Universal checks
The released verifier includes checks for secret exposure, agent scope escalation, system-data exposure, destructive infrastructure operations, application authorization, broken access control, CSV formula injection, unsafe file uploads and unvalidated outbound requests.
Design-derived requirements
Your specification supplies context that a generic code check cannot infer. FlowRail derives supported security requirements with explicit scope and relevant constraints, including audience, destination and failure handling. Those requirements are checked where they apply.
Custom rules for pilot projects
Per-project custom guardrails live server-side. FlowRail can compile design-review threats into project rules, and a human veto takes precedence. The flowrail.yaml file created by the installer is not a working interface for authoring guardrails in YAML.
What the results mean
A finding describes a detected violation of an evaluated rule.
Not established means the available context does not establish a requirement. It is distinct from both a violation and verified satisfaction.
An incomplete check is an operational result. Under the default scoped posture, incomplete design-bound writes pause for retry.
At the pull request
The CI gate evaluates universal and enabled project rules. Each rule can be blocking or advisory at that checkpoint, and the project's mode determines enforcement. The CI run is project-scoped rather than bound to the local review.