Back to home

Verification architecture

How deterministic test verification works.

From static AST assertion mapping to synthetic mutation injection and pre-merge CI gate integration. Every finding is mathematically and physically proven against real code.

Delivery method

The life of one verified change.

Planning, AST analysis, mutation testing and pre-merge gating run in a deterministic loop. The steps below follow one change through the verification cycle.

The delivery loopSpecacceptance criteriaAgentsized to the ceilingMachine gatesbuild · tests · propertiesReviewer of recorda second engineerMergesmall batchfailed gates return at machine speedafter the third attempt, an engineer takes overThe meterfirst-pass acceptance · retries per accepted change · delivery stabilityread weeklythe ceiling moves on evidence
  1. It starts as a spec and AST scan

    Pramāṇa parses the repository AST to catalog every assertion matcher and locate unasserted domain error branches before any mutation runs.

  2. Synthetic mutations are cut to size

    Bounded synthetic mutations are generated across business logic: arithmetic operators inverted, booleans flipped, boundary checks dropped, and auth checks bypassed.

  3. The machine proves fault resistance

    Native test suites execute in isolated sandboxes against mutated code. A green exit code (0) proves a surviving mutant, a real defect slipping past CI. Non-zero exit code proves test kill resistance.

  4. The assertion hardening patch is authored

    Vacuous matchers (.toBeDefined(), .toBeTruthy()) are replaced with exact value assertions locking down payload schemas and error invariants.

  5. Pre-merge CI gate enforces branch protection

    A zero-dependency GitHub Action gate runs on every pull request, blocking PRs that introduce vacuous checks or drop assertion coverage.

  6. The verification ledger is handed over

    Full audit trail, surviving mutant proofs, and AST coordinates are recorded in an auditable ledger that your team owns in perpetuity.

Verification controls

What the audit engagement defines.

Scope & Repository Boundary

The target services, test directories, exclusions, and verification invariants.

Verification Baseline

Static assertion count, vacuous matcher ratio, unasserted error branches, and mutation kill rate.

Quality Controls

Accredited ISO/IEC 27001:2022 and ISO 9001:2015 controls governing code handling and isolation.

Continuous CI Protection

Pre-merge gate action configuration, branch protection rules, and PR failure thresholds.

Handover Artefacts

Static assertion ledger, error branch matrix, fault resistance proof, hardening git patch, and CI gate runbook.

Commercial Terms

Fixed £2,500 72-hour audit fee, £499/month CI gate, or milestone-billed institutional procurement contract.

Research and releases

External evidence informs the method.

We use published software-engineering research to shape how we test, review and deliver code. We also track official releases and advisories for technologies in scope.

The research page records each source's type, finding, practical implication and limitation.

See the research and release notes

Client controls

Decisions you retain.

You maintain complete repository ownership, PR review authority, merge decisions, and pipeline gate configuration.

Security & Isolation

Isolated sandboxes.

All mutation runs execute in ephemeral sandboxes under ISO 27001 controls. Zero client code is stored in model weights.

Start verification

Get your test suite audited.

Request a 72-Hour Pramāṇa Audit for your repository, or inspect our founder technical provenance archive.