diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index f01c9ac..803dea2 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -24,7 +24,7 @@ npm run llms
```
This validates that every page in `docs.json` exists and every page on disk is
-reachable from the navigation. CI additionally runs a link check.
+reachable from the navigation. CI also runs a link check.
## Conventions
diff --git a/introduction.mdx b/introduction.mdx
index e138710..4192ca1 100644
--- a/introduction.mdx
+++ b/introduction.mdx
@@ -33,7 +33,7 @@ actually links. Start at [Static analysis](/static-analysis).
**Dynamic analysis** means launching the app under observation and watching
what it does: file events, network destinations, child processes, pasteboard
and camera and microphone access. That needs the
-[privileged helper](/privileged-helper), and for anything you genuinely don't
+[privileged helper](/privileged-helper), and for anything you don't
trust, it should happen inside [VM mode](/vm-mode).
## What it won't do
diff --git a/kill-switch.mdx b/kill-switch.mdx
index 4d4b513..28402d4 100644
--- a/kill-switch.mdx
+++ b/kill-switch.mdx
@@ -6,7 +6,7 @@ description: "Cut the inspected app's outbound traffic system-wide, and watch ho
During a [monitored run](/monitored-runs) you can block the destinations the
inspected app has been contacting, then watch what it does about it.
-This is a genuinely useful test. An app that degrades gracefully when its
+An app that degrades gracefully when its
analytics endpoint disappears behaves very differently from one that blocks the
UI, retries in a tight loop, or refuses to start.
diff --git a/llms-full.txt b/llms-full.txt
index 6138363..b0c8eac 100644
--- a/llms-full.txt
+++ b/llms-full.txt
@@ -41,7 +41,7 @@ actually links. Start at [Static analysis](https://docs.privacycommand.privacyke
**Dynamic analysis** means launching the app under observation and watching
what it does: file events, network destinations, child processes, pasteboard
and camera and microphone access. That needs the
-[privileged helper](https://docs.privacycommand.privacykey.org/privileged-helper), and for anything you genuinely don't
+[privileged helper](https://docs.privacycommand.privacykey.org/privileged-helper), and for anything you don't
trust, it should happen inside [VM mode](https://docs.privacycommand.privacykey.org/vm-mode).
## What it won't do
@@ -228,8 +228,8 @@ Source: https://docs.privacycommand.privacykey.org/static-analysis
What privacycommand extracts from a bundle without running it — the bulk of the report.
-Static analysis reads the bundle on disk. Nothing executes, so this is the part
-you can safely run against something you don't trust at all.
+Static analysis reads the bundle on disk without executing it, so you can run it
+against a bundle you don't trust.
It is also where most of the report comes from. Roughly forty detectors run over
a bundle; this page groups them by the question they answer.
@@ -245,8 +245,8 @@ recognise.
**Notarization**
-A deep dive rather than a yes/no: whether the ticket is stapled, what
-`spctl` says about it, and the SHA-256 of the bundle. Every relaxation is
+This check reports whether the ticket is stapled, what `spctl` says about
+it, and the SHA-256 of the bundle. Every relaxation is
reported with the entitlement or flag responsible.
**Provenance**
@@ -731,7 +731,7 @@ Cut the inspected app's outbound traffic system-wide, and watch how it copes.
During a [monitored run](https://docs.privacycommand.privacykey.org/monitored-runs) you can block the destinations the
inspected app has been contacting, then watch what it does about it.
-This is a genuinely useful test. An app that degrades gracefully when its
+An app that degrades gracefully when its
analytics endpoint disappears behaves very differently from one that blocks the
UI, retries in a tight loop, or refuses to start.
@@ -791,7 +791,7 @@ Source: https://docs.privacycommand.privacykey.org/vm-mode
Run the analysis inside a disposable macOS VM, and ship the observations back to your Mac.
-For a bundle you genuinely don't trust, running it on your own machine is the
+For a bundle you don't trust, running it on your own machine is the
wrong move — even under observation. VM mode moves the execution into a
disposable macOS guest and streams the results back.
diff --git a/static-analysis.mdx b/static-analysis.mdx
index 82079db..01fe93b 100644
--- a/static-analysis.mdx
+++ b/static-analysis.mdx
@@ -3,8 +3,8 @@ title: Static analysis
description: "What privacycommand extracts from a bundle without running it — the bulk of the report."
---
-Static analysis reads the bundle on disk. Nothing executes, so this is the part
-you can safely run against something you don't trust at all.
+Static analysis reads the bundle on disk without executing it, so you can run it
+against a bundle you don't trust.
It is also where most of the report comes from. Roughly forty detectors run over
a bundle; this page groups them by the question they answer.
@@ -19,8 +19,8 @@ a bundle; this page groups them by the question they answer.
recognise.
- A deep dive rather than a yes/no: whether the ticket is stapled, what
- `spctl` says about it, and the SHA-256 of the bundle. Every relaxation is
+ This check reports whether the ticket is stapled, what `spctl` says about
+ it, and the SHA-256 of the bundle. Every relaxation is
reported with the entitlement or flag responsible.
diff --git a/vm-mode.mdx b/vm-mode.mdx
index 8a8c6f1..3bade97 100644
--- a/vm-mode.mdx
+++ b/vm-mode.mdx
@@ -3,7 +3,7 @@ title: VM mode
description: "Run the analysis inside a disposable macOS VM, and ship the observations back to your Mac."
---
-For a bundle you genuinely don't trust, running it on your own machine is the
+For a bundle you don't trust, running it on your own machine is the
wrong move — even under observation. VM mode moves the execution into a
disposable macOS guest and streams the results back.