Security
Trust model
What Pich trusts, what it checks, and what it leaves to a person.
| Component | Trusted for | How it is checked |
|---|---|---|
| SERV Reasoning | Reading advisory prose | Strict schema, verbatim quote check, fixed vocabulary, polarity correction |
| Pich engine | Observing files and picking the verdict | Deterministic tests over 16 expected results |
| GitHub | Serving the files of a public repository | Evidence shows file and line so a reader can open the same file |
| You | Anything unknown, not checkable, or in a client note | Pich lists these explicitly |
Every verdict can be checked by hand: the evidence names the file and line it came from.