Verified Vulnerability Detector — a finding sealed with two independent arms and a reproducible proof-of-concept.
AI-generated image
coming soon · in development

Verified Vulnerability Detector

A security scanner whose findings carry their own proof.

Most scanners flood you with maybes. This one surfaces a finding only when two independent arms byte-lock-agree and a deterministic proof-of-concept reproduces it — no AI-slop false positives, and every refuted suspicion written down too.

Don't trust the scanner. Verify. · Every finding is measured and reproducible.

What it is

proof, not a maybe

A source-audit engine for less-hardened open-source code — path traversal / LFI, injection (SQLi / SSTI / command), authentication bypass, IDOR, deserialization, unsafe file upload. It follows the taint from source to the real sink and reproduces the impact on an isolated local before it calls anything a finding.

Each result is checked by the doer≠checker discipline: a second, independent arm from a different model family reproduces the same conclusion, and only a byte-lock agreement plus a deterministic PoC passes the gate. A suspicion that does not reproduce is written out as refuted, not shipped as noise.

A scanner that proves the bug — not one that guesses at it. If two independent arms don't agree and the PoC doesn't reproduce, it isn't a finding.

Why it's different

the moat in an AI-slop market

Two-arm byte-lock verification

Every finding is reproduced by a second independent arm (different model family). Echo is excluded by construction — agreement is only meaningful across families.

Deterministic, reproducible PoC

A finding ships with a one-command reproduction on an isolated local target. You re-run it yourself; you never take the scanner's word.

The refuted case is spoken

When a suspicion does not hold up to an adversarial re-check, it is recorded as refuted — the honesty is part of the output, not hidden.

Live proof: the same engine earns bounties

The engine behind this product is the one we run on real, paid bug-bounty programs — the market itself is the proof that it finds real vulnerabilities.

No false-positive flood

The universal complaint about AI security tools is slop. The gate here fails closed: an unverified suspicion never reaches you as a finding.

Source-available

The engine is source-available (BSL 1.1); non-production use is free, production and commercial use require a commercial licence. Non-production use stays free, and you can audit the gate itself.

Check us, don't trust us

Each finding ships its own reproduction. You point it at an isolated copy of the target and re-run the PoC — on your machine, offline — and watch the impact happen. The verdict is yours, not ours.

Licensing

source-available · commercial for production

Source-available under BSL 1.1: non-production use is free; production/commercial use requires a commercial licence. Non-production use stays free; each version converts to AGPL-3.0-or-later on 2030-09-20.

Status

honesty is part of the product

Coming soon. Want the launch notice, or an early look for your codebase? Tell us the stack and we'll reach out when the packaged detector is ready.

Notify me Back to products