What the buyer is really asking
Can any change reach production without a second person looking at it? Buyers want the rule enforced by tooling, not habit. Branch protection settings are the usual proof.
Other ways buyers ask it
Every one of these wants the same answer:
- “Is all code peer reviewed before deployment?”
- “How do you conduct code reviews?”
- “Do code reviews include security checks?”
Evidence to have ready
- Repository branch protection settings
- A sample merged pull request showing approval
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.