archaic technology.' Per Borges and Wired/NYT reporting, Russo disregarded an investigation by SSA public servants into Musk/Trump fraud claims and instead directed Akash Bobba (then a 21-year-old former Palantir intern) to conduct his own analysis using SSA's personal data on Americans.
updated 2026-06-03 23:47:07
confirmed personnel

[79] John Solly (sometimes spelled 'Solley') is a DOGE-aligned hire who joined the SSA in March 2025 in the Office of the CIO. On 2025-06-10 Solly initiated the NUMIDENT cloud-transfer request that Borges identifies as the genesis of the unsecured-cloud exposure.

Verified in Borges disclosure footnote 3 (citing Wired 'This Is DOGE 2.0' 2025-07-10) and Borges' specific narrative of the June 10-25 escalation. Solly is one of three DOGE-affiliated names Borges directly emailed on 2025-08-11 for information about the cloud security concerns and received no response.
updated 2026-06-03 23:47:07
confirmed personnel

[80] Edward 'Big Balls' Coristine's DOGE-SSA role began after he resigned from DOGE in June 2025 and reappeared at SSA 'days later.' His prior history includes: membership in the cybercrime group 'The Com,' a 2022 Telegram-handle hire of a hacker for a DDoS cyberattack, firing from cybersecurity firm Path Networks for leaking secrets to a competitor, and ownership of Tesla.Sexy LLC which operates Russian-registered domains.

Verified in Borges disclosure footnote 3, cross-referencing Krebs on Security 2025-02-28, Bloomberg 2025-02-07, Wired 2025-02-06 / 2025-06-04 / 2025-06-24 / 2025-07-30. He became a full-time federal employee in May 2025 at GS-15 (one of the highest GS rates possible). The fact that Coristine has a documented history of cybercrime adjacency materially affects the gravity of his access to NUMIDENT-class data.
updated 2026-06-03 23:47:07
confirmed personnel

[81] Akash Bobba is independently named in the Borges whistleblower disclosure (footnote 3) as the DOGE personnel directed by Michael Russo to conduct his own analysis of Musk/Trump's SSA-fraud claims using SSA's personal data on Americans. This is independent of and complements his role — separately verified via the CISA dotgov-data CSV — as the security contact (akash@ndstudio.gov) for usadf.gov.

Per Borges footnote 3 citing NYT 2025-06-16. Bobba is described as 'a 21-year-old former Palantir intern.' The Borges→USADF→NDS dossier on Bobba is now multi-source: Wired profiled him as one of the original DOGE engineers, NYT documented his role in SSA fraud claims analysis, and the CISA CSV documents his current security-contact role over a federal agency website.
updated 2026-06-03 23:47:07
confirmed personnel

[82] Payton Rehling is a DOGE member at SSA who, alongside Aram Moghaddassi, requested PSNAP and SNAP MI database access on 2025-03-14 through a process that bypassed SSA's Systems Access Management (SAM) approval system.

Named in Borges disclosure p.10 as one of the two specific DOGE members requesting the EDW access that bypassed SAM. Less public reporting on Rehling than on the other named DOGE-SSA personnel.
supporting:
  https://whistleblower.org/wp-content/uploads/2025/08/08-26-2025-Borges-Disclosure-Sanitized.pdf
    fetched 2026-09-15 09:49:05 · sha256 0b5a3f421745107a…
updated 2026-06-03 23:47:07
confirmed personnel

[88] Steve Davis — Elon Musk's longtime lieutenant from SpaceX/X/Boring Company, a more senior figure than the 19-22-year-old DOGE engineer cohort — told SSA staffers in late spring 2025 that DOGE 'would soon start linking various sources of Social Security data for access and analysis,' with the explicit goal of building a centralized cross-agency database providing unprecedented access to Social Security records, taxes, medical diagnoses, and other private information. Per Washington Post reporting and Borges disclosure footnote 22.

