Skip to content
LyraShield AIOpen beta

Methodology

A security result should say what it knows—and what it does not.

LyraShield AI preserves scope, coverage, evidence provenance, and retest state as separate facts. It does not turn scanner confidence or missing evidence into a universal security verdict.

Last reviewed: · Maintained by LyraShield Security + Engineering

What every new scan record preserves

Scope
The authorized target, available source, scan mode, and immutable result-manifest checksum.
Coverage
Which checks completed, were limited, were skipped, or did not apply, including retained limitations.
Provenance
Which scanner produced a candidate and whether an independent verification receipt exists.
Outcome
The server-owned retest result and the evidence boundary behind validated or inconclusive status.

Evidence states are not interchangeable

Detected candidate

A scanner found a signal worth reviewing. Confidence can help prioritize it, but does not prove exploitability.

Independently verified

A separate verification receipt supports the finding. Engine confidence alone never creates this state.

Retest-confirmed

A server-owned deterministic retest found the relevant condition absent after a fix, with complete applicable coverage.

Inconclusive

The available retest evidence cannot establish that the condition is gone. The uncertainty remains visible.

What this methodology does not claim

  • It does not prove an application has no vulnerabilities.
  • It does not imply every one of the Vibe Security 50 controls is machine-testable.
  • It does not replace an authorized penetration test or specialist point tool.
  • It does not open a Fix PR until a server-generated patch is bound to an exact approval.

How should you interpret a LyraShield AI result?

Read the result in this order: confirm the authorized target and mode, inspect completed and limited coverage, separate detected candidates from independently verified findings, then read the retest receipt and retained limitations. A score or confidence value never replaces those facts.

For a broader catalog of web application verification requirements, consult the OWASP Application Security Verification Standard. This reference does not imply certification or full ASVS coverage.

Start with a check you can inspect.

The free tools run locally in your browser and state their limits.

View free tools