Proof and evidence

Current product proof, ready for review

BareBones Ticketing buyers can review current product surfaces, a synthetic workflow walkthrough, release and package evidence as it becomes customer-approved, bounded security-assessment language, deployment direction, and the account handoff path.

Buyer proof packet

Evidence buyers can request

The packet is designed for governed buyers who need concrete review material before they evaluate or purchase self-hosted service desk software.

Product surface map

Open the live demo and click through requester, service catalog, agent queue, project-linked work, external participant, and administrator surfaces yourself. Nothing to install, no form to fill in.

Open the live demo

Sample workflow walkthrough

The demo carries a worked scenario: intake, service lane, queue ownership, workflow and SLA movement including a paused clock, external participation, and a specialist confined to one department. Walk it as any role. For a written assessment against your own operation, ask.

Walk it in the demo Request a written fit assessment

Evaluation manual

The BareBones Ticketing RC2 manual is approved for use as evaluation and operator guidance. The first working-service example was walked live end to end before approval.

Release and package evidence

When customer artifacts are approved, review release notes, checksum or provenance evidence, edition eligibility, and the website verification path that controls package and manual visibility.

Security-assessment summary

Review what was checked, what remains tracked, and how to interpret the current internal assessment.

Review assessment summary

Deployment direction

Review the current 1.0 direction for Windows Service hosted Kestrel packages and single-node Linux Docker Compose families, with unsupported deployment promises kept out of scope.

What you receive

A written fit response can answer requested proof points, identify unavailable evidence plainly, connect terms and procurement routes, and recommend the smallest useful next step.

Security assessment summary

Internal assessment with traceable scope

BareBones Ticketing underwent a documented, OWASP-informed internal product-security assessment of a traceable non-production build. The assessment combined dependency review, source-assisted control review, bounded unauthenticated passive web testing, a narrow requester-only authenticated check comprising one passive ZAP request, service probing, and Greenbone vulnerability scanning. No new material application vulnerability was validated within the assessed scope. One Medium CI/CD supply-chain finding remains tracked for remediation.

How to read it
  • Internal review of a traceable non-production build.
  • Useful for buyer diligence, not a replacement for an independent audit or certification.
  • Open remediation stays tracked as product work.
What a buyer can ask for
  • A written BareBones Ticketing fit assessment.
  • A guided walkthrough of the current product surfaces.
  • Release notes and package checksum or provenance evidence when a customer-approved package is available.
  • A summary of payment, account, license, download, billing, and support routing.
  • Scoped implementation planning for service catalog, workflow, access, SLA, and handoff needs.
Evidence still earned over time
  • Customer testimonials, logos, and adoption metrics require real customer permission.
  • Regulated-release, validation, security-certification, high-availability, and scale proof require future evidence.
  • Migration and download claims stay tied to approved product artifacts.

Next step

Ask for the proof that fits your decision

Send the service management problem, the evidence you need, and any procurement or review deadline. Finlay.works will answer in writing and will say plainly when a requested proof point is not available yet.

Request proof-led fit help