Technical hub
The codafort tools, on your machine.
Four binaries, one per analysis moment, plus the public contracts all of them emit. They work offline-first with deterministic results, and your code only leaves your machine if you send it.
npx codafort scan . # or: curl --proto '=https' --tlsv1.2 -fsSL https://codafort.dev/install.sh | sh
codafort mcp install # Claude Code · Codex · Cursor · OpenCode · Antigravity
⚠ Pre-launch. The commands above start working at launch (v0.1.0): the installer, the npm package and the Homebrew tap aren't published yet.
codafort
code · pre-execution
Checks source code in 16 languages for flaws such as SQL injection, secrets, dependencies with known vulnerabilities, insecure IaC and supply-chain risk. scan · explain · fix · vet (AI code) · gate · attest · MCP server.
codatrace
live app · in-process
Observe-only IAST: runs inside your running app, confirms which codafort findings were reached by untrusted data and states what it did not measure. For Python, Node and JVM apps. Requires a Pro licence (waitlist for now).
codaprobe
live app · over the networkAPI-first DAST against live apps, over the network. It only tests the scope you authorised: anything outside the allowlist, or ambiguous, is refused. It can write a verifiable audit log. Authorisation is the first page of the docs. Requires a Pro licence (waitlist for now).
codaprobe guide →codacrash
artifact · crash and profileStrictly defensive crash forensics: reads a crash dump or an app's heap and pinpoints root cause, CRASH_ID and exploitability, without using the network.
codacrash guide →Inside your agent loop
MCP server for Claude Code, Cursor and any stdio client: the agent checks every diff before committing, and vet gives the verdict on the change.
Measured precision
Precision is measured and published at codafort.com/benchmark, against CodeQL and Semgrep, per language. Detection is free and complete.
Open contracts
SARIF 2.1.0, CycloneDX/SPDX and the coda-*/1 contracts published at /schemas, from the canonical Finding to the counter-signed declaration (coda-attestation/1).