How it works

One self-hosted engine, from discovery to a fail-closed gate.

Every discipline runs inside your own infrastructure, feeds one deduplicated finding model, and is enriched by a local LLM - your code and data never leave the network.

Pipeline

Discover - scan - prove - correlate - enforce

  • Discover - inventory apps, repos, images and infrastructure from your SCM, CI and cloud connectors.
  • Scan - native DAST, SAST (inter-procedural taint), SCA, container, IaC and secrets engines run on your runners.
  • Prove - each gap is confirmed in-band before it is raised (see the proof methodology).
  • Correlate - findings from every engine collapse by fingerprint into one risk-weighted Vulnerability - deduped, reachability-aware.
  • Prioritize - reachability + KEV/exploit funnel + ML triage turn hundreds of alerts into the few that matter.
  • Enforce - a fail-closed CI/CD gate (Monitor - Block) stops risky releases; evidence is written to a tamper-evident vault.
# data flow - all inside your network SCM / CI / Cloud -> Scanners (DAST · SAST · SCA · IaC · Container · Secrets) -> Prove (in-band confirmation) -> Correlate + dedupe -> one Vulnerability posture -> Local LLM (triage · business impact · fix) [local model, offline] -> CI gate (Monitor -> Block) + Evidence vault x nothing phones home · no source egress
Architecture

Self-hosted, air-gapped, sovereign

Deploys with Docker Compose

Runs entirely in your infrastructure - on-prem, private cloud or fully air-gapped. Offline model and advisory updates.

Local LLM

By default a local model does triage, business-impact and fix suggestions, so no prompts or code leave your network. Using an external model is opt-in and can be disabled platform-wide.

Data residency

Source is cloned into an isolated sandbox; bring-your-own scanners can keep images on the host and upload only SARIF.

Evidence vault

Every proven finding stores its PoC request/response and attack chain - tamper-evident, mapped to your frameworks.

Access & audit

SSO / SAML / OIDC / SCIM, RBAC, MFA and an append-only audit log; per-user data scoping by project and application.

One posture

A deterministic 0-100 score and A-F grade, trended over time, across every app and discipline.

See it on one of your own apps - live in 30 minutes

From discovery to a proven attack chain. A PoC in your own environment.