The schema and CLI are open forever. The hosted verification tier — clean-room benchmark execution, cryptographic signing, and the registry badge — is the commercial product.
Yes. The schema spec, the CLI, and the local verify command will always be free and open-source. The commercial product is the hosted verification service — re-running your benchmarks in a clean environment so the trust score is independently attested.
We clone your repo at the tagged commit into an isolated container with no network access, run the reproducibility.command from each benchmark, and compare the output to the value you declared. If it matches, the benchmark is independently confirmed. The result is signed with our key.
Enterprise tier includes dedicated runners with configurable timeouts. For the Verified tier, benchmarks with "deterministic": false or runtimes over 30 minutes are flagged as unverified rather than failed — your card stays valid.
Install the app on your repo. Every PR that touches capability_card.json gets a status check — schema valid, trust score, and a diff of what changed. Merging a card that degrades trust score requires explicit override.
The hosted verification service is in development. Join the waitlist and we'll reach out when your spot is ready — early access is free for the first 90 days.
No spam. One email when you're in.