CounterProof

Finding got cheap. Proving got hard.

CounterProof is an independent adversarial review practice for modern codebases — machine-written code above all. We deliver the one thing you cannot produce in-house: an independent, signed, evidence-graded security assessment, built for the scrutiny of regulators, acquirers, insurers, and enterprise customers.

Code written by a model and reviewed by the same model has been reviewed by nobody.

01

Why you're here

Nobody buys a code review. They buy what it unlocks.

You're not reading this because you woke up wanting a security assessment. Something is asking you for evidence.

A regulator
The EU Cyber Resilience Act requires you to “apply effective and regular tests and reviews of the security” of your product (Annex I Part II(3)), and your technical documentation must contain “reports of the tests carried out to verify conformity” (Annex VII(6)) — kept for at least ten years after placing on the market, or the support period if longer (Article 13(13)). Article 14 notification of actively exploited vulnerabilities and severe incidents starts 11 September 2026; the Regulation applies in full from 11 December 2027. Most products may self-assess — which is not relief, it is exposure: the burden of producing records that stand up falls entirely on you.
An acquirer or investor
Technical diligence is where AI-assisted codebases now get discounted. An independent assessment on the table changes that conversation before it starts.
A cyber-insurer
Underwriters increasingly price the gap between “we test internally” and “an independent party tested and signed.”
An enterprise customer
Their security questionnaire has no checkbox for “our model reviewed its own output.”

Three of these four never accept your own word about your own code — independence is the property they are buying, and it is the one property no team can supply for its own work. The fourth, the regulator, will often take your self-assessment — and then hold you to every record behind it. Either way the evidence has to hold. That is what we produce.

02

What you get

The deliverable is the point.

An engagement produces a CounterProof Assessment under a persistent engagement identifier (CPR-YYYY-NNN — what your maintainers, your acquirer, or your fix commits cite). Every finding is either confirmed against your source — exact file and line, reproduction path, impact classification — or explicitly graded as plausible-only. Nothing padded, nothing scanner-generated, nothing you can't act on.

Every finding names the evidence rung it actually reached — source trace, compile-proof, test, or live reproduction — and never implies a higher one. Every path:line citation is machine-resolved against the exact revision we reviewed before the report leaves our hands. You can check our work. That is deliberate.

To an authority
Structured to be included in your technical documentation as an Annex VII(6) test report, evidencing the Part II(3) testing duty. It supports the file you assemble; it is not the file, and it does not verify conformity across Annex I.
To a diligence team
Evidence-graded, reproducible, scoped, with our name on the risk.
To your own engineers
Short enough to read, precise enough to fix. We can stay through the patch and independently verify each fix against the finding it targets, recording what we verified and at which revision — so you end with a record of what was checked, not a list of notes.
03

Why this can't be done in-house

You could run the same models. You can't be independent.

Running multiple AI models over your own code replicates our tooling and loses the property that matters. Your team chooses what the reviewers see, frames the questions, and judges the answers — and every one of those choices carries your assumptions straight back into the review. That is not a discipline failure; it is structural. The author of a system cannot be its own adjudicator.

So even a flawless internal review is still your own word about your own code. What they are buying is a third party willing to sign. We are not a notified body and we do not certify conformity; we produce the independent evidence that supports your assessment and is structured to be re-examined by anyone else's.

The method doesn't care who — or what — wrote your code. Independence is missing from human-written code just as often. Machine-written code only makes the gap impossible to ignore.

04

The disclosure that comes with that

You would find this anyway. Better you hear it from us.

CounterProof is part of a group that builds payment and digital-asset custody infrastructure. That is where this method was forged — and it means that if you build in those markets, our affiliate may be adjacent to you, or competing with you.

So: before any engagement, we tell you exactly what the group builds and where it operates, in writing. You decide whether that is acceptable, and you decide before you have paid us anything. If it is not acceptable, that is a legitimate answer and we would rather hear it at the start.

What our independence claim does and does not cover, precisely: we do not issue an assessment on code authored by CounterProof or by any company in our group. That boundary is structural. It is a statement about whose code we review, not a claim to have no commercial interests anywhere near your sector — no review firm with real domain expertise can honestly claim the latter, and we are not going to pretend otherwise.

05

Who we are

Two people, named, on the record.

A signed assessment means someone's name is on it. These are the names.

Vincent Soons
Upstream contributor to Fedimint, the federated Bitcoin custody protocol — public contributions, checkable by anyone who wants to. Builds the reproduction harnesses and leads the cryptographic and consensus review.
Luuk Soons
Building in Bitcoin and sound-money infrastructure since 2013. Owns the method, the regulatory posture, and every disclosure decision — including the one above.

We are father and son, and we are two people. Both are facts a diligence team turns up on its own, so we would rather say them here: a two-person practice takes fewer engagements than a firm, declines everything outside its domain, and cannot hide a weak pass behind a brand. That is the trade, and it is the reason the method is written down and mechanised rather than carried in someone's head.

06

Notes

What we are reading in the Regulation.

All notes →

07

Talk to us before the deadline does.

counterproof@protonmail.com