LaunchProofby CompanyNerve

Three checks. Explicit boundaries.

The initial automated pack uses the CompanyNerve adapter and customer execution. Each check needs an approved plan and a working baseline.

LP-AUTH-001 / v0.1.0

Anonymous private project access

A known private project and its authorized owner. The baseline must succeed before an anonymous read is tested.

Initial local / CI pack
LP-TENANT-001 / v0.1.0

Cross-organization project access

Two disposable workspaces, fixture actors, and a project owned by workspace A. The wrong workspace must receive no protected fields.

Initial local / CI pack
LP-PAID-001 / v0.1.0

Free access to paid project report

A declared paid project report operation, a paid fixture, and a free fixture. The paid baseline must succeed before denial is scored.

Initial local / CI pack

Missing setup is not a pass.

An expired fixture session, a missing endpoint, or a failed permitted baseline prevents a verified result. Reports retain skipped, unsupported, error, and inconclusive outcomes.

See how gaps appear in a report

Outside this pack

Checkout, subscription cancellation and expiry, webhook replay, role changes, revocation, secret scanning, and managed execution are not included in the initial automated claim.

Passing these checks is not a complete security assessment, legal certification, or proof that every endpoint is safe.

Full catalog and unsupported scope
  • Member invokes owner action: Requires disposable mutations and verified before/after state.
  • Removed member retains access: Requires authorized membership removal and retained session.
  • Final owner removal: Requires disposable owner lifecycle fixture.
  • Checkout return grants access: Requires controlled checkout navigation and entitlement observations.
  • Sandbox checkout grants access: Requires real Stripe sandbox subscription and signed webhook verification.
  • Scheduled cancellation access: Requires verified provider period and cancellation fixture.
  • Ended subscription access: Requires controlled subscription termination and consistency window.
  • Forged webhook: Requires isolated billing state and authorized webhook action.
  • Duplicate or stale webhook: Requires real associated sandbox events and verified side effects.
  • Provider environment separation: Requires independently verified provider inventory.
  • Flat-rate teammate billing: Deferred billing pack; requires real invoice and teammate fixture.
  • Clock policy boundaries: Requires synchronized application and provider clocks.
  • Deployment identity: No supported trusted build marker; identity remains customer-declared.
  • Transport observations: Transport advisory pack is not implemented.
  • Local source secret scan: Source scanning is not implemented; report redaction is not a source audit.
Prepare your local setup