Skip to content

An independent verdict on production readiness

Can you put your name on code you didn't write?

gitdiffy independently judges whether an AI-built application is ready to own, ship or inherit — beyond a security scan and signed by people who don't work for the build tool.

For the party inheriting the risk — and the builder who wants to provide evidence.

Assesses repositories built withread-only input · any stack
Lovablerepository sourceReplitrepository sourceCursorrepository sourceBoltrepository sourcev0repository sourceClaude Coderepository sourceWindsurfrepository sourceGitHub Copilotrepository sourceDevinrepository sourceBase44repository source

Two sides · one standard

Evidence at the moment risk changes hands.

For makers · not only developers

You do not need to read code to know whether your product is ready.

Turned a good idea into a working app with AI? Share the repository. gitdiffy translates its technical condition into a clear decision about production, ownership and what should happen next.

  1. 01You share the repository link
  2. 02We investigate and translate the risk
  3. 03You receive a clear ruling in plain language

Price & scope check

A fixed price starts with measurable scope.

Provide a public GitHub repository or connect a private repository read-only. We count only first-party assessable code and record the exact commit.

  • Full assessment across eight gates
  • Signed ruling and evidence
  • 60-minute report walkthrough

Read-only. We execute nothing and retain no source code after measurement.

Connect private GitHub repository

Private access uses a short-lived installation token; neither that token nor source code is stored.

LOC Lines of Code: first-party code lines we actually assess. Libraries, generated code, tests and documentation do not count toward price.

The gap

The demo works. That was never the question.

AI tools can ship something that runs and looks finished in an afternoon. They do not tell you whether the code can be maintained, defended or truly owned.

i.It runs
ii.Can you own it?
iii.Who signs off?

The assessment

Eight gates. From code to control.

Proven analysis engines provide depth. gitdiffy adds the judgment that determines whether an AI-built codebase can truly be inherited.

01Engine + review

Security

Injection, secrets, vulnerable dependencies and weak authorisation.

02Engine + review

Privacy

Personal data, production dumps and credentials in code or history.

03Engine

Quality

Complexity, duplication, dead code and the ability to change safely.

04Engine + review

Architecture

Coupling, layers, dependencies and room to build responsibly.

05gitdiffy original

Provenance

How much scaffold remained untouched and what was demonstrably understood?

06gitdiffy original

Substance

Does the application actually do what the README, demo and proposal claim?

07gitdiffy original

Governance

Ownership, security contact, change history and manageability.

08The ruling

Readiness

One weighted, defensible ruling with the shortest path to green.

Independence

The builder cannot be the only party vouching for what it made.

Every finding is traceable, the method is versioned and the ruling is fixed before remediation is offered.

Our verdict never depends on who fixes the findings.

How it works

From repository to ruling.

Not a dashboard of disconnected alerts, but a decision a non-technical owner can use.

01

Scope

Repository, commit and decision context set the bar and fixed price.

git · read-only · fixed commit
02

Assessment

Engines and human review normalise, deduplicate and weigh the evidence.

evidence · deterministic · traceable
03

Ruling

Ready, Conditionally Ready or Not Ready, with blockers and priorities.

signed · defensible · shareable
04

Fix & prove

Your team, the builder or Evergreen fixes; a separate assessor verifies.

separation of duties · same standard

When it matters

At the moment risk changes hands.

agency → client

Accepting a deliverable

Know what you are signing for before acceptance.

prototype → production

Promoting an AI build

Find which shortcuts will meet real users and real data.

seller → buyer

Technical due diligence

An independent view of the codebase behind the product.

Transparent scope

Small application, lower entry. Large codebase, appropriate depth.

Price follows the amount of assessable first-party code. Dependencies, build output, generated files and tests do not count toward price.

Up to 10,000 assessable LOCFrom
€1,950
Up to 25,000 assessable LOC
€2,750
Up to 50,000 assessable LOC
€3,950
Up to 100,000 assessable LOC
€5,950
Up to 200,000 assessable LOC
€8,950
More than 200,000 lines or multiple independent products: fixed quote.
Fixed quote

Includes a signed report and 60-minute walkthrough.

LOC Lines of Code: only first-party code lines we actually assess. Libraries, generated files, tests and documentation do not count toward price.

Want it fixed, not just diagnosed?

Close the blockers. With whoever you choose.

Evergreen can close the technical gaps, but the original ruling remains unchanged and an implementing engineer never signs off their own work.

Ask about full remediation ↗
  • Separate fixed-scope quote
  • Free choice of implementer
  • Re-assessment against the same standard
  • Re-assessment within 90 days at 30%

gitdiffy Certificate

A Ready ruling becomes publicly verifiable proof.

When the assessed commit passes the gitdiffy Standard, it receives a unique certificate and badge. Clients, buyers and stakeholders can verify with gitdiffy which repository and commit passed, under which methodology and whether the certificate is still valid.

gitdiffyby Evergreen ITgitdiffy Standard v1.0
ReadyGITDIFFY-2026-0001 · VERIFIED
  • Unique public certificate ID
  • Exact repository and commit SHA
  • Methodology version and issue date
  • Live status: valid, expired or revoked

Questions

Things people ask first.

Do you get access to our source code?+Show answer

Read-only and only for an explicitly selected repository. Private repositories use a GitHub App with Metadata and Contents read access only.

Is this the same as a penetration test?+Show answer

No. A pentest finds exploitable vulnerabilities. gitdiffy judges whether a codebase can responsibly be owned and operated; security is one of eight gates.

Do you execute our code?+Show answer

Not during price measurement. The repository is only counted and classified in a temporary isolated environment.

Can the building agency request an assessment?+Show answer

Yes. The standard and report are identical regardless of whether the builder or recipient orders it.

Can you fix the findings too?+Show answer

Yes, under a separate remediation engagement. The engineer who changes the code cannot sign the re-assessment alone.

Fixed scope · independent ruling

Tell us which decision you need to make.

We respond within one business day with scope, access steps and a fixed price.

No mailing list. Used only for this request.