FINIPE FINIPE Fini Proof™
Proof-based code verification

Green CI is a promise.
Fini Proof™ is the evidence.

Developers and AI agents now write code faster than anyone can review it. Fini Proof checks every change in your own CI. Each finding comes with a command that reproduces it, and each check is tested against a planted bug to show that it can actually fail.

6 checks 54/54 planted bugs caught Runs in your CI · code never leaves
~/orders-service · pull request #214
$ npx fini-proof check --base origin/main
  engines  hollow-tests secrets fail-open skip-ratchet tenant-filter migrations
  controls 54/54 planted defects caught before scanning

  HIGH  src/orders/order.service.ts:42  TENANT_FILTER_MISSING
        orderRepository.findOne() on multi-tenant table orders
        has no tenant_id filter: one customer can read another's order.
        proof: fini-proof prove --engine tenant-filter --file src/orders/order.service.ts --line 42

  HIGH  test/refund.spec.ts:18  HOLLOW_TEST
        test has no assertion: it passes whatever the code does.

VERDICT: FAIL 2 blocking · 6/6 engines measured · evidence .fini-proof/runs/9c1e…json

$ git commit -am "scope order lookup by tenant, assert refund"
$ npx fini-proof check --base origin/main
VERDICT: PASS 0 findings · 6/6 engines measured 
Runs in your CI · code never leavesEvery finding reproducible54/54 planted bugs caughtMade in India · Startup India (DPIIT)

The problem

Code is written faster than it can be checked.

A reviewer reads the diff and trusts the green tick. The expensive bugs sit where the tick is lying.

01

Tests that cannot fail

An AI agent asked to "add tests" often writes tests with no real assertion. Coverage goes up, CI goes green, and nothing is protected.

02

One customer sees another's data

In multi-tenant SaaS, one query without a tenant filter is a data leak and a DPDP Act incident. It looks like any other line in the diff.

03

A green CI that never ran

A step with || true, a skipped suite or a .only left in by mistake. The pipeline reports success because nothing was checked.

How it works

Other reviewers comment. Fini Proof proves.

A check that has never been seen to fail is not evidence. So before any check reads your code, it has to catch a bug we planted.

  1. Prove the check can fail

    Each engine runs against planted defects (negative controls) and clean samples (positive controls). If it misses one, it reports NOT_MEASURED. It never reports a pass.

  2. Scan the change

    In a pull request only the changed files are judged, so old debt does not block new work. Existing migrations and skips are recorded once as a baseline.

  3. Hand over the proof

    Each finding has its file, line, rule, a fix, and a prove command that reproduces it. The run writes an evidence file with a hash of every input.

FAIL · HIGHsrc/orders/order.service.ts:42

TENANT_FILTER_MISSING. orderRepository.findOne() on the multi-tenant table orders has no tenant_id condition. Any tenant's request can reach every tenant's rows.

Fix
Add the tenant condition from the signed-in context, not from user input.
Reproduce
fini-proof prove --engine tenant-filter --file src/orders/order.service.ts --line 42
Check proven by
tenant-filter/NC-2: a planted unscoped findOne that the engine must catch on every run
Deliberate exception
// fini-proof: tenant-exempt platform-admin report (SEC-19), with the reason kept in code review
PASS

Every engine ran, every control behaved, and no blocking finding remains.

FAIL

At least one blocking finding. Each one names its file and line and comes with its proof.

NOT_MEASURED

Something could not be checked: an unreadable file, a missing base branch, or a check that missed its planted bug. We never turn "could not check" into a pass.

Six checks, each with its own planted bugs

The defects that get past review.

These are deterministic engines, not a language model's opinion. The same input always gives the same verdict, and you can reproduce every result offline.

hollow-tests

Tests that test nothing

Finds tests with no assertion, or only constant assertions, in JS/TS, Python and more.

it('refunds the order', async () => {
  await refund(order.id)
})
HOLLOW_TESTHIGH
tenant-filter

Cross-tenant data leaks

A query on a multi-tenant table with no tenant condition. Reads your schema to find which tables hold tenant data.

prisma.invoice.findMany({
  where: { status: 'DUE' },
})
TENANT_FILTER_MISSINGHIGH
migrations

Dangerous migrations

Dropped tables and columns, type rewrites, NOT NULL with no default, and migrations with no way back.

