Early access

Your AI agent says it’s done. Prove it.

An independent verification layer for software built by AI coding agents. It tests behavior, surfaces hidden assumptions, and flags what you didn’t know to ask about.

Coding agentbuild #214
[v] Implemented project permissions.
All tests pass. 42/42.
Feature complete.
Ready to ship ->
Verification report · interactive demo
AUTH-07[x] INVARIANT VIOLATED

Removed member can still access project data.

Claim
Removed members cannot access project data.
Check
Removed member sends an authenticated request.
Result
200 OK. Expected 403.

The problem

AI got very good at writing code. That created a new problem.

Coding agents build features in minutes. You’re still the one who has to find out whether those features keep their promises.

Before AI coding agents
  1. Human writes code
  2. Human reviews code
  3. Human tests product
With AI coding agents
  1. AI writes code
  2. AI says “done”
  3. Human asks: “Is it actually done?”

The hard part isn’t syntax errors. It’s what the product quietly gets wrong, or was never asked to get right:

missing requirementsunexpected edge casesincorrect permissionsbroken state transitionsUI and API disagreethird-party calls nobody noticedobligations nobody listed

The core idea

You don’t have to know what you forgot to ask.

Your coding agent knows what it built. Assay checks what it promised, including the promises nobody wrote down. You shipped a team app. But did anyone verify:

01 · ACCESSCan a removed member still access a project?

02 · DATAIs the data actually gone after a delete and a refresh?

03 · PRIVACYDoes that “just a font” request send your visitors’ IP addresses to a third party?

04 · ANALYTICSWhat can your session replay record from a form field?

05 · EMAILIf you email your waitlist, are unsubscribe and sender requirements covered?

06 · ASSETSWhere did that image come from, and are you allowed to use it?

07 · DISCOVERABILITYDoes the site have the important discovery files it needs, such as robots.txt, sitemap.xml, or llms.txt?

functional behaviorauthorization anduritydata integrityprivacycompliance signalsthird-party integrationsbusiness rulesoperational requirementsassets and licensingsite discoverabilityhidden assumptions

How it works

Claim. Check. Evidence.

01

Discover claims

Reads the application and its stated behavior to find what it promises, explicitly and implicitly.

02

Turn claims into checks

Important claims become invariants. Assay generates adversarial scenarios designed to break them.

03

Run them, keep the evidence

Checks execute against the application where possible. Every result carries the request, the response and the outcome.

04

Keep what matters

Useful invariants persist and re-run on future changes. What can’t be verified automatically is surfaced for human review.

BUILD->VERIFY->FAIL->FIX->VERIFY AGAIN->SHIP

Why it’s different

Here’s the claim. Here’s the test. Here’s what happened.

Assay doesn’t tell you your code looks suspicious. It states a claim, tries to break it, and shows you the result. You decide when to ship. Then act on the finding, fix it, and verify the fix.

CLAIM->INVARIANT->CHECK->EVIDENCE->FINDING->ACTION->RE-VERIFICATION

Try it: fix the finding, then re-run verification.

Example output

Evidence, not vibes.

One run, many kinds of promises: behavior, privacy, compliance signals, site configuration, and assets. Privacy and compliance findings are review flags, never legal conclusions.

ASSAY VERIFICATION
APPLICATION
verified: APP-01Authentication works
verified: APP-02Project creation works
failed: AUTH-07Removed members can still access project data
evidence: removed member, authenticated request to /projects/42 -> 200 OK
PRIVACY
needs review: PRIV-03External font request may expose visitor IP
evidence: request to a third-party font host on first page load
needs review: PRIV-07Analytics configuration may capture form input
COMPLIANCE
needs review: LEGAL-01Age-related requirements need review
needs review: EMAIL-02Marketing email unsubscribe requirements need review
needs review: EMAIL-04Required sender/contact information needs review
DISCOVERABILITY
verified: SITE-01robots.txt is present and reachable
verified: SITE-02sitemap.xml is present and valid
needs review: SITE-03llms.txt is missing
ASSETS
needs review: ASSET-01Image licensing information is missing
1 failed · 7 need review · 4 verified
Compliance and legal items are review flags for a qualified human, not conclusions.
[v] verified [x] failed [?] unverified [!] needs review

Interactive demo · simulated results. Assay is in development; this is the report format we are building toward.

Differentiation

Not another coding agent.

Your coding agent is optimized to build the feature you asked for. Assay is optimized to challenge the result. Each layer has a job.

AI coding agentsBuild what you asked for.
Unit testsCheck known behavior.
Security scannersLook for known classes of vulnerabilities.
Browser testingExercises known workflows.
AI code reviewComments on the code.
Independent verificationLooks for evidence that the product’s promises are false, incomplete, or unverified.

Assay verifies itself

This page was checked first.

If we say software should be verified, our own should survive it. Only what we verified is listed here, plus the one issue we found. The checks are in the site repository (npm run check).

ASSAY SELF-CHECK
built site + migration files · checked 2026-10-05
verified: Fonts served locally; no font-provider requests
verified: Page-load third-party requests limited to Cloudflare Web Analytics
verified: No session replay or advertising trackers
verified: This site’s own code sets no cookies and uses no browser storage
verified: Forms collect only the fields the privacy policy lists
verified: Form input limits match database constraints
verified: Waitlist marketing consent is optional and unticked by default
verified: Anonymous database access is insert-only; waitlist and contact submissions cannot be read publicly
verified: No service-role key or other server secrets are exposed in the client build
verified: Privacy policy names the services this site actually uses
verified: robots.txt is present and reachable
verified: sitemap.xml is present and reachable
needs review: FORM-01
No rate limiting beyond insert-only access and input length limits.
Potential spam / abuse risk under sustained traffic.

Early access

We’re building the independent verification layer for AI-generated software.

You’re on the list.We’ll let you know when the beta is ready.
Privacy Policy