Where CAI came from, and who runs it
Who decides what the standard says.
The Code Assurance Index was created and published by Canine Development in 2026, and contributed to the Code Assurance Initiative — the organisation the standard is now published under, and the one this page will eventually describe as governing it. It exists because any assessment of a codebase compresses a great deal of evidence into a short answer, and the choices made inside that compression are normally invisible to whoever is handed the result. Writing those choices down, and publishing them separately from the software that applies them, is what lets the person on the receiving end check them.
The Initiative is not yet an incorporated body and its steering group is being assembled. Today it has one member, Canine Development, and this page will name the others as they join. An organisation existing is not the same as a group of people deciding, and the second is what independence requires.
Until that group is complete, the standard is held still. CAI will not be materially changed while the body that ought to decide such changes is still being assembled, so the rules published today are the rules a score will be measured against. Independence is what the steering group is being formed to provide, and CAI will not use the word before it can point at who holds it.
Four questions, four answers
Open means four different things. Three are true today, and the fourth is being built.
Plenty of things get called open, so it is worth being specific about which parts of CAI are. They are worth keeping apart, because blurring them together is how a standard gets sold as more independent than it is.
Reading the rules: open
Every rule that turns measurements into a score is published on this site, in full. Reading them needs no account and costs nothing.
Checking a score yourself: open
The program that applies the rules is free, and its source code is public. Anyone can read it, run it, change it, or use it to argue against a score they were handed.
Using the standard: open
Any company can score codebases under CAI and publish the results, with no licence to buy, no fee and nobody's permission to ask for. The rules are the same for every company that uses them.
Changing the rules: not yet open
This is the part the steering group is being founded to take on. The standard now has an organisation of its own, which is where it is published — but there is still no board, no written constitution and no vote, so the standard is held still rather than changed by whoever happens to hold the pen. The standstill is what stands in for governance until governance exists.
What holds in the meantime
What holds, whoever is holding the pen.
The standstill is a commitment, and a commitment is only as good as what sits underneath it. Four things hold underneath, and each one works whether anybody behaves well or not.
A change becomes a new version
Any change that could move a score, on code that has not itself changed, becomes a new version of the rules. The version a score names does not change under it afterwards, so the rules it was judged by can still be read.
Every score says which version it used
So when a number goes up or down, the record shows why: the code changed, the rules changed, or a newly published security advisory moved a finding under rules that stayed the same. The last of those is recorded in the score's changelog.
Nothing scores in secret
A way of scoring that is not in the published rules is rejected before it can ship, so there is no private rule for anyone to appeal to. Given the evidence a score was computed from, anyone can work the number out again from the published rules.
A contract can freeze the rules
A project can be tied to one fixed version of the rules for the length of an agreement, so a number agreed at the start and the number at the end can be compared.
The bar for independence
What would have to change before this page uses the word.
A separate website, an organisation of its own and a different logo are not evidence of independence. These are the conditions this page will be held to before it uses the word.
- The steering group exists, its members are named here, and Canine does not control it.
- How a change gets proposed, and how one gets turned down, is published, along with who decided and why.
- More than one company is scoring codebases under the standard, so it is not being written around a single product.
- The rubric versions are published by the Initiative, not by an implementation. They are currently minted and pushed by Watchdog, which is an implementation and a commercial product — so the software being measured writes the rules it is measured by. This is the condition furthest from being met, and the one that matters most.
- The licence lets anyone take a copy of the standard and run it their own way, so disagreeing does not need permission. This one is already true.
A board with one company on it is not governance.
The quick version of this is to gather a group, fill it with people unlikely to object, and call the result independent oversight. It buys the appearance cheaply and invites the scrutiny it was meant to deflect. Registering an organisation is the same move one step earlier: a name is not a governing body, and this page will not treat the two as the same thing. It will say the steering group exists when it does, and it will name who sits on it.
Disagreeing
Two different complaints, with two different routes.
If you think one particular finding inside a score is wrong, it can be challenged. A person looks at it, and where the finding turns out to be wrong the fix goes wherever the fault was: a detector that misread the code is the implementation's to fix, and a rule that gave the wrong answer is the standard's, which adds a test so the same mistake cannot happen again. The score itself is not adjusted, because challenging a finding is meant to improve the measuring rather than move a number.
If you think the rules themselves are wrong, that is a different complaint and it goes to the people who write them. Write to them and say what is wrong and why. A standard is read most carefully by the people who did not write it, and that is the reading this one wants.