QFinch Research · Application security

Read coverage before counting findings

A useful security result tells you what was examined and what remains unknown.

QFinch editorial · 11 October 2026 · General guidance

Define the assessed surface

A source repository, container image and web endpoint expose different information to an assessment. A web scan does not provide source-code coverage. A container inventory does not automatically describe every file in its linked repository. Choose the assessment that matches the question.

Check completion and freshness

Before comparing counts, review the target revision, assessment time and execution status. A failed, partial or stale assessment can produce a misleading picture if it appears alongside complete results without qualification. No findings is a result within a scope, not proof of security.

Evaluate against your stack

Language, framework, manifest and infrastructure-format support vary by assessment. Ask which inputs were accepted, which checks ran and what was excluded. During QFinch Early Access, this scope is reviewed with experts before setup rather than inferred from a sample project.

Use a comparable reassessment

Agree how the team will validate a proposed fix. Compare the relevant target, configuration and evidence after the change. Record any remaining assessment gaps so they do not disappear behind a smaller finding count.

This article is educational. Validate actions against your application, advisory evidence and organizational procedures. QFinch is in beta.

← All research articles