Source-code trust infrastructure
AI-built software, backed by evidence.
V2P audits the source, guides remediation, and turns an eligible result into a scoped public signal people can verify.
One path from code to a public status.
Choose the source, inspect private evidence, make changes under your control, and publish only when the updated snapshot meets the required gates.
Submit source
Connect a GitHub repository and choose the source snapshot to assess.
Scan with two layers
Deterministic static checks and AI specialist agents analyze the relevant source.
Review evidence
See category scores, file-level findings, severity, evidence, and context.
Repair and re-audit
Use suggested patches and prompts, review each change, then run a fresh audit.
Publish the result
When eligible, issue a certificate and seal tied to the assessed snapshot.
Detailed findings stay private. Public verification is created only when a result is issued.
How the source is analyzed
Two analysis layers. One governed result.
Different tools answer different questions. V2P combines their evidence, then applies consistent scoring and eligibility rules.
Deterministic static scanners
Programmatic checks look for known source patterns such as exposed secrets. Where relevant and available, specialist tools also inspect Python security patterns and dependency vulnerabilities.
Specialist AI agents
V2P's proprietary audit workflow routes relevant files to Security, Performance, UX & Reliability, and Code Quality specialists for contextual review.
Fixed scoring and gates
Findings are normalized into the 100-point rubric. Deterministic score bands, coverage rules, pillar minimums, and critical-security gates decide the eligible public status.
See the program before you start
Three clear screens. One guided path.
V2P keeps the work concrete: choose the source, follow the audit, then act on evidence before you publish anything.
Choose the source
Connect GitHub, select a repository, and confirm the branch or source snapshot to assess.
Follow the audit
See which pillar is running and track progress while the same weighted methodology is applied.
Repair, re-audit, then publish
Review private evidence, apply fixes under your control, run a fresh audit, and issue a result only when ready.
Illustrative product previews. Exact results and available actions depend on the submitted source and audit state.
4 pillars. 20 points. One repeatable standard.
The weighted rubric produces a score out of 100. Separate coverage, pillar, and critical-security gates determine whether a public status can be issued.
Security
5 rubric points · weight 35 of 100
Security
5 rubric points · weight 35 of 100
Protect secrets, identities, access, inputs, and sensitive data.
- Secrets & API Key Managementweight 8
- Authentication & Session Managementweight 7
- Authorization & Access Controlweight 7
- Input Validation & Injection Preventionweight 7
- Data Exposure & Privacyweight 6
Pillar weight: 35 of 100
Performance
4 rubric points · weight 20 of 100
Performance
4 rubric points · weight 20 of 100
Find costly queries, slow interfaces, weak caching, and blocking APIs.
- Database & Query Performanceweight 5
- Frontend Performanceweight 5
- Caching & Data Fetchingweight 5
- API & Backend Performanceweight 5
Pillar weight: 20 of 100
UX & Reliability
5 rubric points · weight 22 of 100
UX & Reliability
5 rubric points · weight 22 of 100
Test the code paths that shape resilient, accessible user experiences.
- Error Handling & Resilienceweight 6
- User Experience & Accessibilityweight 5
- Form & Input Handlingweight 4
- Responsive Design & Mobileweight 4
- Loading & Empty Statesweight 3
Pillar weight: 22 of 100
Code Quality
6 rubric points · weight 23 of 100
Code Quality
6 rubric points · weight 23 of 100
Assess architecture, types, dependencies, tests, documentation, and AI-code patterns.
- Code Organization & Architectureweight 5
- Type Safety & Consistencyweight 4
- Dependency Managementweight 3
- Testing Coverageweight 3
- Documentation & Readabilityweight 3
- Vibe-Code Patternsweight 5
Pillar weight: 23 of 100
app/api/webhooks/route.ts
Verify the provider signature before processing.
The handler accepts a request body before its authenticity is established.
const payload = await request.json();
await processEvent(payload);Validate the signed raw payload first, reject invalid requests, and test the failure path.
Suggestions are not applied or verified automatically.
Evidence you can act on.
Each finding points to a file, explains the risk, and gives your team a concrete place to start.
A result buyers can verify.
The certificate and seal point to a public record tied to the assessed source snapshot.
- Score and public status
- Declared audit scope
- Issue date and audit version
- Source fingerprint
This source snapshot met the V2P source-audit standard at the stated revision and scope.
Runtime behavior, infrastructure, deployment identity, ownership, or business outcomes.
Ready for an evidence-backed result?
Scan the source. Fix the risks. Publish a result buyers can verify.
Connect a repository and assess one source snapshot against the complete 100-weight V2P rubric.
What does V2P actually assess?
V2P assesses the submitted source snapshot across Security, Performance, UX & Reliability, and Code Quality. It does not inspect a live deployment, cloud configuration, or runtime behavior.
How does V2P analyze the code?
V2P combines deterministic, non-AI static analysis with a proprietary audit workflow that routes relevant source to AI specialist agents across the four pillars. The resulting findings are normalized before fixed scoring rules and gates are applied.
What do the three score ranges mean?
Below 75 does not pass. Scores from 75 through 89.9 are Certified Site — Verified by V2P. Scores from 90 through 100 are Verified with Distinction by V2P. Coverage, pillar, and critical-security gates still apply.
Can a score of 75 or higher still fail a gate?
Yes. The overall score is only one requirement. Insufficient eligible-source coverage, a critical Security finding, or a required pillar minimum can prevent or limit a public status.
Are suggested fixes applied automatically?
No. V2P provides AI-assisted repair guidance, remediation prompts, and suggested patches. Your team reviews and applies changes, then runs a new audit to assess the updated source.
What becomes public?
Detailed findings remain private. An issued verification result can disclose the score, public status, scope, issue date, audit version, and source fingerprint.
Does V2P inspect my live application or cloud infrastructure?
No. V2P assesses the submitted source snapshot. It does not prove runtime behavior, cloud configuration, deployment identity, repository ownership, or business outcomes.
When should I re-audit?
Re-audit after material source changes or after your team applies remediation. A new audit assesses the updated snapshot; it does not silently carry the previous result forward.
Is V2P a penetration test or compliance attestation?
No. V2P is a source-code audit and verification program. It can complement other security and compliance work, but it does not replace runtime testing, penetration testing, or a legal compliance attestation.
V2P assesses submitted source code. It does not verify runtime, infrastructure, ownership, or deployment identity.

