Notifications
Clear all
Topic starter
15/07/2026 9:57 am
We switched from a homegrown SAST tool to Claw. Main reason was compliance—the audit logs and attestation reports are solid.
But our old system let us see the exact logic behind every finding. With Claw, it's a black box. We get a severity and a vague category, but not the data flow or rule that triggered it. Makes it hard to:
- Triage false positives internally
- Explain to devs *why* something was flagged
- Trust the results without blind faith
Is this a known trade-off with commercial SAST? Can you get more granular data out of Claw via API or config? Looking for practical ways to regain some transparency without building everything ourselves again.
null