Davis is the senior on-record voice articulating the DOGE 'join all data across government' strategy. Distinct from the young-engineer cohort (Coristine, Bobba, Rehling, Solly) — Davis is the strategic operator. WaPo 2025-05-07 'Why Elon Musk's DOGE is amassing sensitive government data.' Borges disclosure also cites him at footnote 22 (Natanson, Menn, Rein, Siegel).
updated 2026-06-04 04:49:22
confirmed personnel

[89] Tiffany Flick — Acting Chief of Staff to the former SSA Acting Commissioner, ~30-year career SSA civil servant — retired on or about 2025-02-16 and filed a sworn declaration in AFSCME v. SSA (1:25-cv-00596, D. Md.) detailing 'significant steps taken by SSA career civil servants to protect sensitive data as members of DOGE descended on the agency.' Her declaration states that DOGE employees pressured her and then-Acting Commissioner Michelle King for 'immediate access' to all SSA systems and were 'evasive' when asked why, and describes Michael Russo as 'obsessed with unsubstantiated claims of Social Security fraud rather than with the actual operational needs of the agency.'

Flick's declaration is a sworn primary source — much stronger than journalist-reported allegations. Her direct quote in court filings: 'A disregard for our careful privacy systems and processes now threatens the security the data SSA houses about millions of Americans.' Her testimony is also referenced in Borges disclosure footnote 20 (citing The Guardian 2025-03-10). She is the inside-baseball witness with the most institutional knowledge of the very-early-DOGE-at-SSA fact pattern (late January through mid-February 2025).
updated 2026-06-04 04:49:22
confirmed personnel

[90] Michelle King — Acting Commissioner of the Social Security Administration — resigned in February 2025 rather than hand DOGE the broad sensitive-data access DOGE personnel were demanding. Possibly including addresses, banking information, medical records, income information, and employment history.

Verified via PBS News and Mashable Feb 18, 2025. Resignation-in-protest by a federal-agency-head is a fact pattern that strongly corroborates Flick's and Borges's accounts. King and Flick worked alongside each other; both refused DOGE's demands; both left the agency in the same time window. Mashable reported the data potentially at risk: addresses, banking, medical records, income, employment history.
updated 2026-06-04 04:49:22
confirmed personnel

[94] Edward Coristine's Tesla.Sexy LLC (founded 2021 when he was 16) controls 'dozens of web domains,' of which a handful are registered to Russia. Documented domains include: 'Helfie' (an AI Discord bot operating in the Russian market) and 'faster.pw' (inactive but archived 2022-10-25 with Chinese-language content advertising 'multiple encrypted cross-border networks').

Per Wired (Greenberg 2025-02-06), Krebs on Security 2025-02-28, and Mediaite. The faster.pw 'multiple encrypted cross-border networks' finding extends Coristine's foreign-internet-infrastructure footprint beyond Russia to include China-market cross-border circumvention services. Per security-clearance experts cited in the same reporting, foreign-internet-business ownership of this kind would normally raise red flags on a background check. Coristine was full-time federal employee at GS-15 by May 2025, with access to Treasury data and (per Borges) SSA NUMIDENT data. Recorded in extension of claims 66, 80.
updated 2026-06-04 13:57:49

policy

21 claim(s)
confirmed policy

[62] EO 14338 §3 explicitly sets July 4, 2026 as the deadline for federal agencies to 'produce initial results' of the America by Design initiative. The date is not a hidden code-side feature flag — it is the statutory milestone written into the executive order's plain text.

Verified by grep of the GovInfo cached snapshot of FR 2025-16396 (sha 77c63cfddf3e…). Quoted passage: 'Heads of agencies shall consult with the Chief Design Officer to implement the America by Design initiative at their respective agencies and shall produce initial results by July 4, 2026.' This reframes Will Hold's reading: the July 4 date is structural, not a hidden flip switch — but it does mean the cert-creation timeline we documented (passports.gov 2026-05-05, vote.gov 2026-04-10) is the runway to that deadline.
supporting:
  https://www.govinfo.gov/content/pkg/FR-2025-08-26/html/2025-16396.htm
    fetched 2026-05-29 22:21:11 · sha256 77c63cfddf3efa77…
  https://www.federalregister.gov/documents/2025/08/26/2025-16396/improving-our-nation-through-better-design
    fetched 2026-05-29 22:18:30 · sha256 293074fe9dd7407d…
updated 2026-06-03 14:31:50
confirmed policy

[63] Executive Order 14399 ('Ensuring Citizenship Verification and Integrity in Federal Elections') was signed March 31, 2026 and published April 3, 2026 (FR doc 2026-06601). §4(c) requires DHS to 'establish the infrastructure necessary to compile, maintain, and transmit the State Citizenship List' within 90 days of the order.

