Evidence methodology
Show the work, preserve the uncertainty
OSSPublicAudit records exact review targets, reproducible artifacts, verification state, freshness, and blind spots. Evidence tiers describe the strength of the published record—not the security of a project.
Evidence tiers
E0 · Tracked
A repository, release, or commit is tracked but not reviewed. Zero findings must not be inferred.
A repository, release, or commit is tracked but not reviewed. Zero findings must not be inferred.
E1 · Automated baseline
Reproducible automated checks are recorded with scope and artifacts.
Reproducible automated checks are recorded with scope and artifacts.
E2 · Documented AI review
An exact-target AI-assisted review has a public receipt, methods, and limitations.
An exact-target AI-assisted review has a public receipt, methods, and limitations.
E3 · Independent multi-model review
Independent runs or reviewers corroborate the evidence.
Independent runs or reviewers corroborate the evidence.
E4 · Reproduced and human-validated
Material findings and relevant artifacts receive independent reproduction and human validation.
Material findings and relevant artifacts receive independent reproduction and human validation.
Three separate ledgers
Confirmed funding received, estimated review capacity, and verified usage from completed runs are never treated as interchangeable. Community-attested usage does not enter provider-verified totals.
Freshness and blind spots
Evidence can become stale when releases, dependencies, submodules, build configuration, hardware assumptions, or deployment conditions change. Excluded code and unreviewed physical or operational attack surfaces remain visible.