Rule-based analysis · RAG breach knowledge base · Claude fallback (low-confidence only)
Scope risk scored deterministically using a static risk table covering 50+ Microsoft Graph, GitHub, Vercel, Slack, and Google scopes. No AI needed, no API calls, instant.
App/vendor name is searched against a Supabase table of 12+ known breach records (SolarWinds, CircleCI, Context AI…). Full-text search — no embeddings, no LLM.
Only fires when both rule engine and KB return low confidence — unknown vendor, unknown scopes. Claude gets the KB context + scope list and returns a plain-English assessment.