Docs / Acceptance

The claim travels with its evidence.

An observed result, its exact commit and the conditions that produced it. Acceptance keeps those three connected.

01 / Recorded results

Three outcomes.
No hidden fourth.

30 September 2026 · Internal GitHub rehearsal · 0.1.0-beta.4 · Earlier SpecProof name.

PASS

7

Executed behaviors

FAIL

6

Executed behaviors

UNKNOWN

0

Executed behaviors

Tested commits match their corresponding PR heads. Each result links the verdict to its observed behavior and execution record.

Inspect the runs, commits and observations ↗

A measured sample. A bounded claim.

The broader internal rehearsal reports 26 expected-verdict runs with 26 matches. Nine seeded-violation runs produced zero observed false PASS results.

This small synthetic sample is not a production accuracy estimate, certification or competitor benchmark.

02 / Security observations

Inspect what
was actually tested.

These observations belong to the recorded release and workflow. They are not an independent audit or a claim of complete vulnerability absence.

01

Read-only workflow

The recorded permissions were Contents: read and Metadata: read.

02

Specified canary checked

Saved logs contained zero matches for the acceptance canary. This tests that canary, not every possible leak.

03

Cleanup recorded

Runtime cleanup completed in the recorded runs where Docker executed.

04

Rules protected

Rules came from the base commit, preserving the judging policy against changes in the tested PR.

03 / Release acceptance

The entire path
has to hold.

A screenshot or marketing statement cannot satisfy an engineering acceptance gate.

Gate 01

Execution profiles

Reproducible installation, valid and violated cases, unsupported-environment UNKNOWN, immutable judge inputs, state observations, failure injection and clean teardown.

Gate 02

Controlled Fix

Explicit consent, bounded budget, protected judge, held-out verification, customer checks and validation of the actual patch SHA.

Gate 03

The whole product

Account isolation and revocation, panel/commit/evidence consistency, installation and removal, rollback, monitoring and restore acceptance.

Outside this record.

This rehearsal does not establish acceptance across all five language and database tracks, organization-owned private-action sharing and required checks on every GitHub plan, Fix quality or repair costs, or production reliability on customer code.

Trust boundary / 3 October 2026

Evidence with context.
Never a blank guarantee.

Customer-CI inherits the trust of the customer's runner and workflow. A checksum is not an attestation signature. No SOC 2 or ISO certification is claimed.

Optional metadata, evidence sharing and model-provider requests have separate data paths. Local verification does not silently grant code access, and neither does a support subscription.

Security and data paths ↗Website privacy ↗Report a security issue ↗