What "human-signed findings" means - and why it should decide your vendor
There is a version of AI-driven security that is genuinely good and a version that is genuinely dangerous, and from the outside they look almost identical. Both point automated tools at your systems. Both produce a lot of findings, fast, cheap. The difference is entirely in what happens between the tool producing output and that output reaching you.
We describe every deliverable we produce as human-signed. It is the single most important word in how we work, and it is worth being precise about what it does and does not mean - because “AI-powered security” is about to be written on everything, and you need a way to tell the two versions apart.
The problem with unsupervised machines
Point a vulnerability scanner at a real company’s estate and it will find things. It will also find thousands of things that are not things:
- False positives - a version banner that suggests a vulnerable release when the fix was backported; a “finding” on a path that returns 404 to everyone; a TLS warning about a cipher no client will ever negotiate.
- Context-free severities - a “critical” CVSS score on a service that is firewalled off, or on a bug for which no exploit exists and never will.
- Duplicates and noise - the same issue reported forty times across forty hosts, each as a separate line item, none of them prioritised.
A security program that treats that raw dump as its output does not have visibility. It has a new full-time job: someone has to read the thousand alerts to find the ten that matter, and if nobody does, the ten drown with the rest. Automating the scanning without automating the judgment just moves the bottleneck downstream to you.
Now add a large language model that writes confident, fluent prose about each finding, and you have made it worse. The output reads authoritatively. It is wrong at exactly the same rate, but now it is persuasively wrong, and it takes more expertise, not less, to tell which paragraphs to trust.
What signing actually means
Here is the rule we hold ourselves to: nothing reaches a client without a named security professional validating it and putting their name to it. That is the signature. It is not a metaphor and it is not a marketing flourish - it is a gate in the delivery process that findings have to pass through, and a person who is accountable for what gets through.
Concretely, when an automated stage flags something, a human:
- Confirms it is real - reproduces the exposure, or verifies it against the actual live behaviour of the asset, not just a banner or a version string.
- Confirms it matters to you - is the vulnerable thing actually reachable, actually exploitable, actually yours? A critical bug behind an authenticated internal-only endpoint is a different priority than the same bug pre-auth on your marketing site.
- Decides the priority honestly - correlating exploitability signals (is it in CISA KEV? what’s its EPSS probability?) with your context, so “fix now” means now and “schedule it” means it can wait.
- Writes the fix, not just the finding - what to change, in terms your engineers can act on.
Everything that fails step one or two dies there. It does not reach your inbox. The value we add is as much in what we delete as in what we deliver. You get the ten findings that are real, not the thousand that aren’t - and each of the ten has a person standing behind it.
Why we let machines do the rest
To be clear, this is not anti-automation. The opposite. AI agents do the enormous, repetitive, continuous toil - discovery across your external estate, re-checking assets, correlating feeds, running assessment at a cadence no human could sustain by hand. That automation is exactly why continuous monitoring can cost SMB prices instead of enterprise ones: the marginal cost of one more scan, one more asset, one more day of coverage is nearly zero.
The economics only work because the machines do the toil. The trust only works because they don’t do the signing. Both halves are load-bearing. Take away the automation and you are back to enterprise pricing. Take away the human sign-off and you are back to alert fatigue with better prose. We keep both, deliberately, and we are open about which does which: the machines do the toil; the people take the responsibility.
How to tell the two versions apart
Whether or not you ever work with us, this is a useful question to put to any security vendor - especially any “AI-powered” one:
- Who, by name and role, reviews a finding before I see it? If the answer is “our platform” or “our algorithm,” you are buying the raw scanner output with a nicer UI. You will do the triage yourself.
- What is your false-positive rate, and what happens to false positives? A vendor proud of their sign-off process can tell you where noise dies. One that can’t, sends it to you.
- Can a person explain and stand behind this specific finding? Real findings survive questions. Machine-confident hallucinations get vaguer the harder you push.
The reason this should influence your vendor choice is simple: security findings are only useful if you can act on them, and you can only act on the ones you trust. A report you have to independently re-verify is not a report - it is homework. The signature is what turns output into something you can take to your engineers, your auditor, and your board without doing the verification twice.
The gate is the product
It would be cheaper for us to skip the human step. That is precisely why we don’t. In a market about to be flooded with automated security tooling, the scarce, valuable, honest thing is not another scanner - it is a named professional willing to put their name on what the scanner found, and to delete the 990 findings that were never real.
That gate is not overhead on top of the product. For a security deliverable, it is the product. Everything else is just how we get enough signal to the person doing the signing.
Want to see what human-signed findings look like for your estate - the real ten, not the noisy thousand? A 30-minute scoping call is where we start. See what’s exposed.
Get new posts by email
Security engineering, compliance without theatre, open-source threat intel. No tracking, no forwarding your address, unsubscribe in one click.