Ship & Sleep / Verification

Acceptance your company can rely on — and check.

A report is an opinion until you can verify who issued it, what exactly it covered, and that nobody changed it afterwards. Ship & Sleep verification closes all three gaps with one mechanism: pinned scope, published fingerprints, and a public register.

The mechanism

Four parts, none of them magic.

01Public criteria

Every check runs against a versioned, published criteria catalog — backups and restorability, secrets and access, error handling, dependency state, monitoring, and the money paths. The catalog lives in the Handbook; the statement names the exact version used. No moving goalposts.

02Evidence, archived

Every finding is backed by evidence — logs, configurations, restore timings — collected into an archive the client keeps. The report doesn't ask to be believed; it asks to be checked.

03Version-pinned verdict

The verdict is bound to an exact code state — the commit hash — and a date. That's the honest boundary of any assessment: we certify what we examined, not what someone deploys next week. The pin is printed on the statement, so nobody can quietly stretch it.

04The public register

Every Verification Statement gets an ID and a SHA-256 fingerprint of the report document, published in our register. Anyone — a buyer, a bank, an investor — can look up the ID and confirm that the statement exists, what it covered, and that the document in their hands is bit-for-bit the one we issued.

The Verification Statement

One page. Everything checkable.

Sample verification statement document

The statement itself is deliberately short: statement ID, issue date, scope (commit hash and environment), criteria version, the report's SHA-256 fingerprint, and one of three verdicts.

Verified

No critical findings open against the criteria catalog at the pinned code state. The strongest sentence we issue — and we issue it sparingly.

Verified with reservations

The named findings are open, everything else holds. The reservations are listed on the statement itself, so the document can't be waved around as more than it is.

Not verified

Critical findings open. This verdict exists because a verification that can't fail is a sticker, not a statement.

Builders whose delivery earns a verdict may link it — a plain badge that points at the register entry, nothing more. The badge is only as good as the lookup behind it, which is the point.

What this is not

A Verification Statement is a point-in-time assessment of a pinned code state against published criteria. It is not an ISO or SOC 2 certification, not a penetration test, not insurance, and not a promise about code we haven't seen. Anything deployed after the pinned commit is outside its scope — which is exactly why the commit hash is printed on the document.

If you need those other things, we'll say so in the report and point you to the right kind of provider. Selling a $249 check as a security audit would be the kind of lie this whole mechanism exists to prevent.

Give your invoice a verdict, not a feeling.

Acceptance Check with Verification Statement — $249 flat, five business days, register-backed.

Request an Acceptance Check