Open-source audit · one each week
Apply for an open-source audit.
We take one open-source project each week and run Proof on it at our own cost. If we take yours, we agree the schedule with you before anything starts.
What this costs you, and what it asks of you
No fee. One open-source pre-release audit each week, self-funded, coordinated with the maintainers and run on their schedule. No invoice, and no commercial follow-up. What it asks of you is a maintainer who will read the findings and tell us when a release is coming.
One a week means most applications get a no. We answer either way, and we say why. The standing offer, in full →
Four conditions we cannot waive
Maintainers
A maintainer agrees to the audit, answers questions about what the code is supposed to do, and reads what comes back.
Build
We can build and test the project from a clean checkout, on documented steps, without asking you to sit with us.
Scope
One component you can name and we can bound. A whole repository is too much for one week.
Publication
You agree, before we start, that the requirements, findings, and reproducers can be published on the public register.
If we take your project, this comes back
-
The map of your promises.
Every promise we recover, joined to the code that carries it and the tests that check it. You can open any link in it and see what it was built from.
-
Each place the code breaks one.
A short list of findings. A person reads each one before it reaches you, so nothing on the list is a guess.
-
The tests that pin each break.
One test per finding, pinned to an affected revision or an agreed pre-release branch. A reproducer pins the finding one of two ways: it fails until the fix lands, or it asserts the broken behavior while that behavior is live and flips when the fix lands. The record says which. Run them yourself. Keep them in your suite.
A person validates every finding before it reaches you.
Private code? Request demo instead →