operate
Finding Memory — Triage Once
Accept, dismiss, or fix a finding once — the Brain stops re-flagging it.

What you get
Your judgement is remembered
When you accept a risk, mark a false positive, or fix an issue, the Brain records that disposition against the finding — so the next scan doesn't resurface a decision you already made.
Signal, not repetition
Scans stop nagging you about triaged findings, so what's left on the report is genuinely new — not the same accepted item on every run.
Survives re-scans and redeploys
A disposition is tied to the finding's fingerprint, not the scan run. Redeploy, re-scan, or switch branches and an accepted-risk stays accepted — the reasoning you typed once travels with it, so whoever reviews later sees why it was closed.
How disposition recall works
- 1
A scan surfaces a finding.
- 2
You accept the risk, mark it a false positive, or fix it.
- 3
The Brain stores that disposition against the finding.
- 4
Future scans recall it and don't re-flag it unless it materially changes.
What this check inspects
Every disposition you've recorded — fixed, accepted, false positive — with the reasoning you gave.
Which findings are genuinely new since the last scan.
Whether an accepted risk has changed in severity and deserves revisiting.
Who decided what, and when.
What it means when this fails
Without memory, every scan re-reports everything and the team learns to ignore the report — the single most common way security tooling becomes useless. With it, a scan shows what changed, and accepted risks stay accepted with the reasoning attached.
Questions
- What if I accept something I shouldn't have?
- The decision is recorded with its reasoning, so it can be reviewed rather than quietly forgotten. If severity changes, it resurfaces.
- Does this hide real problems?
- Only what you explicitly dispositioned. New findings always surface.
- Does it survive redeploys?
- Yes — dispositions are tied to the finding's fingerprint, not to a scan run.
What it replaces
Snyk Team
Per contributing developer, 5-seat minimum (~$1,500/yr entry). Code + dependency scanning; does not deploy your app.
GitHub Code Security
CodeQL scanning, Dependabot, dependency review. Billed per active committer; GitHub repos only.
ZipLoom Solo — all 28 features included
Deploy, security scan, and monitoring in one flat price. Guild $40/mo · Studio $70/mo · Business $299/mo.
Related features