FINIPE

Fini Proof™ · proof-based code verification

Green CI is a promise.
Fini Proof is the evidence.

Developers and AI coding agents now write code faster than anyone can review it. Fini Proof checks every change in your own CI and gives one verdict: PASS, FAIL or NOT_MEASURED. Every finding comes with a command that reproduces it, and every check must catch a planted bug before it may judge your code.

Configured trial: 7 days, 7 proof commands, 1 repository. The CLI starts its trial on the first proof command; account creation does not reset it.

Already using Fini Proof? Sign in to your Developer workspace
Example: Fini Proof on a pull request
$ npx fini-proof check --base origin/main  engines  hollow-tests secrets fail-open skip-ratchet tenant-filter migrations   HIGH  src/orders/order.service.ts:42  TENANT_FILTER_MISSING        proof: fini-proof prove --engine tenant-filter --file src/orders/order.service.ts --line 42  HIGH  test/refund.spec.ts:18  hollow-tests/NO_ASSERTION VERDICT: FAIL  (exit 1) · evidence .fini-proof/runs/<run id>.json$ git commit -am "scope order lookup by tenant, assert refund"$ npx fini-proof check --base origin/mainVERDICT: PASS  (exit 0)
  • Runs in your CI — your source never leaves
  • Every finding comes with a proof command
  • Every check must catch a planted bug first
  • Your code never trains a model

The problem

Code is now written faster than it can be checked.

A reviewer reads the diff and trusts the green tick. The expensive bugs sit where the tick is wrong.

01

Tests that cannot fail

An agent asked to “add tests” often writes tests with no real assertion. Coverage goes up, CI goes green, and nothing is protected.

02

One customer sees another’s data

In multi-tenant software, one query without a tenant filter is a data leak. In the diff it looks like any other line.

03

A green pipeline that checked nothing

A step with “|| true”, a skipped suite, a “.only” left in by mistake: the pipeline reports success because nothing was checked.

How it works

Other tools comment. Fini Proof proves.

A check that has never been seen to fail is not evidence. So before a check reads your code, it has to catch a defect we planted.

  1. 1

    Prove the check can fail

    Each engine first runs on planted defects (negative controls) and clean look-alikes (positive controls). If it misses one, the result is NOT_MEASURED — never a pass.

  2. 2

    Check the change

    On a pull request only the changed files are judged, so old debt does not block new work. Existing skipped tests and applied migrations are recorded once as a baseline.

  3. 3

    Hand over the proof

    Each finding names the file, line and rule, with a fix and a prove command that reproduces it. Every run writes an evidence file with a hash of every input, and SARIF for code scanning.

PASS

Every check ran, every control behaved, and nothing blocking remains.

FAIL

At least one blocking finding, each with its file, line and proof command.

NOT_MEASURED

Something could not be checked — an unreadable file, a missing base branch, a check that missed its planted bug. “Could not check” is never turned into a pass.

Six built-in checks

The defects that get past review.

Deterministic engines, not a language model’s opinion: the same input gives the same verdict, and every result can be reproduced offline.

hollow-tests

Tests that test nothing

Tests with no assertion or only constant ones, swallowed errors and un-awaited promises — in Jest, Vitest, Mocha, node:test, pytest and unittest.

tenant-filter

Cross-tenant data access

A query on a multi-tenant table with no tenant condition. It reads your schema to find which tables hold tenant data — raw SQL, TypeORM, Prisma, Knex, Django, SQLAlchemy and more.

migrations

Dangerous migrations

Dropped tables and columns, type rewrites, NOT NULL without a default, and migrations with no way back — plain SQL, Flyway, Prisma, TypeORM, Knex, Alembic, Django and more.

fail-open

CI that passes by accident

Steps and scripts that report success when they failed: “|| true”, “set +e”, continue-on-error, an empty catch, “except: pass”.

secrets

Committed secrets

Cloud keys, private keys, API tokens and real values in .env files. If gitleaks is installed, Fini Proof runs it and holds it to the same planted-defect test.

skip-ratchet

Quietly skipped tests

A focused “.only” is always caught. Existing skips are recorded once; after that the count can only go down unless someone writes down why.

