Exhibit A — signed case
Provable Security

Security you can prove.

Every AI-found vulnerability travels a signed evidence pipeline — proven, or refused. Not another scanner. The end of the false positive.

governed frontier models · A–H signed gates · cross-repo taint · single-tenant
CASE · 01KXPKT02QM4 CRITICAL · 9.8

Unauthenticated endpoint exposes all claim records

A01 · Broken Access Control
AB CD
SIGNED Needs evidence — the pipeline refused to over-claim.
signer tenant:local:root · Ed25519 · payload sha256 9f2a…c71b
Governed frontier models A–H signed gates 0 rubber-stamped Single-tenant — no code leaves
The problem

The market is stuck between noise and blind trust.

AI writes code at 10× — and reproduces missing authorization, injection sinks, and business-logic flaws at 10× with it. The tools meant to catch it fail in opposite directions.

Failure one · noise

Legacy scanners

SAST / DAST / SCA flood teams with thousands of “possibles” nobody can stand behind. Triage never ends; real bugs hide in the pile.

Failure two · blind trust

Naïve AI scanners

Faster guesses — now hallucinated. An unverifiable claim from a model is not evidence. It’s a liability with better grammar.

§

Quaestor is the third way: a governed evidence pipeline. What can’t survive the gates is refused, not softened.

How it proves

Six stages. Eight signed gates. One chain of custody.

Every finding walks the same path, and every gate decision is Ed25519-signed with a per-tenant key. The signature is the product.

0

Sanitise

Secrets stripped, redacted, sealed — before a model sees a line.

B

Map

The codebase cartographed: entrypoints, sinks, reachability.

C

Source→sink

The exploit path traced and proven, not asserted.

F

Negative control

The counter-test that a real bug must survive.

G

Impact

Blast radius calibrated — CVSS, OWASP, CWE.

H

Readiness

Report-grade, or refused. No middle ground.

The quick guide

From a repo URL to a signed fix — in five acts.

This is the whole story. Point Quaestor at a repository; it does the rest — and every claim arrives with its proof, its refutation, or an honest "not yet."

1

Sign in

Your workspace, isolated to you — cloud, private cloud, or on-prem.

2

Point at a repo

Paste a GitHub URL. It's sanitised and sealed before a model reads a line.

3

Investigate

Tainted input traced across files — and across every linked repository.

4

Verdicts

Signed if proven; disproven or needs-evidence if not. Never dressed up.

5

Fix, fast

Your developer gets the path and an AI-assisted fix. Re-scan auto-closes it.

The moat

We publish what we disproved.

A metric surface competitors structurally cannot produce: proof rate, mean time-to-evidence, and the one that matters most — disproven rate.

25Candidates found
23Held for evidence
2Disproven
0Rubber-stamped

One real repo, one governed run. The pipeline refused to over-claim — and that integrity is the moat. You can copy a prompt; you cannot copy a tribunal.

One platform, three readers

For every defender, developer and decision-maker.

Developer

Fix what’s real.

Zero false positives to wade through. Every case ships with a proven path and the exact fix.

  • Assigned-to-me, by severity
  • What each case actually ships
  • Clean-gate rate
Defender

Own the portfolio.

The gate funnel, evidence SLAs, and signed coverage across every repo — one governed view.

  • Needs-evidence + SLA
  • Signed coverage by repo
  • Disproven, not buried
Decision-maker

Report with proof.

Quantified risk posture and a board-ready pack — every number traces to a signed verdict.

  • Risk posture & exposure
  • Quarterly board pack
  • Audit chain of custody
Editions

One platform, from first scan to the enterprise.

Every edition ships the same signed dossier — what scales is the portfolio, the roles, the board report, and the trust boundary.

Verify

Public-repo scans · Quaestor-Verified badge · shareable signed dossiers.

Team

Private repos · discovery on any framework · full portal & analytics · bring-your-own backends.

Business

RBAC · SSO · saved views · scheduled reports · board & compliance packs · API.

Enterprise / Private

Single-tenant — no code leaves · risk quantification · audit export · dedicated support.

Prove your repo.

Point Quaestor at a repository and get back a signed dossier — proven cases, disproven claims, and a chain of custody you can take to the board.