Skip to content
Canine
Se Watchdog

Canine Development · Onboarding

Before you read on

The way through

What we never say

Every line below is something a well-meaning colleague could say, and that would cost us exactly what we sell. It binds every conversation, whichever product it is about. The list is public so you can hold us to it.

About the measurement

  • "We certify you" — We measure the automatable part. You declare. We never certify.
  • "Our precision is X%" — We have published the method, but not yet a result. When there is one we publish it — including when it is inconvenient.
  • "A green score means the code is secure" — A clean automated result is necessary, not sufficient.
  • "We can tell whether code was written by an AI" — We measure hollowness by shape, not by origin. Stylometric AI detection is a credibility trap, and we reject the claim.
  • "We are SOC 2 certified" — We are not, today, and we say so openly. Instead: EU operation on our own hardware, a signable data processing agreement and a factual control statement. Self-hosted removes the question.
  • "We cover every language" — Here is the live list, and how deeply each language is examined. Some languages we do not cover — and we say so before you pay.
  • "The report guarantees quality" — Reports are delivered as they are, for information and planning. They do not replace human review.
  • "We can fix it for you" — We are read-only. We hand the findings to your own tooling; the hand on the code is always yours.
  • "We can adjust the number" — No party can move the number. Only the code moves it.

About an appraisal in a deal

  • "We audited the seller" — We measured a codebase, at one commit, that someone gave us access to. A company is not a codebase: the team, the contracts, the customers and the accounts are not in the survey and never were.
  • "The signature means they have nothing to hide" — It proves the result is the one we issued and that nobody has edited it since. It does not prove you were shown everything — the seller chooses which repository, and which commit.
  • "That is what the software is worth" — Rebuild cost is what it would cost to write again; value-at-risk is what the findings put at risk. Neither is a market valuation. We never price an asset or a deal.
  • "Their 76 beats the other bidder's 71" — Two numbers compare when they were scored against the same rubric version. Across versions they do not, and we always say which version produced a number.
  • "A frozen rubric means the number cannot drop" — Freezing fixes the ruler, not the asset. The number can still fall, and when it does, that is the codebase telling you something.
  • "We're on your side" — We are commissioned by one side and neutral to both, by structure: no success fee, never a delivering party, the same rubric whoever pays. We will not argue your case, and the number does not know who paid for it.
  • "The report says whether to do the deal" — It says what condition the code is in and what the findings put at risk. Price, people, market and contract are not in the survey, and the decision was always yours.