Skip to content

Product

Evidence

A signed record that a specific thing was fixed, that anybody can check.

The problem

Your customer’s security questionnaire asks whether you remediate vulnerabilities. You say yes. They have no reason to believe you, and you have nothing to show them.

How it works

  • Each proof names the finding, the change, the test, and the re-scan that confirmed it, with a signature over all four and the time it was made.
  • It verifies against a published key. The checker is public and needs nothing from us, so the proof outlives our relationship with you.
  • Proofs chain: each one carries the hash of the last, so a record cannot be quietly removed from the middle.
  • A share link is expiring, revocable, logged, and can carry a password. What it shows is redacted to what the reader needs.

What it does not do

A proof says one finding was fixed and re-checked. It is not a certification, it does not say your product is secure, and the document says so on its face.