For buyers
They will not show you the code. You can still check it.
Asking for repository access is reasonable. Refusing to hand it to someone who might not buy is also reasonable. A certificate is the third answer: a graded, evidence-backed read on the code, at a link you can check yourself, without anybody handing over source.
Nothing here needs an account. The seller starts it, and the first part is free for them.
Struck code certificate· Loopnote
VC-01J9XKQ2 · commit 9f3c1a · 6 Aug 2026
0 critical · 9 high · 8 medium · 3 of 7 claims verified
Every certificate has a public verify page. Open one and check it against the listing yourself.
Ask the seller. It costs them nothing to start.
We need a read-only connection to the repository, and only the owner can grant that, so this begins with them. The ask is small and the refusal is informative: a seller who will not connect a read-only scan of one commit has told you something a longer conversation would not.
- 1
They connect one repository, read-only
Not an account on their GitHub, not write access, and not their other repositories.
- 2
It is analysed at one commit, then the machine is destroyed
Their source is never kept and never trains a model. Findings, short excerpts, and hashes survive.
- 3
They see about a third of the findings free
They decide whether to publish after reading it. The full report and the certificate are $299.
Before we go further, would you be willing to run a Struck Code certificate on the repository? It is read-only access to one repo at one commit, they do not keep your source, and the first part of the report is free, so you can see what it says before you spend anything. It gives me a graded read on the code with the evidence attached, without you giving me or anyone else access to it. https://struckcode.com
Send it as it is, or write your own. Either way the link goes to the seller rather than to you, because the connection has to come from their side.
What a certificate answers
Nine graded dimensions, weighted for a change of owner rather than for code taste, on top of an inventory of what you are actually buying. The heaviest one is whether the features in the listing exist in the code at all.
Billing and AI economics only apply to products that have them. When they do not, the remaining weights renormalize rather than scoring a zero for something the product was never trying to do.
Read the methodology, MV-2026.3Inventory and architecture
What you are actually buying
- 25%
Claims and functionality
Do the advertised features actually exist in the code
- 20%
Security
Can someone reach data or money they should not
- 10%
Billing integrity
Does the paywall actually hold
- 10%
Code quality and maintainability
How hard will this be to work on
- 10%
Tests and CI
Can you change it without breaking it
- 10%
Dependencies, licensing and IP
Can this be sold and kept running
- 10%
Operability and transferability
Can a new owner run it without the founder
- 5%
Provenance and bus factor
Where did this code come from
- 8%
AI and LLM economics
Do the AI features have a viable cost structure
And what it does not
The boundary is printed on the certificate itself and repeated in the report. Treat any diligence product that will not tell you where it stops as a product that has not thought about it.
Revenue, MRR, and churn
We read source code, so we could not audit a bank statement if we wanted to. The marketplace's Stripe connection is what verifies money, and a code certificate that implied otherwise would be worth less, not more.
Anything after the certified commit
A certificate is a point-in-time read, bound to a commit fingerprint. Code written afterwards is not covered by it, which is why a stale issue date matters and why you can ask for a rescan.
Whether the price is fair
The grade tells you what condition the asset is in and what the fixes would cost you. What it is worth to you is your call and your advisor's.
The seller paid for it. Why is it worth anything to you?
It is the right question, and the answers are structural rather than promises. Nothing below depends on us being nice about it.
Check a live certificateThe methodology is published
Every check, weight, and cap is public and versioned. You can read what a B- means before you ask.
No model produces a number
Models find things. Scoring is a pure function over those findings, so the same input scores the same.
Every report prints its ledger
Each deduction is itemised, so you can recompute the grade by hand if you want to.
Every finding cites evidence
File, line range, and a snippet checked against the real tree. Findings that do not check out are dropped.
The certificate is always issued
We do not withhold a bad grade, so there is no version of this where paying more buys a better result.
It is bound to a commit
Rewriting the code after certification cannot improve the grade. It can only make the certificate stale.
Or take the seller's money out of it
Who pays does not change the instrument. Scoring is deterministic, the certificate is issued whatever the grade, and the methodology is public, so there is nothing for the money to move. If you would rather remove the question anyway, pay for the scan yourself. You get a link, the seller connects the repository, and claiming it is how they agree you see the report.
Unclaimed after 30 days, we refund you without being asked.
No account, no subscription, no buyer fee
- Selling now
You are listed, or listing this month
Get the graded certificate a buyer can check without you handing the repository to anyone.
Read this instead - Selling later
You will sell, but not yet
Find out what a buyer will find while there is still time to fix it. A grade now is a to-do list.
Read this instead - Buying
You are looking at someone else's listing
The seller will not show you the code. Ask them for a certificate instead. It is free to start.
You are here