The numbers. Not the promises.
SauronSec’s precision is measured on public, reproducible test sets — the OWASP Benchmark. Here are the raw results, class by class, including where we aren’t perfect.
Honesty, not make-up. Five classes out of six reach ~100% detection, with zero false positives everywhere. Path traversal plateaus at 56.4% because part of the cases are blind (no observable signal) — a limit shared by every dynamic scanner. We show it rather than hide it.
Reproducible, verifiable.
Public benchmark
The OWASP Benchmark provides thousands of labelled test cases (true/false). No custom tuning: same binary, same cases.
Precision & recall
Precision = zero false alarms. Recall = real flaws aren’t missed. Both matter; one without the other is worthless.
145 internal tests
Beyond the public benchmark, a regression suite keeps every module honest at each release.
A false positive costs more than a missed flaw.
Every false alarm means a distracted developer, eroded trust, a report that eventually goes unread. Zero false positives isn’t a marketing line: it’s what makes a report actionable.