Verified via Federal Register API (we already have a cached metadata fetch at FR 2026-06601.json) and the GovInfo full-text fetch (sha aa45807ac575). EO directs DHS through USCIS, SSA, USPS, the Attorney General; references the SAVE program as a data source. EO does NOT explicitly name the National Design Studio, Login.gov, or the Election Assistance Commission — those are Will Hold's inferences based on infrastructure ownership.
updated 2026-06-03 14:31:50
confirmed policy

[68] On March 24, 2025, a DOGE team member at the Social Security Administration signed a 'Voter Data Agreement' with a political advocacy group (widely suspected to be True the Vote). The agreement bypassed SSA's internal data-exchange safeguards. SSA discovered it during an unrelated review in November 2025.

Verified via Democracy Forward press release (April 2026) and Democracy Docket coverage. Democracy Forward has filed FOIA requests and a lawsuit seeking the agreement, the identity of the signer, two Hatch Act referrals, and SSA DOGE-team communications with election-denying organizations. SSA admits the bypass occurred but says it has not yet found proof the data was actually shared. This corroborates Will Hold's quote.
updated 2026-06-03 14:31:50
confirmed policy

[69] Two federal lawsuits challenge EO 14399: (a) League of Women Voters of Massachusetts v. Trump (1:26-cv-11549, D. Mass.) filed April 2, 2026; (b) Common Cause v. DOJ (1:26-cv-01352, D.D.C.) filed April 21, 2026. The cases allege violations of the Privacy Act, separation of powers, and the APA.

Verified via Immigration Policy Tracking Project and Civil Rights Litigation Clearinghouse. The Common Cause complaint refers to DOJ's 'Voter Registration Nationalization Policy' and alleges DOJ has demanded statewide voter registration lists from nearly every state.
updated 2026-06-03 14:31:50
confirmed policy

[70] Will Hold (2026-05-31) reports that the DOJ told a federal court the agencies named in EO 14399 'had not yet begun preparations and were still in the deliberative phase' — despite the vote.gov staging certificate having been issued April 10, 2026 (predating the DOJ filing).

RESOLVED 2026-06-03 afternoon. The DOJ filing Will Hold referenced is the 2026-05-01 Defendants' Combined Memorandum of Law in DSCC v. Trump (1:26-cv-01114 D.D.C., Doc 106-1). The filing's language is nearly verbatim to Will Hold's paraphrase. See claims 85-87 for the verbatim quotes and the sharper finding that the DOJ representation about SSA is in tension with the Borges-documented June 2025 unsecured NUMIDENT cloud copy that pre-dates EO 14399.
updated 2026-06-04 02:53:44
confirmed policy

[71] The Will Hold investigation 'Trump Is Replicating Vote.gov to Recreate Musk's 2024 Election-Rigging Platform' (2026-05-31, by 'This Will Hold') reaches conclusions aligned with The Drey Dossier's May 26 piece on the National Design Studio. Will Hold attributes the convergence to independent investigation by both parties.

Will Hold explicitly credits Drey Dossier and links to her May 26 piece. Many factual claims overlap (40 unannounced subdomains, AutoMonitor 540 lines, PostHog routing, EOP ownership of passports.gov, loveisaskill.cloudflareaccess.com gate). Will Hold adds: specific DOGE→NDS personnel named, the EO 14399 timeline contradiction, the March 24 2025 SSA Voter Data Agreement, and the framing that the July 4 2026 EO 14338 deadline is the 'switch-over' date.
updated 2026-06-03 14:31:50
confirmed policy

[72] On 2025-08-26 Charles 'Chuck' Borges, the Social Security Administration's Chief Data Officer, transmitted a formal whistleblower disclosure through the Government Accountability Project to the U.S. Office of Special Counsel and four Congressional committees. The 18-page disclosure documents that DOGE-affiliated SSA personnel created an unsecured cloud copy of SSA's NUMIDENT database — containing the personal data of over 300 million Americans — without independent security controls.

