Cognium Research
Evidence before claims.
Reproducible SAST benchmark results and practical guides for evaluating static-analysis accuracy, false positives, and real developer workflows.
Read the results. Check the method.
Each benchmark claim links to the dataset, scanner configuration, scorer, and machine-readable output used to produce it.
Benchmark results · 8 min
OWASP Benchmark Java SAST results
How cognium-dev scored on all 2,740 Java cases, including the exact methodology, limitations, and public evidence.
Read the reproducible test → Measurement guide · 7 minSAST false positives, explained
Understand TPR, FPR, precision, and Youden score—and why a single percentage never tells the whole story.
Learn the metrics →