Home / Proof

The numbers. Not the promises.

SauronSec’s precision is measured on public, reproducible test sets — the OWASP Benchmark. Here are the raw results, class by class, including where we aren’t perfect.

100%
Precision
100%
Recall
0
False positives
OWASP Benchmark — by classDetectionFP
SQL injection99.6%0
Command injection100%0
Cross-Site Scripting100%0
XPath injection100%0
LDAP injection100%0
Path traversal / LFI56.4%0

Honesty, not make-up. Five classes out of six reach ~100% detection, with zero false positives everywhere. Path traversal plateaus at 56.4% because part of the cases are blind (no observable signal) — a limit shared by every dynamic scanner. We show it rather than hide it.

Methodology

Reproducible, verifiable.

Public benchmark

The OWASP Benchmark provides thousands of labelled test cases (true/false). No custom tuning: same binary, same cases.

Precision & recall

Precision = zero false alarms. Recall = real flaws aren’t missed. Both matter; one without the other is worthless.

145 internal tests

Beyond the public benchmark, a regression suite keeps every module honest at each release.

Why it matters

A false positive costs more than a missed flaw.

Every false alarm means a distracted developer, eroded trust, a report that eventually goes unread. Zero false positives isn’t a marketing line: it’s what makes a report actionable.

Convinced by the numbers?

Let’s move on to your site.

Ready to scan without a shadow of doubt? Request an audit