A model is never allowed to be the evidence
- Decision
- Language models participate in the pipeline as a source of hypotheses, but model judgement cannot raise a finding's verification rung. Only concrete analysis — graph reachability, taint tracing, sandboxed execution — can.
- Why
- A fluent, confident and wrong explanation is the characteristic failure of model-assisted security tooling. Making the ladder structurally unreachable by a model means that failure cannot silently become a verdict.
What it cost
The tool is far more conservative than an LLM reviewer and will leave findings at a low rung that a model would happily call exploitable.
