Was it engineered, or just generated?
Rock is read by its layers, and so is a codebase. A repo survey reads every layer of it — the whole repository, not a sample. Credentials that were committed and later removed, the licences you would inherit, where the knowledge actually sits, and how much was written with an AI agent. Free on any public repository.
Public repos need no access at all. For private ones, the Report tier uses a GitHub App with read-only scope, revocable at any time, and the token is discarded when the run finishes.
Every rated finding carries a commit SHA, a path and a line range. A finding you cannot click through to is not a finding.
The share of the codebase written with an AI agent is stated with a confidence level, and it never affects a rating.
Every report says how much of each dimension it read, and which questions belong to a person. On the free tier too.
Two sides of the same table
The same reading serves both. One side is finding out what it owns; the other is finding out what it is about to buy.
Sell side
In a real process, an investment bank puts someone like me in front of your engineering team weeks before anyone else sees the code. Every problem found then is a problem you still have time to fix. Found later, it is a discount.
Buy side
Your diligence team has a fixed number of hours and more targets than hours. A repo survey is a cheap first read — enough to tell which targets deserve the expensive attention, and which questions to open with when they get it.
What each layer gets you
Read a row across. The repo survey reads the code; a panel of models reviews that reading; a person gets what a repository does not contain. The check counts come straight from the assessor, so this grid is never out of date.
| Dimension | Repo survey Free any public repository | Report €249 one private repository | Hire us from €12,000 a real engagement |
|---|---|---|---|
| 01Architecture & Codebase — including AI provenance | ✓ 6 checks | ✓ Panel review of every finding | ✓ Design review with your architects · build-vs-buy calls |
| 02Engineering Process & SDLC Maturity | ✓ 7 checks | ✓ Panel review of every finding | ✓ Practice interviews · postmortem and incident-response review |
| 03Organizational Health | ✓ 5 checks | ✓ Panel review of every finding | ✓ Team interviews · levelling · culture · retention risk · who actually mentors |
| 04Product & Engineering Maturity | ✓ 5 checks | ✓ Panel review of every finding | ✓ Roadmap review · whether the debt is acknowledged and funded |
| 05Security & Reliability Posture | ✓ 10 checks | ✓ Panel review of every finding | ✓ Incident history · threat model · penetration-test review |
| 06Observability & Operations | ✓ 3 checks | ✓ Panel review of every finding | ✓ On-call rotation · SLOs · whether anyone watches the telemetry |
| 07Fit with the Acquirer | ✓ Integration plan against your stack, your systems and your people | ||
| Delivery | |||
| Every finding carries a commit, a path and a line range | ✓ | ✓ | ✓ |
| Shareable page, listed in the library | ✓ | ✓ | ✓ |
| AI provenance, stated with a confidence level | ✓ | ✓ | ✓ |
| Private repositories | · | ✓ | ✓ |
| Evidence appendix with full SHAs and line ranges | · | ✓ | ✓ |
| PDF export and owner rebuttals | · | ✓ | ✓ |
| Re-runs with a diff view for 30 days | · | ✓ | ✓ |
| Written for your investment committee | · | · | ✓ |
| Named partner on the engagement | · | · | ✓ |
| Run a repo survey | Buy a Report | Start a conversation | |
This is the row you hire a person for. No repository contains the acquirer. Integration cost, which of your systems this architecture has to absorb, whether the team wants to stay after close — those come from the room, not the commit log. The other six rows are the intake work, already done, so an engagement starts from evidence instead of a questionnaire.
Start a conversationRecently surveyed repositories
Every listed report is a public page. Browse the library →
| sindresorhus/is | TypeScript |