Skip to main content

Trust

What Verify does, and exactly what it avoids.

No compliance badges, no absolute security claims. These are the verified operating facts and their residual risks.

Local execution

Orchestration runs on your Windows machine in Windows PowerShell 5.1 or PowerShell 7+. No additional PowerShell module or package-manager installation is required; Git remains required, and Claude Code CLI is required for Execute mode.

Outbound data boundary

In Execute mode the Claude Code CLI adapter runs through your own Claude Code CLI account. There is deliberately no separate NovarraAI cloud service, hosted queue, or SaaS backend.

No telemetry, no licence check, no update check

The examined release performs no Supervisor telemetry, no licence check, and no update check. Product delivery accounts are not part of V1.

No automatic Git integration

A read-only Git wrapper observes repository changes and refuses stage, commit, push, merge, rebase, reset, clean, checkout, stash, tag, fetch, and pull. Nothing integrates itself.

Repository state is checked

Verification observes repository changes through a read-only Git chokepoint and evaluates configured evidence before a completion outcome is available.

Reviewer mutation is constrained

The reviewer is a fresh context separated from the writer. Verified Git mutation and integration operations remain blocked. No broader reviewer-write-isolation claim is made without refreshed artifact evidence.

Reviewer

Reviewer separation is enforced in the workflow.

  • A writer has no direct state transition to DONE.
  • Only the reviewer stage can reach DONE.
  • A separate, fresh reviewer context evaluates the work against the configured evidence criteria; this is process separation, not third-party certification.
  • Deterministic machine checks run before completion can be accepted.
  • Protected-path human gates require your applicable decision before work proceeds.
  • DONE is a review outcome, not proof of correctness.

Evidence

State and recovery stay on your machine.

The examined release supports persistent state and recovery, so a run can pick up again after an interruption. Evidence and state live in the working repository tree, and the reader of this page decides how long to keep them. DryRun is the default and writes no runtime state.

Residual risks

Nothing here removes your judgment.

  • The product is a release candidate; the final customer package and fresh package-verification evidence remain open.
  • It does not guarantee correctness, security, safety, or production readiness.
  • Claude Code CLI compute and network behavior is governed by the environment and account you configure.
  • No independent external usability test has been performed yet.
  • Commercial paid launch is NO-GO while the launch gates remain open.
  • PASS does not guarantee absolute correctness, security, compliance, safety, or production readiness.
  • Post-review integrity and final-package verification will be claimed only after they are rerun against the exact customer archive.

Trust the evidence, not the assertion.

Review the demo criteria and current scheduling status. Any walkthrough will remain tied to authentic product behavior.