Coverage

One product. Every surface. No separate bill.

14 languages, 19 configuration formats and six review surfaces. Code, dependencies, inventories, cryptography, secrets and configuration are one product and one plan, not modules sold apart.

14
Languages
19
Configuration formats
6
Review surfaces
1
Plan, everything included

What gets examined

Six surfaces, one run.

A release decision needs all of these together. Splitting them across products is a licensing choice, not a technical one.

SAST

Source-code review

Injection, traversal, unsafe deserialization, weak cryptography, dynamic code execution and the rest of the classes that matter, mapped to CWE.

SCA

Dependency review

Direct and transitive components matched offline against an advisory database that ships with the scan, so a dependency check tells no one which libraries you depend on.

SBOM

Software inventory

CycloneDX 1.5 and SPDX 2.3 exports that state their own scope, so a source inventory is never mistaken for a built-artifact one.

CBOM

Cryptographic inventory

Every algorithm in use, sound ones included, classified by kind and by whether a quantum computer would break it outright. An inventory that lists only the broken algorithms cannot answer a migration question.

Credentials

Secrets review

Credentials and sensitive values in code and configuration. A finding carries a redacted preview and a hash, never the value itself, so the secret stays on your machine.

IaC

Configuration review

Infrastructure, container and pipeline configuration, where a single permissive setting undoes the code review above it.

Built today

What the engine does now.

Coverage is easy to claim and hard to check, so these are counts from the repository rather than estimates. Each rule has a vulnerable fixture it must find and a safe fixture it must leave alone, and none of them ship until both pass.

649
Detection rules, each with two fixtures
135
Distinct CWEs covered by those rules
286k
Advisories in the offline database, across 10 ecosystems
28
Credential detectors, entropy filtered

Exports

Results move into the tools you already use. Nothing here is a premium format.

SARIF 2.1.0

Findings, with the data-flow path and the coverage the scan achieved.

CycloneDX 1.5

Software inventory, stating the scope it was built from.

SPDX 2.3

Software inventory in the second standard format.

CycloneDX VEX

One entry per advisory, listing every component it affects.

CycloneDX 1.6 CBOM

Cryptographic inventory, with quantum-vulnerable algorithms marked.

JSON

The complete result, for anything the formats above do not carry.

Depth of analysis

Three levels, stated per language.

Most tools say a language is supported without saying what that means. We state the depth, because the difference decides which findings you get.

L1

Inventory and dependencies

Every component you depend on, matched against known vulnerabilities, with software and cryptographic inventories you can export.

Lockfiles and manifests are parsed, components identified by package URL, and advisories matched offline against a database that ships with the scan. This is the layer that answers what is in the build and which known issues apply to it.

L2

Direct code analysis

Unsafe API use, weak cryptography, disabled protections, hardcoded credentials and insecure configuration, found in the code itself.

Rules run over the parsed syntax of each file. Findings name the exact call and line, and each rule states what it cannot determine.

L3

Data-flow analysis

Injection and traversal flaws traced from the point untrusted input enters to the point it reaches a dangerous operation.

The analysis follows a value within a function and at module level, recognising the sanitizers that make a path safe. Findings carry the path itself, so a reviewer can check the reasoning rather than trust a score. Flow between functions is not followed yet, and every rule of this kind says so in its stated limits.

Languages

14 with data-flow analysis, 14 in total.

Every language here is part of the same product and the same plan. Coverage for your stack is confirmed in writing during scoping.

Languages and depth of analysis
LanguageDepthRulesFrameworks and focus
PythonL382Django, Flask, FastAPI, SQLAlchemy
JavaL369Spring, Jakarta, JDBC, Jackson, Maven, JSP and Thymeleaf
JavaScriptL346Node, Express, GraphQL, EJS, Handlebars and Nunjucks
GoL337Standard library, database/sql, os/exec, net/http
PHPL334Laravel, Symfony, PDO, WordPress, Twig and Blade
C#L326ASP.NET Core, Entity Framework, appsettings and web.config
TypeScriptL326Node, Next.js, NestJS, Angular and Vue
CL319Memory safety, integer conversion, format strings, signals
C++L319Memory safety, casts, exceptions, iterator invalidation
KotlinL317Spring, Ktor, Android
RubyL318Rails, ActiveRecord, ERB
SwiftL313Application and device code
RustL312Unsafe blocks, axum, sqlx, Command, Askama
ScalaL311Play, Slick, Doobie, Twirl, Akka

Configuration formats

A permissive setting here undoes the code review above it, so configuration is reviewed in the same run rather than sold as a separate cloud product.

Configuration formats and depth of analysis
FormatDepthRulesFocus
TerraformL223AWS, Azure, GCP and OCI resources
KubernetesL211Pod security context, namespaces, RBAC and limits
DockerfileL213Base image, package pinning, user and trust store
GitHub ActionsL212Workflow triggers, action pinning, script injection
Dependency manifestsL111Lockfile integrity, pinning and declared licences
AnsibleL212Shell tasks, file modes, checksums and secrets
nginxL211TLS policy, headers and upstream request framing
HTTP headersL211Baseline headers, content security policy and values
Android manifestL210Exported components, backup and cleartext traffic
CI pipelinesL210Unpinned images and secrets in pipeline files
CloudFormationL214Public storage and permissive policies
OpenAPIL210Deprecation policy and per-operation security
PulumiL210Stack secrets and public resource properties
SQLL210Migrations, procedures, definers and grants
SSH configurationL212Host key size and post-quantum key exchange
CrossplaneL210Connection secrets and managed resource settings
HTMLL210Subresource integrity on third-party scripts
iOS property listL210App transport security exceptions
JenkinsL210Pipeline steps interpolating branch and change data

One plan

Everything is included.

No per-language pricing, no separate SAST, dependency, secrets or infrastructure products, no charge per scan and no premium export format. One agreement covers the product as it grows.

As the product grows, existing customers receive the additions under the same agreement.

Discuss an evaluation
Every language and format on this page
Every review surface: code, dependencies, inventories, cryptography, secrets, configuration
Unlimited repositories and unlimited scans
All export formats: SARIF, CycloneDX, SPDX, CBOM
The dashboard, triage, decision history and reports
CI integration on every supported platform
The magdox CLI on Windows, macOS and Linux

A useful next conversation

Find the right product for your review workflow.

Tell us what you need to examine, where your work runs, and what evidence your team needs.

Contact about FDIE Discuss Code Security

Prefer to talk it through? Book a call with our team.