ALTER TABLE "Order"
  ADD COLUMN "region" TEXT NOT NULL;
ADD_NOT_NULL_NO_DEFAULTHIGH
fail-open

CI that passes by accident

Pipeline steps whose failure is swallowed, and entry-point guards that silently skip the real work.

- run: npm test || true
FAIL_OPENHIGH
secrets

Committed secrets

Keys and tokens in code or config. The report never prints the full secret back.

const stripe = new Stripe(
  'sk_live_51H…')
SECRET_COMMITTEDHIGH
skip-ratchet

Quietly skipped tests

Existing skips are recorded once. After that the count can only go down, unless someone writes down why.

it.skip('charges GST on delivery', …)
describe.only('happy path', …)
SKIP_RATCHETHIGH

Guardrails for AI coding agents

The agent that wrote the code does not decide when it is done.

Claude Code, Codex, Cursor and Copilot are fast. They are also happy to report "all tests pass" about tests that assert nothing. Fini Proof sits between the agent and "done".

Claude Code hooks

A Stop hook blocks the agent from finishing while the verdict is FAIL or NOT_MEASURED, and gives it the findings to fix. A PostToolUse hook checks each file the moment it is written.

MCP server

fini-proof mcp gives any MCP client three tools: check, explain_finding (re-runs the proof) and list_rules. It uses the same licensed path and evidence as the CLI.

Codex and any agent

An AGENTS.md section plus a CI gate. The gate also fails a pull request in which the agent edits the checker's config or baseline, unless a human approves.

Loop guard

If an agent keeps failing, it is allowed to stop after a set number of attempts. You are then told plainly that the work is not verified. It is never passed off as done.

You can tell the agent to "make CI green". It cannot switch off the check that decides.

Works where you already work

One command in the pipeline you already have.

CLI (Node 20+) GitHub Actions GitHub App · check runs + annotations early access GitLab CI Jenkins Bitbucket Pipelines GitLab / Bitbucket app beta MCP server Claude Code OpenAI Codex SARIF · JSON · text IDE extension planned
# .github/workflows/fini-proof.yml  (GitLab, Jenkins and Bitbucket have one-line templates too)
- uses: actions/checkout@v4
  with: { fetch-depth: 0 }
- run: npx --yes fini-proof@0.3.0 check --base origin/${{ github.base_ref }} --sarif-out fini-proof.sarif
  env: { FINI_PROOF_LICENCE: ${{ secrets.FINI_PROOF_LICENCE }} }

Where it fits

Built to sit next to your existing tools.

Keep your linter, your SAST scanner and your AI reviewer. Fini Proof answers a different question: can this green result be trusted?

AI review commentsLinters and SASTFini Proof
What you getSuggestions written by a language modelPattern matches against known rulesFindings with a command that reproduces each one
Can the check itself be trusted?Not shownUsually assumedEach engine must catch planted bugs on every run, or the result is NOT_MEASURED
Same input, same answerCan vary between runsYesYes, with an evidence file that hashes every input
Tests that assert nothingSometimes noticedRarelyDedicated engine
Cross-tenant data accessSometimes noticedGeneric rules onlySchema-aware: knows which of your tables are multi-tenant
Stops an AI agent declaring "done"NoNoClaude Code hooks, MCP, Codex gate
Where your code goesOften to a vendor cloudVariesNowhere. It runs in your CI or VPC

Categories are described in general terms; individual products differ. Fini Proof is designed to be bought alongside an existing SAST or SCA tool, not instead of one.

Security and your data

Your code stays in your building.

  • Runs inside your CI or VPC. The engines are deterministic and need no model call, so your source is never uploaded.
  • Offline licence. An Ed25519-signed licence file is checked locally, which also works for air-gapped sites.
  • No lock-in. Results come out as JSON and SARIF 2.1.0, so you can keep them if you ever leave.
  • Evidence you can audit. Each run records the engine versions, the hash of each input file and the verdict, so a reviewer can re-check it later.
  • Secrets stay secret. A detected key is never printed in full in reports.

