Skip to content

Glossary

Not verified

Named items nobody checked, listed rather than quietly dropped.

Last updated September 20, 2026

What it means

Not verified is the list of things that matter and that a check from outside cannot reach: sign in behaviour, row rules, rollback, rate limits, payment handling, key rotation, customer data handling, AI controls, error monitoring.

Most tools leave these out, and the result reads as if the app were covered. It is not covered. An assessment of 200 AI-built apps found 91.5 percent carried at least one vulnerability, and most of what that study counts lives behind the login.

So ShipReady names each one, explains why a URL cannot see it, and gives a way to test it yourself in a few minutes. A Launch Review moves items off this list by having a person look. Nothing else does.

Incidents where it mattered

No incident in the library maps to this one yet.

Back to the glossary

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026