Verified true positives.
Open PRs. Zero ceremony.

Your scanners produce 4,000 alerts. 12 matter. Verdict shows you which — verified against your code, your prod asset map, and your dependency graph. Then it opens the PR.

Sign up with email, then connect GitHub or GitLab with an access token. Works on any tier — we scan your lockfiles against OSV ourselves, no Dependabot required.

No card. No GitHub account required. Free during preview.

not ready to connect a repo?

20 minutes. We'll show you which of your alerts actually matter — no card, no commitment.

5 verified · cut from 4,182 raw findings(99.7%)acme-inc
Prototype pollution in lodash.mergewithacme/billing-api4.6.2
Live AWS access key leakedacme/data-pipelinerotate
axios SSRF via crafted URLacme/billing-api1.7.4
requests cert verification skippedacme/ml-trainer2.32.0
Outdated express with known DoSacme/marketing-site4.19.2

Verified, not detected

Seven deterministic stages — severity, EPSS, KEV, fix-availability, prod-asset, runtime-dep, and Tree-sitter import reachability. Findings that don't clear them go to Likely or Suppressed — never silently dropped.

Auto-PR / Merge Request

When the verifier says yes, Verdict opens a PR on GitHub or a Merge Request on GitLab — draft until CI is green, then ready to review. Monorepo-aware.

Works on any host, any tier

GitHub + GitLab. We scan your lockfiles against OSV ourselves — no Dependabot or GitLab Ultimate needed. Already have Snyk, Dependabot, or Trivy? We dedup them into one canonical finding.

verdict · v0.1 · previewBuilt additively — keep your existing scanners.
Verdict