Source-code trust infrastructure

AI-built software, backed by evidence.

V2P audits the source, guides remediation, and turns an eligible result into a scoped public signal people can verify.

Verify AI-written code before it reaches users.Protect users with a clear, scoped signal of what was assessed.Give leaders visibility into how technical and operator teams build with AI.Take vibe-coded apps further with structured review, remediation, and verification that reduces engineering-review friction.
V2P source audit seal
Assessed source snapshotNot runtime or deployment proof
Deterministic static checksAI specialist agents4 pillars · 20 weighted checksSnapshot-specific public status

One path from code to a public status.

Choose the source, inspect private evidence, make changes under your control, and publish only when the updated snapshot meets the required gates.

Submit source

Connect a GitHub repository and choose the source snapshot to assess.

Scan with two layers

Deterministic static checks and AI specialist agents analyze the relevant source.

Review evidence

See category scores, file-level findings, severity, evidence, and context.

Repair and re-audit

Use suggested patches and prompts, review each change, then run a fresh audit.

Publish the result

When eligible, issue a certificate and seal tied to the assessed snapshot.

Detailed findings stay private. Public verification is created only when a result is issued.

How the source is analyzed

Two analysis layers. One governed result.

Different tools answer different questions. V2P combines their evidence, then applies consistent scoring and eligibility rules.

01 · Non-AI

Deterministic static scanners

Programmatic checks look for known source patterns such as exposed secrets. Where relevant and available, specialist tools also inspect Python security patterns and dependency vulnerabilities.

02 · AI-assisted

Specialist AI agents

V2P's proprietary audit workflow routes relevant files to Security, Performance, UX & Reliability, and Code Quality specialists for contextual review.

03 · Governed

Fixed scoring and gates

Findings are normalized into the 100-point rubric. Deterministic score bands, coverage rules, pillar minimums, and critical-security gates decide the eligible public status.

See the program before you start

Three clear screens. One guided path.

V2P keeps the work concrete: choose the source, follow the audit, then act on evidence before you publish anything.

v2p.app / new audit
SourceConnect your repository
HChuman-co-pilot / productPrivate repository · main
Use this repository
01

Choose the source

Connect GitHub, select a repository, and confirm the branch or source snapshot to assess.

v2p.app / audit in progress
Audit progressApplying the 20-point rubric62%
Security5 checks completePerformanceAnalyzing sourceUX & ReliabilityQueuedCode QualityQueued
02

Follow the audit

See which pillar is running and track progress while the same weighted methodology is applied.

v2p.app / private report
86/100
Certified Site · Verified by V2PEvidence ready to review4 high-priority findings
Verify webhook signaturesSecurityAdd request timeoutsPerformance
Review findings
03

Repair, re-audit, then publish

Review private evidence, apply fixes under your control, run a fresh audit, and issue a result only when ready.

Illustrative product previews. Exact results and available actions depend on the submitted source and audit state.

4 pillars. 20 points. One repeatable standard.

The weighted rubric produces a score out of 100. Separate coverage, pillar, and critical-security gates determine whether a public status can be issued.

Security

5 rubric points · weight 35 of 100

Protect secrets, identities, access, inputs, and sensitive data.

  1. Secrets & API Key Managementweight 8
  2. Authentication & Session Managementweight 7
  3. Authorization & Access Controlweight 7
  4. Input Validation & Injection Preventionweight 7
  5. Data Exposure & Privacyweight 6

Pillar weight: 35 of 100

Performance

4 rubric points · weight 20 of 100

Find costly queries, slow interfaces, weak caching, and blocking APIs.

  1. Database & Query Performanceweight 5
  2. Frontend Performanceweight 5
  3. Caching & Data Fetchingweight 5
  4. API & Backend Performanceweight 5

Pillar weight: 20 of 100

UX & Reliability

5 rubric points · weight 22 of 100

Test the code paths that shape resilient, accessible user experiences.

  1. Error Handling & Resilienceweight 6
  2. User Experience & Accessibilityweight 5
  3. Form & Input Handlingweight 4
  4. Responsive Design & Mobileweight 4
  5. Loading & Empty Statesweight 3

Pillar weight: 22 of 100

Code Quality

6 rubric points · weight 23 of 100

Assess architecture, types, dependencies, tests, documentation, and AI-code patterns.

  1. Code Organization & Architectureweight 5
  2. Type Safety & Consistencyweight 4
  3. Dependency Managementweight 3
  4. Testing Coverageweight 3
  5. Documentation & Readabilityweight 3
  6. Vibe-Code Patternsweight 5

Pillar weight: 23 of 100

Read the full methodology
File-level findingHigh

app/api/webhooks/route.ts

Verify the provider signature before processing.

The handler accepts a request body before its authenticity is established.

const payload = await request.json();
await processEvent(payload);
AI-assisted repair guidance

Validate the signed raw payload first, reject invalid requests, and test the failure path.

Suggestions are not applied or verified automatically.

Evidence you can act on.

Each finding points to a file, explains the risk, and gives your team a concrete place to start.

File-level evidence Paths, severity, excerpts, and context.
Repair guidance Suggested patches, prompts, and next actions.
Fresh re-audit Assess the updated source with the same rubric.
See the platform
V2P verification seal

A result buyers can verify.

The certificate and seal point to a public record tied to the assessed source snapshot.

  • Score and public status
  • Declared audit scope
  • Issue date and audit version
  • Source fingerprint
What it proves

This source snapshot met the V2P source-audit standard at the stated revision and scope.

What it does not prove

Runtime behavior, infrastructure, deployment identity, ownership, or business outcomes.

View a sample result

Ready for an evidence-backed result?

Scan the source. Fix the risks. Publish a result buyers can verify.

Connect a repository and assess one source snapshot against the complete 100-weight V2P rubric.

4 risk pillars20 weighted checks100 total rubric weight
What does V2P actually assess?

V2P assesses the submitted source snapshot across Security, Performance, UX & Reliability, and Code Quality. It does not inspect a live deployment, cloud configuration, or runtime behavior.

How does V2P analyze the code?

V2P combines deterministic, non-AI static analysis with a proprietary audit workflow that routes relevant source to AI specialist agents across the four pillars. The resulting findings are normalized before fixed scoring rules and gates are applied.

What do the three score ranges mean?

Below 75 does not pass. Scores from 75 through 89.9 are Certified Site — Verified by V2P. Scores from 90 through 100 are Verified with Distinction by V2P. Coverage, pillar, and critical-security gates still apply.

Can a score of 75 or higher still fail a gate?

Yes. The overall score is only one requirement. Insufficient eligible-source coverage, a critical Security finding, or a required pillar minimum can prevent or limit a public status.

Are suggested fixes applied automatically?

No. V2P provides AI-assisted repair guidance, remediation prompts, and suggested patches. Your team reviews and applies changes, then runs a new audit to assess the updated source.

What becomes public?

Detailed findings remain private. An issued verification result can disclose the score, public status, scope, issue date, audit version, and source fingerprint.

Does V2P inspect my live application or cloud infrastructure?

No. V2P assesses the submitted source snapshot. It does not prove runtime behavior, cloud configuration, deployment identity, repository ownership, or business outcomes.

When should I re-audit?

Re-audit after material source changes or after your team applies remediation. A new audit assesses the updated snapshot; it does not silently carry the previous result forward.

Is V2P a penetration test or compliance attestation?

No. V2P is a source-code audit and verification program. It can complement other security and compliance work, but it does not replace runtime testing, penetration testing, or a legal compliance attestation.

V2P assesses submitted source code. It does not verify runtime, infrastructure, ownership, or deployment identity.

Vibe to Production Verified Site