Your code, protected.
AI writes more code than any team can review. codafort reviews every change while the agent codes, fixes the flaw before the commit and turns the result into security proof your customer can check on their own.
Pre-launch: codafort is not available to install yet. Join the waitlist →
$ codafort vet # the change the AI just wrote ▲ crit SF-1 SQL injection api/users.py:42 verdict: BLOCKED · 1 blocking $ codafort fix SF-1 && codafort vet verdict: PASS $ codafort attest create --evidence vet.json verdict: pass · Ed25519 ✓ $ codafort attest verify token.txt # free, offline, anyone ✓ signature VALID · counter-signed by codafort
Illustrative output: review, fix, declare and verify.
the risk of coding with AI
The agent writes with confidence, and nobody reviews everything it writes.
Almost half of AI-generated code ships with a security flaw, and each "improve this" round raises the odds. Reading every line cannot keep up with the agent. And customers, auditors and vendor-risk committees want to know what was checked. codafort reviews every change at the agent's pace and keeps the result as evidence.
who it is for
From the founder who codes with an agent to the CIO who answers to the auditor.
You ship fast. codafort checks at the same pace.
You don't need to know what SQL injection is to avoid shipping one. codafort explains the risk in a few lines and the agent applies the fix. When your first big customer asks for security evidence, you already have it.
The same standard on every change, from every dev and every agent.
The review happens in the editor, in the PR and in CI, with the same result in each. Every verdict says what was checked and what was left out, and you decide what fails the build.
Evidence ready for audits and vendor due diligence.
The result comes out as a counter-signed declaration that the customer or auditor checks on their own, for free and without installing anything. For financial services, there is a map of the evidence against Brazilian CMN and ANBIMA rules.
how it works
Three steps, inside the agent's work.
Connect it to the agent
One command connects codafort to Claude Code, Codex, Cursor, OpenCode and Antigravity. There is no server to host and no dashboard to open.
It reviews every change
While the agent writes, codafort checks whether data from outside reaches a dangerous spot, such as the database, and proposes the fix. The agent applies it and you approve.
The result becomes proof
Each change's verdict is recorded. When someone asks for evidence, codafort counter-signs the set, and the recipient checks the declaration at /verify.
where it fits
From the first prompt to the customer who asks for proof, without changing tools.
While the code is written
The agent consults codafort on every change and gets back only what was confirmed. In VS Code, Neovim or Helix, the finding shows up on the line itself.
Before it reaches the main branch
The same standard runs in the pipeline and publishes the result to GitHub code scanning. You define what fails the build, on any plan.
When someone asks for proof
The counter-signed declaration goes into the data room or the vendor review. The recipient checks, for free and offline, who issued it and that it has not changed since.
the suite
Four ways to check what your agent wrote.
Start with the code, where finding and fixing flaws will be free. Once the app is live, the other three tools show what really happens to it, and each one tells you what it could not check.
codafort freeIn your code
Reads code in 16 languages, Delphi included, and finds where data from outside reaches a dangerous spot. It also flags dependencies with known flaws, secrets left in the code and exposed infrastructure and CI settings.
codatrace paid planRunning app, from inside
Watches the app in Python, Node or Java while it is used or tested, and shows which of those findings actually happened. It only observes. Anything nobody exercised shows up as "not measured", never as safe.
codaprobe paid planRunning app, from outside
Tests your API over the network the way an outsider would, and only at the address you authorized. Every request is logged for later review. A route the test did not cover stays unchecked.
codacrash freeWhen the app crashes
Reads a crash record and tells you what caused it, whether the flaw looks exploitable and which crashes are the same problem. It is for defense only. Analyzing one crash will be free; grouping them across many machines is part of a paid plan.
measured precision
False alarms cost the team's time and its trust in the tool.
On the OWASP Benchmark, measured against CodeQL and Semgrep in the same run, codafort raised no false positives across 2,740 cases and found as much as CodeQL. The caveat travels with it: we tuned codafort looking at this test, and the others did not. That is why we also publish per-language results on third-party tests, including where we still lose.
| Precision | Recall | False positives | |
|---|---|---|---|
| codafort | 1.000 | 0.972 | 0 |
| CodeQL 2.27 | 0.721 | 0.972 | 531 |
| Semgrep OSS 1.177 | 0.693 | 0.882 | 552 |
OWASP Benchmark 1.2 (Java, 2,740 cases), all three tools in the same run, on 2026-09-28. Precision: how many alerts were real. Recall: how many real flaws were found.
plans
Plans and pricing: being defined.
What is already decided: finding and fixing vulnerabilities in code will be free. Paid plans come out at launch, and people on the waitlist hear first.
pre-launch
Be among the first to use it.
Leave your e-mail: we will tell you when codafort opens and invite the first ones to try it.