Candidate findings lack context
A reported pattern can ignore call paths, trust boundaries and system invariants.
In development Early-access waitlist
We don’t find bugs. We validate them.
Truscova Verify is being built for protocol and audit teams that need to determine whether a scanner- or AI-generated Solidity finding actually applies to the code in context.
Designed to validate findings produced by AI coding agents, smart contract scanners and audit teams.
Example finding sources
Target product model
The problem
Automated scanners and AI assistants can produce more candidate findings than teams can confidently evaluate. Pattern matches alone do not establish reachability, exploitability, or business impact.
Verify starts where those tools stop: with one reported claim and the question, “Does this apply here, under these assumptions?”
A reported pattern can ignore call paths, trust boundaries and system invariants.
Every unsupported alert competes with genuine risks for scarce review attention.
Teams need to see the assumptions and evidence behind an assessment.
Target workflow
Verify is being designed around a narrow task: evaluating a specific finding, not searching the entire codebase for new vulnerabilities.
Provide
Supply the reported vulnerability, target function and the code needed to evaluate its conditions.
Examine
Translate the claim into checkable conditions, then inspect reachability and the assumptions that affect the result.
Assess
Return an assessment with the evidence considered, remaining uncertainty and missing context.
Target assessment model
The intended output is not a probability score. Each finding is assessed as true, false or inconclusive, with the conditions and evidence behind that result.
The available evidence supports the reported finding under the stated assumptions.
The reported conditions are not present or reachable in the reviewed context.
Important context or evidence is missing, and the uncertainty is stated directly.
What the assessment should show
A useful result does more than name an outcome. It records what was evaluated, what evidence mattered, and what could change the conclusion.
Clear boundaries
Clear limits are part of a trustworthy security product. These statements describe the intended product boundary and will be refined as supported finding classes are validated.
Being built to
Not designed to
FAQ
Verify is still in development. Answers below describe the current intended scope, not a promise of unsupported capability.
The candidate vulnerability claim, the target Solidity function and enough codebase context to evaluate the relevant conditions and call paths.
The available context cannot support or reject the claim responsibly. The assessment should state what is missing and what could resolve the uncertainty.
No. Verify is intended to assess specific candidate findings. It does not explore the whole codebase for novel logic errors or replace a scoped manual audit.
Not through this page. Join the waitlist for product access, or request an expert review to discuss scope and data handling before sharing material.
Protocol engineering teams, smart contract auditors and security-tool builders working with concrete Solidity findings and willing to provide structured feedback.
Early access
Join the waitlist to hear about early access and product research. We will use your work email to manage your request and contact selected teams.
What happens next: your email is added to the waitlist immediately. We may contact selected teams for product research or early access. Joining does not guarantee access.