Non-AI
Deterministic static scanners
Built-in pattern checks look for exposed secrets. Where relevant and available, specialist scanners also inspect Python security patterns and dependency vulnerabilities.
Implemented source-audit standard
V2P combines deterministic static scanners with a proprietary audit workflow powered by AI specialist agents. Findings are mapped to a fixed 100-point rubric, then coverage, pillar, and critical-security gates determine the eligible public status.
The audit does not ask one model for a single opinion. It combines programmatic checks, contextual AI review, and governed scoring.
Non-AI
Built-in pattern checks look for exposed secrets. Where relevant and available, specialist scanners also inspect Python security patterns and dependency vulnerabilities.
AI-assisted
Relevant files are routed to Security, Performance, UX & Reliability, and Code Quality specialists for contextual source review.
Governed
V2P normalizes the findings, applies the 20 weighted categories, and evaluates the result against explicit status and eligibility rules.
Each point has a weight and a defined scope. The 20 weighted scores roll into one overall score out of 100.
Secrets, authentication, authorization, injection risk, and sensitive-data exposure.
Hardcoded API keys, tokens, passwords, or secrets in source code. Whether .env files are gitignored. Secrets that leak into the client bundle.
Password hashing, session expiry, token rotation, CSRF protection, secure cookie flags, logout invalidation.
Users can only access their own data. RLS policies, middleware guards, role-based access, and protected admin routes.
SQL injection, XSS, command injection. Validation and sanitisation of user input. Parameterised queries.
Sensitive data (PII, passwords, tokens) leaking through logs, error messages, or API responses. HTTPS enforcement.
Queries, interface performance, caching, data fetching, APIs, and blocking operations.
N+1 queries, missing indexes, unoptimised queries, missing pagination, large unbounded selects, connection pool configuration.
Large bundle sizes, missing code splitting, unnecessary re-renders, missing image optimisation, unoptimised fonts, lazy-loading.
Appropriate caching, proper use of SSR/SSG/ISR, efficient data fetching, avoidance of request waterfalls.
Slow endpoints, missing rate limiting, inefficient algorithms, blocking operations in async code, missing timeouts on external calls.
Errors, accessibility, forms, mobile behavior, loading states, and empty states.
Unhandled promise rejections, missing try/catch, generic error messages, missing error boundaries, crash-prone edge cases.
Missing alt text, no ARIA labels, poor keyboard navigation, missing focus management, insufficient colour contrast, lack of semantic HTML.
Form validation (client + server), loading states during submission, error display, disabled states, double-submission protection.
Layouts work on mobile, touch targets sized correctly, no horizontal overflow, critical features accessible on small screens.
Skeleton loaders or spinners during fetches, meaningful empty states with CTAs, handling of slow-network conditions.
Architecture, types, dependencies, tests, documentation, and AI-generated anti-patterns.
Separation of concerns, proper component decomposition, consistent file structure, avoidance of god files/components.
Loose `any` types, missing type annotations on function boundaries, inconsistent naming conventions, unused variables/imports.
Up-to-date dependencies, no known vulnerabilities, no unused packages, appropriate use of peer dependencies.
Presence of tests (unit, integration, e2e), test quality, coverage of critical paths, proper mocking practices.
Useful README, complex logic has comments, API endpoints are documented, code is self-documenting.
AI-generated anti-patterns: boilerplate bloat, leftover template code, TODO/placeholder code, inconsistent multi-session patterns, over-engineered abstractions, and missing error handling.
Findings reduce a category score according to severity and confidence. Category scores are weighted, summed, and converted to a 0-100 overall score. Pillar scores are the average of their category scores.
Submitted source files, deterministic category scoring, file-level findings, remediation guidance, re-audits, certificates, public verification pages, and embeddable seals.
Runtime behavior, load testing, penetration testing, infrastructure configuration, deployment identity, repository ownership, compliance attestation, or business outcomes.
Connect a repository, choose the snapshot, and begin with the same 4-pillar, 20-point rubric.
Start an audit