For agencies and delivery firms · terms
You stay prime. We work under your paper.
The commercial answers, in one place. Nothing here is an offer you can accept. A signed agreement binds us; this page does not.
What we agree with you.
| Question | Answer |
|---|---|
| Who contracts with the client? | You do. You are the prime, and the client signs one contract. |
| Who invoices the client? | You do, for the whole engagement, at your own rates. |
| Who contracts with Proof? | You do, under a master subcontract and a project order. |
| Does the client know we are involved? | Yes. We are a named specialist subcontractor, and they authorise the access. |
| Who owns the remediation? | You do. You scope it, price it and perform it. |
| Who verifies the remediation? | We do. We grade the fix against the requirement it was meant to keep. |
| Can we co-brand it? | Yes: delivered by your firm, assurance by Proof. |
| Can it be white-labelled? | No, not while independent evidence is part of the claim. |
| Who owns the artifacts? | The client keeps durable rights to the requirements, tests, reproducers, evidence and exports. |
| Will you approach our client? | Not without your written approval. Registered accounts are protected. |
| What do you charge? | A fixed wholesale fee, and a recurring component fee where the audit continues. Agreed in writing before any work. |
| Who sees a finding? | The client sees every confirmed finding, in full. Neither of us can withhold or edit one. |
Access to the client's code, and what we do not hold
Two models. A public repository, or private code under an NDA we countersign before we read a line. Access is read-only, and scoped to the component.
Engagement code reaches three AI subprocessors, Anthropic, OpenAI and xAI, only through their commercial APIs, under terms that exclude training on customer data. If your client's policy excludes a provider, the engagement runs on the ones they allow.
Two answers their reviewers will want first: we hold no SOC 2 report, and we delete what we hold within 30 days of exit. The rest is on Trust. Where your client's own NDA governs, we read it and work inside it. We do not promise to comply with a document we have not seen.
None of the above is an offer you can accept. A signed agreement binds us; this page does not. And this is new: no outside team has yet run a remediation program off one of these registers. Our one public audit ran on a Go library of ours and found seven real defects. What that means for a component your size is what a first engagement would tell us both.
Ask these first.
“It will find things my team shipped.”
It will find things everyone shipped, including whoever came before you. A finding records the change that introduced the defect, because “when did this start” is useful. Records name the engineer who owns a fix and whoever reviewed it. That is accountability for the fix, not blame for the bug.
You are also the firm that brought the standard in. From the day the gate lands, you hold a record of what was true before your team touched the code.
“What if it finds more than my client will pay to fix?”
Then they have a plan. Findings carry severity, so the queue is orderable and nothing has to be fixed at once. A client who defers a low-severity finding has made a decision on the record. Without the register those defects are still there, and nobody's name is on the decision to keep them.
“Will you compete with us on the fixing?”
We sell fix sprints for clients who have nobody. We would rather have somebody, which is why this page exists. In your accounts we do not quote them.
More usefully, we do not sell staff. No engineers in your client's teams, no seats, no dev hours. The only fee we charge again is for the audit.
Fix work is priced separately, so the party grading a fix has no stake in having written it. DO-178C uses the same rule for airborne software: at higher criticality levels, the check is done by someone other than the author. That rule protects the gate, not your revenue. The written term protects your revenue.
One more, since we raised it. An introduction fee gives us a commercial tie to the firm writing the fixes we grade. Two things bound it: the fee attaches to the introduction, never to how much we find, and your client sees it in writing. If that is still too close, we will take the engagement without a fee.
“Is this a pile of machine-generated bug reports?”
The checks are deterministic instruments: solvers, coverage measurement, link resolution. They run at a volume no person could reach. Most of what runs reports nothing. What surfaces is a much smaller set, and a person clears it one at a time.
A finding ships with a reproducer that fails on the client's main, or it does not ship. That is a commitment in the contract, not something the gate can prove to you. You can check our published miss instead. A defect escaped one of our own audits under full coverage. The postmortem names the gap.
“Can we add a subcontractor under our client contract?”
That is the question to settle first, because under this model we do sit under your paper. Most master agreements allow a named subcontractor with the client's written approval, and that approval is the step we build into the sequence. Check your clause before you offer it, and we will work within whatever it requires.
We countersign your client's NDA before we read a line of private code. Access is read-only and scoped to the component. Whose data is in scope is a question for your counsel, not an answer from us.
“What does this cost us and our client in time?”
From your client: about two hours of the owners' time in week one, to approve the requirements. Then a named contact for escalations, and a walkthrough in week four.
From you: an introduction, an owner for the relationship, and a seat in the room. After that, the work you take on is the work you already sell, and it arrives pre-specified.
We read code. We do not write it. The record and the gate arrive as a pull request their engineers merge.
Back to the partner page · Selling into regulated accounts · Trust