Last updated: July 2026
Inferr asks engineers to run a scanner on their own machine. That only works if you can verify what it does, not just trust it. This page is that verification — plain language, linked to the actual source.
The scanner is not a black box. Read the exact code before you run it:
npx inferr-scan actually installs.Every scan ends with a preview of exactly what would be uploaded — repo names, commit counts, languages, detected tools — before anything leaves your machine. Run with --dry-run to see that preview and stop there; nothing is sent anywhere. You decide, with the evidence in front of you, before any upload happens.
Short version: metadata only — commit counts and dates, languages, detected AI tools and frameworks. Never source code, file contents, or real file paths (paths are SHA-256 hashed before they leave your machine). Full detail lives in the Privacy Policy.
Your Proof-of-Work score is built from four factors. We publish what they are and roughly what they reward — not the exact formula. A published formula is a cheat sheet for gaming it, and that defeats the point of the score. What you get instead is confidence bands, not false-precision numbers.
The two engineer tracks are weighted differently on purpose — an AI Engineer is judged more on AI depth and production maturity than raw commit volume; an AI-Assisted Builder more on sustained history and what shipped. Every profile lands in one of four bands — early, developing, strong, or elite. We keep exact point values and saturation curves unpublished, and we adjust them over time as we learn what gaming looks like. Your own score breakdown — how you scored on each of the four factors — is visible on your profile.
Where we are today, plainly:
No third-party security review has been performed yet. We won’t claim one exists before it does. If you’re a security engineer and want to look under the hood — or run a review — we want to hear from you: security@inferr.works.