Rima is not a security audit and the page says so before the price does. It finds secrets that should not be committed, and failure paths that swallow their own errors. It does not probe running systems, does not test exploitability, and produces nothing usable against a third party.
Does the software’s operational behaviour support what it claims — or does it report success while swallowing the errors that say otherwise?
Two checks, chosen because they are high-precision and commonly missed.
The second check exists because of a bug in our own repository. A calibration script wrapped its corpus loaders in a broad try/except that printed one line and continued. A schema mismatch silently dropped an entire corpus from the evidence base for a whole working session. The script said so, in a wall of output, and nobody read it. A swallowed exception is not a style problem — it is a measurement problem. The system reports success while doing less than it claims, and every number downstream inherits that without a footnote.
Four questions, asked in the same order every time.
The last number is the honest one. The first version of this module detected five swallowed handlers, counted them in a measure, and then built its report without passing the findings through. It printed “no findings” over five it had already found — the exact failure this suite exists to catch, in the module written to catch it. The fix was one line. The response was a rule in the shared contract: a report with an empty findings list now refuses to construct, because “nothing found” is a conclusion and has to be stated, not inferred from silence.
The section a competent buyer reads first.
Every report this product emits ends with its own version of this list, generated from the run rather than written by hand. A report cannot be constructed without one — the validator refuses.
Fixed scope, fixed price, and a report you can argue with.
The documents surface, running in your browser — the real engine, installed into the page. Nothing is uploaded, because there is no server to upload it to. Or send one artifact and we will look at it: you get the finding either way, including if the finding is that nothing is wrong.
One product run against your artifacts, with a written report: measures, findings by severity, the resolution floor, and the limits. The price is fixed before the work starts and quoted from the size of your company, not from how the conversation goes.
Where it gets interesting — the findings on one surface routinely explain the numbers on another.
Five surfaces, one decision procedure. Each deploys separately, so one product's failure cannot take another down.
| Product | Surface | In one line |
|---|---|---|
| Nullius | documents | Your retrieval score is measuring your wording. |
| Auctus | growth | Most campaign wins are smaller than the experiment could see. |
| Fiscus | money | Finding the savings is the easy half. Proving one happened is the other. |
| Arbol | assistant | The layer that answers from your documents, and shows you which ones. |
One test set, one experiment, one statement export, one repository. The first look costs nothing and the finding is yours either way.
rishabh@op2ra.com