Methodology

How VICE turns security signals into findings

VICE separates observation, evidence, confidence and severity so every result explains what was seen, how certain it is and what to do next.

01SIGNALobserved02EVIDENCEattached03FINDINGqualifiedBVICE82/100
01 / Methodology

Audit profiles

Light scan

Public, passive checks for TLS, security headers, exposed files and other signals visible without authentication.

light.audit3 stages
01TLS
02HEADERS
03FILES

Full audit

The complete verified-domain audit, including active but non-destructive probes across the supported web security modules.

full.audit4 stages
01SURFACE
02PROBES
03RLS
04CODE

Custom audit

A verified audit limited to the modules you select when you need a focused check or a faster retest.

custom.audit3 stages
01SCOPE
02MODULES
03RETEST
02 / Methodology

Evidence and confidence

04 / 04

Confirmed

VICE observed direct evidence that proves the condition, such as exposed data or a reproducible security control failure.

confidence04 / 04
03 / 04

Probable

Several strong signals point to the issue, but one missing proof prevents VICE from calling it confirmed.

confidence03 / 04
02 / 04

Heuristic

A pattern deserves review, but it is not enough on its own to claim a vulnerability.

confidence02 / 04
01 / 04

Informational

Useful context about the attack surface or hardening state with no vulnerability claim.

confidence01 / 04
03 / Methodology

Scoring without false precision

VICE Score

The VICE Score weights severity and confidence, caps repeated findings from the same rule and excludes weak signals from punitive scoring. It is a prioritization tool, not a certification.

headerstlssupabase82

Scope and safety

Light scans stay passive. Deeper probes require a verified domain and remain confined by protocol, DNS, IP, redirect and request budgets. Credentials never travel to a secondary origin.

TXT · _vice-verify.acme.devRLSAUTHSTORAGE

Known limits

An automated audit is a point-in-time view. It cannot prove that every code path is safe, replace a manual penetration test or see private systems that were not connected.

$ GET acme.dev/.env200 OK# .env · productionDATABASE_URL=••••••••••••STRIPE_SECRET_KEY=sk_live_51H…SUPABASE_SERVICE_ROLE=••••••RESEND_API_KEY=••••••••
Editorial details
Published by
Webba Creative Technologies
Technical review
VICE maintainers
Published
Updated

Resources