Deduplication
Run three scanners over one codebase and the same weakness arrives three times in three dialects. Sinterly deduplicates with a three-tier confidence model — automation where it is safe, human judgement where it is not.
The three tiers
- Tier 1 — automatic merge. All four criteria match: asset identifier, CWE, affected file or endpoint, and vulnerability class. The findings merge automatically; the matching criteria are recorded and the merge is reversible by the AppSec Lead.
- Tier 2 — queued for confirmation. Three of four criteria match, or the same CVE appears with location variance. The findings stay separate with a pending indicator until the AppSec Lead confirms or rejects the merge in the dedup queue.
- Tier 3 — flagged only. Two of four criteria match. Both records are marked as related; nothing merges without a human deciding.
Every decision — automatic or human — lands in the audit log with the criteria that drove it.