What we claim — and what we don't.
We build verification tools — so our own words get the same test. If anything here reads stronger than its evidence, treat it as a bug and tell us.
What we do claim
- Our tools do the specific operations described — sandboxing, SBOM/CVE scans, behavioural UI checks, evidence-based diagnosis, signed verdicts.
- Signed outputs are independently verifiable, by the method described.
- Figures describe what was actually measured — never a market size dressed as a track record.
- Estimates are labelled, with their basis shown.
- Our commercial model — including affiliate referrals — is disclosed.
What we don't claim
- That anything is unbreakable or compromise "impossible". Security is measured, never absolute.
- Certifications we haven't completed. No badge is displayed before it's earned.
- Invented customers, logos or case studies. Scenarios are labelled illustrative.
- That findings are legal determinations. They're engineering signals for your review.
- That our tools act on your systems. They advise; you decide.
Each headline, with its proof and its boundary.
For every product, the claim we make, what backs it, and where it stops. Nothing here should surprise a security or procurement team doing due diligence.
"Signed evidence about an open-source AI tool before you deploy it."
Evidence: Docker sandbox · syft SBOM · grype CVE · OWASP LLM checks · Ed25519-signed quorum reports.
Limit: Certifies a specific version under a specific test — evidence for review, not a warranty.
"Flags risky checkout-UI patterns in CI, fully offline."
Evidence: Static + behavioural checks · zero egress · SARIF and exit codes.
Limit: QA signal, not a legal determination; no headline accuracy number until the corpus supports one.
"Diagnoses why an AI incident happened, from payload-free telemetry."
Evidence: Payload-free OTel ingestion · evidence graph · air-gapped deterministic verify engine.
Limit: Diagnosis is a hypothesis for engineers, not auto-remediation; seeded knowledge is labelled.
"A signed risk verdict a smart contract can verify — advisory only."
Evidence: Quorum-proven inputs · replay-proof signatures · real-EVM-tested contract (solc 0.8.24).
Limit: Advisory, never a kill-switch; unprovable inputs return UNKNOWN.
"Estimates SaaS-stack waste and ranks open-source swaps."
Evidence: Transparent per-seat × team × overlap calc · client-side calculator · repo-signal rankings.
Limit: Directional estimate, not an audited figure; referral links disclosed.
Don't take our word for it — take the signature.
This is what verifying one of our evidence bundles looks like. Press the button and watch each check run.
Interactive walkthrough of the real verification sequence, using an illustrative bundle.
The same steps run offline against our published public keys.
We'd rather be verifiable than badged.
Formal certifications are valuable, but a logo is not evidence — and displaying one before it's earned is exactly the kind of claim we build tools to catch. So we keep this simple and honest.
Our position today
- We publish no certification badge we have not completed. If you don't see one here, we don't hold it — and we won't imply otherwise.
- We describe our actual security practices factually, in plain terms, rather than through the visual language of accreditation.
- When we begin or complete a formal audit, we'll state its exact status and scope here — not before.
For your due diligence
- Several products run air-gapped, with zero-egress code paths — so you can inspect their behaviour inside your own environment.
- Signed outputs are verifiable independently, without trusting our servers.
- Technical detail for a security review is available under NDA. Start a conversation →
If a claim outruns its evidence, tell us.
We mean the standard on this page literally. Bring a system for us to run against, or a question about any claim we've made — both get a straight answer.