PUBLIC · NO GITHUB ACCESS REQUIRED

Your checks passed.
But did that exact code land?

GitHub, CI, and review evaluate a particular candidate. Merge Proof follows that evidence through landing and shows whether the evaluated content is actually the content that became merge truth.

HOW MERGE PROOF KNOWS

Bind the evidence. Identify what landed. Compare.

GitHub reports checks, reviews and merge history. Git commit and tree IDs name the exact content. Merge Proof keeps those facts distinct and makes the deterministic comparison.

  1. Provider evidenceGitHub evidenceChecks, reviews and PR state bound to one observed candidate.
  2. Git identityEvaluated treeb1ec95450a69
  3. Provider historyLanding observationMerged commit and landing event, when available.
  4. Git identityActual landed tree13426dad6335 or unavailable.
  5. Merge ProofCompareSame, different, or missing a required fact.
b1ec95450a69 = b1ec95450a69VERIFIEDRequired evidence is satisfied and the evaluated tree landed.
b1ec95450a69 ≠ 13426dad6335FAIL · DIFFERENT CONTENT LANDEDA sufficiently bound comparison demonstrated a mismatch.
b1ec95450a69 vs unavailableNOT_PROVENThe required landing comparison cannot be completed, so Merge Proof does not guess.

Important boundary: Git identities identify content. They do not independently authenticate GitHub's checks, reviews or merge records.

THREE HONEST OUTCOMES

See what each conclusion means.

EXAMPLE PROOF · VERIFIED

The evaluated tree is the tree that landed.

Checks and approval applied to one exact candidate. The observed landed tree matches the evaluated merge-target tree.

INSPECT VERIFIED

EXAMPLE PROOF · FAIL

Different content landed.

Required checks passed for PR #41 against main at M0. Main advanced, loose required checks allowed the PR to merge without retesting that combination, and a different tree landed.

INSPECT FAIL

EXAMPLE PROOF · NOT_PROVEN

A required fact could not be established.

Candidate identity, evidence binding and currentness were established. No landing identity is bound, so Merge Proof refuses to guess.

INSPECT NOT_PROVEN

SAFE TO TRY

Observe and report—without blocking your merges.

Merge Proof observes and reports without blocking your merges. Early Access reports what happened; it does not enable a required merge policy during the trial.

Free CLI · point-in-time verification

Run or replay evidence yourself when you choose. Local use is free.

Use the free CLI →

Hosted Merge Proof · $29/month per observed active developer

After the trial, hosted Merge Proof observes selected repositories, tracks PR evidence and currentness, reconciles provider history, observes supported landings, and retains proof receipts.

First successful proof → seven-day no-card trial → $29/month per observed active developer. No automatic charge at trial expiry.

CONNECT GITHUB FOR A REAL PR

7 days free. No card. Connect GitHub only after you are ready.

SECURITY & ACCESS

Don't trust Merge Proof more than necessary.

See exactly what authority you grant before connecting.

Can Merge Proof access source?

Yes. Contents read is real source access. Workflow text, API patch text and exact Git objects may reach the server to bind identities and reconstruct supported tree facts.

Do you store my source?

Receipts store normalized evidence, paths, hashes and proof facts—not incidental patch or decoded workflow text. A private partial bare mirror retains exact Git objects and receipt refs for replay.

Does my source go to AI?

No. Source contents are not sent to an LLM or AI provider, and no AI model decides the verdict.

Can Merge Proof change my code?

Not through the standard connection. It has no Contents write authority and cannot push commits or modify repository files.

What can Merge Proof write?

Checks read/write lets it publish or update its receipt Check on the PR. That does not grant repository-file write authority.

FULL PERMISSION & DATA-HANDLING DETAILS

Don't trust Merge Proof more than necessary. See the exact authority before connecting.

Standard GitHub App repository access

  • Read: Actions, Administration, Commit statuses, Contents, Merge queues, Pull requests, and GitHub's mandatory Metadata permission. These reads collect workflow/check evidence, repository rules, Git identities, merge-queue state, PR state, and landed content identifiers.
  • Checks: read and write. Read check results and publish or update the Merge Proof receipt Check on the PR. That write can create or update this App's Check Run output; it cannot change repository files.
  • Organization members: read. Verify that the signed-in billing user is an organization owner.

GitHub sign-in: the OAuth request adds no extra OAuth scopes. The short-lived user token is kept in process memory while Merge Proof checks your identity, App installations, authorized repositories, and organization-owner status.

Technical access and processing: Contents read is real source access. GitHub API responses can include workflow text and diff patches, and reconstruction fetches exact Git objects into a private partial bare mirror. Merge Proof uses these inputs to bind identifiers, inspect workflow action references, and deterministically reconstruct trees; it does not execute customer code.

Persistence and AI boundary: receipts retain normalized evidence, identifiers, paths, hashes, rules, checks, reviews, actors, workflow provenance, and reconstructed Git facts. Exact Git objects and receipt references are retained for replay. Incidental API patch text and decoded workflow text are not written into receipts. No source contents are sent to an LLM or AI provider; no AI model decides the verdict.

Write authority: this standard grant does not include Contents write, Secrets, Workflows write, or organization administration. It cannot push commits, change branches or files, merge or close PRs, post PR comments, alter repository settings, edit branch protection/rulesets, or modify Actions workflows. A separate optional Enhanced Policy Proof companion, if explicitly enabled later, has repository Administration write authority but is constrained by Merge Proof to policy reads; it is not part of this standard connection.

After uninstall or revocation: new collection stops and hosted access fails closed because current installation/repository access is rechecked. Historical receipts, evidence, retained Git objects, account records, and operational backups are not automatically erased; current code defines durable retention, not a customer-selectable deletion deadline.