Continuous Correctness Audit

Install Proof on one consequential component.

Find the bugs your tests missed. In about four weeks, you get approved requirements, confirmed findings with reproducers, agent-ready fix context, and a gate in your CI that keeps checking every change.

Explore a live graph → seeded product demo; read the labels first

01 · The shape

One component. Fixed fee. About four weeks.

A Continuous Correctness Audit is a standing engagement against a written bar. We formalize the requirements for one component you choose with us, your engineers approve them, and we prove and test the code against every approved clause.

Scope

one component

Install

roughly four weeks

Price

fixed after scoping

Decision owner

about two hours in week one

Engineering team

about two hours a week while we install

The fee is quoted at scoping and fixed before work starts, and it covers re-verification of the fixes you land during the install. Everything the install produces is yours, whether or not you continue.

The claim is bounded on purpose: within a declared scope, for declared behaviors, with evidence commensurate with the consequence of failure. A person validates every finding before you see it, so we take a small number of engagements at a time.

The audit is how Proof gets installed. Proof is what stays. The graph, the records and the gate keep running whether or not the engagement continues. The install is the component-level way to begin. The other two ways, one real change or ten unresolved items from one component, start from a demo request. What Proof is, in full, is on the product page.

02 · Approval

Your engineers approve the promises.

Nothing is judged against a requirement your engineers have not approved. We draft, the owners of the component approve, and only then can a clause fail a build. The drafting is ours, which is why approval costs the decision owner about two hours in week one.

  1. Week 0

    Scope one component, countersign the NDA

    We agree the shape and the fee before work starts. We countersign your NDA before reading a line.

  2. Week 1

    Requirements the owners approve

    We index the code first, then its history and the places intent lives: the tracker, the support queue, the docs nobody updated. Your engineers approve every requirement before any code is judged.

  3. Weeks 2–3

    Worst cases, obligations, evidence, first findings

    Approved requirements become formal properties. We check the specification itself for realizability, consistency and vacuity, so a bad clause cannot condemn good code. Where code and approved requirements disagree, we write it up.

  4. From week 4

    The gate goes live

    The evidence corpus lands in your repository and the gate wires into your CI: a broken requirement blocks the merge. We walk your team through every finding and every proof. That is the end of the install, not of the audit.