Evidence methodology

Show the work, preserve the uncertainty

OSSPublicAudit records exact review targets, reproducible artifacts, verification state, freshness, and blind spots. Evidence tiers describe the strength of the published record—not the security of a project.

Evidence tiers

E0 · Tracked
A repository, release, or commit is tracked but not reviewed. Zero findings must not be inferred.
E1 · Automated baseline
Reproducible automated checks are recorded with scope and artifacts.
E2 · Documented AI review
An exact-target AI-assisted review has a public receipt, methods, and limitations.
E3 · Independent multi-model review
Independent runs or reviewers corroborate the evidence.
E4 · Reproduced and human-validated
Material findings and relevant artifacts receive independent reproduction and human validation.

Three separate ledgers

Confirmed funding received, estimated review capacity, and verified usage from completed runs are never treated as interchangeable. Community-attested usage does not enter provider-verified totals.

Freshness and blind spots

Evidence can become stale when releases, dependencies, submodules, build configuration, hardware assumptions, or deployment conditions change. Excluded code and unreviewed physical or operational attack surfaces remain visible.