Partner program · for agencies and delivery firms

You keep the client. We add the proof.

You own the remediation. Proof works inside your engagement as the independent intent, evidence and acceptance layer: what the component must do, fix-ready findings your team can remediate, and the evidence you can use to prove the result.

You stay prime Proof verifies Your team delivers

01 · The economics

Sell outcomes, not capacity.

You buy two fixed-price lines from us and resell both under your own contract. What they produce is scoped, evidenced engineering work your team prices separately.

A client who bought eight engineers asks what the number is now that a model writes the first draft. Procurement compares your rate card against three firms with the same capability deck. Growth inside your own accounts needs a better reason than “we have people available”.

The real work stays invisible. Your team feels it in the estimates they pad. You cannot put it in a proposal, because “this needs work” is an opinion, and your client has one already.

An assurance line gives you something to sell that is not headcount. Every confirmed finding it produces is remediation with an agreed finish line, which your engineers scope and bill at your own rates. Two lines are predictable, and the third keeps arriving for as long as the audit stands.

02 · The unit of work

A finding is a work order.

It arrives as work you can reproduce, understand, estimate and accept. Not another opinion about the code.

We index the client’s code first. Their history and support queue supply the why. Out of that comes the intent graph: the promises the software makes, approved by the engineers who own it, linked to the code and tests that carry each one, and to every place the code breaks one. A finding looks like this:

Read it as a scope document. The requirement says what the software owes. The reproducer is the acceptance test. It is agreed before anyone writes a line of the fix. When the fix lands, the gate re-checks the requirement, the traceability and the coverage.

The gate then stays in the client’s CI and runs on every release without us, and the standing audit keeps the record current as the software changes.

How to read the status line

An unresolved problem is a known issue. KI-3 was one. Its fix is upstream, so the issue, the fixing change and the evidence together now form a verified defect record. Read the record for shape and the status line for where it stands.

A reproducer pins a finding one of two ways: it fails until the fix lands, or it asserts the broken behavior while that behavior is live and flips when the fix lands. The record says which; this one took the second path.

Severity is our assessment, weighted by reachability and impact; a starting point for your triage, not a CVSS determination. The claim is bounded on purpose: a declared scope, declared behaviors, evidence sized to the consequence of failure.

03 · Who does what

You stay prime. Proof stays independent.

Your client signs one contract, with you. We work behind it as a named specialist subcontractor. What you resell is AI-native software assurance, for changes made by humans and by coding agents. You pay us a fixed wholesale install fee and a flat monthly standing-audit fee, both agreed before work begins. Neither depends on the number or severity of findings.

The client

Owns and decides

Approves us as a named subcontractor and authorises the access. Approves what the software must do, and chooses what to repair.

Proof

Builds, then keeps re-auditing

The install puts the intent graph, the evidence and the gate in place for one component. The standing audit then keeps them current: new behaviour reviewed, affected evidence invalidated, your fixes re-verified. A person validates every finding before it reaches anyone.

Your firm

Sells, builds, maintains

Sets the client-facing price on both our lines and invoices. Remediation, features and ongoing delivery are yours.

Our independence rests on our own fee, and on nothing you charge. We are not paid per finding and take no percentage of the remediation, so the assessment cannot earn more by growing. What you charge on top of our lines, and what you charge to repair what we find, is your business and does not touch the check. Every fix, including any we write ourselves, must satisfy the same approved requirements and the same client-owned evidence gate.

Working under your contract does not weaken that. What it could weaken is reporting: a verifier that reports only through the party being measured can be leaned on. So the routing is written into the engagement. Every confirmed finding reaches the client, in full, whatever it says about anyone. You cannot withhold one, and neither can we, and that binds us the way the five commitments do. A coordinated-disclosure embargo or a legal restriction can delay what we are allowed to put in writing; it does not change who the finding goes to.

Why now, and where the rule comes from

New EU rules are pushing regulated clients to demand inspectable evidence from the suppliers they depend on. The legal duty is theirs, and producing the engineering evidence can become part of your delivery.

The independence rule is older than us. DO-178C, the guidance airborne software is certified against, marks many verification objectives at higher criticality levels as requiring independence, so the check is done by someone other than the item’s author.

The reporting rule is borrowed too. Under 45 CFR 95.626, the US federal rule for independent checks on at-risk state benefit systems, the verifier reports to the federal agency at the same time it reports to the State. We take the routing and leave the org chart alone.

Yours

  • You control the sale, hold the client contract, and invoice the client.
  • You own the remediation and the delivery that follows.
  • We do not approach your registered clients — the ones you have already worked with — without your written approval.
  • We do not quote fix sprints in your accounts, and we do not sell staff: no engineers placed in your client’s teams, no seats, no hourly delivery.
  • Co-brand it: delivered by you, assurance by Proof.

Ours

  • We control the method and the bar.
  • Every confirmed finding reaches the client, in full. An embargo or a legal restriction can delay the detail; it does not change who receives it.
  • Our fees are fixed from the declared scope and change cadence.
  • The client keeps durable rights to the requirements, tests, reproducers and evidence.
  • No full white-label, while independent evidence is part of the claim.

