Skip to main content
Accuracy · v4.0

Nothing gets reported until it has been exploited

Every candidate finding is now validated by replay before it reaches your queue. Unreproducible candidates are dropped rather than downgraded, which is what takes a scanner queue from thousands to dozens.

Version
4.0
Released
January 31, 2026
New features
3
Category
Accuracy

What's new

Features and improvements in this update

New features

3
  • Validation replay before reporting

    Each candidate is re-executed in isolation and the exploit outcome is checked against the expected effect. A finding that cannot be reproduced twice does not become a finding.

  • LLM-assisted triage with evidence grounding

    Model-assisted analysis is constrained to the captured request, response and code context, and any claim it makes must be supported by that evidence. It ranks and explains; it does not decide that something is exploitable.

  • Suppression with recorded reasoning

    Dropped candidates are retained with the reason they were dropped and re-evaluated when the relevant code or configuration changes, so a suppression is auditable rather than invisible.

Improvements

2
  • Cross-scanner deduplication

    The same issue found by SAST, DAST and dependency analysis is reported once, with all three pieces of evidence attached, instead of as three tickets for three teams.

  • Confidence surfaced on every finding

    Where a finding is validated but context-dependent, the confidence and what it depends on are stated on the finding rather than left to be inferred from severity.

Benefits

What it changes for you

Stated as work removed rather than capability added, the only version of a benefit that can be checked.

  • A queue small enough to actually read

    Customers moving from multi-scanner setups typically see reported findings fall by more than 90% while the count of genuinely exploitable issues goes up, because the real ones stop being buried.

  • Engineering trust, which is the scarce resource

    One unreproducible finding costs more than it appears: it teaches the team that the queue is noise. Validating before reporting is how that trust is kept.

  • Defensible suppressions at audit time

    An auditor asking why a known CVE is not in the remediation plan gets a recorded reason and the date it was last re-evaluated.

Upgrade

Getting it

Getting this update

Default behaviour from 4.0.0. Unvalidated candidates remain available through the API for teams that want to review them separately.

pip install --upgrade aiptx

See Your Attack Surface in Real-Time

Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.