Static analysis
SAST · source & dependencies
Parses your repo to a real AST across six languages, maps architecture and data flow, and reasons about trust boundaries — so you see what's actually reachable.
- Python · JS/TS · Go · Java · Ruby
- Secrets, IaC & insecure config
- SCA via OSV CVE database
- STRIDE threat model + CWE mapping