Detected candidate
A scanner found a signal worth reviewing. Confidence can help prioritize it, but does not prove exploitability.
Methodology
LyraShield AI preserves scope, coverage, evidence provenance, and retest state as separate facts. It does not turn scanner confidence or missing evidence into a universal security verdict.
TL;DR
Every finding carries one of four evidence states: detected candidate (a scanner signal that needs review), independently verified (a separate receipt supports it), retest-confirmed (a deterministic retest found the condition absent), or inconclusive (the retained evidence cannot establish resolution). A score or clean result never overrides these facts.
Last reviewed: · Maintained by LyraShield Security + Engineering

A scanner found a signal worth reviewing. Confidence can help prioritize it, but does not prove exploitability.
A separate verification receipt supports the finding. Engine confidence alone never creates this state.
A server-owned deterministic retest found the relevant condition absent after a fix, with complete applicable coverage.
The available retest evidence cannot establish that the condition is gone. The uncertainty remains visible.

A public scorecard may include a release verdict. The verdict is derived from the frozen LyraShield Score using the same versioned model that produced the grade. It is an interpretation aid, not an override of the underlying evidence.
Read the result in this order: confirm the authorized target and mode, inspect completed and limited coverage, separate detected candidates from independently verified findings, then read the retest receipt and retained limitations. A LyraShield score or confidence value never replaces the underlying scope, coverage, evidence-state, and retest facts.
For a broader catalog of web application verification requirements, consult the OWASP Application Security Verification Standard. This reference does not imply certification or full ASVS coverage.
LyraShield AI does not claim "SOC 2 compliant," "certified," "guarantees security," "AI safety tested" (without a named framework), or "adversarial robustness proven." Each of those requires external attestation, a reproducible evaluation corpus, a defined threat model, or a formal certificate that LyraShield has not yet obtained.
An evidence state describes how much support a finding has. Detected, independently verified, retest-confirmed, and inconclusive are separate states, not interchangeable labels.
No. A score is an interpretation aid derived from the evidence. It does not override the underlying findings, coverage limits, or retest receipts.
It means the assigned check completed without reporting anything in scope. It is not the same as 'passed' or 'secure'; it only records that the check ran and returned nothing.
It is a fixed list of 50 controls LyraShield AI reviews on AI-built apps. 43 are routed to code or URL review where applicable and 7 require operational or human evidence outside the scan because a repository or URL scan cannot establish them safely.
The free tools run locally in your browser and state their limits.