Signed certificates. Cryptographic proof packs. Honest scope disclosure. Built for the AI code era — and every line written before it. From indie projects to enterprise, fintech to healthcare, defence to SaaS — if your code ships, Nucleus proves it was reviewed.
Public GitHub, GitLab, and Bitbucket repositories. Results in 15 seconds to 5 minutes depending on repository size. Large repos processed asynchronously.
Real scan of expressjs/express. All values deterministic and independently verifiable.
Full analysis report with gate results, security findings, code metrics, and improvement suggestions.
View Example →Ed25519 signed PDF certificate with cryptographic proof hashes, independently verifiable by anyone.
View Example →Downloadable proof pack containing all artifacts needed to independently replay and verify the result.
View Example →Paste the full AI response including code blocks. Nucleus will extract the code and verify the implementation against your claims.
Submit your code
Provide a public repository URL, upload a ZIP archive, or paste source code directly. Nucleus Verify clones the repository, indexes every file, and builds a complete artifact map before analysis begins.
Five verification gates
Every submission passes through 5 deterministic gates: Artifact Integrity (file tree hashing), Determinism (triple-ordering reproducibility), Contract Adherence (dependency and licence checks), Build Validation (config and manifest analysis), and Structural Integrity (architecture and complexity scoring). Each gate produces a pass/fail result with detailed evidence.
432 standard + 249 enhanced operators (681 total) across 8 packs
After gates pass, Nucleus runs its full operator suite across 19 source languages — scanning for security vulnerabilities, supply chain risks, compliance violations, code quality issues, and AI/LLM-specific risks. Business plans unlock 8 enhanced packs adding Semgrep (3,800+ rules across 65+ languages), a local 250,000+ CVE database, and AI-powered analysis. Each operator is a focused detection rule that produces structured findings with severity, location, and remediation guidance. Enterprise customers can request custom operators tailored to their specific compliance frameworks, internal policies, or industry regulations.
Signed certificate and proof pack
You receive a cryptographically signed verification certificate and a downloadable proof pack containing all gate results, operator findings, deterministic hashes, and scope disclosures. Anyone can independently replay the verification to confirm the result — no trust required.
GitHub Actions — verify on every push
Add Nucleus to your CI/CD pipeline in 3 lines. Verify every push and pull request automatically. Certificate posted to every PR. Works with GitHub Actions, GitLab CI, CircleCI, Jenkins — any pipeline that can call an API. View on GitHub →
Every repository passes through the same deterministic verification pipeline.
What Nucleus Verify does not check: runtime correctness, security vulnerabilities, business logic, performance, accessibility.
Real result from a public repository verification. All values are deterministic and reproducible.
Every verification run produces the same cryptographic hashes for the same input. You can independently replay any proof pack to confirm the result.
Same repository, same seed, same hashes. Always.
When AI claims it built something, Nucleus Verify checks if the structural evidence actually exists in the code.
Real finding from a verification run. The AI claimed it implemented file upload, but the code contained no upload handling, multipart parsing, or file storage logic.
915 public repositories. Python and JavaScript ecosystems. Zero consistency errors.
A system that verifies 41% of real-world repositories is honest. A system that verifies 90% is lying.
Every certificate explicitly lists what was not verified. Honest disclosure is a core design principle.
Verify AI-generated code before it ships. Certificate in every PR. Know exactly what was built vs what was claimed.
Structural gaps caught before production. Audit trail for every decision. Trust scores you can track over time.
SOC 2 ready. PostgreSQL audit log. Ed25519 signed. Independently replayable. Full chain of custody.
| Feature | CodeQL | SonarQube | Snyk | Nucleus Verify |
|---|---|---|---|---|
| Finds vulnerabilities | ✓ | ✓ | ✓ | ✓ |
| Cryptographic signing | ✗ | ✗ | ✗ | ✓ |
| Independent replay | ✗ | ✗ | ✗ | ✓ |
| Tamper-evident chain | ✗ | ✗ | ✗ | ✓ |
| Honest scope disclosure | ✗ | ✗ | ✗ | ✓ |
| DORA / FCA evidence | ✗ | ✗ | ✗ | ✓ |
| Works alongside existing tools | — | — | — | ✓ |
Nucleus Verify finds vulnerabilities and produces cryptographically signed proof that the review happened — independently verifiable by anyone. It works alongside your existing tools or as a complete verification solution on its own.
Start free. Scale when you're ready.
Need just one certificate? $4.99 one-time per verification. Available on the result page.
For enterprise enquiries, custom plans, or volume pricing contact contact@altermenta.com