How it works
CodeProof sits between code generation and repository acceptance. A change goes in as a base commit and a candidate commit. Out comes a sealed evidence bundle and a PASS, REVIEW_REQUIRED or BLOCK decision made by a versioned, deterministic policy.
CODE IS PROPOSED → AUTOMATION COLLECTS EVIDENCE → POLICY EVALUATES EVIDENCE → HUMANS AUTHORIZE EXCEPTIONS → AI MAY EXPLAIN (NEVER VERIFIES)
All data here is mock-up data. The DemoPay repository, its commits, the developers and approvers, and every credential found by the scanner are synthetic fixtures. Nothing touches a real codebase.
What happens to every change
- Intake
The request is validated strictly: no tenant, URL or command can be smuggled in the body. The repository must be registered to the caller's tenant, and an idempotency key means the same change is never verified twice.
- Materialize
Files are read straight from git objects. Path traversal, odd filenames, escaping symlinks and oversized files are refused and recorded.
- Diff
Which files changed, which are tests, dependency manifests, or security-sensitive (authentication, payments, secrets, CI).
- Build, tests and coverage in a sandbox
The code runs in a throwaway Linux sandbox with no network, a read-only system, an unprivileged user and hard limits on CPU, memory, processes and time. Results are only accepted with a per-run secret nonce.
- Baseline
The same run at the base commit, so CodeProof can see removed tests and coverage drops, not just failures.
- Static analysis
Rules over the code's syntax tree. A finding only counts as new if it wasn't already there at the base commit.
- Secrets
Added lines are scanned for credentials. Only a fingerprint and a 4-character preview are kept; the raw value is never stored.
- Dependencies
Every new package is checked against a controlled index without installing it, and every import in changed code must resolve. A package that doesn't exist (a "hallucinated" dependency) blocks.
- Policy
Rules compare the collected facts to fixed thresholds. BLOCK beats REVIEW beats PASS. AI metadata is refused as a policy input.
- Evidence
Everything is written as canonical JSON, hashed with SHA-256, signed with an HMAC attestation, encrypted at rest and stored append-only. Anyone with access can re-check the hash later.
- Humans
REVIEW_REQUIRED and most BLOCKs can get a human exception from an approver or security reviewer, never from the person who submitted the change. Leaked secrets can't be waived: you rotate them.
Run it live
Each scenario is a real commit in the synthetic DemoPay repository. Pick one: the page signs in as Ada (developer), submits it, and shows what the sandbox and policy produced. A change that was already verified is reused, not re-run.