Human-in-the-loop
Direct answerA named person validates exploitability, severity and disclosure before a finding is reported to a client or maintainer.
In more detail
Every firm on this index states it. The CIRCL study shows why: the AI rated four of seven severities too high and one critical too low. The person who signs the report is accountable for those calls.
Related terms
False positive rate, Precision vs recall, Agentic scanning, LLM plus fuzzing, LLM plus symbolic execution or formal verification, Hallucinated vulnerabilities, Triage burden, Benchmark contamination, AI-assisted audit vs AI audit, Prompt injection in auditing pipelines, Responsible disclosure of AI-found bugs, Continuous scanning and run-count coverage, Proof-of-concept harness, Threat model file, Severity calibration
Getting help
Firms on this index that handle this in practice: zkSecurity, Trail of Bits, Zellic, Nethermind Security.