DORA · EU banks
Audit rights on paper → artifact at handoff
When you need to practically exercise monitoring / audit rights under DORA Art. 30(3)(e)(i) on a code delivery — with a portable artifact for the acceptance file.
Product 2.0 · pilot candidate
SecureFix runs the agreed checks on the delivered Go, Python or JavaScript repository and returns a signed PDF — findings, versions, hashes, verdict — that you attach to the acceptance file.
Built for DORA Art. 30(3)(e)(i) — evidence on ICT third-party deliverables.
SecureFix records what was checked, with which tools, what was found, and what was sealed for a concrete handoff in Go, Python, or JavaScript (including mixed). The buyer verifies pack integrity themselves. One line of category clarity: not an IDE scanner — an acceptance / audit-record pack for the handoff file.
The pilot was run with a client under NDA; the client and the findings are not disclosed. On a call we can walk through the methodology and a redacted sample report.
Pilot pricing on request after scope review (language + repo bounds).
Also: sample Bundles, verify a Bundle, schema v1. Owner-run available: code stays with you. For a pilot you can wire a GitHub webhook so a pull request builds the same acceptance pack.
Languages: Go, Python, JavaScript (including mixed delivery). Public samples on this site are Go fixtures; Python/JS use the same Bundle schema. Product roadmap.
$ securefix audit ./example-service
✔ fmt passed
✔ vet passed
✔ build passed
✔ test passed
⚠ gosec findings recorded (demo)
✔ govulncheck recorded
[•] Sealing Evidence Bundle…
↳ result.json + report.pdf · integrity hashes
✔ Bundle sealed — findings retained
Demo sketch (Go terminal). A real Bundle uses the same seal format for a single-language scope or a mixed delivery (Go + Python + JavaScript in one pack).
One product — three reasons to buy. DORA is one example below, not the homepage headline.
DORA · EU banks
When you need to practically exercise monitoring / audit rights under DORA Art. 30(3)(e)(i) on a code delivery — with a portable artifact for the acceptance file.
SOC 2 · ISO 27001
For B2B SaaS and teams that need portable proof of software-delivery controls at audit time — without claiming SecureFix “grants” SOC 2 / ISO.
DevSecOps
When Engineering / AppSec accept code from a vendor or another team and want a sealed trail: scope, tools, findings, review — outside the other party’s CI.
Not an abstract “compliance department” — roles accountable for passing audits or accepting a delivery.
Head of Compliance
Close the gap “audit rights exist, but there is no portable record of the code handoff” — without buying another org certificate.
CISO
See what was actually checked at handoff, with pack integrity — instead of trusting the vendor’s green tick.
Engineering Lead
Agreed scope, recorded tool versions, and a review trail next to the acceptance act — for the team and for the auditor.
Three founders — product, engineering, and finance. Operator-stage details: Legal.
CEO, co-founder
20+ years in fibre-optic transmission networks at a regional grid operator: line engineer, then engineer (2nd category), responsible for acceptance and commissioning of optical links. Now runs product, pilots and partner delivery.
CTO, co-founder
8 years in software development, including 4 years on Go. Owns the audit pipeline, architecture, and core engineering.
CFO, co-founder
Background in tax administration and corporate/public-sector finance (including Gazprom and the Ministry of Finance of Bashkortostan). Runs SecureFix financial model, compliance, and operations finance.
A bounded delivery in Go, Python, or JavaScript — or a mixed repo with multiple stacks in the operator contour (one sealed pack). Agreed handoff or Owner-run under your control.
Orchestrated stages with recorded tool versions by language (e.g. Go: gosec · govulncheck; Python: Bandit · pip-audit; JavaScript: eslint · npm-audit).
PDF + machine-readable evidence with integrity checks — outside either party’s CI.
CI scanners (gosec, Bandit, eslint, npm-audit, etc.) produce findings inside your pipeline. SecureFix adds a portable acceptance pack for both sides at handoff: PDF + hash-checked Evidence Bundle, recorded tool versions, and operator review — without requiring the other party to trust your CI logs alone.
| CI scanner | SecureFix | |
|---|---|---|
| Main output | Findings in the pipeline | Portable acceptance pack (PDF + Bundle) |
| Where it lives | Usually inside one CI | Can run outside either party’s CI |
| Integrity of the pack | Usually not packaged as a sealed handoff artifact | Hash-checked Evidence Bundle |
| Operator review | Optional / outside the tool | Designed into the acceptance record |
| Category | Findings in a pipeline | Acceptance / audit-record pack for handoff |
Now = Product 2.0 acceptance pack (Go / Python / JavaScript). What comes next: product roadmap.
The buyer needs a sealed record of what was checked on this delivery.
Demo fixture · public sample scope · same Bundle schema for Python/JS
B/W anatomy: human PDF · machine JSON · hashes / signature — one pack per delivery.
Trust Summary from the demo run — what an auditor / CISO sees.
Open PDFPassed demo run · 0 findings · fixture only.
Download ZIPFailed demo run · multiple findings · artifacts only.
Download ZIPAlso: all three Bundles, Python/JS rehearsal ×10, verify in browser, schema v1, legal. Product line: 2.0 · schema v1.
Paste a short Go snippet — visual preliminary layout only (nothing uploaded). A full Evidence Bundle is produced in the operator contour.
For a pilot — email info@securefix.pro. Include company, language (Go / Python / JavaScript), scope size, and timeline.
Pilot pricing on request after scope review.
By contacting us you agree to the legal notice.