Find the bugs in your project — before anyone else does.
A read-only, deterministic bug-finder that runs sealed on your own machine and hands you the findings as structured JSON. No account, no telemetry, nothing leaves your box. Free once your machine is connected. The entry-level product on the same verification engine as the Verified Vulnerability Detector.
Read-only · deterministic · your machine, your findings.
Point it at a project. It runs one scan window over the code — read-only, never modifying a file — with per-language engines and generic detectors, and writes every finding into a structured JSON report you own: file, line, class, severity, detector, and whether the finding is proven or advisory.
It finds and shows; it does not fix. The paid tiers above it apply deterministic fixes in parallel windows — Basic is the honest map that tells you how many bugs you have and where.
Read-only bug-finder; findings saved as structured JSON; one scan window. The core engine is built and verified; the sealed, downloadable box is being packaged.
free once your machine is connected · box in packagingAdds a rule-based judge that re-checks every finding before you see it — fewer maybes, more proven-or-advisory clarity.
on the roadmapAdversarial attempts to break each finding: a suspicion that does not survive the attack is written out as refuted, not shipped as noise.
on the roadmapAbove Basic: Pro (monthly — up to five parallel windows that apply deterministic fixes to what Basic found) and Enterprise (monthly, priced per machine). Both are staged after the Basic box ships; pricing is announced when they do, not before.
Ships as a Sovereign Box: read-only root filesystem, air-gapped (no network), non-root, no telemetry. Your code is mounted read-only; only the JSON comes out.
Same input, same map. It never modifies a file. A structural scan, not a coin-flip — you can re-run it and get the same answer.
Every finding is a JSON record — file, line, class, severity, detector, proof status — ready for your own tooling, tickets, or the Pro tier's fixes.
The detection engine is the one behind the Verified Vulnerability Detector and our live bug-bounty line. Basic is the entry door to the same machinery.
It tells you what it measured and what it could not. A language without an installed engine is reported as unmeasured, never as a false "clean".
The engine is source-available (BSL 1.1): non-production use is free, production and commercial use require a commercial licence — and you can audit the scanner itself.
Mount your project read-only, run one window, read the map:
Exact image name and the one-line installer are published with the box.
Source-available under BSL 1.1: non-production use is free; production/commercial use requires a commercial licence. The Basic tier's free use is for your own machine once connected; each version converts to AGPL-3.0-or-later on 2030-09-20.
Want it first? Tell us your stack and we'll send the box the day it ships — and the one-line install to run your first free scan.