Borges is a career civil servant with 22 years U.S. Navy service (Air Medal with Combat Distinguishing Device, Operation Iraqi Freedom) and prior CDO roles at NAVAIR, GSA, OMB, and CDC. He named the disclosure as covering 'Violation of Laws, Rules & Regulations, Abuse of Authority, Gross Mismanagement, and Substantial and Specific Threat to Public Health and Safety.' Cited statutes: 5 U.S.C. § 2302, 5 U.S.C. § 1213, and 5 U.S.C § 7211.
supporting:
  https://whistleblower.org/wp-content/uploads/2025/08/08-26-2025-Borges-Disclosure-Sanitized.pdf
    fetched 2026-09-15 09:49:05 · sha256 0b5a3f421745107a…
updated 2026-06-03 23:47:07
confirmed policy

[73] DOGE personnel at SSA — specifically named as Edward Coristine, Aram Moghaddassi, John Solly, and Michael Russo — bypassed SSA's Systems Access Management (SAM) approval to obtain access to Enterprise Data Warehouse (EDW) databases starting around 2025-03-14, including unauthorized 'equipment pin access' (untraceable to a specific user) and 'write access' (ability to edit data).

Documented on Borges disclosure p.10-11. Specific databases accessed: PSNAP and SNAP MI. Requested by DOGE members Payton Rehling and Aram Moghaddassi. The EDW team discovered the unauthorized access on 2025-03-17 — three days after it was granted. Cited statutory violations: 26 U.S.C. § 6103 (Federal Tax Information), 18 U.S.C. § 1030(a)(2) (Computer Fraud and Abuse Act, exceeding authorized access).
supporting:
  https://whistleblower.org/wp-content/uploads/2025/08/08-26-2025-Borges-Disclosure-Sanitized.pdf
    fetched 2026-09-15 09:49:05 · sha256 0b5a3f421745107a…
updated 2026-06-03 23:47:07
confirmed policy

[74] Within 24 hours of the 2025-03-20 federal court Temporary Restraining Order (AFSCME v. SSA, 1:25-cv-00596, D. Md.) prohibiting DOGE access to SSA data, DOGE officials restored access for 2 DOGE employees with 42 different new and expanded user profiles — including 'specifically identified privileges that should not have been granted.' Four days later, on 2025-03-24, SSA Defendants certified compliance with the TRO to the court under oath.

Documented on Borges disclosure p.11-12. The Borges disclosure characterizes the restoration as 'circumvented the judicial mandate.' Statutory violations alleged: 18 U.S.C. § 1030 (CFAA), 5 U.S.C. § 552a (Privacy Act), 44 U.S.C. § 3551 et seq. (FISMA), 5 U.S.C. Appendix (Inspector General Act), and 18 U.S.C. § 371 (Conspiracy to circumvent a federal court order). Borges notes that the simultaneous timing of the unauthorized restoration AND the under-oath certification of compliance is the core of the allegation.
updated 2026-06-03 23:47:07
confirmed policy

[75] Between 2025-06-10 and 2025-07-15, DOGE personnel at SSA — coordinated by Aram Moghaddassi and John Solly — obtained administrative access to a Virtual Private Cloud within SSA's AWS Agency Cloud Infrastructure (AWS-ACI), transferred a live copy of the NUMIDENT database (the entire population of US Social Security card applicants) into that VPC, and then self-authorized a 'Provisional Authorization to Operate' the environment despite an internal SSA Risk Acceptance Request Form having labeled the project 'very high risk' (estimated risk score 15) with explicit warnings of 'catastrophic impact to SSA beneficiaries and SSA programs' if NUMIDENT were exposed.

