We tried to prove them innocent. Here is what happened.
Every finding we deliver uses Analysis of Competing Hypotheses. The CIA developed it. Intelligence analysts, forensic accountants, and securities regulators use it. We use it because it is the only framework that survives cross-examination.
The method: list every possible explanation for the evidence, including every innocent one. Then test each explanation against the facts. You are not building a case for guilt. You are destroying every path to innocence. What survives is irrefutable, because you already killed every alternative.
Case File: consensus-engine vendor and a major bug bounty platform.
A researcher submits a critical finding to a vendor through a major bug bounty platform. Three explanations are on the table. Scroll the evidence and watch which ones survive — the panel on the left tracks each hypothesis as the facts arrive.
Good-Faith Process
The vendor runs a legitimate security program. Reports are triaged honestly, findings are remediated, and disclosure follows industry norms.
Process Failure
The vendor intends to operate properly but suffers miscommunication, understaffing, or honest mistakes in triage and remediation timing.
Coordinated Suppression
Vendor and platform coordinate to close valid reports without credit, suppress disclosure, and silently patch while denying the finding externally.
A real finding has been submitted and acknowledged. All three hypotheses survive. A good-faith process would accept it. No honest mistake has occurred yet. No suppression has begun.
Under H1, the good-faith process found the finding non-exploitable — but it was already confirmed real. We try harder: perhaps a different severity rubric was applied. H1 survives, but now requires an assumption. Under H2, an inexperienced triager erred. H2 survives. Under H3, the account exists to close reports. H3 survives.
Under H1, this is coincidence: the vendor independently discovered, verified, and remediated the same vulnerability in three days while simultaneously ruling the external report invalid. H1 now needs two coincidences stacked together. Under H2, the triage was wrong but engineering saw the report and acted — so why was the report never reopened? H2 now needs the mistake to stay uncorrected despite internal awareness.
Under H1, a good-faith program assigns CVEs to confirmed security fixes. A legitimate program does not ship a security patch with no advisory. H1 is dead. Under H2, the CVE was forgotten — and so was the advisory, and so was the downstream notification. Three independent omissions from one honest mistake. H2 is dying.
Under H2, this is understaffing — a stretched team leaning on AI. But a stretched team does not spin up a new account to merge a single commit, nor generate an AI fix for a vulnerability it officially called non-actionable three days earlier. H2 cannot explain why a finding closed as “not valid” produced an emergency AI-assisted patch merged by a ghost account. H2 is dead.
Under H3, the refusal fits a system where vendors control their own triage outcomes and the platform has no commercial incentive to override paying customers. The platform is not a neutral arbiter. It is a vendor-funded service that profits from report volume, not report outcomes.
The vendor did not fail to disclose once. They failed to disclose seven times in a single release. This is not a process failure. It is a disclosure policy. The policy is silence.
Two innocent hypotheses entered. Neither survived contact with the evidence.
Every innocent explanation was tested first, and failed.
No single piece of evidence convicts. The conviction comes from the systematic elimination of every alternative. This is how every finding we deliver is structured. Not “we found guilt.” Rather: we searched for innocence, exhaustively, and it does not exist in the evidence.
