MLVibeScan

Methodology & transparency

What MLVibeScan measures — and what it does not

MLVibeScan provides reproducible technical observations rather than a blanket security guarantee. Test depth, evidence and product status remain visible so results can be examined.

Test scope

StageAccessExamples
PassivePublic URL, no accountTLS, headers, delivered JavaScript, secrets, DNS and known exposures
DeepPurchase and technical domain verificationControlled read-only API, auth, database and rate-limit probes
SourcePurchase, domain verification and explicit ZIP uploadJS/TS source, configuration, lockfiles and agent rules; project code is never executed

Evidence and confidence

“Directly observed” proves served behaviour. “Strong signal” is an unambiguous technical inference. “Context” marks a plausible observation that depends on application context. Confidence is shown separately as confirmed, high or medium.

Confirmation before high severity

Critical and high findings receive an independent counter-check where technically possible. If confirmation fails, confidence or severity is reduced. Failure of an external source never becomes a negative finding.

False positives and redacted proof

We assess meaning and usage, not strings alone. A Stripe pk_live key or Supabase anon key is not a secret by itself. Free proof cards contain only safe redacted observations; tokens, internal endpoints and exploitable detail stay private.

Safe testing limits

Passive scans behave like a visitor. Deep checks are bounded, controlled and read-only; reset probes use invented addresses. ZIP files are analysed without install, build, hooks or network egress and are deleted afterwards.

Data sources

MLVibeScan combines its own versioned signatures with DNS, TLS certificates, package and vulnerability information and curated supply-chain indicators. External-source availability is monitored; an outage is not rated as a flaw in the scanned app.

Data minimisation and deletion

Raw HTML, JavaScript and uploaded source are not retained. Structured findings remain only until the displayed deletion deadline. Public summaries are opt-in, aggregated and contain no locations or evidence.

Attestation and limits

A badge requires an active domain pass, domain verification, a deep scan no older than 30 days and no open critical or high findings. Automated testing is not a penetration test and cannot guarantee complete security.

Change status

Scope is versioned. Only production checks count as available; beta and planned checks remain explicitly labelled.

Methodology version: 1.0 · Production: – · Beta: – · Planned: –

Loading the current live scope.

Scan your own app for free