Pallos AgentBack to Pallos
SCANNING METHODOLOGY

What Pallos checks—and what it cannot prove.

Pallos uses focused, deterministic rules to review supported code and configuration. Every result separates verified signals from checks that could not be completed.

Read-only review

Pallos reads only the repositories you select. It does not edit, push, merge, or deploy code.

Evidence first

Findings point to the affected file and explain the detected pattern without exposing saved secrets.

Honest coverage

Untested checks stay marked unknown. A clean scan is not presented as proof that an application is secure.

SUPPORTED CHECKS

Current scanner coverage

The private beta is primarily designed for JavaScript, TypeScript, Next.js, Supabase, and common surrounding services.

UNDERSTANDING RESULTS

Risk, score, and coverage measure different things

Risk level follows the most serious verified issue, so one high-severity authorization problem can make the result High Risk.

Score summarizes passed and failed checks. It is not a certification.

Coverage shows the percentage of available checks Pallos could actually run. Unknown checks do not silently count as passed.

KNOWN LIMITS

Pallos is a focused second pass.

It does not replace penetration testing, manual code review, compliance work, or testing every business rule and authorization path. Results depend on the files and integrations available during a scan.

Beta changelog · September 2026

Added clearer score definitions, explicit coverage reporting, capped result lists, dependency advisory checks, and verified-fix history.