Skip to content
CAI
Software that uses CAICheck a score

The standard, and the software that uses it

CAI is the rules. An implementation is software that applies them.

The Code Assurance Index is a set of published rules, a scale from 0 to 100, and a free program that does the arithmetic. The code itself is examined by other software.

That software is an implementation: it does the measuring and produces a score under those rules. The standard says what a score has to mean, and the implementation does the work of producing one. Because the two are separate, a score can be checked by somebody who does not trust whoever produced it.

Where the line falls

What the standard does, and what an implementation does.

The standard provides

The rules for what counts and how much, the scale from 0 to 100, the list of what has to be measured, and a free program that turns measurements into a number. All of it published, and none of it looks at code.

An implementation provides

The measuring. It examines a codebase, produces the measurements the rules ask for, applies the rules to them, and hands over the result with the evidence attached.

What building one involves

You can check a score without the engine that produced it.

Turning measurements into a number is fully published. The rules are on this site, and the program that applies them is free to download and run. Examining a codebase to produce those measurements is each implementation's own work, and that part is not published.

The evidence is what makes that workable. A score arrives with the measurements it was built from, so an engine you cannot read still has to show what it produced, and a reader who disagrees can point at a specific measurement. Given the same measurements, any implementation applying the same version of the rules reaches the same number, because that part is arithmetic. Arriving at the same measurements is the harder problem, and the standard does not claim to have solved it.

The listing

Software that uses CAI today.

Two, and both are built by Canine Development — the studio that created the standard and contributed it to the Code Assurance Initiative. A standard whose only implementations come from its own author has not yet been tested by anyone else, and that is a fact about how far CAI has got, not a claim about how good it is.

Watchdog

Produces scores. Measures a codebase and publishes a CAI score with its evidence.

watchdog.canine.dev

Assay

Reads scores. Turns CAI evidence into a report for a decision, such as a purchase.

assay.canine.dev

The standard does not vet anyone.

There is no register of approved software, and nothing here certifies an implementation as correct. Listing something records that it exists, so a reader can see how widely the standard is used.

If your software produces CAI scores, or reads CAI evidence to support a decision, this page should say so. Get in touch and it gets added, with no fee and nothing to apply for. If the standard ever starts approving implementations instead, the governance page will say so first.

Read what the standard asks for before building against it.