> TheAuditor / blog
• release, ci, engineering

The First Hour Is Part of the Product

Before calling the release build ready, we ran it on a clean machine the way a new customer would, and hardened everything that pass turned up: safe interrupts, pinned tools, exit codes CI can trust, and a plain list of what leaves your machine.

Before calling the release build ready, we took it to a clean machine and used it the way a new customer would: download it, set up the analysis tools, connect an agent, analyze a project, interrupt a run partway through, and run it again.

A developer’s machine carries months of configuration that quietly smooths over rough edges. A clean one carries none of it, which is exactly why the pass is worth doing before anyone else installs the build. Everything it turned up is fixed in the release build.

What the pass hardened

  • Any machine, any locale. The binary runs without a UTF-8 locale configured and uses its own bundled certificate store on every Linux distribution.
  • Lint results that are real results. Setup installs pinned, checksum-verified copies of the analysis tools, and the linter configuration ships inside the binary, so a lint step does not come back empty just because nothing ran, the silent zero we treat as the most dangerous output a scanner can produce.
  • Every tool explained. Each tool the agent sees carries its full description in the compiled build, so the agent never has to guess what a tool is for.
  • Nothing in the tree can stall a scan. Special files, and file names that are not valid UTF-8, are skipped with a notice.

Interrupting a run is safe

We pressed Ctrl-C at several points during indexing. Each run stopped cleanly and reported itself as interrupted, and the next run completed with its integrity checks passing and the databases intact. A long phase is stopped only when it stops making progress or runs well past a limit scaled to the project’s size, and the run says why.

Exit codes mean one thing each

CI can act on them: 0 analysis complete with no findings, 1 findings reported, 2 error, 3 incomplete, 6 another analysis of the project is already running, 130 interrupted. An incomplete run never reads as a clean one.

The smaller edges

An internal error prints one line with a stable reference, and aud diagnostics packages a support file. TheAuditor refuses to analyze your home folder or a drive root. Connecting an agent works before the first analysis, in Claude Code or OpenAI Codex, and keeps your own hooks and permissions in place.

What leaves your machine

Your source code, file names, symbols, and findings are never sent by TheAuditor. Telemetry is announced before anything is sent, and aud telemetry off turns it off. Two things are not telemetry and are documented next to it: a daily license check-in, which turning telemetry off does not stop, and the package lookups a full analysis makes against public registries, which an offline run skips. The bill of materials in the release archive lists every network service the tool or its bundled tools contact, so the answer to “what does this talk to” is a file you can read.

Why the first hour matters

The first hour decides whether a tool gets a second one. It also matters for a reason specific to this product: an agent calls TheAuditor in the background, often while you are doing something else. A tool in that seat has to survive an interrupt and report an error as an error, because it is working exactly when nobody is watching. That is the bar the release build is held to.

Honest scope note

A clean-machine pass is not the reproducibility scorecard we described in Done Is a Standard, Not a Date. That scorecard, the same results across every build and both operating systems, is still being measured on the current engine, and we will publish it when it passes, not before.

TheAuditor is in final commercial release preparation and ships when its hardening checks pass. Subscribe on the main site for launch news.

Was this useful?