Sequence (Borges p.13-15): 2025-06-10 Solly requests cloud env for NUMIDENT; 2025-06-11 morphs to 'test environment' then to 'full administrative access'; 2025-06-12 OCIO career official issues high-risk Risk Acceptance Request Form; 2025-06-23 CIO approves DOGE admin access but NOT NUMIDENT transfer (pending technical discussions of security controls); 2025-06-24 admin access confirmed; 2025-06-25 Solly requests NUMIDENT transfer; Michael Russo (no longer SSA CIO — by then 'special advisor') approves with single word 'Approved….' on Borges p.15; 2025-07-15 Aram Moghaddassi self-authorizes Provisional ATO with language 'I have determined the business need is higher than the security risk associated with this implementation and I accept all risks associated with this implementation and operation.' NUMIDENT contains the SS-5 application data for every US Social Security card ever issued: name, place/date of birth, citizenship, race/ethnicity, parents' names and SSNs, phone, address. Late June 2025: no verified audit or oversight existed over the cloud, no one outside the former DOGE group had insight into code being executed against the live data. Statutory violations: 44 U.S.C. § 3553(b) FISMA, 5 U.S.C. § 552a(e)(1) Privacy Act, 18 U.S.C. § 1030 CFAA, 44 U.S.C. § 3554(b) FISMA continuous monitoring.
supporting:
  https://whistleblower.org/wp-content/uploads/2025/08/08-26-2025-Borges-Disclosure-Sanitized.pdf
    fetched 2026-09-15 09:49:05 · sha256 0b5a3f421745107a…
updated 2026-06-03 23:47:07
confirmed policy

[76] After Borges made internal disclosures starting 2025-08-06 and emailed information requests to Edward Coristine, John Solly, and OCIO Executive Officer Mickie Tyquiengco on 2025-08-11, the SSA Office of General Counsel advised employees not to respond to Borges' inquiries — leaving Borges, as CDO, without the information his statutory role requires.

Borges p.17. This is a separate retaliation-pattern claim from the underlying data-access claim. Borges has since filed a Prohibited Personnel Practices complaint over alleged retaliation, per Katz Banks Kumin LLP reporting cited via web search. Worth tracking for any OSC or Merit Systems Protection Board findings.
supporting:
  https://whistleblower.org/wp-content/uploads/2025/08/08-26-2025-Borges-Disclosure-Sanitized.pdf
    fetched 2026-09-15 09:49:05 · sha256 0b5a3f421745107a…
  https://katzbanks.com/news/social-security-administration-whistleblower-files-retaliation-complaint-with-the-office-of-s
    fetched 2026-09-15 09:49:06 · sha256 35a0a36afa4d77af…
updated 2026-06-03 23:47:07
confirmed policy

[83] FIVE separate federal lawsuits challenge EO 14399, not two as initially documented. Three have been consolidated in the D.D.C.; the two D. Mass. cases have, per Judge Talwani's 2026-04-28 order, been allowed to proceed in Massachusetts after DOJ's motion to transfer was denied.

The five cases, in filing order: (1) DSCC v. Trump, 1:26-cv-01114 (D.D.C., filed 2026-04-01) — DSCC, DCCC, DNC, Democratic Governors Association, Senator Schumer, House Minority Leader Jeffries; (2) League of Women Voters of Massachusetts v. Trump, 1:26-cv-11549 (D. Mass., filed 2026-04-02); (3) League of United Latin American Citizens v. Exec. Off. of the President, 1:26-cv-01132 (D.D.C., filed 2026-04-02); (4) NAACP v. Trump, 1:26-cv-01151 (D.D.C., filed 2026-04-03) — joined by Common Cause, Common Cause Education Fund, Black Voters Matter Fund; (5) State of California v. Trump, 1:26-cv-11581 (D. Mass., filed 2026-04-03) — 21 states + Mass + Va + DC + Gov Shapiro of PA. The three D.D.C. cases are consolidated. Note: Common Cause v. DOJ, 1:26-cv-01352 (D.D.C., filed 2026-04-21) — which we previously documented — is a separate case about DOJ's 'Voter Registration Nationalization Policy' demanding state voter rolls; it is not directly challenging EO 14399 itself.
updated 2026-06-03 23:47:07
unverified policy

[84] The D.D.C. Consolidated EO 14399 cases have a defined briefing schedule with DOJ opposition briefs to plaintiffs' preliminary-injunction motions due 2026-05-01 and plaintiffs' reply briefs due 2026-05-08. The 'deliberative phase' / 'have not yet begun preparations' DOJ language that Will Hold attributes to the EO 14399 litigation — if it exists — is almost certainly in the 2026-05-01 DOJ opposition brief in DSCC v. Trump (lead consolidated case 1:26-cv-1114, D.D.C.), not in the procedural transfer-motion briefing in the D. Mass. cases.

