for those who need to trust · vendor due diligence · data room
Security proof your customer checks on their own.
Today AI finds and fixes flaws. What customers, auditors and vendor-risk committees still need is to know the fix was real, not a silenced alert. The counter-signed declaration brings together the analysis result and the evidence from each tool, and codafort signs it with a key no AI agent holds.
how it works
Whoever declares pays; whoever verifies does not.
| Step | Who | What |
|---|---|---|
| 1 · measure | vendor | Each codafort tool records what it checked and what it could not check. |
| 2 · declare | vendor | The vendor assembles the result against a security standard, such as OWASP ASVS, and the verdict follows a public rule. |
| 3 · counter-sign | codafort | codafort counter-signs. In environments without internet access, signing happens locally, with a key delegated by codafort. |
| 4 · deliver | vendor | A package for the data room, with the declaration, the compliance map and verification instructions, or a format that automated policy tools read. |
| 5 · verify | buyer | Free and offline, at /verify or from the command line, with no license and no need to trust whoever produced it. |
It follows the logic of a SOC 2 report, renewed with every software release, in minutes. Counter-signing is part of a paid plan; verifying is always free.
what the buyer sees
The questions auditors ask, answered in the declaration itself.
Which code was analyzed and at which version. With which rules. What result came out, by severity. Against which standard, and what the verdict was. What the tools that run against the live app confirmed and what they did not measure. Who issued it and when.
New evidence on the same analysis does not edit the previous declaration: it produces a new one that supersedes it. And evidence only tightens the verdict: if the running app confirms a flaw, the declaration fails.
proves × does not prove
Proves
Who made the declaration and that it has not changed: the license holder declared that this result, at this version of the code, with these rules and this evidence, reached this verdict, and codafort counter-signed it. Once issued, nobody can alter it without invalidating the signature.
Does not prove
That the declared result is true, because codafort does not redo the analysis. That there are no vulnerabilities. It does not replace an independent pentest (Brazilian CMN Res. 5.274, Art. 22-A) or a security program: it is complementary evidence for vendor assessment. What the tools did not measure shows up as "not measured".
Regulatory map (Brazilian CMN 4.893/5.274, ANBIMA) at /compliance.