Independent technology assurance

Everyone can build software. Can you trust it?

SpringFur turns code analysis, security findings and architecture evidence into an explainable view of technology quality, risk and readiness — from a vibe-coded repository to enterprise and OT.

Explore the rating
First scan free Private by default Evidence behind every score
SpringFur alpaca with fine turquoise and lime fibers woven through its fleece
SpringFur rating
4.2 ★★★★☆
Good · Model v1.0

From builder workflow to accountable technology decision

VIBE CODERSDEVELOPERSEXPERTSARCHITECTSOWNERS
From uncertainty to evidence

Four steps. No mystery score.

Objective measurements produce the rating. AI helps explain and fix what matters — it never invents the official result.

01 / CONNECT

Choose your repository

Connect GitHub with read-only, repository-level access or upload source directly.

02 / SCAN

Measure what matters

Code quality, security, dependencies, tests and architecture — with visible coverage.

03 / UNDERSTAND

Follow the evidence

Every score traces to metrics, findings and the exact place in your code.

04 / IMPROVE

Fix. Rescan. Prove.

Take the prompt to your coding agent and verify that quality actually improved.

A rating experts can challenge

Friendly on the surface. Serious underneath.

SpringFur separates deterministic scoring from AI interpretation. That makes every rating reproducible, versioned and transparent enough for experienced developers, security experts and auditors.

See how the model stays current →
Assessment / web app

My Lovable Project

Commit 4f8c2a · 2 minutes ago
Overall
4.2
★★★★☆
Maintainability
4.4
Security
3.6
Testability
4.0
Architecture
4.2
HIGH
Authorization missing on 3 data mutationsEvidence in api/projects.ts · Fix before public launch
Beyond another code scanner

Issues are inputs. Assurance is the outcome.

Static analysis is essential, but a list of findings does not tell an architect or owner whether a technology is understandable, governable and ready for its intended use. SpringFur combines evidence from code, tools, platforms and technical context into one challengeable assessment.

Sonar finds issues in code. SpringFur turns technical evidence into decisions about quality, architecture, risk and readiness.
01 / SIGNALS

Code and scanner findings

Native SpringFur measurements plus evidence from trusted quality, security, dependency and supply-chain tools.

02 / CONTEXT

Architecture and operational meaning

Connect findings to repositories, services, platforms, integrations, business capabilities and OT assets.

03 / EVIDENCE

Coverage, provenance and uncertainty

Show exactly what was assessed, by which method, with which version — and what remains unknown or requires expert review.

04 / DECISION

Explainable technology assurance

Support accept, improve, invest, replace or investigate decisions without turning a technical score into a false guarantee.

Use the evidence you already trust

One assurance layer. Many evidence sources.

SpringFur is designed to complement specialist tools rather than recreate every scanner. Connectors normalize their findings into the SpringFur Evidence Graph, retain provenance and add architecture, business and regulatory context.

SonarQube

CANDIDATE

Quality gates, maintainability, reliability, security and coverage as traceable assessment evidence.

Snyk

CANDIDATE

Application, dependency, container and infrastructure security findings linked to affected technology assets.

Semgrep

CANDIDATE

Rule-based code and security findings with source location, rule identity and confidence preserved.

GitHub Advanced Security

CANDIDATE

Code scanning, secret scanning and dependency evidence connected to repository and solution context.

Architecture tooling

ROADMAP

Exchange technology context with ArchiMate, Sparx Enterprise Architect and other architecture repositories.

Your existing tool

DEMAND-LED

Versioned import adapters and an open evidence contract let customer demand determine the next connector.

INTEGRATION CANDIDATES · CONNECTORS ARE PRIORITIZED AND BUILT WITH LAUNCH CUSTOMERS · NO IMPLIED CURRENT AVAILABILITY
One evidence graph from code to enterprise

Start small. See the whole picture.

SpringFur combines its own measurements with specialist evidence and adds the context needed for accountable technology decisions.

PLATFORM EXTENSIONS

SpringFur Platform

Assess maatwerk on Salesforce, Business Central and other platforms for alignment, access and upgrade safety.

Explore platform scans →
MULTI-REPOSITORY

SpringFur Solution

Understand architecture, integration, resilience, observability and deployment across a complete solution.

Explore solution quality →
TECHNOLOGY LANDSCAPE

SpringFur Enterprise

Map applications, integrations and critical dependencies. Find concentration risk and calculate blast radius.

Explore enterprise intelligence →
OPERATIONAL TECHNOLOGY

SpringFur OT

Assess PLC and automation software in its controller, I/O, machine and production context — offline and evidence-led.

Explore OT quality →
Built in Lovable?

Ship the vibe. Verify the code.

Sync your Lovable project to GitHub, let SpringFur inspect the real repository and take an evidence-backed fix prompt straight back into your workflow.

$ springfur scan my-lovable-app
✓ 214 files analyzed
✓ dependencies verified
✓ authorization paths checked
QUALITY RATING   4.2 / 5
3 changes recommended before publish
European by design

Evidence that fits the European way of building trust.

SpringFur is designed around privacy, explainability, independent assessment and verifiable control. Regulation is not reduced to a badge: technical evidence is mapped to the context in which qualified experts make decisions.

01

Privacy and source sovereignty

Least-privilege access, explicit retention, transparent AI processing and European deployment options as the platform matures.

02

Versioned regulatory profiles

Candidate evidence mappings for the Cyber Resilience Act, AI Act, NIS2 and national implementations such as the Dutch Cyberbeveiligingswet.

03

One evidence base, multiple obligations

Reuse findings, dependency inventories, architecture context and attestations without duplicating the underlying assessment.

04

Human legal and audit judgment

SpringFur shows what is evidenced, missing or uncertain. Applicability and final compliance conclusions remain accountable human decisions.

Living methodology

The market changes weekly. So does the evidence.

SpringFur continuously monitors platform releases, vulnerabilities, standards and emerging AI-code patterns. Changes only enter the rating after expert review, regression testing and a published Quality Model update.

QUALITY MODEL v1.0 · CURRENT
PLATFORM SIGNALS

Release notes and deprecations

Lovable, Salesforce, Microsoft, GitHub and the wider AI development ecosystem.

TECHNICAL SIGNALS

Vulnerabilities and standards

Security advisories, dependency health, OWASP, CWE, frameworks and language releases.

PRACTICE SIGNALS

What real code teaches us

False positives, new implementation patterns and review by an independent expert panel.

PUBLIC OUTPUT

AI Software Quality Radar

A recurring view of what builders and technology leaders should pay attention to now.

Know what you built before the world uses it.

View sample report