13 controls, each one a question with a defined way of being answered. For every control: what it evaluates, how a result is established, the weakest evidence that can pass it, and the external clauses it maps to.
6 of them are production gates. A failing gate is not averaged away by strong results elsewhere, which is the difference between a score and an average.
security
What separates users, data and privileged actions from everybody else.
Whether the behaviour that works today survives more of everything.
SA-CORE-009high
Database queries are index-backed at scale
Established by:
schema inspection, query plan analysis
Passes at:
E2 or better, which is source verified
Mapped to:
CWE CWE-1049 · OWASP API Security Top 10 API4:2023
What this page does not publish
Weights, thresholds, the scoring arithmetic, and the exact pass, partial and fail criteria stay in the pack. Publishing what is evaluated and how a result is established is what makes a score inspectable. Publishing the arithmetic would not make a reader better informed, and it would make the result easier to aim at than to satisfy.
Deeper packs extend this set per application risk profile. This page describes StackAttest Core 1.0, which is the baseline that applies to virtually every web and API product.
Mapping is not certification
A mapping means a StackAttest control references a clause in that external vocabulary. It is not a claim that StackAttest, or any product it validates, is certified, accredited, approved or reviewed by OWASP, NIST, MITRE or anybody else. None of those organisations endorses this work. Evidence toward a practice is not conformance with it, and a control that maps to an ASVS clause does not award an ASVS level.