Historical Bug Discovery Rate
The historical bug discovery rate is a metric that tracks how many vulnerabilities an auditor identifies over a series of projects. This data point helps to evaluate the effectiveness of a firm's audit process and their level of diligence.
A consistently high discovery rate might indicate a firm that is exceptionally thorough, or it could suggest that they are auditing less mature, more vulnerable codebases. Conversely, a very low discovery rate might suggest either a high-quality development team or an auditor who is missing significant issues.
Analysts use this rate in conjunction with other data to build a profile of an auditor's capabilities. It is a useful, albeit imperfect, indicator of how likely an auditor is to find bugs in a new project.