Assay · System documentation
How a decision report works
- What a decision report is
- The journey of a report
- Where the evidence comes from
- The evidence contract
What a buyer sets up
Where the evidence comes from
Assay assesses software without ever receiving it. The chain runs from a supplier's own measurement, through a signed package they choose to share, to a buyer's report.
The chain
- The supplier measures. The code is scanned where it lives, by the supplier's own arrangement, producing scores and the findings behind them.
- The result is signed and published. The measurement becomes a delivery — a package carrying the verdict, the commit it measured and the rubric version it was scored under, cryptographically signed and lodged in a registry.
- The supplier grants access. Evidence is not public by default. A supplier decides which buyer may see which delivery, and can withdraw that access later.
- The buyer builds a report. Assay pulls the granted evidence, verifies it, and assesses it against the buyer's bar.
Assay never receives source code. It works exclusively over signed evidence, and what reaches a buyer's report is measurement-level: which areas came out weak, the score each carried, how confident that measurement was, and a plain-language statement of what it means in practice. Not file paths, not line numbers, not code.
Why the supplier stays in control
Access is granted per buyer and can be revoked. That is what makes suppliers willing to have their code measured at all: sharing a result with one customer does not publish it to the market, and a finished engagement does not leave evidence circulating indefinitely.
The corollary matters for buyers: a report can only be built where a supplier has shared evidence. Assay cannot obtain a measurement the supplier has not chosen to provide, and reports that fact plainly rather than treating an absence as a failure.
What travels with the evidence
Enough for the claim to be checked independently, years later: the verdict, the exact commit measured, the rubric version it was scored under, and the signature that binds them together. That combination is what allows a third party to confirm the measurement without trusting either the supplier or us.
This page is a summary, not the formal record. Storage, retention periods, encryption and the complete list of subprocessors are documented on the security and data handling page. Where the two differ, that page is authoritative.