Technical hub
The codafort tools, on your machine.
Four binaries, one per analysis moment. They are offline-first and deterministic, and your code only leaves your machine if you send it. Plus the public contracts all of them emit.
npx codafort scan . # or: curl --proto '=https' --tlsv1.2 -fsSL https://codafort.dev/install.sh | sh
codafort mcp install # Claude Code · Codex · Cursor · OpenCode · Antigravity
⚠ Pre-launch. The commands above start working at launch (v0.1.0): the installer, the npm package and the Homebrew tap aren't published yet.
codafort
code · pre-execution
Static analysis engine: SAST with interprocedural taint, SCA, secrets, IaC and supply-chain across 16 languages. scan · explain · fix · vet (AI code) · gate · attest · MCP server.
codatrace
live app · in-processObserve-only IAST: confirms at runtime which static findings were reached by untrusted data, and states what it did not measure. Python, Node and JVM agents in the same tarball. Requires a Pro licence (waitlist for now).
codatrace guide →codaprobe
live app · over the networkAPI-first DAST with a fail-closed allowlist scope, differential oracle and SHA-256-chained audit log. Only against an authorised target: authorisation is the first page of the docs. Requires a Pro licence (waitlist for now).
codaprobe guide →codacrash
artifact · crash and profileStrictly defensive crash/binary forensics: reads the dump directly (Minidump, ELF/Mach-O core, HPROF, hs_err, V8 heap) and pinpoints root cause, CRASH_ID and exploitability, with no third-party debugger and no network.
codacrash guide →Inside your agent loop
MCP server for Claude Code, Cursor and any stdio client: the agent checks every diff before committing, and vet gives the verdict on the change.
Precision as the product
A CI gate that requires precision 1.000 on the NIST Juliet categories it covers, on every change to the engine or the rules. Detection is free and complete, and low noise is what the gate protects.
Open contracts
SARIF 2.1.0, CycloneDX/SPDX and the coda-*/1 contracts published at /schemas, from the canonical Finding to the counter-signed declaration (coda-attestation/1).