Corrections log

A security tool that never publishes its mistakes is asking to be taken on faith. This page is the opposite of that: every verdict we published and later corrected, what went wrong, and what we changed so it would not happen again.

No dispute has been upheld to date.

Read that precisely. It means nobody has reported a verdict of ours as wrong and been proven right yet. It is not a claim that our verdicts have all been correct, and you should not treat it as one. This is a young service with modest volume, detection is imperfect by nature, and a clear result can be wrong. An unbroken record is not something we could prove even if we had one, so it is not something we claim.

How to dispute a verdict

If you publish an artifact and believe our malicious or flagged verdict is wrong, email contact@lazaretto.dev with the package or hash. Our commitment, which is referenced from the Terms:

What we already publish about our limits

Corrections are the last line, not the first. We also say up front where a verdict is weaker than it looks: a scan that could not read part of an artifact says so, a known-bad check that could not run reports null rather than "no match", and an unpinned package with a version-scoped advisory returns "cannot determine" rather than a guess. See where our data comes from and the disclaimer.

Machine-readable: /corrections.json