Read-only review
Pallos reads only the repositories you select. It does not edit, push, merge, or deploy code.
Pallos uses focused, deterministic rules to review supported code and configuration. Every result separates verified signals from checks that could not be completed.
Pallos reads only the repositories you select. It does not edit, push, merge, or deploy code.
Findings point to the affected file and explain the detected pattern without exposing saved secrets.
Untested checks stay marked unknown. A clean scan is not presented as proof that an application is secure.
The private beta is primarily designed for JavaScript, TypeScript, Next.js, Supabase, and common surrounding services.
Risk level follows the most serious verified issue, so one high-severity authorization problem can make the result High Risk.
Score summarizes passed and failed checks. It is not a certification.
Coverage shows the percentage of available checks Pallos could actually run. Unknown checks do not silently count as passed.
It does not replace penetration testing, manual code review, compliance work, or testing every business rule and authorization path. Results depend on the files and integrations available during a scan.
Added clearer score definitions, explicit coverage reporting, capped result lists, dependency advisory checks, and verified-fix history.