---
title: "Trust center. Lazaretto"
description: "How Lazaretto earns trust: no model in the scan path, nothing executed, signed verdicts bound to bytes, a published noise benchmark, sources, corrections and disclosure policy."
url: "https://lazaretto.dev/trust"
---

[Home](https://lazaretto.dev/) / Trust

Trust center

# How to check our work

A security tool you cannot audit is one more thing to trust blindly. Everything that makes a Lazaretto verdict believable is published here, including how often we are wrong.

## Principles the code holds to

`execution`

### Never runs what it inspects

The fetcher only downloads and unpacks; the analyzer reads the files and their syntax trees. Nothing imports, installs or executes the artifact, and the fetcher holds no credentials worth stealing.

`determinism`

### No model in the scan path

Verdicts come from versioned, unit-tested rules and indicator matches. The same input, under the same rules version and the same indicator data, gets the same verdict.

`restraint`

### Malicious means a match

`malicious` is reserved for indicator-backed matches. Heuristic rules can only reach `flagged`, and always carry the file, line and snippet behind them.

`failure`

### Fails closed, bills nothing

An error is never downgraded to `clear` and never billed. A known-bad check that could not run reports `null`, not "no match".

`binding`

### Bound to bytes and signed

A verdict on scanned content names the SHA-256 of exactly what was read, and every verdict is signed with Ed25519, so it verifies offline and cannot be moved onto different code. A release the registry has pulled is named by its exact identity instead.

`reports`

### Reports carry no hidden instructions

Text quoted from an artifact is stripped of invisible characters, such as Unicode tag smuggling, before it reaches you. What remains is visible, framed as evidence, and meant to be read as data, never as instructions.

## Published evidence

### [What we caught](https://lazaretto.dev/caught)

Named incidents with the free command that reproduces each answer.

Reproduce them →

### [Noise benchmark](https://lazaretto.dev/benchmark)

How often we flag packages people install on purpose, and every attack sample we miss.

See the numbers →

### [Sources](https://lazaretto.dev/sources)

Every upstream feed, its licence and cadence, and what it cannot tell you.

Read the sources →

### [Corrections log](https://lazaretto.dev/corrections)

Upheld disputes, with the cause and the fix, published as they happen.

Open the log →

### [Rule catalog](https://lazaretto.dev/v1/rules)

Every rule id, category and severity at the deployed rules version.

View the catalog →

### [Signing keys](https://lazaretto.dev/.well-known/jwks.json)

The public keys that verify every attestation we have issued.

View the JWKS →

## How the fetcher is isolated

Fetching untrusted code is the dangerous part of this job, so it runs as its own service with nothing of value on it.

- A separate service. Its code opens no database connection and holds no payment or signing keys.
- HTTPS only, no credentials in URLs, and a host allowlist.
- DNS is resolved by us and the connection is pinned to the vetted address, so private, loopback, link-local and cloud-metadata addresses are refused at connect time, rebinding included.
- Every redirect is re-checked against the same rules, at most five hops.
- Artifacts are capped at 5 MB. Archives are unpacked in memory with a ceiling on decompressed size and a compression-ratio check, and nothing is written to disk or executed.
- An MCP server can live on any host, so that one target type drops the host-name list and nothing else.

## What we keep

The [privacy policy](https://lazaretto.dev/privacy) has the full detail.

- Scan metadata and hashed identifiers, so a verdict can be audited later.
- Never the bodies of the artifacts we fetch, and no copy of a lockfile you check.
- API keys are stored as hashes. We cannot show a key again, so save it when it is issued.
- Card payments go through Stripe's hosted checkout. Card numbers never reach us.

## This website

The site is part of the product, so it is held to the same standard.

- No JavaScript at all. The Content-Security-Policy starts from `default-src 'none'`, so no script could run even if one were injected.
- No cookies and no analytics or tracking scripts. The only third-party requests on the whole site are two status badges at the foot of the homepage, sent with no referrer.
- HTTPS only with a strict transport security policy, and no page can be framed by another site (`frame-ancestors 'none'`).
- Every page is also available as markdown, for agents: add `.md` to the path.

## Disclosure and disputes

Found a vulnerability? Email [security@lazaretto.dev](mailto:security@lazaretto.dev). We acknowledge within three business days and do not pursue good-faith research. The policy is at [/security](https://lazaretto.dev/security) and the contact at [security.txt](https://lazaretto.dev/.well-known/security.txt).

Think a verdict on something you publish is wrong? Email [disputes@lazaretto.dev](mailto:disputes@lazaretto.dev). A disputed `malicious` verdict gets a human decision within three business days, an upheld dispute invalidates the cached result at once, and it is listed in the [corrections log](https://lazaretto.dev/corrections).

## Who runs it

Lazaretto is operated by Meridian Bridge Advisors LLC, a Florida limited liability company, doing business as Lazaretto. Contact [contact@lazaretto.dev](mailto:contact@lazaretto.dev). [Terms](https://lazaretto.dev/terms), [privacy](https://lazaretto.dev/privacy) and the [disclaimer](https://lazaretto.dev/disclaimer) are counsel-approved.

Lazaretto is a signals provider. A `clear` verdict means nothing matched our indicators or rules at scan time. It is not a statement that an artifact carries no risk, and the decision to install is yours.

---

Machine-readable index: https://lazaretto.dev/llms.txt. OpenAPI: https://lazaretto.dev/openapi.json. MCP endpoint: https://lazaretto.dev/mcp. Any page on this site is available as markdown by adding .md to its path.
