the suite

Four tools, from code to the app in production.

Each tool looks at the software at a different moment: before it runs, while it runs from the inside, while it runs from the outside and after a crash. All of them deliver results in the same format, and that is what the counter-signed declaration brings together for your customer.

in the code

codafort free

Reviews the code your team and agents write, in 16 languages: Python, Java, JavaScript, TypeScript, Go, C, C++, Ruby, PHP, C#, Rust, Swift, Kotlin, Dart, Scala and Pascal/Delphi. It flags where data from outside reaches a dangerous spot, dependencies with known flaws, secrets left in the code and exposed infrastructure and CI settings. For each finding, it explains the risk and proposes the fix.

It runs on the developer's machine, inside the AI agent, in the editor and in CI, and delivers results in the formats GitHub, SonarQube and software inventory tools already read.

Shows

✓ The path the data takes through the code to the dangerous spot.

✓ Dependencies with known flaws, exposed secrets, insecure settings.

Does not show

✗ Whether that path happens in production: that is codatrace.

✗ That there is no vulnerability. How much it finds is published per language.

running app, from inside

codatrace paid plan

Of the findings in the code, which ones really happen when the app runs? codatrace watches the app in Python, Node or Java during use or testing and confirms which dangerous paths outside data actually took. The team fixes what is real first.

It only observes: it does not change responses, block requests or alter the app's behavior. If something fails inside it, the app keeps running and only the observation is lost.

Shows

✓ Findings that happened at runtime, with no protection on the path.

✓ Those that were reached, but with the right defense on the path.

Does not show

✗ That the rest is safe: anything nobody exercised shows up as "not measured".

✗ On Java, SQL queries and XSS are not covered yet.

running app, from outside

codaprobe paid plan

Tests your API over the network the way an outsider would, from the API specification or by discovering the routes on its own. It only reports a flaw when it can observe it in the response.

It only tests the address you authorized and refuses any ambiguous target before sending the first packet. By default it does not change data, keeps secrets out of the report and respects rate limits. Every request goes into a log an auditor can check later.

Shows

✓ The flaw as seen from outside, on a target you authorized.

✓ The exact log of what was sent.

Does not show

✗ Anything outside the routes the test covered.

when the app crashes

codacrash free fleet: paid plan

Reads the record a crash leaves behind (Windows, Linux, macOS, Java and Node) and tells you what caused it, whether the flaw looks exploitable and which crashes are the same defect. It also helps find performance bottlenecks. It works offline.

Analyzing one crash will be free. Collecting and comparing crashes across many machines is part of a paid plan.

Shows

✓ The likely cause of the crash and where it happened.

✓ The severity, on the same scale as the code findings.

Never

✗ Generates an exploit or attack tool. It is for defense only.

Start with the code, which is free. The other tools come in when someone asks for proof.

Pre-launch: codafort is not available to install yet. Join the waitlist →