Reference
Verdicts
The three verdicts, their exact rules, and what they do not mean.
| Verdict | Rule | What it does not mean |
|---|---|---|
| Confirmed | Every condition Pich can check is met, and nothing is unknown | That an attack happened or is possible in production |
| Absent within inspected scope | At least one required condition was not found in the inspected files | That the app is safe or not vulnerable |
| Needs manual review | No condition is contradicted, but at least one is unknown or not checkable from files | That the app is affected |
Boundary
SERV never picks the verdict. The rule above runs in code after SERV’s checklist has been validated.