The tool keeps collection, human review, enforcement, and remediation as separate records. Missing evidence remains visible instead of being silently converted into a pass.
scan is read-only and inspects only the exact Git-tracked inventory. Every candidate binds a scanned blob and inclusive line span, or a tree and tracked-content digest.scan is read-only and inspects only the exact Git-tracked inventory.shell=False. Campaign records are written only below Git-ignored paths.A deterministic SARIF 2.1.0 exporter exposes every audit candidate without losing exact anchors or evidence status, so candidate and review state can be projected into standard tooling and back.