AI that shows its work.

Turn a GitHub issue into a CI‑green pull request — with proof (tests, diffs, and a replayable audit trail). Ship faster without guessing.

Beta: Issue → PR w/ proof (CI + supply‑chain checks)

Ship with confidence, not guesswork

Verified PRs, not vibes

Every change comes with proof: diffs, commands, and required test evidence in AI‑Strict mode.

Supply‑chain guardrails

Detect new dependencies, block typo‑squats (registry checks), and flag HIGH/CRITICAL OSV vulns before merge.

Secure by default

LLM is OFF by default. Control behavior with .vmp.yml profiles (observe / standard / ai_strict) and approval gates.

Autonomy is fine. Unverifiable autonomy is risk.

Verified Merge Pack

VMP Report
Verdict
Policy Verified
Not a security guarantee — policy checks only
Enforcement
Status: ENFORCED (required check)
Bypass detection: active
Evidence
CI checks passed (3/3)
Test evidence attached
SAST: CodeQL passed
Supply‑chain
New deps: 1 (lodash@4.17.21)
Registry check: exists
OSV scan: 0 HIGH/CRITICAL
Slopsquatting: age 2y, 45 versions
Governance
LLM mode: SAFE (no egress)
Profile: ai_strict
Ops
/saved incident
/reports export (CSV/JSON)
Large/binary file → Needs Approval
New dependency detection
Registry existence check (npm / PyPI)
OSV HIGH/CRITICAL vulnerability scan
Slopsquatting defense (age/history)
Branch protection enforcement check
Bypass detection + reporting
SAST evidence collection
AI‑Strict requires test evidence
LLM mode: SAFE / ASSISTED / HOSTED
Residual risk transparency
.vmp.yml profiles
Supply‑chain + slopsquatting Enforcement + bypass detection LLM SAFE by default

Public Progress

Next

Custom policy gates
Risk scoring + rollback

In Progress

Team approval workflows

Done

Supply‑chain + OSV scan
Slopsquatting defense
Enforcement status check
Bypass detection
SAST evidence collection
LLM mode transparency
Residual risk reporting

Founding access is limited

We're onboarding a small cohort to shape the defaults: verification, safety, and team workflow.

Priority onboarding
Founding pricing (locked in)
Direct input on verifiers + evals

Early access users get the first invites — ranked by join time and referrals.

Join the waitlist