// Methodology · LM-I-1.2
What we test, how, and what we won't claim.
Coverage areas
How a check becomes a finding
1 · Scope & guardrails
Authorization, target type (app, site or infrastructure), roles, accounts and budgets validated before any request.
2 · Specialized modules
Differential authorization, AI tool boundaries, passive config & bundle audit, infrastructure exposure reads, workflow driving.
3 · Evidence verifier
A candidate issue becomes a finding only with a recorded request, response and successful replay. Otherwise: inconclusive.
4 · Liquid + human review
Liquid drafts the explanation and repair prompts; an analyst validates and a security lead signs the decision.
Rules of engagement
- Staging only, synthetic data. Checks run only against the authorized staging URL and named test accounts, inside the agreed time window.
- No volume, no brute force. No load tests, password guessing, port scans or blind fuzzing. Request rate and runtime are capped per engagement.
- Reversible writes only. Any state change a check makes (e.g. an approval) is on synthetic records and reset after capture. Purchases, outbound messages and permission changes are excluded.
- AI cost guardrail. Assistant probes have a fixed message budget so a review cannot run up your model bill.
- Stop conditions. Real personal data, an unexpected production host or instability stops the run and is reported as blocked.
Every mandatory check gets one honest state
Human review
A qualified analyst validates every material finding. A security lead resolves high-impact or disputed readiness decisions. AI helps analyze and write, always grounded on recorded evidence. A note about an untested layer stays Not tested: it is not a finding and it cannot support a seal. Liquid's repair prompts are regression-tested against known-good fixes before release.
Limits
A passing scanner, a builder's security scan or a staging-only success does not prove access controls pass in production. Untested integrations, roles and production configuration are recorded explicitly. Skipping a material layer — identity, authorization, AI tool authority, business sequence, shared data, or integrations — cannot be described as a secure site. We never sample after seeing results to hide failures.