In development Early-access waitlist

We don’t find bugs. We validate them.

Turn smart contract findings into decisions you can defend.

Truscova Verify is being built for protocol and audit teams that need to determine whether a scanner- or AI-generated Solidity finding actually applies to the code in context.

Designed to validate findings produced by AI coding agents, smart contract scanners and audit teams.

Example finding sources

  • Codex
  • Claude Code
  • Gemini CLI
  • Security scanners
  • Audit workflows

Target product model

One claim Reviewed in context
Explicit assumptions No opaque score
Evidence trail Designed to be inspectable
Solidity first Initial technical focus

The problem

A finding is a signal, not yet a verdict.

Automated scanners and AI assistants can produce more candidate findings than teams can confidently evaluate. Pattern matches alone do not establish reachability, exploitability, or business impact.

Verify starts where those tools stop: with one reported claim and the question, “Does this apply here, under these assumptions?”

01

Candidate findings lack context

A reported pattern can ignore call paths, trust boundaries and system invariants.

02

Noise consumes expert time

Every unsupported alert competes with genuine risks for scarce review attention.

03

Decisions need an audit trail

Teams need to see the assumptions and evidence behind an assessment.

Target workflow

From candidate claim to reviewable assessment.

Verify is being designed around a narrow task: evaluating a specific finding, not searching the entire codebase for new vulnerabilities.

  1. 01

    Provide

    The claim and relevant context

    Supply the reported vulnerability, target function and the code needed to evaluate its conditions.

  2. 02

    Examine

    Conditions and assumptions

    Translate the claim into checkable conditions, then inspect reachability and the assumptions that affect the result.

  3. 03

    Assess

    The evidence-supported outcome

    Return an assessment with the evidence considered, remaining uncertainty and missing context.

Target assessment model

Three outcomes, each with a reason.

The intended output is not a probability score. Each finding is assessed as true, false or inconclusive, with the conditions and evidence behind that result.

T

True

The available evidence supports the reported finding under the stated assumptions.

F

False

The reported conditions are not present or reachable in the reviewed context.

I

Inconclusive

Important context or evidence is missing, and the uncertainty is stated directly.

What the assessment should show

Enough context for another reviewer to follow the decision.

A useful result does more than name an outcome. It records what was evaluated, what evidence mattered, and what could change the conclusion.

  • 01 The original candidate claim
  • 02 Scope and code context reviewed
  • 03 Conditions and assumptions tested
  • 04 Supporting or contradicting evidence
  • 05 Outcome, limitations and next action

Clear boundaries

What Verify is and what it is not.

Clear limits are part of a trustworthy security product. These statements describe the intended product boundary and will be refined as supported finding classes are validated.

Being built to

  • Evaluate one candidate Solidity finding at a time.
  • Make assumptions and missing context visible.
  • Connect an outcome to inspectable evidence.
  • Support triage of scanner- and AI-generated findings.

Not designed to

  • Discover every vulnerability in a codebase.
  • Replace a scoped manual security audit.
  • Guarantee the absence of exploitable behavior.
  • Hide uncertainty behind a confidence score.

FAQ

The important questions first.

Verify is still in development. Answers below describe the current intended scope, not a promise of unsupported capability.

What information would an assessment need?

The candidate vulnerability claim, the target Solidity function and enough codebase context to evaluate the relevant conditions and call paths.

What does “Inconclusive” mean?

The available context cannot support or reject the claim responsibly. The assessment should state what is missing and what could resolve the uncertainty.

Does Verify replace a security audit?

No. Verify is intended to assess specific candidate findings. It does not explore the whole codebase for novel logic errors or replace a scoped manual audit.

Can I submit code today?

Not through this page. Join the waitlist for product access, or request an expert review to discuss scope and data handling before sharing material.

Who is early access for?

Protocol engineering teams, smart contract auditors and security-tool builders working with concrete Solidity findings and willing to provide structured feedback.

Early access

Help shape the future of finding validation.

Join the waitlist to hear about early access and product research. We will use your work email to manage your request and contact selected teams.

What happens next: your email is added to the waitlist immediately. We may contact selected teams for product research or early access. Joining does not guarantee access.