← Home
Trust

Every claim has a receipt.

Marketing copy is cheap. We replaced ours with live counters, signed attestations, audit-log exports, and a public benchmark you can re-run yourself. Below: every place we let you check our work.

1 · Signed by Patchguard AI

Each AI repair carries a Proof-of-AI card: the exact tier used, the upstream request-id, the per-call latency, and the cost on your account. Copy the JSON, open a Patchguard support ticket — we can verify the request-id came from your call.

See an example repair →

2 · Live, not declared

Below is the real Forensic-tier call counter from the last five minutes — the same widget that lives on the home page. If our primary tier is unavailable, this badge turns amber rather than going dark. We don't get to hide degradations.

3 · We watch your supply chain too

Your AI supply chain — agent frameworks, MCP servers, model SDKs — ships CVEs like everyone else. Live count from NVD — when one shows up, we want our customers to be the first to know.

4 · Tamper-evident audit log

Every state change in your org — repo connected, SBOM generated, CVE detected, repair started, patch deployed — is appended to a hash-chained audit log. Export the entire chain in one click; hand it to your SOC2 auditor.

Download audit log (JSON) →Download audit log (CSV) →

Login required. Exports are scoped to your org by row-level security at the database layer.

5 · Public benchmark, reproduce locally

Our detection and repair numbers come from a 200-CVE seed corpus across 8 languages, run against Patchguard and competitors with the same harness. Every number is reproducible from this repository — no private API.

View benchmark + reproduce instructions →

6 · Compliance roadmap (in progress)

We are not yet SOC2 Type II certified — and we will not pretend otherwise. We have the controls in place (RLS, audit chain, encryption, sandboxed AI). Formal attestation is the next step. We will publish the report number here when issued.

Status: Type I scope locked, Type II window opens 2026-Q3.

7 · Self-attack feed — AI breaks, AI fixes

Every 30 minutes the scheduler points our own scanner at our own production lockfiles. If we regress, the same AI that runs your repairs opens a fix on us first. The timeline below is live — if it stops updating, we have broken something you can see.

Loading self-scan history…