Skip to content
CAI
Software that uses CAICheck a score

Check a score

Check a score you were given.

A survey is one measurement of one codebase at one moment: the evidence that was gathered, the score that follows from it, and the version of the rules used to get there. The producer is whoever ran that measurement and signed the result.

If somebody has handed you one, two things can be checked here in your browser, with no account and nothing installed. You can test that the package really came from the producer it names and has not been edited since it left them, and you can take the evidence inside it and work the score out again for yourself.

Would you rather not paste evidence into a web page? Both checks run offline as well, with the open-source reference scorer: your machine, code you can read, and this site nowhere in the loop.

Verify a signed survey
Score an evidence bundle

Check one

Work the number out again.

Given the same evidence and the same version of the rules, the scorer reaches the same number every time. That is what makes a CAI score something you can check rather than something you have to believe.

Obtain the evidence

Every survey carries the evidence behind its score: the measurements that were taken, how they combined into each lens, and the rubric version they were scored under.

Run the open scorer

Run the open-source reference scorer over that evidence, pinned to the rubric version the survey names. The scoring arithmetic is public, so anyone who prefers to can write their own implementation of it instead.

Compare

The same evidence under the same rubric version reaches the same number on your machine as it did on the producer's. That is the guarantee the standard makes, and this is the step where you hold it to it.

Check two

Verify a signed delivery.

A delivery is signed and content-hashed at the moment it is produced. Two checks confirm both, and they answer different questions.

Check the signature

Ed25519-verify the package signature against the issuer public key. A valid signature proves who issued the package: it was signed by the holder of that key, and not assembled by whoever passed it on. It does not say the number inside is correct. Checking that is a separate job, and it is the first check on this page.

Check the content hash

The package carries a hash taken over its own contents. Recompute it and compare the two. Change a single byte anywhere inside the package and they stop matching, which is what lets a delivery be passed from hand to hand and still be worth something at the end.

What the two checks prove together: the package is the issuer's, and it reached you unaltered. Whether the number inside follows from the evidence is the other check on this page. Whether the evidence describes the code fairly is a judgement no check on this page can make for you.

Who this page is for.

This is the page a buyer's or acquirer's own advisors use. The check does not change with who produced the score: the same rules, the same evidence, the same arithmetic, whoever issued the package you were handed.

Check the number you were handed.

How the number is worked out → the standard