The DOJ memorandum of law I retrieved is purely procedural — it argues for transfer under the first-to-file rule and contains no statements about implementation status of the EO. We need the DOJ opposition brief to plaintiffs' PI motions in the D.D.C. consolidated cases (filed 2026-05-01) to verify Will Hold's specific characterization. DOJ counsel of record on the transfer motion: Brett A. Shumate (Assistant Attorney General), Eric J. Hamilton (Deputy AAG), Joseph E. Borson (Asst. Branch Director), Stephen M. Pezzi (Senior Trial Counsel FL Bar 1041279), Esam K. Al-Shareffi (Trial Attorney D.C. Bar 90010174). These attorneys are likely also of record in the D.D.C. consolidated cases.
updated 2026-06-03 23:47:07
confirmed policy

[85] The DOJ filing Will Hold referenced is the Defendants' Combined Memorandum of Law in Support of Their Motions to Dismiss and in Opposition to Plaintiffs' Motions for a Preliminary Injunction, filed 2026-05-01 in DSCC v. Trump, 1:26-cv-01114-CJN (D.D.C.) (Document 106-1). The filing characterizes agency implementation of EO 14399 in language nearly verbatim to Will Hold's paraphrase: 'these three suits were each filed well before any agency had taken any steps to implement the Executive Order—and before the agency defendants even knew how they might try to implement the President's directions, or on what timeline. Even to this day, none of the possible future agency actions contemplated by the Executive Order have been finalized—and some have not even started' (p.1). 'As of this filing, no such lists have been created, nor has any of the "infrastructure" contemplated by Section 4(c) of the Order' (p.2). 'Indeed, the relevant agencies themselves are still deliberating regarding the Executive Order's possible future implementation' (p.9). 'DHS has not yet made any determination that preparing these lists is either "feasible" or "consistent with applicable law"' (p.18). 'Those deliberations are ongoing' (p.33).

Will Hold's specific paraphrase ("had not yet begun preparations and were still in the deliberative phase") is faithful to the filing's actual language. The DOJ filing cites three supporting agency declarations: Decl. of M. Mayhew (DHS), Decl. of J.B. MacBride (SSA), and Decl. of S. Monteith (USPS). Authoring DOJ attorneys: Brett A. Shumate (AAG, Civil Division), Eric J. Hamilton (Deputy AAG), Joseph E. Borson (Asst. Branch Director), Stephen M. Pezzi (Senior Trial Counsel, D.C. Bar 995500), Esam K. Al-Shareffi (Trial Attorney, D.C. Bar 90010174).
updated 2026-06-04 02:53:44
confirmed policy

[86] The DOJ representation in DSCC v. Trump that SSA's State-Citizenship-List infrastructure does not yet exist (filed 2026-05-01) is in tension with the Borges whistleblower disclosure: by that date, SSA's NUMIDENT database — the single most valuable record set for compiling a State Citizenship List — was already running as a live copy inside an SSA AWS-ACI Virtual Private Cloud under DOGE administrative control, with a self-signed 'Provisional Authorization to Operate' that bypassed the SSA Office of Information Security's three required mitigations (no production data, DIS involvement, FISMA ATO).

The Borges disclosure establishes that the live NUMIDENT cloud copy was approved 2025-06-25 by Michael Russo and the Provisional ATO was self-signed 2025-07-15 by Aram Moghaddassi — both pre-dating EO 14399 (signed 2026-03-31). The DOJ's representation in the May 1 filing that 'DHS has not yet made any determination' about Privacy-Act feasibility of SSA data sharing for the State Citizenship List is technically accurate at the SORN level (DHS publishes the SORN, not SSA), but elides that an unauthorized live mirror of the underlying SSA data is already in place under DOGE control with no independent security oversight. The contradiction is structural rather than verbal: DOJ tells the court the infrastructure does not exist; the relevant infrastructure does exist, just on the wrong side of FISMA. The vote.gov staging certificate (2026-04-10, issued by Let's Encrypt to an NDS-controlled hostname under loveisaskill.cloudflareaccess.com) is similarly not 'the infrastructure contemplated by Section 4(c)' — that is DHS-built; vote.gov is NDS-built — but it is evidence that the broader White-House-owned alternative voter-verification infrastructure is being stood up in parallel.
updated 2026-06-04 02:53:44
confirmed policy

