# Signals, not warranties

> What an inspect.software result does and does not claim — the honest boundary between visible practice signals and a formal audit or guarantee.


Every report, badge, and certification published by inspect.software carries
the same disclaimer: **results are signals, not warranties.** This page states
precisely what that means, because trust in the record depends on never
claiming more than the evidence supports.

## What a result claims

A health index and its underlying metrics reflect **publicly visible
practice**: commit and release history, contributor distribution, community
files, CI and test configuration, registry publishing state, and
security-relevant signals such as those measured by the
[OpenSSF Scorecard](/wiki/security-posture). Every claim is:

- **Observable** — derived from public data anyone can fetch.
- **Reproducible** — every metric echoes its inputs, and the formulas are
  published in the [methodology](/methodology).
- **Versioned** — each report records the metrics version it was produced
  under, so a result can be re-derived later.

## What a result does not claim

- **It is not a code audit.** No line-by-line review of correctness,
  performance, or vulnerability is performed. A project with exemplary process
  can still ship a defect.
- **It is not a security guarantee.** [Security posture](/wiki/security-posture)
  measures visible security hygiene — it cannot rule out an undiscovered
  vulnerability or a compromised maintainer account.
- **It is not a judgement about a person or country.**
  [High-Risk Jurisdiction Exposure](/wiki/jurisdiction-exposure) routes
  policy-defined public profile evidence into enhanced review. It does not
  determine nationality, citizenship, trustworthiness, sanctions status,
  repository permissions, or malicious intent.
- **It is not an endorsement.** Inclusion in the public record means a
  repository was inspected, not that inspect.software recommends it.
- **It is not a ranking.** Two records can be read side by side — the
  [comparison view](/compare) exists for exactly that — but the index weighs
  categories that different projects have different and legitimate reasons to
  answer differently. A comparison is a reading, not an order of merit.
- **It is not a prediction.** A well-maintained project can be abandoned next
  month. Scores describe the observable present and recent past.

<div class="md-callout warn"><span class="md-callout-icon">△</span><div><b>Certifications are signals, not warranties.</b> They inform review and procurement; they do not replace expert judgement, legal review, or an independent security assessment where one is required.</div></div>

## Why this boundary is kept strict

The value of the record comes from its restraint. A registry that overstated
its results would be gamed by marketing and discounted by engineers; one that
states exactly what it measures can be relied on for exactly that. The same
restraint appears in the formulas themselves: missing data is excluded and
weights renormalized — never guessed, never counted against a project (see
[the health index](/wiki/health-index)).

## Independence

Published results are independent of payment. Free public-interest scans and
paid certifications run the same versioned methodology, and no commercial
relationship — sponsorship, certification fees, vendor alignment — can alter
a published value. Where a scan intentionally narrows the methodology, the
report says so explicitly (see [scan configuration](/wiki/scan-configuration)).
