// Badge policy
No public site-secure seal.
A review is one app, one stated use, one environment, and one date. A seal cannot carry which layers were actually tested, so Liquid does not issue one. A private quote is allowed only when every material layer was recorded and no Critical, High, or Medium finding is still open.
What you can say
- Share the private report, including every layer marked Gap or Not in this review.
- "Reviewed by Liquid on [date] for [stated use], method LM-I-1.2." — only when that report says a private quote is allowed, and only with people who need it.
- Retest results, with their own date.
What you can't say
- Any public badge, seal, logo, or “site seguro” mark — including on a public website.
- "Certified secure" or "hacker-proof".
- A seal while any material layer is Not in this review or Gap, or while a Critical, High, or Medium finding is not Fixed.
- Treating a header scan, a passive read, or a locked scope as a complete review.
- Using an old review after the app has materially changed.

> liquid.explaining
If someone asks whether your app is safe, point them to the scope and date in your report. That's the honest answer.