Technical hub

The codafort tools, on your machine.

Four binaries, one per analysis moment, plus the public contracts all of them emit. They work offline-first with deterministic results, and your code only leaves your machine if you send it.

How it will work, at launch
npx codafort scan .          # or: curl --proto '=https' --tlsv1.2 -fsSL https://codafort.dev/install.sh | sh
codafort mcp install         # Claude Code · Codex · Cursor · OpenCode · Antigravity

⚠ Pre-launch. The commands above start working at launch (v0.1.0): the installer, the npm package and the Homebrew tap aren't published yet.

codafort code · pre-execution

Checks source code in 16 languages for flaws such as SQL injection, secrets, dependencies with known vulnerabilities, insecure IaC and supply-chain risk. scan · explain · fix · vet (AI code) · gate · attest · MCP server.

codafort guide →
codatrace live app · in-process

Observe-only IAST: runs inside your running app, confirms which codafort findings were reached by untrusted data and states what it did not measure. For Python, Node and JVM apps. Requires a Pro licence (waitlist for now).

codatrace guide →
codaprobe live app · over the network

API-first DAST against live apps, over the network. It only tests the scope you authorised: anything outside the allowlist, or ambiguous, is refused. It can write a verifiable audit log. Authorisation is the first page of the docs. Requires a Pro licence (waitlist for now).

codaprobe guide →
codacrash artifact · crash and profile

Strictly defensive crash forensics: reads a crash dump or an app's heap and pinpoints root cause, CRASH_ID and exploitability, without using the network.

codacrash guide →

Inside your agent loop

MCP server for Claude Code, Cursor and any stdio client: the agent checks every diff before committing, and vet gives the verdict on the change.

Measured precision

Precision is measured and published at codafort.com/benchmark, against CodeQL and Semgrep, per language. Detection is free and complete.

Open contracts

SARIF 2.1.0, CycloneDX/SPDX and the coda-*/1 contracts published at /schemas, from the canonical Finding to the counter-signed declaration (coda-attestation/1).