CerbIA

Gate behavior

Understand how SecurityGate combines scanner findings, actions, scores, and thresholds into a verdict.

reference
gate
verdict

SecurityGate evaluates one entry with an ordered set of scanners and turns their findings into a verdict. It is created by Runner from the configured scanners, score aggregator, threshold, fail-fast setting, and scanner-error policy.

Findings and scores

A scanner emits a ScanOutcome: risk score, rationale, and optional match spans. The gate adds the scanner ID, display name, severity, and action to make a Finding.

Only findings with action BLOCK contribute to the aggregate. Their input to the configured score aggregator is:

weighted score = finding.risk_score × finding.severity.weight

The entry is safe when there are no blocking findings or when the aggregate is strictly below threshold. WARN and PASS findings are retained for review but do not contribute to the aggregate.

Content-type routing

Scanners may restrict their accepted content_types. Before calling a scanner, the gate compares the entry’s type with that restriction. A non-matching scanner is recorded as skipped with its reason; it does not produce a finding or affect the aggregate.

Fail-fast behavior

When fail_fast is enabled, the gate stops after the first blocking finding whose severity-weighted score reaches the configured threshold. With it disabled, the gate runs every compatible scanner and returns all findings.

Scanner errors

on_scanner_error determines how scanner exceptions affect the result:

Policy Behavior

fail

Re-raises the original error.

block

Continues according to fail-fast settings and forces an unsafe verdict.

skip

Records a skipped scanner with an execution-failure reason.

The output GateVerdict includes is_safe, aggregate score, rationale, findings, and skipped scanners. See Score aggregators for the available combination strategies.