Trust

We audit ourselves
like we audit your changes.

Our whole product is independent verification of AI-authored code. So here are the enterprise claims we make — each marked shipped, partial, or roadmap, with the gap named where one remains. The row-level evidence (repo paths, cycles) lives in the gated ledger this page transcribes; here we show the claim and its honest status. A gap with a plan is a roadmap. A hidden gap is a landmine. We publish ours.

✓ 5 shipped ◐ 3 partial ◷ 4 on the roadmap

Shipped

  • Separation of duties — the reviewer isn't the author

    The authoring model never grades its own diff; a quorum of rival-vendor models reviews it. The rest of the product is built on this separation. It is live.

  • Per-commit, replayable evidence bound to every verdict

    Every verdict is written to a per-SHA artifact bound to the commit + a diff hash; amend the commit and the binding breaks. Deterministic aggregation kernel authoritative in production. (Cryptographic signing is not yet shipped.)

  • Loud, audited bypass — every override is an event, not a silent escape

    Structured reason, actor allowlist, reason taxonomy, append-only NDJSON ledger. Works even without the CLI installed.

  • Full fleet dashboard — verdicts, per-critic findings, per-PR cost

    Fleet console + per-critic run detail + exec rollup, with server-enforced tenant scoping.

  • Policy engine + trusted-surface rebind

    Part of the shared gate logic; designed to close the self-modifying-policy attack class.

Partial

  • Multi-vendor adversarial quorum

    Four rival-vendor critics are active in production today; additional configured critics are not in the active roster. The count you see reflects the active roster, not the configured maximum.

  • Per-commit evidence trail + audited bypass ledger for compliance

    The structured trail ships and maps to the evidence a SOC2 CC8.1 control asks for. A packaged, auditor-consumable evidence pack (one-command export) is not yet shipped.

  • Per-repo cost controls

    Per-repo + per-critic cost visibility ships. Enforcement caps (a spend ceiling that blocks) do not yet.

On the roadmap

  • BYOK — bring your own vendor keys

    The managed shared-key path ships. Per-tenant key isolation is not built — the BYOK key source is a stub today. On the roadmap.

  • VPC / on-prem deployment

    Hosted multi-tenant SaaS is the only shipped deployment. VPC / on-prem is not built.

  • SOC2 CC8.1 evidence pack

    We hold no SOC2 certification and make no claim to. The auditor-consumable evidence pack — built from the trail above — is not yet shipped.

  • SSO (SAML / OIDC) + SCIM

    No customer-facing SSO ships today. Enterprise identity is on the roadmap.

How this page stays honest

The source of truth is a diffable, critic-gated ledger file in our platform repository; this page is transcribed from it. When a capability ships, its row moves from roadmap to shipped. The transcription is currently manual — a build-time sync that renders this page directly from the gated ledger is itself on our roadmap, and we'll say so here rather than imply an enforcement that isn't wired yet.

Get Started

Ask us about any row.

Each claim above resolves to a repo path, a cycle, or a named gap — bring the hardest one to a call.