Vulnerabilities, secrets, exploitability across files. The audit-evidence side.
verdicts: pass · warn · fail
- Reasoning across file boundaries — not pattern matching
- Fail/warn verdicts you can gate CI on
- Per-repo memory of accepted false positives
- Audit trail mapped to SOC 2 / ISO 27001 / PCI-DSS