Where we are today

Plain status, no inflated claims.

We are an early-stage product from Finipe, a Startup India (DPIIT) recognised company. Here is what is done and what is not.

READY CLI, 6 engines, SARIF/JSON output, CI templates, MCP server, Claude Code and Codex integration
EARLY ACCESS GitHub App (check runs + annotations); GitLab and Bitbucket apps in beta
PLANNED IDE extension; SOC 2 readiness begins after our first production customers. We are not certified today.

What changes for your team

Less time reviewing. More reason to trust the release.

CTO / Head of engineering

Adopt AI coding without the blind spot

  • Let agents write more of the code while a check you control decides what counts as done.
  • One evidence file per release for audits, clients and DPDP questions.
  • A clear pass/fail signal across teams and vendors.
QA lead

Stop trusting coverage numbers

  • Find the tests that pass whatever the code does.
  • Stop skipped tests piling up without anyone deciding.
  • Spend manual testing time where the proof says the risk is.
Developer

Findings you can act on in minutes

  • File, line, rule and fix, plus one command to reproduce it.
  • Only your change is judged, not years of old debt.
  • Exceptions are written next to the code, with a reason your reviewer can see.
IT services delivery head

Hand over code you can defend

  • Attach proof of verification to every client delivery.
  • Per-repository pricing that fits a fixed-bid project.
  • Fewer escaped defects and fewer disputes at acceptance.

Estimate it yourself

What review time is worth to you.

These are your own assumptions, not a measured result. The pilot measures real hours saved on your repository.

Return on subscription
5.8×
Time value per month₹17.3 L
Team plan per month (annual)₹3.0 L
Break-even per developer per week21 min

Uses 4.33 weeks per month and the Team price of ₹1,499 per active contributor per month, excluding GST.

Pricing in Indian rupees, excluding 18% GST

Start with a pilot. Pay for people who ship.

An "active contributor" is a person or agent identity that authored at least one verified change in the month. You do not pay for inactive seats.

START HERE

Free trial

₹014 days, 1 repository
  • All 6 engines, CLI and CI templates
  • Claude Code, Codex and MCP integration
  • Sign up with your Finipe account
Start free trial
MOST TEAMS BEGIN HERE

3-week pilot

₹1,50,000fixed, 1 repository · 100% credited to year one if you convert within 60 days
  • Full engine run and triage with our engineers
  • Proof for every finding and a measured false-positive rate
  • Measured hours-saved report and a go/no-go readout
Book a pilot
AFTER THE PILOT

Team

₹1,499per active contributor per month, annual (₹1,799 monthly)
  • PR verification and CLI
  • 40 verified changes per contributor per month, pooled; ₹15 per extra change
  • Hosted in India on Finipe Cloud, or in your own CI
Talk to us
Repository · ₹29,999 per repository per month. Up to 30 active contributors on one repository. Easy to price into a fixed-bid client project.
Enterprise VPC from ₹30 lakh per year · On-premises from ₹60 lakh per year. Runner in your cloud or air-gapped, SSO/SAML, audit export, custom gates. Indicative prices, confirmed after a scoping call.

Design-partner offer for our first two customers: pilot at ₹75,000 and year-one Team pricing locked at ₹1,299, in exchange for a reference case study and monthly product feedback.

Coming for enterprise teams

Run the whole engineering organisation on FINIPE™.

Fini Proof™ is the first FINIPE product for IT companies. These are being built on the same FINIPE platform and are not available yet. Pilot customers get early access.

UPCOMING

Company admin portal

  • Your team, roles and permissions in one place
  • Seats, repositories and licences
  • Usage and verification history per project
  • One sign-in with your FINIPE account
UPCOMING

FINIPE CRM

  • Clients, deals and projects for IT services firms
  • Proof reports attached to each client delivery
  • Pipeline from enquiry to invoice
UPCOMING

FINIPE HRMS

  • Employees, attendance, leave and payroll
  • Developers join Fini Proof straight from the employee directory
  • Access removed automatically when someone leaves

FAQ

Questions teams ask before a pilot.

