Become a sponsor to Antoni (Tony) Jagodka
Most of what software teams call "review evidence" is an assertion: a green checkmark, a vendor log, a screenshot of an approval. I build tools that replace assertions with something a third party can recompute.
The flagship is source-review-coverage, a GitHub Action that issues one signed in-toto attestation per merge: which tree each approval covered, which tree actually shipped, and how one became the other. Anyone with git can replay it offline — no vendor, no dashboard, no trusting the party being audited. The interesting part is the failure case: when bytes ship that no approval covered (a hand-resolved conflict, a push after the last approval), the verifier emits the exact diff, because those lines were reviewed by nobody, by construction. That question — what did the agent change and who reviewed it — is starting to arrive from auditors instead of colleagues, and it deserves a better answer than a screenshot.
Around the flagship sit smaller tools in the same spirit: reversible (undo for what shell commands did to your files), evidence-tier (per-claim provenance: ran it, read it, was told it, recalled it, inferred it), and verified-examples (docs examples CI actually re-runs and attests, instead of hoping they still work).
I hold the work to its own standard: the spec is public, the verifier states plainly what a pass does not establish, and the repo runs its own action on every merge. Upstream, a fix of mine is merged in sigstore-python and the predicate is proposed at in-toto/attestation.
Sponsorship buys maintenance: the fortnightly release train, reviewing and integrating external contributions (credited by name), and the slow careful work of keeping a verifier honest. The organization tier gets priority on issues. If your team is starting to be asked for evidence about AI-written changes, sponsoring keeps the tool that answers that question alive and independent.
Featured work
-
DrVelvetFog/sui-x402-facilitator
An independent x402 facilitator on Sui — non-custodial verify/settle for the Sui exact scheme. Live at sui-facilitator.onrender.com
TypeScript 1 -
DrVelvetFog/source-review-coverage
in-toto attestation predicate: evidence that a source revision was covered by the review it claims
Python -
DrVelvetFog/reversible
rv — reversible shell actions: git-tree snapshots, append-only journal, per-path undo. Closes the gap Claude Code checkpointing documents.
Python -
DrVelvetFog/x402-verified-agent
The verified-resource gate for the Sui agent economy — x402 payment + PoR unique-human + Walrus memory + local inference. Trust-minimized: non-custodial, on-chain-verifiable, local inference.
TypeScript -
DrVelvetFog/uig-studios-ai
UIG Studios AI — local-first desktop AI agent you can check up on: undo for shell commands, code-stamped evidence tiers, verified examples, OKF memory, safety gates that don't depend on the model. …
JavaScript
0% towards 5 monthly sponsors goal
Be the first to sponsor this goal!
$5 a month
Select- Get a Sponsor badge on your profile
The keep-it-alive tier. This funds the fortnightly release train, review and integration of external contributions, and the upkeep of a verifier that holds itself to its own spec. Most sponsorships land here, and every release ships because of them.
$10 a month
Select-"Your name in the release notes"
Everything in the $5 tier, plus your name or handle in the thanks section of the release notes, alongside the contributors — releases ship every two weeks and credit people by name.
$100 a month
Select- Logo or name on project website
- Have your bug reports prioritized
For teams that rely on the tools. Your issues and bug reports go to the front of the queue, and your name or logo goes on the project site. If your organization is starting to be asked for evidence about AI-written changes, this keeps the tool that answers alive — and gets your problems with it fixed first.