Guardrails for AI coding agents

The agent that wrote the code does not decide when it is done.

Coding agents are fast — and happy to report “all tests pass” about tests that assert nothing. Fini Proof sits between the agent and “done”.

Claude Code hooks

A Stop hook keeps the agent from finishing while the verdict is FAIL and hands it the findings. A PostToolUse hook checks each file as it is written.

MCP server

“fini-proof mcp” gives any MCP client three tools — check, explain_finding and list_rules — on the same licensed path and evidence as the CLI.

Codex and any agent

An AGENTS.md section plus a CI gate. The gate also fails a pull request that changes the checker’s own config or baseline without human approval.

Who made it, who verified it

Every evidence file records who made the change — a person or an agent — and which verifier checked it. A verifier cannot attest its own change.

You can tell an agent to make CI green. It cannot switch off the check that decides.

Works where you already work

One command in the pipeline you already have.

  • CLI (Node.js 20+)
  • GitHub Actions
  • GitLab CI
  • Jenkins
  • Bitbucket Pipelines
  • Daily run of the default branch
  • SARIF · JSON
  • MCP server
  • Claude Code
  • OpenAI Codex
  • GitHub App · check runsEarly access
  • IDE extensionPlanned
Example CI step (GitHub Actions)
- uses: actions/checkout@v4
  with: { fetch-depth: 0 }
- run: npx --yes fini-proof check --base origin/${{ github.base_ref }} --sarif-out fini-proof.sarif
  env: { FINI_PROOF_LICENCE: ${{ secrets.FINI_PROOF_LICENCE }} }

Security and your data

Your code stays where it is.

  • Runs in your CI. The engines are deterministic and need no model call, so your source code is never uploaded.

  • Evidence, not code. Sending results to your Developer workspace is optional and sends the evidence file — hashes, rules and verdicts. An edited evidence file is refused.

  • Offline licence. An Ed25519-signed licence is checked on your machine with no network call, so it works on air-gapped runners too.

  • No lock-in. Results come out as JSON and SARIF, so you keep them if you ever leave.

  • Never trains on your code. Customer code is never used to train or fine-tune any model.

Plain status, no inflated claims

  • Ready

    CLI, six checks, proof state, SARIF and JSON, CI templates, MCP server, Claude Code and Codex integration.

  • Early access

    GitHub App with check runs and annotations. Results uploaded to your Developer workspace show as self-reported until the hosted verifier ships.

  • Planned

    IDE extension. SOC 2 and ISO 27001: not certified today, and we do not claim to be.

Who it is for

Built for the people who sign off on software.

CTO / VP Engineering

Adopt AI coding without the blind spot

Let agents write more of the code while a check you control decides what counts as done.

Head of QA and release

Stop trusting coverage numbers

Find the tests that pass whatever the code does, and stop skipped tests piling up without anyone deciding.

CISO and compliance

Change evidence you can re-check

Each run records engine versions, input hashes, the verdict and who made the change — exported as JSON and SARIF.

IT services delivery head

Hand over code you can defend

Attach proof of verification to every client delivery, so acceptance is about evidence, not opinion.

Get started

Run it on your worst repository.

Create a workspace account to keep evidence, or start locally with the CLI guide.

Free trial

Configured trial: 7 days, 7 proof commands, 1 repository. Consult the CLI guide for the installed version’s enforced limits.

Create a workspace account

Plans and pricing

$20 for 1 developer(s) per month, prepaid before applicable tax

See plans and pricing

Already have an account? Sign in

FAQ

Questions teams ask first.

See what your green CI has been hiding.

Explore the trial guide and current prepaid plans on the developer page.

Create a workspace account Go to Developers