Application Identity and Scope
Every assessment is anchored to an unambiguous definition of what is being reviewed.
- The application, version, and source commit under review are precisely identified.
- The deployment environment and in-scope components are documented.
- Exclusions are stated explicitly in the assessment scope and the public record.