Skip to main content

Buyer due diligence

A clear record before a larger commitment.

This is the public record of how we approach delivery, proof, and handoff. It names what you can inspect now and what a project review should confirm for your specific risk, scope, and procurement path.

We reply within two business days with a fit decision and the smallest responsible next step.

Execution record

Technical ownership stays connected to delivery.

We keep scope, technical judgment, and client communication close to the work. The engagement record is designed to make decisions, progress, and the next owner legible throughout delivery.

  1. Scope before build

    The proposed outcome, boundary, decision owner, and acceptance evidence are made explicit before implementation begins.

  2. Visible execution

    Work is reviewed against the shipped change and the next decision, not reported through a detached status layer.

  3. Operating handoff

    Source, architecture context, operating notes, and the next owner are part of the delivery record.

Inspectable delivery controls

Shipped, in public

Buyer-facing interpretation of the public mcp-scan commit log below - controls visible in those changes, not a claimed commercial outcome the repository cannot prove.

  1. Scanner decisions

    False-positive guards plus broader credential and environment-file coverage.

  2. Repeatable releases

    Hermetic tests, current runtime support, and complete build artifacts.

  3. Dependency controls

    Exact version pins, severity-gated audits, and an inspectable public history.

8 public changes, April to June 2026:

CommitChange
71f9753fix: harden scanner false-positive guards
2c8114dfix(ci): include data/ in build artifacts for test stage
381866bfix(ci): drop Node 18 + exclude pre-existing robustness hang
2f2f349fix(deps): pin lodash to 4.17.21 exact, audit gate at critical only
8d0b0a1fix(golden-tests): hermetic, machine-portable, stable across runs
820eaedfix(data-controls): restore token-class API Key keywords
b1cfa2afix(env-leak): scan all env file variants per directory
53411c5fix(lib): sbom is a path string, not a boolean
mcp-scan commit log, public repo

The delivery lead stays on the build through the production handoff. The full studio roster is public. See the studio

What delivery can include

Artifacts are tied to the lane, not hidden behind a sales process.

Exact inclusions are set in the scoped engagement. These are documented artifacts from the public delivery catalog.

  • Architecture decision notes with alternatives
  • Scoped outcome and acceptance criteria
  • QA proof and responsive checks where UI is involved
  • Deployment or launch-readiness notes
  • Scope lock document with acceptance criteria by milestone
  • Production deployment checklist and launch report
Inspect engagement scope and pricing

Public evidence

What can be inspected now.

Public evidence has a source and a stated verification boundary. Confidential work remains described at the level that can be responsibly published.

Live in production

PL Maps: replaced a paid MapQuest dependency with map infrastructure PowerLiens owns, shipped in 4 weeks

Public case study, interface demo with synthetic records, and a live production endpoint. PowerLiens owns the system.

PowerLiens case study

Public product surface live

ProTeach: a homeschool platform our founder co-founded and built end to end, predating ThynkQ, not a client engagement

The public marketing surface and privacy-screened captures are reviewable. Repository evidence is summarized because the source is private.

Public ProTeach surface

NDA-protected

One NDA-safe healthcare AI engagement: intake, scheduling, and operations

The public description is intentionally limited. It does not claim a client identity, outcome numbers, or independent verification.

Work index

Public

Technical writing depth: production playbooks, architecture decisions, AI integration guides

Multiple long-form pieces show implementation detail, tradeoff analysis, and production pitfalls.

Writing index

Public

Open source security tooling for MCP infrastructure

The public repository and package can be inspected directly for technical review.

mcp-scan source

Public

Founder engineering footprint: profiles, open source, and public delivery record

The profile states the founder's execution lanes and links directly to LinkedIn, GitLab, and the mcp-scan npm package. Commit history and post dates remain visible at those sources.

Founder profile

Project-review boundary

What we confirm privately, before you commit.

A public website cannot answer every procurement question truthfully. The project review is where the proposed work is made specific without publishing client-sensitive details or generic assurances.

Scope and acceptance

The proposed boundary, milestones, exclusions, and evidence that would show the work is ready.

Execution ownership

Who owns the technical decisions, the direct communication path, and the review cadence for the proposed engagement.

Security and procurement fit

Which security, access, confidentiality, and commercial questions are relevant to the proposed scope.

Partner and dependency fit

Whether the proposed scope needs specialist capacity or third-party dependencies beyond the work described publicly.

Next decision

Bring the constraint. We will make the responsible next step clear.

Share what is blocked, what is already true, and what needs to be safe when it ships.

Request a project review