PASS
7Executed behaviors
Docs / Acceptance
An observed result, its exact commit and the conditions that produced it. Acceptance keeps those three connected.
01 / Recorded results
30 September 2026 · Internal GitHub rehearsal · 0.1.0-beta.4 · Earlier SpecProof name.
Executed behaviors
Executed behaviors
Executed behaviors
Tested commits match their corresponding PR heads. Each result links the verdict to its observed behavior and execution record.
Inspect the runs, commits and observations ↗The broader internal rehearsal reports 26 expected-verdict runs with 26 matches. Nine seeded-violation runs produced zero observed false PASS results.
This small synthetic sample is not a production accuracy estimate, certification or competitor benchmark.
02 / Security observations
These observations belong to the recorded release and workflow. They are not an independent audit or a claim of complete vulnerability absence.
01
The recorded permissions were Contents: read and Metadata: read.
02
Saved logs contained zero matches for the acceptance canary. This tests that canary, not every possible leak.
03
Runtime cleanup completed in the recorded runs where Docker executed.
04
Rules came from the base commit, preserving the judging policy against changes in the tested PR.
03 / Release acceptance
A screenshot or marketing statement cannot satisfy an engineering acceptance gate.
Gate 01
Reproducible installation, valid and violated cases, unsupported-environment UNKNOWN, immutable judge inputs, state observations, failure injection and clean teardown.
Gate 02
Explicit consent, bounded budget, protected judge, held-out verification, customer checks and validation of the actual patch SHA.
Gate 03
Account isolation and revocation, panel/commit/evidence consistency, installation and removal, rollback, monitoring and restore acceptance.
This rehearsal does not establish acceptance across all five language and database tracks, organization-owned private-action sharing and required checks on every GitHub plan, Fix quality or repair costs, or production reliability on customer code.
Trust boundary / 3 October 2026
Customer-CI inherits the trust of the customer's runner and workflow. A checksum is not an attestation signature. No SOC 2 or ISO certification is claimed.
Optional metadata, evidence sharing and model-provider requests have separate data paths. Local verification does not silently grant code access, and neither does a support subscription.
Security and data paths ↗Website privacy ↗Report a security issue ↗