Anything else? Ask in the pilot call. We will show you on your own code.

How is this different from an AI code reviewer?

An AI reviewer writes comments that a language model thinks are useful, and they can change from run to run. Fini Proof runs deterministic checks. Each finding comes with a command that reproduces it, and each check must catch planted bugs before its silence counts. The two work well together.

And from a linter or a SAST scanner?

Linters check style and SAST tools check known vulnerability patterns. Fini Proof looks for things that make a green result untrustworthy: tests that cannot fail, CI steps that swallow errors, skipped suites. It also checks two costly SaaS risks: cross-tenant queries and destructive migrations. Keep your SAST tool.

What about false positives?

We measure them on real code. Each engine is tuned against public open-source SaaS repositories, and we can share the report on request. When a query looks unscoped but there is a sign of a check nearby, it is reported as UNPROVEN (low, non-blocking), not HIGH. The pilot report gives you the measured false-positive rate on your own repository.

Does my code leave my network?

No. The engines run inside your CI runner or VPC and need no model call. The licence is verified offline. Nothing is uploaded unless you choose Finipe Cloud hosting.

Your code is never used to train or fine-tune any model. To improve the checks we use anonymised check results only: which rule fired or missed, on which language and framework, and how long it took. File paths, names and code are removed first. Enterprise and VPC contracts can switch this off.

Which languages and frameworks are supported?

JavaScript and TypeScript (Node, NestJS, Next.js; TypeORM, Prisma, Sequelize-style, Knex) and Python (Django, SQLAlchemy, Alembic, pytest, unittest). Raw SQL is checked in Java, Go, PHP, C# and others. Migrations are covered for plain SQL, Flyway, golang-migrate, goose, dbmate, Prisma, TypeORM, Knex, Alembic and Django. Tell us your stack: new engine targets come from pilots.

What does NOT_MEASURED mean?

It means we could not check something: an unreadable file, a missing base branch, or an engine that missed its planted bug. Most tools would stay silent and let that count as a pass. We report it, so a skipped check can never pass as a clean one.

How do the AI agent guardrails work?

For Claude Code we ship hooks. The Stop hook blocks the agent from finishing while the verdict is FAIL or NOT_MEASURED and gives it the findings to fix. For any MCP client there is a check tool. For Codex and other agents, an AGENTS.md section plus a CI gate. The gate also fails the pull request if the agent edits the checker's configuration or baseline without human approval.

How long does setup take?

A first run is one command. For a CI gate you add one step and run fini-proof baseline once, which records existing skipped tests and already-applied migrations so that only new changes are judged. For the tenant check you confirm your tenant column and any shared query helpers during onboarding.

What if something is flagged on purpose?

Write the exception next to the line with a reason, for example fini-proof: tenant-exempt platform-admin report or fini-proof: allow DROP_COLUMN CHG-812. It stays visible in code review. There is no hidden ignore list.

How does pricing work, and is there a trial?

There is a 14-day free trial on one repository, with sign-up through your Finipe account. Most teams then run a fixed ₹1,50,000 three-week pilot, which is fully credited to year one if they convert within 60 days. After that it is ₹1,499 per active contributor per month on annual billing, or per repository for project teams. Prices exclude GST.

Are you SOC 2 or ISO 27001 certified?

Not yet, and we will not claim to be. We begin SOC 2 readiness after our first production customers. Until then, the product is designed so that certification matters less: it runs in your environment, sends out no code and needs no model call.

Who is behind Fini Proof?

Finipe, an Indian company recognised under Startup India (DPIIT). The checks come from the verification gates we built for our own platform, where every gate must show it can fail before it is trusted.

What support do we get?

During a pilot you work directly with our engineers on triage. Enterprise plans include a named success engineer and an SLA. Team plans get email support in Indian business hours.

Run it on your worst repository.

Sign up with your Finipe account, run one command, and see what your green CI has been hiding. If you want us in the room, book the pilot.