Trust

Customer code and findings stay controlled.

Proof is a commercial Continuous Correctness Audit service. The internal audit engine is proprietary; delivered findings must stand on inspectable evidence your team can review, rerun, and retain.

Default posturePrivate first
Findings

Private by default; publication requires written approval.

Access

Least-privilege repo or artifact access matched to the scoped path.

Evidence

Reproducers, severity rationale, affected surface, and retest result are inspectable.

Commercial identity

Proof is the public brand.

  • Proof is built and operated by ProbeLabs.
  • The procurement packet can include contracting entity, jurisdiction, tax details, insurance posture, and security questionnaire answers.
  • Security, legal, and vendor questionnaires can be routed through [email protected].
  • NDA, services agreement, DPA, and customer-specific procurement steps can be handled before repository access.

What stays private

No public naming without approval.

  • Customer name, repository, source code, findings, and evidence artifacts are private by default.
  • Public field notes, case studies, or sanitized reports require written customer approval.
  • Coordinated vulnerability disclosure, embargoes, advisories, and CVE support are handled case by case.
  • Proof does not publish customer-specific intelligence as marketing material without approval.

Customer data handling

Access is scoped to the reviewed path.

AreaDefault expectation
Source accessUse the narrowest practical access mode: public source, read-only private repo access, exported archive, specific branch, or customer-provided artifact bundle.
SecretsCustomers should not share production secrets. Proof scopes review around source, tests, configs, traces, and reproducible fixtures.
RetentionRetention and deletion windows are agreed during scoping. Evidence needed for ongoing cadence can be retained under the services agreement; one-off artifacts can be deleted after handoff.
AI systemsProof may use AI-assisted analysis as part of its proprietary workflow. Customer-specific handling, no-training commitments, subprocessors, or local/private analysis requirements should be agreed before access.
Evidence ownershipCustomer-facing reports, reproducers, regression tests, and retest notes are delivered as inspectable artifacts. Proof's internal orchestration, prompts, scoring, and private corpora remain proprietary.
Plain version: Proof's engine is private. The evidence you receive should not be a black box.

Disclosure handling

Security findings are coordinated.

  • Findings are shared with the customer or authorized maintainer first.
  • Publication, third-party notification, and advisory language require approval.
  • Embargo timing, CVE/advisory support, and maintainer coordination are agreed per finding.
  • Reports distinguish correctness impact, security impact, exploitability, preconditions, confidence, and remediation status.

Lead privacy

Form data is used for scoping.

  • Contact forms collect the fields submitted, timestamp, source page, and approximate country from Cloudflare request metadata.
  • Form data is used to reply, qualify fit, and prepare a scoping conversation.
  • To request deletion of a lead record, email [email protected].
  • Do not submit secrets or private source code through the website form.