Scope & Repository Boundary
The target services, test directories, exclusions, and verification invariants.
Verification architecture
From static AST assertion mapping to synthetic mutation injection and pre-merge CI gate integration. Every finding is mathematically and physically proven against real code.
Delivery method
Planning, AST analysis, mutation testing and pre-merge gating run in a deterministic loop. The steps below follow one change through the verification cycle.
Pramāṇa parses the repository AST to catalog every assertion matcher and locate unasserted domain error branches before any mutation runs.
Bounded synthetic mutations are generated across business logic: arithmetic operators inverted, booleans flipped, boundary checks dropped, and auth checks bypassed.
Native test suites execute in isolated sandboxes against mutated code. A green exit code (0) proves a surviving mutant, a real defect slipping past CI. Non-zero exit code proves test kill resistance.
Vacuous matchers (.toBeDefined(), .toBeTruthy()) are replaced with exact value assertions locking down payload schemas and error invariants.
A zero-dependency GitHub Action gate runs on every pull request, blocking PRs that introduce vacuous checks or drop assertion coverage.
Full audit trail, surviving mutant proofs, and AST coordinates are recorded in an auditable ledger that your team owns in perpetuity.
Verification controls
The target services, test directories, exclusions, and verification invariants.
Static assertion count, vacuous matcher ratio, unasserted error branches, and mutation kill rate.
Accredited ISO/IEC 27001:2022 and ISO 9001:2015 controls governing code handling and isolation.
Pre-merge gate action configuration, branch protection rules, and PR failure thresholds.
Static assertion ledger, error branch matrix, fault resistance proof, hardening git patch, and CI gate runbook.
Fixed £2,500 72-hour audit fee, £499/month CI gate, or milestone-billed institutional procurement contract.
Research and releases
We use published software-engineering research to shape how we test, review and deliver code. We also track official releases and advisories for technologies in scope.
The research page records each source's type, finding, practical implication and limitation.
See the research and release notesClient controls
You maintain complete repository ownership, PR review authority, merge decisions, and pipeline gate configuration.
Security & Isolation
All mutation runs execute in ephemeral sandboxes under ISO 27001 controls. Zero client code is stored in model weights.
Start verification
Request a 72-Hour Pramāṇa Audit for your repository, or inspect our founder technical provenance archive.