04 · What changes for you

Four outcomes you can put in a proposal.

01

A reason to be in the room

You arrive at a review with specific, evidenced defects in the client’s own code. That is not the meeting where you ask whether budget opened up.

02

Acceptance stops being an argument

The acceptance evidence is agreed before the fix, and both sides can run the same check. A red test can still mean an afternoon or a month: we define what completion means, and you price the work to reach it.

03

Staff changes cost you less

A new engineer’s first pull request is graded against approved promises. When something breaks, the record carries the origin we could establish.

04

Something to say in an RFP

Every firm on the shortlist claims senior people. You commit to an independent correctness audit, and the reader can check it: the bar is published, and so is a defect we missed.

05 · The operating model

One operating model, six steps.

No second vendor relationship for your client to negotiate.

01 · You sell it

You sell the assessment as part of your engagement.

02 · The client authorises

The client approves Proof as a named specialist subcontractor.

03 · We deliver the baseline

One component. Requirements your client’s engineers approve, and a register of confirmed findings.

04 · You sell the fix

You scope, price and perform the remediation, at your own rates.

05 · We verify

We grade the result against the requirement, and the gate stays in their CI.

06 · The audit stands

The gate runs on every merge. Each month we review what changed, update the bar, validate new issues, re-verify your fixes and state where the component stands.

Pick a secure account, not your largest. And pick a component that is outside a live warranty: the timing warning is below, next to fit.

06 · After the first backlog

Every fix creates more work you can prove.

A first engagement produces confirmed findings. What keeps a partner in the account is what comes after.

Change records

Changes carry their own record

A feature or behaviour change gets a record that states its intent and the requirements it moves. Your team keeps building, and the graph says what the work was for.

Verified defect records

A resolved issue leaves evidence behind

A closed known issue becomes a verified defect record: the original failure, the fixing change, and a regression test pinned in CI. The audit warns when one passing test is used to claim a whole class is closed.

Coverage

Coverage grows one component at a time

A new component gets a full install, separately scoped or sized into the standing fee. More covered surface is more work you are already positioned to do, and more margin on both our lines.

Agent access

Your agents read the same graph

Your coding agents query the intent graph directly: the requirements, hazards, known issues, changes, reproducers and verification obligations your client’s engineers approved. The agent starts from approved intent instead of rediscovering the system from raw code.

What an agent can and cannot do

The agent’s access is read-only by construction, and it sees exactly what its owner is allowed to see. An agent cannot change your client’s code, edit the audit, or start one; audits are run by a person.

Claude Code, Codex, or any MCP client reaches the same live surface your client’s engineers read. What the agent receives →

07 · What to say to your client

The sentence that opens the conversation.

“We want to put an independent check around one component you depend on. We bring in a specialist as a named subcontractor under our contract with you. They write down what the component must do, and your engineers approve it. Any violation comes back as a test we can run ourselves. My team fixes what it finds. They verify the result and leave the checks running in your CI. Every later change, made by hand or by a coding agent, is graded against the same requirements. You keep the requirements, the tests and the evidence.”

Do not present the results alone. We co-present them with you; that is what keeps the evidence credible in your client’s eyes, which is the whole reason it is worth anything to them.

08 · Fit

Where it fits—and where it does not.

A fit if

  • You own a delivery outcome, not only the people. Your contract names a deliverable.
  • You hold an account where you could raise this with a VP of Engineering.
  • Your engineers could take a queue of reproducers and burn it down.
  • You would rather compete on what you can prove than on your rate.

Not this page if

  • You want published margins and a partner portal. We have neither.
  • You need a certified penetration test. Engage an accredited security firm.
  • You only place individual engineers, and the client directs the work.
  • You want the audit branded as your own work.
  • Your own team would be the one told about the findings. Read the audit itself instead.

Before you pick a component · the warranty warning

Not every finding becomes paid work for you. Where the code sits inside a warranty period, an SLA, or a fixed-price scope, the fix is yours to absorb. Warranties normally cover every defect found in the period, whoever finds it, and acceptance does not close the question.

So the timing matters more than the account. The right moment to bring us in is before you sign, or before your client accepts. Six weeks into a warranty is the wrong moment. Check your own contract first; we cannot read it for you.

The reverse is also worth knowing. If you are taking over somebody else’s codebase, no standard clause protects you from what they left behind. A dated baseline is the only thing that does, and that is what the first engagement produces.

The engine is language-agnostic; the published work is Go, and that is the only depth we can show you today. C and C++ arrive through the compiler’s own coverage measurement, in the same gate. Where every other stack stands is in the language table. Another stack? Say so on the form and you get an honest timeline.

Start

Start with one account.

You need not name the client. Tell us what your team maintains, the stack, and who would own the remediation. Every request gets a reply — a scoping call or an honest no.

Private by default. Do not name your client here; we can talk about the account on a call. Nothing is agreed until it is in writing.

The engagement your client would get, in full: the Continuous Correctness Audit.

Proof was founded by Leonid Bugaev and operates both the Proof platform and its named assurance practice. Who stands behind the work →

Prefer a call? Ask for 20 minutes →