Skip to main content

FAQ

What does CodeRifts do, in one sentence?

On a boundary that requires it, a contract change does not cross without a signed grant for that exact change set.

/blog/receipt-dora-nis2-ai-act/

What does a receipt prove, and what does it not?

The open verifier checks it offline against a pinned key snapshot — no account, no call to us. A decision is an authorisation answer for the submitted request, not an observation that anything was merged, deployed or published.

/blog/receipt-dora-nis2-ai-act/

Do you store my code or my spec?

Repository and branch identifiers are stored; spec content is not. Core Diff reads configured specification files, and opt-in MigraGuard/ActionGuard read configured migration files, application source references and workflow YAML, in memory only; none of that file content is persisted

/privacy/

What happens if your server is down — does the check pass or fail?

Measured 2026-10-02 with our API unreachable, timing out, or answering 5xx: on the enforcing profile, a head commit that carries a valid signed receipt for its own diff still passes offline without calling us, and every other case fails closed (the contract-gate check concludes failure); if the CodeRifts App cannot post its `CodeRifts / issuer` run, a repository that requires that context stays blocked as "Expected — waiting for status", GitHub's documented behavior for a required check that never reports.

/docs/enforcement-status/#api-unreachable

Does it work on private repositories?

Free authorization requires a provider-verifiable public repository. Authorize and enforce private contract changes at supported boundaries.

/pricing/

What does it cost?

Free $0; Team $149/month after beta (Team is $0 during public beta); Enterprise from $1,500/month. No Pro tier is sold.

/onboarding/ /pricing/

Which contract formats?

CodeRifts reads the diff of the contracts a pull request touches — OpenAPI, GraphQL, protobuf, AsyncAPI and MCP tool manifests, together as one change set

/blog/receipt-dora-nis2-ai-act/

How is this different from a breaking-change linter (oasdiff, Optic, Spectral)?

Use oasdiff if you only need the structural delta in a CI pipeline you assemble yourself. On GitHub, a required check refuses the merge until a receipt for that diff verifies on the runner; the receipt names the operation it was granted for (merge, deploy, publish or a tool call) and expires.

/compare/oasdiff/ /blog/receipt-dora-nis2-ai-act/

What changes in an MCP server's tools does it catch?

classifies what breaks (a removed field, a parameter that became required, a narrowed enum, a tool whose description gained an instruction)

/blog/receipt-dora-nis2-ai-act/

Who approves — does the receipt name the person?

It does not prove the receipt names a person. Line five says the approver is not in the signature.

/docs/hosts/mcp-server/

Can I verify a receipt without you?

The open verifier checks it offline against a pinned key snapshot — no account, no call to us.

/blog/receipt-dora-nis2-ai-act/

Is it DORA / AI Act compliant?

A receipt alone does not satisfy Article 9(4)(e); it is one record inside a process that does. It does not assign or evidence human oversight.

/docs/evidence/record-keeping/ /blog/receipt-dora-nis2-ai-act/

Who requires it today?

No external repository requires the check yet.

/blog/receipt-dora-nis2-ai-act/

How do I start?

Analysis is free and needs no account; the check is on the GitHub Marketplace

/blog/receipt-dora-nis2-ai-act/ https://github.com/marketplace/actions/coderifts-contract-gate /install/