Evidence your team can inspect and act on. A V2P result is more than an overall score. It connects weighted rubric outcomes to source locations, findings, context, and controlled next actions.
From observation to decision
Observed source pattern A relevant file, excerpt, and audit category. Reviewable guidance Impact, context, and a suggested way forward. Fresh, scoped result A new audit confirms the updated source snapshot. 20 category scores Severity-ranked findings File-level references Reviewable repair guidance
File-level finding High · Security
app/api/webhooks/route.ts · request handler
Verify the provider signature before processing. The handler accepts and acts on a request body before establishing that it came from the expected provider.
const payload = await request.json();
await processEvent(payload);01 Where A file path and, when available, a line range identify the source location connected to the finding.
02 What The finding explains the observed pattern, its severity, category, and why it matters in the submitted source.
03 Evidence Relevant excerpts and context make the result inspectable instead of asking your team to trust a label alone.
04 Next action Suggested remediation, prompts, or patches give reviewers a concrete starting point without applying changes automatically.
Prioritize Sort the private findings by severity, confidence, pillar, and affected source area.
Decide what needs attention first Repair Use the evidence and suggested next action inside your existing engineering review process.
Your team controls every change Re-audit Submit the updated source and compare a fresh result against the previous audit.
Confirm the current snapshot Publish Issue an eligible result only when its score, scope, coverage, and fingerprint are ready to share.
Public disclosure stays scoped Detailed evidence stays private. The private report contains the information your team needs to investigate and improve the code.
Private report Detailed findings, file references, excerpts, confidence, severity, remediation guidance, workflow state, and internal review activity.
Public verification Only the issued score, public status, scope, date, audit version, fingerprint, and explicitly supported summary fields—not the proprietary source or private findings.
Get evidence tied to the source. Assess one repository snapshot against the complete V2P rubric, then use the private report to decide what happens next.