We assessed ourselves. Then published it.
Most security pages tell you what a company is good at. We publish the evidence behind ours. That includes source reviews against recognised standards and live hostile testing of a non-production deployment. Verdicts and limitations stay intact; sensitive test details do not become an attacker's checklist.
Live application security assessment
We authorized GPT-5.6 Sol to probe a non-production deployment through browser sessions, the REST API, and MCP/OAuth. Here is what it tested, how it tested it, what it did not test, and the result.
ISO/IEC 25010:2023
An AI agent graded our whole codebase against the ISO/IEC 25010 product-quality model: architecture, reliability, security, maintainability, and the rest. Here are the grades, the reasoning, and what happened when a verification pass threw out two of the three findings.
OWASP ASVS 5.0.0
An AI agent checked the app against the OWASP Application Security Verification Standard and the API Security Top 10, requirement by requirement. Per-chapter pass/fail, the API Top 10 verdicts, a broken-object-access probe on both ways in, and the gaps we still have open.
SOC 2 Trust Services Criteria
We don't pursue a SOC 2 report, so we had an AI agent run the gap analysis honestly: every Trust Services Criterion, what the code already does, and the governance work a real attestation would still need. The technical controls are strong; the paperwork is a deliberate gap.
Why we publish these
Transparency over polish
Most security pages list what a company is good at. We would rather show you the real verdicts, failures and limits included. If you are trusting us with your security findings, you deserve the honest version.
No security by obscurity
Hiding how a system works is not a security strategy we believe in. If our controls hold up, they hold up in the open. Publishing how we are built, and where we fall short, is the opposite of hoping nobody looks.
It keeps us honest
A gap with our name next to it in public is a gap that gets fixed. Putting the scores out there puts us on the hook to raise them, which is exactly the pressure we want.
It tells us what you care about
How people react to these reports shows us which controls and concerns matter most to the teams using the product. That tells us where to invest next, so the roadmap follows real concerns rather than guesses.
