Verify Without Revealing
Prove what is true about your software, infrastructure and runtime — without exposing what is valuable. Analyze → Claim → Proof → Passport → Verify, checked by anyone with the independent verifier, not just us.
- Signed Passports
- No Code Disclosure
- Independent Verifier
- Runtime Attestations
- Supportedlicenses.no_strong_copyleftLevel 3
- Supportedruntime.artifact_matchesLevel 4
- Refutedruntime.no_external_egressLevel 4
- Unknownruntime.data.stays_on_hostLevel 4
Your source code is never shown. Anyone can check the signature with the independent verifier.
How It Works
Analyze → Claim → Proof → Passport → Verify
Analyze
Run ZKAV against your repository, license set, network topology or a running container — on your own machine with the CLI, so nothing leaves your infrastructure — or import a public repository into the hosted workspace (it is a temporary copy for analysis, removed after 7 days without use and deletable at any time).
Claim
State what should be true — a license policy, a network boundary, a runtime property — as a specific, falsifiable claim.
Proof
ZKAV evaluates the claim against what it actually observed and signs the result: supported, refuted, or honestly unknown — never invented.
Passport
Supported claims are assembled into a signed Technology Passport you can share with investors, customers or auditors.
Verify
Anyone can check the passport with the standalone verifier — no account and no source code needed. Proofs are checked against a circuit you pin; the current trusted setup is a development ceremony (see the roadmap).
See ZKAV In Action
Illustrative example — three outcomes, never a made-up confidence score
Claim Result
runtime.no_external_egressEvidence
9 verifiers we stand behind
The architecture-graph engine has 22 methods. Nine of them can name what observes the claim, what would refute it, and what they cannot see — so nine are enabled. The other thirteen are listed below with the reason.
A tool that answers everything answers some of it badly, and one bad proof devalues the rest.
Observed
Derived from your own architecture and schema — we saw this ourselves
- No Persistent Logs
- No Telemetry
- Data Stays Local
- Tenant Isolation
- Authorization on Path
- No Backdoor Path
- No External Connections
- No Direct DB Access
- No PII Leaving Perimeter
Declared
Your signed statement. We record and sign that you said it — we do not confirm it
- Encryption at Rest — a property of the disk, not of the topology
- Encryption in Transit — config shows intent, not the negotiated connection
Not answerable here
Named on purpose. Our silence on these is not evidence in either direction
- Known vulnerabilities — needs an SBOM and a CVE feed
- Supply chain — provenance lives outside your perimeter
- Secrets in logs — would require reading log content, which we refuse to do
- Rate limiting — presence is visible, effectiveness is not
- Admin access — infrastructure credentials bypass application topology
- GDPR / SOC 2 / HIPAA / ISO — a verdict belongs to a licensed professional
You don't have to show everything to prove something is true.
ZKAV lets you prove important properties of software and digital systems without revealing what you need to keep private.
Investors
Show investors the technology is real — without sharing your source code.
Due Diligence
Check the technical side of a project before a deal closes.
Security
Confirm properties of a system without exposing its internal details.
Software
Check code, dependencies and licenses.
Runtime
Confirm the version running in production is the version that was verified.
Privacy
Prove a required property without revealing the underlying data.
What a Passport Says
Illustrative example — three outcomes, not one score
Example Technology Passport
Illustrative — not a real system
runtime.artifact_matchesSupportedthe running container matches the attested build
runtime.no_external_egressSupportedno outgoing IP packet left the allowed networks during the capture window
licenses.no_strong_copyleftRefuteda GPL-licensed dependency was found in the inventory
runtime.data.stays_on_hostUnknowna shared volume neighbour was not independently observed
A refuted claim is not hidden and does not hide the rest of the passport. An unknown claim is not rounded up to supported. That is the whole point of showing three outcomes instead of one number.
Why ZKAV?
Not just another audit tool
| Feature | Traditional Audit | SAST/DAST | ZKAV |
|---|---|---|---|
| No Code Disclosure | |||
| Runtime Attestation (Level 4, requires Private Runner) | |||
| Independent Public Verifier | |||
| Signed Technology Passport | |||
| Honest "unknown" Outcome | Partial | ||
| Setup Time | Weeks | Hours | Minutes |
| Cost | $50k+ | $5k-50k | from $0/mo |
Simple Subscription Pricing
Explorer is free. Upgrade when you need more proofs, passports or runtime attestations.
Explorer
Try ZKAV
- 5 analyses/mo
- 10 proofs/mo
- 3 passports/mo
- No runtime attestations
- Public verifier
Developer
One developer
- 20 analyses/mo
- 5 audits/mo
- 20 passports/mo
- 5 runtime attestations/mo
- 1 monitoring node
Startup
Startups and founders
- 200 analyses/mo
- 50 audits/mo
- 100 passports/mo
- 30 runtime attestations/mo
- Private Runner (opt-in)
Business
Teams and SMBs
- 1,000 analyses/mo
- 250 audits/mo
- 500 passports/mo
- 150 runtime attestations/mo
- Private Runner included
Enterprise
Unlimited analyses, audits, passports, runtime attestations · Private Runner included · Custom entitlement policies · Dedicated support
High-Value Services
For serious due diligence, M&A and regulated deployments
Due Diligence Pack
PlannedAssisted technical review for investors — planned service, not yet offered
M&A Technical Review
PlannedTechnical review for acquisitions — planned service, not yet offered
White Label
PlannedZKAV without branding — planned service, not yet offered
Engineering Insurance
PlannedRisk assessment for insurers — planned service, not yet offered
Private Runner / On-Prem
customAnalysis and runtime observation run on your own infrastructure
ZKAV Developer Preview
Core verification, cryptographic proofs, passports, independent verification and commercial SaaS billing are working today. Production-grade infrastructure and enterprise capabilities are on the roadmap below.
Post-Preview Roadmap
What comes next, once the Developer Preview validates commercial demand
Production Trust
- Production-grade proving infrastructure
- Trusted setup / production cryptographic ceremony
- Key management and rotation
- External security assessment
More Runtime Verification
- Broader runtime environments
- Deeper runtime-bound claims
- Continuous verification
Enterprise
- Private Runner
- Organization & team workflows
- Enterprise audit exports
- On-prem / private deployment
Developer Platform
- CLI & API expansion
- CI/CD integrations
- GitHub/GitLab integration
- Automated verification pipelines
Trust Network
- Public verification
- Passport registry
- Revocation and status infrastructure
- Interoperable verification across products
ZKAV is currently available as a Developer Preview. The roadmap above represents planned product directions and may evolve as verification, security, and production infrastructure mature.
Ready to Build Trust?
Start verifying your software properties in minutes. No code disclosure required.
For companies
Startup or Business plan — analyze, prove, share a Technology Passport.
Create Technology Passport