Code written by a model and reviewed by the same model has been reviewed by nobody.
CounterProof is an independent adversarial review practice for modern codebases, machine-written code above all. We deliver the one thing you cannot produce in-house: a signed, evidence-graded security assessment that regulators, acquirers, insurers, and enterprise customers will actually accept.
WHY YOU’RE HERE
Nobody buys a code review. They buy what it unlocks.
You’re not reading this because you woke up wanting a security assessment. Something is asking you for evidence:
- A regulator. The EU Cyber Resilience Act’s vulnerability-reporting duty begins 11 September 2026; full compliance follows in December 2027. Annex I Part II requires effective and regular security testing of your product — with records that hold up.
- An acquirer or investor. Technical diligence is where AI-assisted codebases now get discounted. An independent assessment on the table changes that conversation before it starts.
- A cyber-insurer. Underwriters increasingly price the difference between “we test internally” and “an independent party tested and signed.”
- An enterprise customer. Their security questionnaire doesn’t have a checkbox for “our model reviewed its own output.”
Every one of these audiences shares a rule: self-review doesn’t count. Not because your team lacks skill — because independence is the property being purchased, and it is the one property no team can supply for its own code.
WHAT YOU GET
The deliverable is the point.
An engagement produces a CounterProof Assessment under an immutable engagement identifier (CCP-YYYY-NNN — what your maintainers, your acquirer, or your fix commits cite, permanently). Every finding in it is either confirmed against your source — exact file and line, reproduction path, impact classification — or explicitly graded as plausible-only. Nothing padded, nothing scanner-generated, nothing you can’t act on.
Every finding also names its evidence rung — source trace, compile-proof, test, or live reproduction — and never implies a higher one than was reached. Every path:line citation is machine-resolved against the exact revision we reviewed before the report leaves our hands. You can check our work; that is deliberate.
It’s built to be handed over:
- To an authority — findings and remediation records structured against CRA Annex I Part II (regular testing, vulnerability handling, documentation).
- To a diligence team — evidence-graded, reproducible, scoped, with our name on the risk.
- To your own engineers — short enough to read, precise enough to fix. We can stay through the patch and re-verify the fix, so the report ends in resolved, not noted.
WHY THIS CAN’T BE DONE IN-HOUSE
You could run the same models. You can’t be independent.
- Running multiple AI models over your own code replicates our tooling and loses the property that matters. Your team chooses what the reviewers see, frames the questions, and judges the answers — every one of those choices carries your assumptions straight back into the review. That’s not a discipline failure; it’s structural. The author of a system cannot be its adjudicator.
- And even a flawless internal review produces a document no regulator, acquirer, or insurer will accept — because what they’re buying is a third party willing to sign.
- The method doesn’t care who — or what — wrote your code. Independence is the property being purchased, and it’s missing from human-written code just as often.
WHERE THE METHOD COMES FROM
We didn’t design this method. We earned it.
CounterProof wasn’t built as a product. It accreted, rule by rule, while we built and secured our own federated custody infrastructure — threshold cryptography, guardian consensus, bearer instruments — where a missed defect doesn’t cost a customer relationship; it costs funds. Ours.
Every rule in the method exists because its absence burned us on our own code first. Citations are machine-resolved because unresolved ones drifted. Findings face independent refutation because confident single-reviewer conclusions were wrong exactly where confidence was highest. We name the evidence rung reached because we once claimed a higher one than we stood on. The method is scar tissue, organized.
And it has never stopped running. Our own codebase — much of it machine-written — goes through the same adversarial review we sell, continuously, under a standing internal register. We were our own first customer, and we are still our hardest one.
- A standing withdrawal contract. If a finding does not survive your maintainers’ scrutiny, we retract it in writing — the report’s footer says so. A review brand that never withdraws is a brand that never admits error, and nobody should believe it. Ours does, in advance, on every report.
- Nothing ships unrefuted. A finding reaches you only after independent model families — not a second pass of the same one — have tried to refute it and failed, with disagreements settled by reading your source, not by vote.
- No unmeasured number, ever. We state operation counts; we never quote a wall-clock, throughput, or rate we did not measure. That rule applies to our marketing too — which is why this page contains no detection percentage.
- We publish our own errors. Our methodology documentation — available under NDA within an engagement — carries a maintained inventory of our own recorded review errors, including the ones outside reviewers found that we had missed, and names its own open gaps. Ask any other provider for theirs.
- Forged on our own money. The method was built to secure threshold-cryptography payment infrastructure we operate ourselves — where a missed finding costs us our own funds. That is the standard your codebase is reviewed against.
- Specialists, not generalists. Rust, protocol implementations, cryptographic code, payments, and anything that touches other people’s money or data.
Pull-quote block:
Sample finding (sanitized)
METHOD (ONE SENTENCE, BY DESIGN)
How it works.
Every assessment is produced under the CounterProof protocol — a multi-lineage adversarial review in which independent model families each attack the findings, and every finding must survive adversarial refutation and source confirmation before it reaches you. Full methodology documentation, including its limits and our own recorded errors, is available under NDA within an engagement.
ENGAGEMENTS
Three ways in.
- Assessment. Fixed-scope adversarial review of a repository or release candidate. The signed report, evidence-graded, under its CCP identifier.
- Assessment + Remediation Verification. We stay through your fixes and independently verify each patch closes its finding — the report ends in resolved.
- Standing Review. Recurring review of releases against your CRA testing obligations. Your Annex I Part II evidence, produced continuously instead of reconstructed in a panic.
Secondary line: Already running your own model reviews? Good — you’ve met the noise. Bring us the findings you can’t adjudicate.
CRA TIMELINE BLOCK
The clock is not ours. It’s Brussels’.
- 11 September 2026 — reporting obligations for actively exploited vulnerabilities begin.
- December 2027 — full CRA compliance required for products with digital elements sold in the EU.
- Today — the testing and vulnerability-handling records you’ll need then are the ones you start producing now.
[Talk to us before the deadline does →]
FOOTER
CounterProof is a practice of Clavestra Capital Ltd. We review code; we do not perform statutory audits. Independent by structure: we never review code we wrote. Proof attests; CounterProof refutes, CounterProof is the adversarial sibling of Clavestra Proof: the discipline of falsification, applied to code.

