Verified true positives.
Open PRs. Zero ceremony.

Your scanners produce 4,000 alerts. 12 matter. Verdict shows you which — verified against your code, your prod asset map, and your dependency graph. Then it opens the PR.

Connect GitHub or GitLab. Works on any tier — we scan your lockfiles against OSV ourselves, no Dependabot required.

See the inbox →

No card. 5-min setup. Free during preview.

5 verified · cut from 4,182 raw findings(99.7%)acme-inc
Prototype pollution in lodash.mergewithacme/billing-api4.6.2
Live AWS access key leakedacme/data-pipelinerotate
axios SSRF via crafted URLacme/billing-api1.7.4
requests cert verification skippedacme/ml-trainer2.32.0
Outdated express with known DoSacme/marketing-site4.19.2

Verified, not detected

Seven deterministic stages — severity, EPSS, KEV, fix-availability, prod-asset, runtime-dep, and Tree-sitter import reachability. Findings that don't clear them go to Likely or Suppressed — never silently dropped.

Auto-PR / Merge Request

When the verifier says yes, Verdict opens a PR on GitHub or a Merge Request on GitLab — draft until CI is green, then ready to review. Monorepo-aware.

Works on any host, any tier

GitHub + GitLab. We scan your lockfiles against OSV ourselves — no Dependabot or GitLab Ultimate needed. Already have Snyk, Dependabot, or Trivy? We dedup them into one canonical finding.

verdict · v0.1 · previewBuilt additively — keep your existing scanners.
Verdict