[87] EO 14399 §4(c) sets a 90-day implementation deadline of 2026-06-29 for the DHS-built State Citizenship List infrastructure. EO 14338 §3 sets a July 4, 2026 deadline for the broader 'America by Design' initial-results milestone. The DOJ's 2026-05-01 filing in DSCC v. Trump argues plaintiffs' challenges are 'unripe' precisely because agencies have until 2026-06-29 to comply — i.e., the DOJ's posture is that nothing concrete will be operational until the cert-rich runway week of July 4.

From the DOJ memo p.33-34: 'The agencies charged with creation of the State Citizenship List have until at least June 29, 2026, to comply with the Order—or, alternatively, to conclude that creating or transmitting such a list is not feasible or consistent with applicable law.' That deadline tracks exactly to the runway implied by our earlier-documented cert log (passports.gov 2026-05-05, vote.gov 2026-04-10) and the EO 14338 July-4 deadline. The two EOs' deadlines are five days apart (2026-06-29 for EO 14399 §4(c); 2026-07-04 for EO 14338 §3). The DOJ's ripeness argument depends on those deadlines not being met — but if they are met, the cert log timestamps will already have proven the implementation began before DOJ's May 1 representations. This is the structural setup Will Hold and Drey both pointed at; it is now on the public docket.
supporting:
  https://www.democracydocket.com/wp-content/uploads/2026/04/2026-05-01-Defendants-combined-memorandum-of-law-in-support-o
    fetched 2026-09-15 09:49:06 · sha256 8e94faad309ce07c…
  https://www.govinfo.gov/content/pkg/FR-2025-08-26/html/2025-16396.htm
    fetched 2026-05-29 22:21:11 · sha256 77c63cfddf3efa77…
  https://www.govinfo.gov/content/pkg/FR-2026-04-03/html/2026-06601.htm
    fetched 2026-09-15 09:49:04 · sha256 aa45807ac5756d53…
updated 2026-06-04 02:53:44
confirmed policy

[91] On 2025-04-17 Rep. Gerry Connolly (then ranking member, House Oversight) sent a letter to SSA Assistant IG for Audit Michelle L. Anderson demanding an investigation into whistleblower allegations that DOGE was building a single cross-agency 'master database' compiling sensitive data from the IRS, SSA, HHS, and Treasury. The letter alleged that 'DOGE engineers have tried to create specialized computers for themselves that simultaneously give full access to networks and databases across different agencies' — calling this 'an apparent attempt to sidestep network security controls' — and that 'Individuals associated with DOGE have assembled backpacks full of laptops, each with access to different agency systems, that DOGE staff is using to combine databases that are currently maintained separately by multiple federal agencies.'

The whistleblower behind the Connolly letter is SEPARATE from Chuck Borges (Borges's disclosure came four months later, August 2025). This is the earlier whistleblower Will Hold's article alludes to. The 'master database' allegation is the strategic frame for what Borges later observed concretely at SSA. Connolly's successor as ranking member, Rep. Robert Garcia, sent a follow-up letter on 2026-03-09 expanding the investigation following Borges's explosive new allegations.
updated 2026-06-04 04:49:22
confirmed policy

[92] The DOGE cross-agency data-consolidation strategy spans at least the SSA (Numident, EDW), IRS, HHS, Treasury, and the USCIS (via the 'data lake' that Coristine and Moghaddassi previously accessed). The strategy is documented through three independent primary-source channels: (a) the Connolly April 2025 letter (anonymous whistleblower), (b) the Borges August 2025 whistleblower disclosure (named whistleblower with documentary evidence), and (c) Steve Davis's direct statements to SSA staffers reported by the Washington Post May 2025. The National Design Studio, populated by DOGE alumni inside the EOP, is the logical next host for that consolidated data once the SSA-side and DHS-side infrastructure is in place.

