Trust
Customer code and findings stay controlled.
Proof is a commercial Continuous Correctness Audit service. The internal audit engine is proprietary; delivered findings must stand on inspectable evidence your team can review, rerun, and retain.
Default posturePrivate first
Findings
Private by default; publication requires written approval.
Access
Least-privilege repo or artifact access matched to the scoped path.
Evidence
Reproducers, severity rationale, affected surface, and retest result are inspectable.
Commercial identity
Proof is the public brand.
- Proof is built and operated by ProbeLabs.
- The procurement packet can include contracting entity, jurisdiction, tax details, insurance posture, and security questionnaire answers.
- Security, legal, and vendor questionnaires can be routed through [email protected].
- NDA, services agreement, DPA, and customer-specific procurement steps can be handled before repository access.
What stays private
No public naming without approval.
- Customer name, repository, source code, findings, and evidence artifacts are private by default.
- Public field notes, case studies, or sanitized reports require written customer approval.
- Coordinated vulnerability disclosure, embargoes, advisories, and CVE support are handled case by case.
- Proof does not publish customer-specific intelligence as marketing material without approval.
Customer data handling
Access is scoped to the reviewed path.
| Area | Default expectation |
|---|---|
| Source access | Use the narrowest practical access mode: public source, read-only private repo access, exported archive, specific branch, or customer-provided artifact bundle. |
| Secrets | Customers should not share production secrets. Proof scopes review around source, tests, configs, traces, and reproducible fixtures. |
| Retention | Retention and deletion windows are agreed during scoping. Evidence needed for ongoing cadence can be retained under the services agreement; one-off artifacts can be deleted after handoff. |
| AI systems | Proof may use AI-assisted analysis as part of its proprietary workflow. Customer-specific handling, no-training commitments, subprocessors, or local/private analysis requirements should be agreed before access. |
| Evidence ownership | Customer-facing reports, reproducers, regression tests, and retest notes are delivered as inspectable artifacts. Proof's internal orchestration, prompts, scoring, and private corpora remain proprietary. |
Plain version: Proof's engine is private. The evidence you receive should not be a black box.
Disclosure handling
Security findings are coordinated.
- Findings are shared with the customer or authorized maintainer first.
- Publication, third-party notification, and advisory language require approval.
- Embargo timing, CVE/advisory support, and maintainer coordination are agreed per finding.
- Reports distinguish correctness impact, security impact, exploitability, preconditions, confidence, and remediation status.
Lead privacy
Form data is used for scoping.
- Contact forms collect the fields submitted, timestamp, source page, and approximate country from Cloudflare request metadata.
- Form data is used to reply, qualify fit, and prepare a scoping conversation.
- To request deletion of a lead record, email [email protected].
- Do not submit secrets or private source code through the website form.