What you get
Four things, and they are yours.
1. A signed report
The methodology, the verdict distribution, and the findings. Written to be attached to a regulator filing, an insurance application or a vendor security review.
2. One signed receipt per claim
Each claim in the inventory gets its own receipt: Ed25519-signed, content-addressed with SHA-256, and re-verifiable in a browser using the same verifier on our public board. You do not need our software, our server or our permission to check one.
3. A summary attestation
A short signed statement proving the work was performed and giving the headline result, containing no technical detail. You can show this to a regulator, an underwriter or a prospect without circulating the full report.
This is the standard audit pattern for a report that holds too much confidential detail: demonstrate that the study was performed, and the main result, without distributing the technical material.
4. The negatives
Every candidate we tested and rejected, and why. A record that only shows the good rounds is not a record. This is usually the part a careful buyer reads first, because it is the part a dishonest vendor would not include.
These belong to you
Client receipts and reports are confidential and client-controlled, exactly as a SOC 2 report or a penetration-test report is. We publish nothing of theirs.
Our public board is a different thing and always was: our own research on public repositories, where no customer’s intellectual property is at stake. The distinction is not a compromise of the “we publish our receipts” position. It is that position, applied honestly.
What a receipt is not
A receipt is evidence of the verification performed. It is not a warranty that the system under test is correct, safe or free of defects, and a verification engagement is not legal, financial, insurance or regulatory advice.
A verdict is a falsification result, never a statement of truth. not_falsified means the claim survived the testing we performed. It does not mean the claim is true.
Ready to scope an engagement?
START WITH A PILOT