Local-first by design

Is this AI-generated repo ready to ship?

RepoAssure boots your app, drives it with real Chromium, and turns what breaks into a readiness score, an evidence bundle, and a repair plan your AI IDE can execute. Entirely on your machine.

100% LOCALVerified
Latest local runTrust Ledger
Content-hashed
Evidence generated locally
$pnpm hardening run ./my-ai-app --browser
Repo profile detected: vite · npm
Booted http://127.0.0.1:5173
Generated hardening-report.md, repair-plan.json, repair-task-package.json
Latest bundle: .hardening/latest/manifest.json
85/ 100
Readiness score
P0: 0P1: 1
What it answers

Four questions a reviewer actually asks

Every run answers the same four questions, with evidence attached to each answer. Figures below come from a recorded benchmark run.

1
Is this repo ready to ship?
Readiness starts at 100 and deducts per finding: 35 for a P0, 15 for a P1, 5 for a P2, 25 if the app never booted. The formula is published, so the number can be checked.

85readiness · P0: 0 · P1: 1

2
What evidence proves it?
Each run writes an evidence bundle. Every artifact records a content fingerprint, so anyone can recompute it on another machine and confirm nothing changed.

4artifacts · all verified

3
What is still blocking acceptance?
Findings are grouped by severity and reviewer impact, each with reproduction steps and captured evidence rather than a bare warning.

1P1 finding · no P0 blockers

4
What should the AI IDE fix first?
The repair plan is ordered and carries a root-cause hypothesis, target areas, and verification commands. An AI IDE consumes it directly instead of guessing.

1repair action · sequenced for handoff

Assurance Graph

See how local evidence connects across the delivery loop

Verified inputs produce content-hashed artifacts and acceptance decisions without leaving your machine.

Assurance GraphAll checks verified
  1. All checks verified
  2. Docs
    VerifiedIn the CLI
  3. Code
    VerifiedIn the CLI
  4. Tests
    VerifiedIn the CLI
  5. ADRs
    VerifiedIn the CLI
  6. Repair Plan
    GeneratedIn the CLI
  7. Patch Plan
    GeneratedInternal tooling
  8. Acceptance
    AcceptedInternal tooling
All checks verified
Docs
VerifiedIn the CLI
Code
VerifiedIn the CLI
Tests
VerifiedIn the CLI
ADRs
VerifiedIn the CLI
Repair Plan
GeneratedIn the CLI
Patch Plan
GeneratedInternal tooling
Acceptance
AcceptedInternal tooling
VerifiedProduces
How it works

Run hardening locally in one command

RepoAssure analyzes your AI-generated repo, boots the app when needed, explores routes, and writes a content-hashed artifact bundle under .hardening/.

How it works
$pnpm hardening run ./my-ai-app --browser
Repo profile detected: vite · npm
Booted http://127.0.0.1:5173
Generated hardening-report.md, repair-plan.json, repair-task-package.json
Latest bundle: .hardening/latest/manifest.json
No source upload. Artifacts stay on your machine.
Delivery roles

Who reads what, locally

The same bundle serves four readers. None of them has to trust the other three.

Developer
Runs hardening, inspects findings, and hands repair tasks to the IDE.
Reviewer
Reads reports, repair plans, and patch plans before approving delivery.
AI IDE
Consumes repair-plan.json and repair-task-package.json without cloud upload.
Maintainer
Records acceptance decisions with content-hashed local evidence.
Proof artifacts

Evidence that stands up to review

Every run produces a content-hashed artifact bundle. Nothing leaves your machine by default.

Artifact previewhardening-report.md excerpt
Generated

Readiness score85 · P0: 0 · P1: 1

P1

Interaction did not produce an observable result on /settings (dead_control).

click_error=TimeoutError: page.click: Timeout 1000ms exceeded.
Evidence
sha256: af83...b91c
Review detail
1 finding, grouped by severity and reviewer impact.
Hardening report
Findings, severity, and evidence mapped to policy rules and best practices.
Open core

Built in the open. Trusted by design.

RepoAssure is open core. The core engine, policies, and artifact formats are transparent and community-driven.

Local-first open core flow
  1. AI repoLocal workspace
  2. RepoAssureCLI · MCP · Action
  3. .hardening/Hashed artifacts
  4. AcceptanceLocal decision
  • Core engine and artifact specs in the open
  • Pluggable policies and analyzers
  • Reproducible, auditable, verifiable
Public repository link opens after the public release gate closes.
Roadmap: Team Cloud and Enterprise
Evidence model · Team Cloud planned

Secure collaboration, centralized policy, and audit at scale.

  • Artifact storage and sharing
  • Role-based access and approvals
  • Enterprise policy management
  • Audit trails and compliance exports
Planned. Focused on private preview.
Trust boundary

Your code stays with you

Two network calls, both to localhost
The product makes exactly two network calls: one health probe and one page crawl, both against the app being tested. There is no third, and no telemetry SDK. Count them yourself.
It cannot write to your repo
Repair plans are plans. Every execution artifact carries a machine-readable no-write proof: targetRepoWriteAuthorized: false.
Tampering shows up
Every artifact records a content fingerprint. Recompute it on another machine and confirm nothing changed — without trusting RepoAssure.
Private preview

Join the private preview

Help shape the future of trustworthy AI code delivery.

Access is by invitation only. Not for public distribution.

Private preview includes invited engineering teams. Partner names are shared only with permission — no public logo wall yet.