Skip to content
You must be logged in to sponsor DrVelvetFog

Become a sponsor to Antoni (Tony) Jagodka

Most of what software teams call "review evidence" is an assertion: a green checkmark, a vendor log, a screenshot of an approval. I build tools that replace assertions with something a third party can recompute.

The flagship is source-review-coverage, a GitHub Action that issues one signed in-toto attestation per merge: which tree each approval covered, which tree actually shipped, and how one became the other. Anyone with git can replay it offline — no vendor, no dashboard, no trusting the party being audited. The interesting part is the failure case: when bytes ship that no approval covered (a hand-resolved conflict, a push after the last approval), the verifier emits the exact diff, because those lines were reviewed by nobody, by construction. That question — what did the agent change and who reviewed it — is starting to arrive from auditors instead of colleagues, and it deserves a better answer than a screenshot.

Around the flagship sit smaller tools in the same spirit: reversible (undo for what shell commands did to your files), evidence-tier (per-claim provenance: ran it, read it, was told it, recalled it, inferred it), and verified-examples (docs examples CI actually re-runs and attests, instead of hoping they still work).

I hold the work to its own standard: the spec is public, the verifier states plainly what a pass does not establish, and the repo runs its own action on every merge. Upstream, a fix of mine is merged in sigstore-python and the predicate is proposed at in-toto/attestation.

Sponsorship buys maintenance: the fortnightly release train, reviewing and integrating external contributions (credited by name), and the slow careful work of keeping a verifier honest. The organization tier gets priority on issues. If your team is starting to be asked for evidence about AI-written changes, sponsoring keeps the tool that answers that question alive and independent.

@DrVelvetFog

At 5 sponsors, the fortnightly release train stops being a spare-time promise and becomes a funded commitment: releases every two weeks, external contributions reviewed and credited, and the verifier held to its own spec.

Featured work

  1. DrVelvetFog/sui-x402-facilitator

    An independent x402 facilitator on Sui — non-custodial verify/settle for the Sui exact scheme. Live at sui-facilitator.onrender.com

    TypeScript 1
  2. DrVelvetFog/source-review-coverage

    in-toto attestation predicate: evidence that a source revision was covered by the review it claims

    Python
  3. DrVelvetFog/reversible

    rv — reversible shell actions: git-tree snapshots, append-only journal, per-path undo. Closes the gap Claude Code checkpointing documents.

    Python
  4. DrVelvetFog/x402-verified-agent

    The verified-resource gate for the Sui agent economy — x402 payment + PoR unique-human + Walrus memory + local inference. Trust-minimized: non-custodial, on-chain-verifiable, local inference.

    TypeScript
  5. DrVelvetFog/uig-studios-ai

    UIG Studios AI — local-first desktop AI agent you can check up on: undo for shell commands, code-stamped evidence tiers, verified examples, OKF memory, safety gates that don't depend on the model. …

    JavaScript

0% towards 5 monthly sponsors goal

Be the first to sponsor this goal!

Select a tier

$ a month

You'll receive any rewards listed in the $5 monthly tier. Additionally, a Public Sponsor achievement will be added to your profile.

$5 a month

Select
  • Get a Sponsor badge on your profile
    The keep-it-alive tier. This funds the fortnightly release train, review and integration of external contributions, and the upkeep of a verifier that holds itself to its own spec. Most sponsorships land here, and every release ships because of them.

$10 a month

Select

-"Your name in the release notes"
Everything in the $5 tier, plus your name or handle in the thanks section of the release notes, alongside the contributors — releases ship every two weeks and credit people by name.

$100 a month

Select
  • Logo or name on project website
  • Have your bug reports prioritized
    For teams that rely on the tools. Your issues and bug reports go to the front of the queue, and your name or logo goes on the project site. If your organization is starting to be asked for evidence about AI-written changes, this keeps the tool that answers alive — and gets your problems with it fixed first.