Blog
The proof behind the verdict.
We write down what we learn building a decision layer for scanner output — the findings, the evidence trails, and the work between a flag and a call you can defend.
Latest
7 postsWe triaged Keycloak's scanner output and published every verdict. Tear it apart.
The full run: what the scanner could not parse, what we do not index, the five queues every finding landed in, and one worked example of why a finding stayed open.
ICTX vs Semgrep Assistant: auditable evidence or a score inside one platform
Two honest answers to the same problem. What Assistant does well, where its verdict stops being checkable, and where a scanner-neutral local tool is the better fit.
Where Spring SAST findings go to die: sanitizers, config, and framework context
Three finding patterns that survive a scanner and die on evidence — a validated binder, a config-gated sink, and a test-only path — and what it takes to close each one.
Deterministic first: why the agent is a tiebreaker, not the engine
Rules over extracted evidence make the call. The agent runs only where the evidence is genuinely ambiguous. Same input, same verdict — which matters more every year.
Reachability analysis explained: what it proves, and what it can't
Sources, sinks, taint and sanitizers in practitioner terms — then the part vendors skip: partial indexing, dynamic dispatch, and framework magic that breaks the graph.
What SARIF triage actually means (and why your scanner doesn't do it)
A working glossary: finding, triage, false positive, LFP, noise, decision record. The words your queue already runs on, defined so two engineers mean the same thing.
A verdict you can't check is a verdict you can't trust
Why a confidence score is the wrong artifact for the person whose name goes on the ticket — and what has to be on the finding instead before anyone can close it.