Internal memo · not a site page

Website v7: options, evaluation, recommendation

Three site concepts were designed from your materials and judged by three hostile lenses (a burned CTO buyer, an AI-lab corp-dev evaluator, an HN cynic). This memo is the scorecard, the recommendation the mockup implements, and the decisions only you can make.

How to use the mockup: the TYPE LAB panel (bottom right) adjusts base size, scale, measure, leading, and font pairing on every page. Turn on Structure notes to see each section's job and every ⚠ flag. The homepage hero has an A/B/C variant switcher.

§ 1 · Your goals, restated

What this site must do at once

  1. Sell audits now. Continuous Correctness Audit engagements are the revenue leg. Buyer: CTO/VP Eng at Series B–D infra and dev-tools companies.
  2. Sell the product eventually. The engine must be visible enough that a product story stays open.
  3. Sell you. An AI lab reading this site should conclude "these are the people who solved verification for AI-written code." Labs acquire named people with public firsts, not fictional institutions.
  4. Ride the moment without being of the moment. YC has spent five RFS cycles telling founders to become AI-native service firms (Fall 2026 RFS: "AI-Native Compliance Infrastructure"). Leverage the wave; never read as another AI agent.
§ 2 · What the research says

Four findings that shaped everything

1. YC's wave is your tailwind, and its collapse is your wedge. The RFS thesis is "companies that do the work, not companies that sell software to help people do the work." Dozens of full-stack AI audit firms got funded on it (Denki, Moby, Tally, Harper). Then Delve, the $32M AI-compliance darling, was expelled from YC in April 2026: 493 of 494 SOC 2 reports were identical boilerplate with conclusions pre-populated before evidence arrived. The category's unsolved problem is now, verbatim, Proof's doctrine: assurance must be checkable. The site agrees with YC's thesis and corrects it: the bottleneck was never headcount, it was unverifiable evidence.

2. Trail of Bits just took "AI-era audit firm" off the table. Their 2026 homepage leads with their own AI-native transformation story; their credibility unit is the archive (946 publications, 620 audits, person-week filters). The available wedge is the proof-object, not the posture: their audit ends in a published PDF; ours never ends, because the gate re-runs in the client's CI. "Published once" vs "re-verifies forever." The mockup copies none of their signature moves (no library homepage, no stat strip, no pillar triads, no branded goodwill program).

3. The "verification layer" lane is crowded and rich; the "correctness audit" lane is empty. Axiom raised $200M at $1.6B for the "correctness and safety layer"; Theorem (Khosla) and Harmonic own formal-verification vocabulary. Scanners (XBOW, ZeroPath, Corgea) own exploitability vocabulary. Nobody between scanners and compliance claims "audit" + "evidence." That's the lane. Bonus: the formal-methods wave (Kleppmann predicting mainstream formal verification, the "vericoding" literature) makes the name Proof land better every month.

4. The trust-gap stats are the hype leverage. Stack Overflow 2025: 46% distrust vs 33% trust; 45% name "almost right, but not quite" as their top frustration. DORA 2025: 90% adoption, 30% little/no trust, over 60% hit AI-related errors post-deploy. The site uses at most two per page, dated and attributed, because this audience distrusts marketing more than it distrusts AI.

§ 3 · The three concepts

Option A · The Standing Audit (services-led)

"Code ships faster than anyone can vouch for it." The firm and the engagement are the product; the engine is the stated unfair advantage. Built around how a $30–150k audit is actually bought: forwardable per-role pages, fixed-fee-to-retainer shape, disqualification as a designed path. Judges: the only concept that books engagements. Weakness: under-serves the acquihire exit; the engine hides one click deep.

Option B · The Evidence Engine (product-led)

"AI writes your code. Who verifies the intent?" The corpus artifact is the hero of every page; the audit is the engine's guided installation. Judges: do not build. A product site with nothing to download reads as enterprise-sales bait in product clothes; it relitigates your own July ruling (the CLI-waitlist site argued against the audit pitch in live deals); and it volunteers for a funding-optics fight with Axiom/Theorem it loses. Its one great move: showing the artifact in the first viewport. Stolen.

Option C · The Correctness Lab (standard-led)

"'Verified' should be a claim you can re-run." The lab publishes the bar, builds the instruments, applies the bar commercially. Highest acquihire score of the three; the own-miss postmortem is the single most disarming trust move any concept owned. Weakness: a self-crowned "standard" with zero external adopters invites "who ratified this?", and lab posture starves the revenue leg.

