Security
Injection, secrets, vulnerable dependencies and weak authorisation.
An independent verdict on production readiness
gitdiffy independently judges whether an AI-built application is ready to own, ship or inherit — beyond a security scan and signed by people who don't work for the build tool.
For the party inheriting the risk — and the builder who wants to provide evidence.
Two sides · one standard
For makers · not only developers
Turned a good idea into a working app with AI? Share the repository. gitdiffy translates its technical condition into a clear decision about production, ownership and what should happen next.
Price & scope check
Provide a public GitHub repository or connect a private repository read-only. We count only first-party assessable code and record the exact commit.
Private access uses a short-lived installation token; neither that token nor source code is stored.
LOC — Lines of Code: first-party code lines we actually assess. Libraries, generated code, tests and documentation do not count toward price.
The gap
AI tools can ship something that runs and looks finished in an afternoon. They do not tell you whether the code can be maintained, defended or truly owned.
The assessment
Proven analysis engines provide depth. gitdiffy adds the judgment that determines whether an AI-built codebase can truly be inherited.
Injection, secrets, vulnerable dependencies and weak authorisation.
Personal data, production dumps and credentials in code or history.
Complexity, duplication, dead code and the ability to change safely.
Coupling, layers, dependencies and room to build responsibly.
How much scaffold remained untouched and what was demonstrably understood?
Does the application actually do what the README, demo and proposal claim?
Ownership, security contact, change history and manageability.
One weighted, defensible ruling with the shortest path to green.
Independence
Every finding is traceable, the method is versioned and the ruling is fixed before remediation is offered.
“Our verdict never depends on who fixes the findings.”
How it works
Not a dashboard of disconnected alerts, but a decision a non-technical owner can use.
Repository, commit and decision context set the bar and fixed price.
git · read-only · fixed commitEngines and human review normalise, deduplicate and weigh the evidence.
evidence · deterministic · traceableReady, Conditionally Ready or Not Ready, with blockers and priorities.
signed · defensible · shareableYour team, the builder or Evergreen fixes; a separate assessor verifies.
separation of duties · same standardWhen it matters
Know what you are signing for before acceptance.
Find which shortcuts will meet real users and real data.
An independent view of the codebase behind the product.
Transparent scope
Price follows the amount of assessable first-party code. Dependencies, build output, generated files and tests do not count toward price.
✓ Includes a signed report and 60-minute walkthrough.
LOC — Lines of Code: only first-party code lines we actually assess. Libraries, generated files, tests and documentation do not count toward price.
Want it fixed, not just diagnosed?
Evergreen can close the technical gaps, but the original ruling remains unchanged and an implementing engineer never signs off their own work.
Ask about full remediation ↗gitdiffy Certificate
When the assessed commit passes the gitdiffy Standard, it receives a unique certificate and badge. Clients, buyers and stakeholders can verify with gitdiffy which repository and commit passed, under which methodology and whether the certificate is still valid.
Questions
Read-only and only for an explicitly selected repository. Private repositories use a GitHub App with Metadata and Contents read access only.
No. A pentest finds exploitable vulnerabilities. gitdiffy judges whether a codebase can responsibly be owned and operated; security is one of eight gates.
Not during price measurement. The repository is only counted and classified in a temporary isolated environment.
Yes. The standard and report are identical regardless of whether the builder or recipient orders it.
Yes, under a separate remediation engagement. The engineer who changes the code cannot sign the re-assessment alone.
Fixed scope · independent ruling
We respond within one business day with scope, access steps and a fixed price.