CAI Founding Papers
How the Code Assurance Index is constructed
Ten lenses, ordered weighting, and the advisory firewall.
Version 1.0 · signed 14 September 2026 by Jimmy Borch · Canine Development · 25 pages
Abstract
What the paper argues.
A code assurance score compresses a large body of technical evidence into a form that can be compared, discussed and tracked. The value of that compression depends on making the construction visible: a strong area should not be able to erase a serious weakness, a missing measurement should not silently become a failure, and interpretive judgement should not be allowed to move a deterministic score.
Measuring a repository and aggregating that measurement into a score are separate processes in CAI: an implementation emits structured evidence, and a reference scorer folds that evidence into a result. Wherever several scores are combined they are ordered from weakest to strongest, and the parameters place the greatest weight on the weakest measured area so that it keeps material influence rather than being averaged away. Those parameters live in the versioned rubric rather than in the scorer, which is why a rubric version identifies the scoring semantics a result was produced under.
CAI is therefore best understood as an inspectable aggregation standard whose assumptions are exposed rather than hidden. The paper sets out those assumptions and the scoring mechanics, and it marks the research questions that would be required only for stronger empirical claims about robustness, calibration or external validity.
Check that you have the signed document.
The PDF is the signed artefact. Same bytes, same hash, whoever you got it from. Run this against the file you downloaded, and compare the result with the digest below it.
sha256sum how-the-codebase-assurance-index-is-constructed.pdf2e190e79c49a0d2c1335b9be1576a469b373efbda894b38f586a034c34325619