Archived version. Claims, numbers, and forms may be outdated. Open the current site.
PROOF · REQPROOF.COM
CH1 · CONTINUOUS CORRECTNESS AUDIT · STANDING INSTRUMENT

Confidence is a steady reading.

Proof is a standing audit of the promises your software makes. It re-runs on every change. When a promise breaks, you know first — as a signed finding with a reproducer, not a production surprise. The flat line is the product.

PROOF · CONTINUOUS CORRECTNESS AUDIT MODEL CCA-1 · SER. NO. 000123
CH1 · PROMISES HELD
● TRACKING
SWEEP 0.5 s/DIV · re-runs on every change
GAIN
SWEEP
TRIG
AUDIT ON
STANDING
CLASSES CLOSED · THIS SESSION
Live rendering of the audit loop: steady trace → finding → class closed → steady again. Findings shown are from the public jsonparser engagement register.
01

The reading: every promise, on one register

An audit you can't inspect is an opinion. Proof keeps a public register of every requirement it watches and every finding it raises — nothing summarized away, nothing quietly dropped. Each row carries its own evidence.

REGISTER · EXCERPT · JSONPARSER ENGAGEMENT STATUS AS AUDITED
IDClassSeverityStatusEvidenceSigned
F-001 panic on malformed input · 8 call sites HIGH CLOSED · SAME DAY reproducer + regression pin named auditor
F-004 Set() silent data loss HIGH CLOSED · FAMILY SWEPT reproducer + public postmortem named auditor
F-REP contract drift (representative example) MED CLOSED spec diff + pinned test named auditor
Rows F-001 and F-004 are real findings from the jsonparser engagement; the contract-drift row is a representative example of the class and is labeled as such on the live register. No entry ships without a reproducer, a status, and a named signature.

Severity

Every finding is graded, in the open. No burying a high behind a summary paragraph.

Status

Open, closed, or waived — with the who and the when. The register never forgets a row.

Evidence

A reproducer, a spec diff, a pinned test. Every claim on the register is re-runnable, not asserted.

Signature

A named person stands behind each verdict. Confidence you can attribute is confidence you can question.

02

A spike isn't a bug fixed. It's a class closed forever.

When the trace spikes, Proof doesn't patch the one site and move on. It formalizes the broken promise, sweeps the whole family, and pins a regression so the class cannot come back. From the jsonparser engagement:

123
Requirements approved
The library's actual promises, extracted from code and docs, formalized, and signed off one by one.
7
Findings raised
Each with severity, reproducer, and status on the public register. Not one summarized away.
8 → 0
Panic sites, closed same day
One panic class, found at 8 call sites. Fixed as a class, pinned as a class — same day.
Full disclosure · F-004

The one that got past us — and what a standing audit does about it

A silent data-loss defect in Set() escaped the initial audit — with 100% MC/DC coverage on the function. A downstream user caught it. We published the postmortem publicly, formalized the missing promise as a requirement, swept the entire defect family, and pinned it.

Coverage told a comfortable story; the register tells the true one. That class is now closed — permanently, with evidence. This is the difference between an audit that happened and an audit that's still running.
03

The corpus compounds, quarter by quarter

A one-time review depreciates the moment it's delivered. A standing audit appreciates: every approved requirement, every closed class, every pinned regression stays in the corpus and is re-verified on every change. The instrument never starts from zero.

Q1Q2Q3Q4
Verified corpus (illustrative) Finding raised ✓ class closed, stays closed

Nothing re-litigated

Approved requirements stay approved until deliberately retired. The audit spends its effort on what changed, not on re-proving last quarter.

Closed stays closed

Every closed class carries a pinned regression. A recurrence isn't a new bug — it's an alarm on a known promise, caught before merge.

Drift is a signal

When code moves away from its spec, the trace shows it as drift — visible on the register, not discovered in an incident review.

04

Agents and humans, held to one bar

Most teams now ship code written partly by AI — and most teams don't trust it. The industry's answer has been vibes: review harder, hope more. Proof's answer is an instrument: the same register, the same evidence bar, whether the diff came from a person or an agent.

Every requirement ships with agent-ready prompts, so your coding agents work inside the contract instead of around it. Every verdict carries a named human signature, so accountability never dissolves into "the model said so."

You don't have to trust the author. You trust the reading.

Trust gap · industry readings
Developers who distrust AI output accuracy46%
vs 33% who trust it — Stack Overflow Developer Survey
Teams using AI in the delivery loop90%
while roughly 30% trust its output — DORA research
What closes the gapevidence
a re-runnable register, not a reassurance
05

Put one component on the instrument

The engagement is deliberately small and sharp: one component, fixed fee, about four weeks to a signed register — then the audit keeps running as your code keeps changing.

T+0

Scope one component

Pick the code whose failures cost you sleep — a parser, a billing path, a sync engine. Fixed fee, agreed up front.

W1–2

Extract & approve the promises

We formalize what the component actually guarantees. You approve each requirement — nothing enters the corpus unsigned.

W3–4

Verify, find, close

Findings land on the register with severity, reproducer, and status. Classes get closed and pinned, not patched.

∞

Then it stands

The audit re-runs on every change. The steady reading — and the first word when it spikes — is what you're buying.

LOG ENTRY · SCOPING REQUEST — — —
Email is enough to start. We reply with scope and a fixed quote — no call required.
CCA-1 · SCOPING CHANNEL NO RETAINER UNTIL SCOPE IS SIGNED