Judge scorecard (average of three lenses, 1–10)

CriterionA · FirmB · EngineC · Lab
Sells audit engagements7.74.75.7
Sells the product/engine4.07.35.0
Acqui-hire legibility6.07.38.0
Rides the moment credibly7.06.36.7
Distinct from Trail of Bits7.08.06.7
Survives hostile scrutiny7.35.07.3

All three judges, independently, recommended the same hybrid rather than any concept as written.

§ 4 · The recommendation (what this mockup implements)

A's chassis. C's soul. B's first screen.

The landing page is built as one argument, not a component stack: claim (hero: the audit that doesn't expire) → wound (the bad-fix release, first position) → category (we audit whether it works) → instrument (failing gate + file tree) → provenance (regulated-industry why-now: NASA lineage, MC/DC, the first-for-Go claim) → compounding (depreciation vs month-twelve) → proof (own miss + embargo dateline) → offerfitroutingsignatureform. Toggle structure notes on the homepage to see each section's role in the arc.

How the goals map: audits are served by the chassis; the product exit stays open because the corpus artifact and instruments pages document the engine without selling it; the acqui-hire exit is served by the instruments page plus the own-miss register (labs read taste); the moment is served by the AI-native lander and the category line, with zero agentic vocabulary anywhere.

§ 5 · Decisions only you can make

Open decisions, ranked by blast radius

1 · Firm voice vs named principal — DECIDED 2026-08-01

Ruling: named-principal practice, reversing the July 29 institutional-firm decision, on the judges' unanimous argument: one LinkedIn lookup detonates a simulated institution, while "the correctness audit practice of Leonid Bugaev (GoReplay, jsonparser)" survives diligence, makes the thin ledger read as "new practice, known engineer," and serves the acqui-hire goal (labs acquire named people).

Implementation: "we" stays the working pronoun (a practice says we, Latacora-style), but identity statements name the principal, and nothing anywhere implies institutional scale or headcount. Migrate to firmer institutional voice when there is a second named reviewer to point at.

Placement refinement (later same day): the homepage must not feel like a one-man business. Its "who signs" section now carries accountability mechanics only (a named reviewer signs every finding; the bar is published; the signature is checkable), which is true at any headcount. The principal's bio and the smallness-as-doctrine disclosures moved to the new /about page; procurement's continuity answer stays on /trust. Guardrail held both ways: no solo-spotlight on the selling page, and no staged team anywhere.

1b · Lead-form funnel — DECIDED 2026-08-01

Ruling: two-step, email-first. Step one asks only for email (the only required field); after submit, the six qualifier fields reveal as optional "help us come prepared" context. Reverses the July 29 form-as-qualifier design for stage reasons: today the binding constraint is market contact, not call capacity, and the deployed subscribe function only persists email+source anyway. Qualification moves to the founder's personal follow-up email (ask trigger and budget posture in the thread; calls only after). Page copy (engagement shape, fit/anti-fit) keeps carrying the disqualification load. Accepted cost: more inbox noise. Revisit when capacity, not pipeline, is the constraint.

2 · The two Tier-1 revalidation facts (homepage §1, the wound)

The July 29 record plans them for the homepage top third; website-next's DESIGN.md rules the same work unconsented. Every judge flagged it: a site whose doctrine is "every claim re-runnable or bounded" cannot carry one unconsented fact on its most load-bearing proof point. The rebuilt landing page makes this decision even more load-bearing: the facts now open the page as its fear beat. If consent fails, §1 needs a replacement wound (the jsonparser Set() miss can carry a weaker version). Resolve before any copy freeze.

3 · Hero variant

A (firm: "Code ships faster than anyone can vouch for it"), C (doctrine: "'Verified' should be a claim you can re-run"), B (question: "AI writes your code. Who verifies the intent?", continuity with the live site), or D (expiry: "The audit that doesn't expire."). Switch them live on the homepage.

Recommendation: D. A observes the problem but stakes nothing. B is a question, and question-heroes now pattern-match to the AI-dev-tool wave; an auditor's job is to answer. C is the best sentence but sells a worldview, not a purchase. D sells the differentiator as a consequence the buyer feels (every audit they have ever bought went stale; this one keeps running), it implies "continuous" without the buzzword every scanner also uses, and it is the sentence a champion can repeat to their CEO. C's line keeps its prominent home as the methodology lede either way.

4 · Verification flags before anything ships

The mockup carries ⚠ notes wherever a number or artifact needs confirmation: the 52-check count (v6 audit found a 52-vs-49 discrepancy), the 758+ self-verification requirement count (likely higher now), the severity-SLA business-day number, the jsonparser postmortem's public availability, and the subscribe function that must persist all seven form fields (today's deployed one keeps only email + source).

§ 6 · Deliberately not built

Absent on purpose

Pages: home · offer · ai-native · methodology · findings · instruments · trust