Pre-Certification Readiness
A practical checklist for the work to complete before you submit a product for review.
- Confirm the app runs from a clean checkout
- Document required environment variables
- Remove unused demo routes and secrets
Publish a verifiable result tied to the source snapshot, scope, rubric, date, and fingerprint that V2P assessed.
V2P Certification records that a submitted source snapshot met the V2P source-audit standard at the stated revision and scope.
The audit applies 20 weighted rubric points across Security, Performance, UX & Reliability, and Code Quality, with coverage, pillar, and critical-security gates.
It is a source-code assessment. It does not prove runtime behavior, infrastructure configuration, deployment identity, repository ownership, or business outcomes.
Below 75
No V2P verification status is issued.
75–89.9
The assessed site is Verified by V2P.
90–100
The assessed site is Verified with Distinction by V2P.
All passing statuses remain subject to source coverage, pillar minimums, and critical-security gates.
Connect your GitHub repository and choose the source snapshot. V2P combines deterministic static scanners with a proprietary AI-agent audit workflow.
Four domain specialists apply the 20-point rubric to the relevant files in the submitted source snapshot.
Receive category scores, file-level findings, evidence, recommendations, and AI-assisted repair guidance.
When the score, pillar minimums, security gates, and source coverage qualify, issue a certificate for that source snapshot.
Embed the V2P seal so visitors can open the public record and inspect its score, public status, scope, date, audit version, and fingerprint.
Certification Guides
Use these guides to understand what evidence to prepare, how to work through findings, and how to keep certification current as the product changes.
A practical checklist for the work to complete before you submit a product for review.
What reviewers look for when validating authentication, authorization, and data protection.
How to prepare a codebase so architecture decisions are easy to inspect and verify.
How to read the findings, prioritize fixes, and turn the report into an execution plan.
Guidance for presenting certification status to customers, partners, and investors.
When to re-audit and how to keep certification aligned with active development.
Concrete file-level evidence and repair guidance for improving the assessed source.
A public result with explicit scope and a fingerprint tied to the source snapshot that was assessed.
A consistent vocabulary for discussing source-code risk without converting an audit into a runtime guarantee.
We offer flexible options depending on your certification journey:
Complete audit with detailed findings and actionable recommendations.
Continuous verification with monthly recertification and live trust seal.
Begin your certification journey. Start with a detailed report or go straight to ongoing verification.
Begin Certification