Open-source audit · one each week

Apply for an open-source audit.

We take one open-source project each week. Proof names what the code must keep doing, and brings back the evidence before a release.

What this costs

No fee. We fund the pre-release audit and run it on your schedule. No invoice, and no commercial follow-up.

One a week means most applications get a no. We answer either way, and we say why. The standing offer, in full →

Four conditions we cannot waive

Maintainers

A maintainer agrees to the audit, answers questions about what the code is supposed to do, and reads what comes back.

Build

We can build and test the project from a clean checkout, on documented steps, without asking you to sit with us.

Scope

One component you can name and we can bound. A whole repository is too much for one week.

Publication

You agree, before we start, that the requirements, findings, and reproducers can be published on the public register.

If we take your project, this comes back

  • The map of your promises.

    Every promise we recover, joined to the code that carries it and the tests that check it. Open any link and see what it was built from.

  • Each place the code breaks one.

    A short list of findings. A person reads each one before it reaches you.

  • The tests that pin each break.

    One test per finding, pinned to the affected revision or an agreed pre-release branch. It fails until the fix, or it asserts the live break and flips when the fix lands. The record says which. Run it and keep it.

A person validates every finding before it reaches you.

Apply with your repository

The repository, your email, and what worries you. If a release is coming, say when.

Paste the full address, for example https://github.com/org/repo

One project a week, so most applications get a no. We answer either way. Nothing starts until the maintainers agree the schedule.

Private code? Request demo instead →