Ready
Every required check has fresh evidence and there are zero open critical or high findings.

Workflow guide
Updated August 17, 2026
A ready verdict means the required connections are active, every required check has current evidence, and no open critical or high finding exists in that evidence. The default freshness window is 24 hours.
Needs Supabase + GitHub
Confirms the connectors an audit depends on are actually active, so no verdict is ever computed with a blind spot.
Needs Supabase
Reads every non-system table and its policy count to catch tables with Row Level Security off, and tables with RLS on but zero policies.
Needs Supabase
Pulls Supabase's own security and performance advisor lints — exposed views, definer functions, unsafe function search paths, auth configuration.
Needs GitHub
Searches your connected repositories for service-role keys and other credentials sitting in client-reachable paths or public-prefixed env vars.
Needs GitHub
Locates and reads the security-critical files — auth handling, middleware, webhooks, env plumbing, migrations — and reviews what they actually do.
Needs GitHub
Resolves your package manifests and checks each dependency against the OSV vulnerability database for known advisories.
Needs Vercel
Classifies deployment environment variables by risk and inspects deployment protection settings on the hosting side.
Every required check has fresh evidence and there are zero open critical or high findings.
Evidence is complete and nothing critical or high is open, but medium and low findings are waiting on a human decision.
Evidence is complete and at least one open critical or high finding stands between you and launch.
One or more required checks has never run, failed, or has gone stale — so no score is reported at all.
The verdict is the safety boundary; the score is supporting detail. Critical and high findings block launch. Medium and low findings cap the result at needs review. Missing required evidence removes the score entirely.
A truncated evidence set cannot certify ready. When Sentrail cannot inspect the complete required scope, it lowers the result rather than treating an incomplete sample as representative.