Browse guides
Product documentation
MAGDOX Code Security documentation
Install the CLI, run local checks and decide what to upload. Reference guides cover commands, data formats and analysis boundaries; operating guides cover CI, coding assistants and offline use.
Versioned CLI and console workflows. Check release and upgrade notes for v1.2 availability.
Choose a first task.
Install and run locally
Choose the supported launcher, authorise private components and run a first scan with explicit coverage.
Start hereAdd a pipeline check
Provision authorised components, scope a CI token and keep incomplete analysis distinct from a threshold failure.
Start hereConfigure a coding assistant
Set explicit repository roots, review host compatibility and verify the v1.2 integration in your client.
Start hereGetting started
Overview
Local scanning, signed rules and optional uploads to your organisation's dashboard.
New Release Notes
CLI and MCP v1.3.2: AI-generated output is marked, each release carries a signed SBOM, MCP results stay readable for agents, and the dashboard gains Super Admin, Remove member and 30-day account deletion. Then v1.3.1: offline licences in one step, and the v1.3, v1.2, v1.1 and v1.0 notes.
Architecture
Where the scanner, rule cache, API and dashboard run, and what moves between them.
Install the CLI
Install the v1.3.1 public launcher, sign in and download the authorised private engine.
Authentication and access
Device sign-in, product access, organisation roles and CI credentials.
Run a scan
Choose checks, write a local report, preview the payload and upload explicitly.
Results and delivery
Local reports and optional dashboard records, with coverage alongside findings.
Reference
CLI reference
Supported commands, scan options and actual exit-code behavior.
Findings payload
The versioned upload structure, snippet permissions and fingerprint limits.
Reports and exports
Choose a findings report or an inventory format for the evidence you need.
Configuration
Command flags, environment variables and dashboard settings actually used today.
Glossary
Terms used in scanning, inventories and review workflows.
Operate
AI integrations
v1.2 authenticated private MCP and plugin setup for local desktop and coding assistants.
AI review with your own model
Optional second opinion on each finding from a provider and model you choose; the engine still decides what is a finding.
Account and notifications
Email-change verification and per-user scan notifications, including a cross-repository daily digest.
CI integration
Run on your CI runner, retain a report and optionally publish findings to the dashboard.
Data and deployment
Local analysis, opt-in result uploads and hosted-service monitoring.
Offline and air-gapped
Provision device-bound offline access, a compatible signed bundle and a pinned vulnerability database.
Security model
Implemented data boundaries and integrity checks, with deployment commitments kept explicit.