Product 2.0 · pilot candidate

An acceptance report for every code handoff.

SecureFix runs the agreed checks on the delivered Go, Python or JavaScript repository and returns a signed PDF — findings, versions, hashes, verdict — that you attach to the acceptance file.

Built for DORA Art. 30(3)(e)(i) — evidence on ICT third-party deliverables.

SecureFix records what was checked, with which tools, what was found, and what was sealed for a concrete handoff in Go, Python, or JavaScript (including mixed). The buyer verifies pack integrity themselves.

The pilot was run with a client under NDA; the client and the findings are not disclosed. On a call we can walk through the methodology and a redacted sample report.

Pilot pricing on request after scope review (language + repo bounds).

Also: sample Bundles, verify a Bundle, schema v1. Owner-run available: code stays with you. For a pilot you can wire a GitHub webhook so a pull request builds the same acceptance pack.

Languages: Go, Python, JavaScript (including mixed delivery). Public samples on this site are Go fixtures; Python/JS use the same Bundle schema. Product roadmap.

product · 2.0 go · python · js integrity · sha256 ai · scaffold only
$ securefix audit ./example-service
 fmt          passed
 vet          passed
 build        passed
 test         passed
 gosec        findings recorded (demo)
 govulncheck  recorded

[•] Sealing Evidence Bundle…
↳ result.json + report.pdf · integrity hashes

 Bundle sealed — findings retained

Demo sketch (Go terminal). A real Bundle uses the same seal format for a single-language scope or a mixed delivery (Go + Python + JavaScript in one pack).

Use cases

One product — three reasons to buy.

DORA · EU banks

Audit rights on paper → artifact at handoff

When you need to practically exercise monitoring / audit rights under DORA Art. 30(3)(e)(i) on a code delivery — with a portable artifact for the acceptance file.

SOC 2 · ISO 27001

Auditors want a portable evidence pack

For B2B SaaS and teams that need portable proof of software-delivery controls at audit time — without claiming SecureFix “grants” SOC 2 / ISO.

DevSecOps

Internal security review at handoff

When Engineering / AppSec accept code from a vendor or another team and want a sealed trail: scope, tools, findings, review — outside the other party’s CI.

Who usually buys

Head of Compliance

Needs an artifact in the dossier

Close the gap “audit rights exist, but there is no portable record of the code handoff” — without buying another org certificate.

CISO

ICT / vendor oversight

See what was actually checked at handoff, with pack integrity — instead of trusting the vendor’s green tick.

Engineering Lead

Acceptance and security review

Agreed scope, recorded tool versions, and a review trail next to the acceptance act — for the team and for the auditor.

Team

Three founders — product, engineering, and finance. Operator-stage details: Legal.

Alexander

CEO · product · pilots

Background as deputy director for finance and procurement: public contracts, supplier oversight, and formal acceptance of deliveries on the buyer side. Now runs SecureFix product, pilots, partner delivery, and go-to-market.

Eldar

CTO, co-founder

8 years in software development, including 4 years on Go. Owns the audit pipeline, architecture, and core engineering.

Gulnara

CFO, co-founder

Background in tax administration and corporate/public-sector finance (including Gazprom and the Ministry of Finance). Runs SecureFix financial model, compliance, and operations finance.

How it works

1

Scope

A bounded delivery in Go, Python, or JavaScript — or a mixed repo with multiple stacks in the operator contour (one sealed pack). Agreed handoff or Owner-run under your control.

2

Checks

Orchestrated stages with recorded tool versions by language (e.g. Go: gosec · govulncheck; Python: Bandit · pip-audit; JavaScript: eslint · npm-audit).

3

Sealed pack

PDF + machine-readable evidence with integrity checks — outside either party’s CI.

We already run scanners in CI — why SecureFix?

CI scanners (gosec, Bandit, eslint, npm-audit, etc.) produce findings inside your pipeline. SecureFix adds a portable acceptance pack for both sides at handoff: PDF + hash-checked Evidence Bundle, recorded tool versions, and operator review — without requiring the other party to trust your CI logs alone.

Typical CI scanner vs SecureFix

CI scanner SecureFix
Main output Findings in the pipeline Portable acceptance pack (PDF + Bundle)
Where it lives Usually inside one CI Can run outside either party’s CI
Integrity of the pack Usually not packaged as a sealed handoff artifact Hash-checked Evidence Bundle
Operator review Optional / outside the tool Designed into the acceptance record
Category Findings in a pipeline Acceptance / audit-record pack for handoff

Fig. 1 — Acceptance architecture

Acceptance architecture

Fig. 2 — Competitive map

Competitive map

Fig. 3 — Product roadmap (public)

Now = Product 2.0 acceptance pack (Go / Python / JavaScript). What comes next: product roadmap.

SecureFix public product roadmap

The customer is not buying our good faith — they are buying the ability not to need it.

Request a pilot View sample PDF

What a sealed acceptance pack looks like

Demo fixture · public sample scope · same Bundle schema for Python/JS

Preview of SecureFix sample Trust Summary PDF

Color PDF preview. Full file opens in the browser.

Black-and-white schematic of sealed pack contents: PDF, result.json, seal

B/W anatomy: human PDF · machine JSON · hashes / signature — one pack per delivery.

Sample PDF

Trust Summary from the demo run — what an auditor / CISO sees.

Open PDF

Clean Bundle

Passed demo run · 0 findings · fixture only.

Download ZIP

Heavy Bundle

Failed demo run · multiple findings · artifacts only.

Download ZIP

Also: all three Bundles, Python/JS rehearsal ×10, verify in browser, schema v1, legal. Product line: 2.0 · schema v1.

Light browser demo

Paste a short Go snippet — visual preliminary layout only (nothing uploaded). A full Evidence Bundle is produced in the operator contour.

Request a pilot Open browser demo

Contact

For a pilot — email info@securefix.pro. Include company, language (Go / Python / JavaScript), scope size, and timeline.

Pilot pricing on request after scope review.

By contacting us you agree to the legal notice.