Start
Introduction
What Pich is, who it is for, and the one rule it never breaks.
Pich tells an agency which of its client Next.js apps a security advisory actually affects. It reads the advisory with SERV Reasoning, checks each app’s code and configuration for the advisory’s exact conditions, and returns one verdict per app with the lines of code behind it.
Who it is for
Small agencies and freelancers who look after roughly 10 to 40 client Next.js apps and have to answer “are we affected?” for each client when an advisory lands.
The mental model
SERV reads the advisory. Plain code decides the verdict. Every verdict shows its evidence and says what Pich could not determine.
The rule Pich never breaks
Boundary
Pich never calls an app safe. The best outcome it reports is “Absent within inspected scope”: at least one required condition was not found in the files it inspected.
Pich never installs, builds, or runs code from a repository you give it.
Where to go next
- How it works for the lifecycle in one picture.
- Try Pich to run it on the live site in about two minutes.
- Verdicts for the exact rules behind each result.