Attestrun

Inspection of closed work

The author discloses no code. The recipient is handed verifiable facts with stated limits rather than our opinion. Between them stands the inspection: it runs over the author's private repository and issues a report on the state of the work.

Who it is for

The author of closed work

Show the state of the work without disclosing a line of code — to the recipient or to us. The inspection reads the repository and issues a report; source code cannot be reconstructed from it and never enters the delivery. File names, paths, the directory tree and code quotations are never published.

Whoever funds it

Read a figure and see at once what bounds it. The report is built so that it cannot be read as a promise: each value carries what it rests on and what it does not cover.

A machine

The report is a file with a declared schema, not a picture. A program reads it, with no human in the loop and without contacting us.

How it proceeds

The start is the author's own hand

The author places the call in their own repository and starts the inspection. There is no button on our side by construction: no one but the owner of a repository can grant access to it, and we are never granted it.

One run, one commit

The inspection reads the repository once, at one full commit, and does not return to it. The report speaks of a named state at a named moment, not of the work in general.

Handing it over is also the author's hand

The author collects the delivery and passes it to the recipient. We do not store the report, do not forward it, and do not stand between the parties.

What the recipient is handed

What follows is the composition of a real delivery, not an intention.

The first thing to read

The state of the signature. The report opens with it rather than with a headline figure: if the work is not attested by the platform, the report says so in its first line and advises treating it as unattested. An unattested delivery differs from an attested one both in a machine-readable field and in the artifact's own name — the two cannot be confused.

What is checked independently

The subject of the inspection, the product commit, the commit and version of the inspection itself, the direction of the work, the development score and the facts of the tree. Checking needs neither access to the author's repository nor any contact with us. The root of trust is taken from the platform directly, never from us: the point of an inspection is to trust no one, ourselves included.

What the delivery contains

Without a signature — four files: the report, the blind run log, the identity anchor of the run, and the canary verdict. With a signature — six: those four, the record of the attesting step, and the signature bundle itself.

What the inspection asserts, and what it does not

It asserts

That the named work exists in the named state at the named moment, and that this was measured rather than recounted. Whatever the run could not measure it lists by name — an empty list of unmeasured properties is an assertion, not a silence.

It does not assert

That the work is good. That it will be finished. That it is free of defects. That the author wrote it: the inspection attests the state of a thing, not its authorship. The volume figure estimates the labour of rebuilding at a fixed rate; it is not a valuation of a company, not a market price for code, and not the size of any cheque. Code quality, the merit of an idea, market need, a person's good faith and the likelihood of success are not measured at all.

Current state and how to take part

Attestrun is in closed alpha: the inspection works and passes live runs, but its own code is still closed while the thing is under development. While it is closed, submission goes through us rather than through a button: write to us and we will set up a run over your repository. Once the code is open, an author will call the inspection from their own repository with no involvement from us — that is the nearest goal of this work.

Two limits are better stated up front. The report has no permanent address today: a delivery lives for a limited time inside the author's run artifact, and the link dies before the report does. And the proof rests on the platform's good faith: if its attesting authority lies, the attestation is void — no inspection can repair that.