Methodology & transparency
What MLVibeScan measures — and what it does not
MLVibeScan provides reproducible technical observations rather than a blanket security guarantee. Test depth, evidence and product status remain visible so results can be examined.
Test scope
| Stage | Access | Examples |
|---|---|---|
| Passive | Public URL, no account | TLS, headers, delivered JavaScript, secrets, DNS and known exposures |
| Deep | Purchase and technical domain verification | Controlled read-only API, auth, database and rate-limit probes |
| Source | Purchase, domain verification and explicit ZIP upload | JS/TS source, configuration, lockfiles and agent rules; project code is never executed |
Evidence and confidence
“Directly observed” proves served behaviour. “Strong signal” is an unambiguous technical inference. “Context” marks a plausible observation that depends on application context. Confidence is shown separately as confirmed, high or medium.
Confirmation before high severity
Critical and high findings receive an independent counter-check where technically possible. If confirmation fails, confidence or severity is reduced. Failure of an external source never becomes a negative finding.
False positives and redacted proof
We assess meaning and usage, not strings alone. A Stripe pk_live key or Supabase anon key is not a secret by itself. Free proof cards contain only safe redacted observations; tokens, internal endpoints and exploitable detail stay private.
Safe testing limits
Passive scans behave like a visitor. Deep checks are bounded, controlled and read-only; reset probes use invented addresses. ZIP files are analysed without install, build, hooks or network egress and are deleted afterwards.
Data sources
MLVibeScan combines its own versioned signatures with DNS, TLS certificates, package and vulnerability information and curated supply-chain indicators. External-source availability is monitored; an outage is not rated as a flaw in the scanned app.
Data minimisation and deletion
Raw HTML, JavaScript and uploaded source are not retained. Structured findings remain only until the displayed deletion deadline. Public summaries are opt-in, aggregated and contain no locations or evidence.
Attestation and limits
A badge requires an active domain pass, domain verification, a deep scan no older than 30 days and no open critical or high findings. Automated testing is not a penetration test and cannot guarantee complete security.
Change status
Scope is versioned. Only production checks count as available; beta and planned checks remain explicitly labelled.
Methodology version: 1.0 · Production: – · Beta: – · Planned: –
Loading the current live scope.