This is the synthesizing claim. Three independent primary sources (Connolly's whistleblower, Borges, and Davis-via-WaPo) describe the same strategy from different angles. The Will Hold / Drey infrastructure findings (NDS-controlled vote.gov/passports.gov preview, Login.gov under Hogan, etc.) are the receiving infrastructure for that consolidated data once it is moved out of the originating agencies and into White House control under Section 3161 staffing (no IG, no FOIA after 12 years).
updated 2026-06-04 04:49:22
confirmed policy

[93] Will Hold's claim that the National Design Studio 'does not appear in any federal procurement database' is supported by direct search of USAspending.gov, FPDS.gov, and SAM.gov: no contracts, awards, or solicitations are recorded under 'National Design Studio' as a vendor or as an awarding office. By contrast, every other Executive Office of the President digital-services unit with a public footprint — the U.S. Digital Service and 18F — does appear with procurement records. The procurement-database absence is consistent with NDS being staffed entirely under Section 3161 (temporary advisory authority, no salary disclosure) and with the studio's infrastructure running on a single private Cloudflare account (loveisaskill.cloudflareaccess.com) rather than through agency procurement channels.

Verified by negative-finding searches across the three primary federal procurement databases. Will Hold's specific framing was: 'his position requires no Senate confirmation, meaning no financial disclosures, and the office does not appear in any federal procurement database. As far as the official record is concerned, Joe Gebbia and the National Design Studio are basically nonexistent.' The procurement-database part is supported. The Senate-confirmation part is supported by EO 14338's text. The salary-disclosure part is supported by Section 3161 authority.
updated 2026-06-04 13:57:49
confirmed policy

[95] Will Hold's framing of the Riverside County, California ballot seizure as parallel to federal DOJ seizures in Maricopa County, Arizona and Wayne County, Michigan is partially misleading. The Riverside seizure was conducted by Riverside County Sheriff Chad Bianco — NOT by the federal Department of Justice — and is being actively challenged in court by California Attorney General Rob Bonta. The seizure targeted ~600,000 ballots from the November 2025 Proposition 50 special election based on activist-group claims of a 45,896-ballot discrepancy that the Riverside County Registrar (Art Tinoco) said was actually 103 votes.

Per CalMatters 2026-04, Democracy Docket, ABC7 LA, and Cyberscoop. The Riverside seizure is real, the 600k figure is approximately accurate, and the ballot-seizure pattern in the broader 2024-2026 period is real — but the specific actor in Riverside is a sheriff (state-level law enforcement), not the federal DOJ. The conflation of state and federal seizures in Will Hold's piece is the only specific factual misframing we have found in cross-checking the article. The DOJ Maricopa and Wayne County seizures are separately attested (per WIRED reporting cited by Will Hold) and remain unverified by this dossier.
updated 2026-06-04 13:57:49
confirmed policy

[97] CORRECTION TO CLAIM 65: The 2025-03-24 preliminary injunction in American Federation of Teachers v. Bessent (8:25-cv-00430, D. Md.) — which named Greg Hogan as one of three exceptions to a court-ordered block on DOGE access to OPM personnel data — was VACATED on 2025-08-12 by the Fourth Circuit Court of Appeals (Published opinion, No. 25-1282). The Fourth Circuit concluded plaintiffs had not shown likelihood of success when considering multiple threshold issues including Article III standing, whether the challenged actions constituted final agency action under the APA, whether the Privacy Act provided an adequate alternative remedy, and whether the Privacy Act's 'need-to-know' exception applied. As of 2025-08-12 forward there is no court-imposed restriction on DOGE access to OPM data in this case, and the Hogan-as-court-ordered-exception framing is mooted.

Important correction to claim 65. The original framing — drawn from Nextgov and Government Executive reporting on the original district-court order — overstated Hogan's current legal status. The district court (Judge Boardman) had carved out Hogan because his statutory responsibilities as OPM CIO under 40 U.S.C. § 11315 include managing OPM IT; he was the eOPF system owner; his access was 'in connection with the performance of duties assigned to him.' That reasoning is now moot. Hogan remains the head of Login.gov inside NDS; that part is unchanged and continues to be the dossier-relevant fact about him.
updated 2026-06-04 14:03:43