About

The practice.

Proof is a correctness audit practice that builds its own instruments. This page is who stands behind the signatures, and what you are actually relying on when you rely on them.

§ 1 · Why this practice exists

The engine came first.

Proof started as an instrument, not a practice, and the instrument started as a response to a pattern enterprise engineering knows well: growth means more tests, more nuance, more edge cases, and still more bugs; the test suite becomes its own scaling problem; new features ship regressions, and regressions cost reputation. The disciplines that answer this (managed requirements, formal proofs, condition-level coverage) existed, but they were locked inside regulated industry.

The engine brought them out. The practice exists because an instrument alone convinces nobody. Someone accountable has to point it at your code, judge what it finds, and sign.

§ 2 · The founder

Leonid Bugaev

Leonid has spent two decades building infrastructure tools engineers run in production: GoReplay, a traffic-replay system used at thousands of companies, and jsonparser, one of the most widely used JSON libraries in Go. He ran engineering at Tyk, the API management platform.

The first public audit in the ledger is of his own library, including the miss and its postmortem. He built the engine, wrote the bar it enforces, and signs against it. Why an audit practice, after two decades of building tools? Because the question that would not go away was whether anyone could prove their software did what they promised, starting with his own.

Leonid Bugaev

GitHub · GoReplay · jsonparser · the public audit

§ 3 · How the practice is built

What you are relying on, and what you are not.

Engagements are led by the practice; findings are issued under named review against a published bar. What you are relying on is that bar, the instruments that enforce it, and a signature you can check against evidence in your own repo. What you are not relying on is anyone's day-to-day presence: the corpus re-runs in your CI without us. A named reviewer can only stand behind so much work, so we take a limited number of engagements each quarter.

Procurement-grade answers on access, data, and continuity live on the trust page. We would rather look small than unverifiable; the market just learned what generated credentials are worth.

§ 4 · Where to go

The work speaks in these places.

The ledger

Dated entries, a validator on record for each, one published miss. Case study →

The bar

Six clauses, the checks that enforce them, and what the audit does not see.

The instruments

The engine, its firsts, and the research lineage behind them.

The engagement

Its shape, commitments, and scoping form. After week four →

Trust

Access, data handling, legal posture, continuity, and disclosure.

AI-native systems

The same bar, for teams shipping model-written code.