for teams that build software with AI

Your code, protected.

AI writes more code than any team can review. codafort reviews every change while the agent codes, fixes the flaw before the commit and turns the result into security proof your customer can check on their own.

Pre-launch: codafort is not available to install yet. Join the waitlist →

✓ Measured, not promised: on the OWASP Benchmark, no false positives across 2,740 cases, where CodeQL raised 531, at the same recall. The full numbers are published, with the caveats and the places where we still lose.

Illustrative output: review, fix, declare and verify.

◍ In your agent
Claude Code · Codex · Cursor · OpenCode · Antigravity
⌘ One command
nothing to host
✎ Fixes it for you
the agent applies, you approve
⛁ Local analysis
code only leaves if you send it
◆ Detection is free
forever
✦ Verifiable proof
customers check it for free

the risk of coding with AI

The agent writes with confidence, and nobody reviews everything it writes.

Almost half of AI-generated code ships with a security flaw, and each "improve this" round raises the odds. Reading every line cannot keep up with the agent. And customers, auditors and vendor-risk committees want to know what was checked. codafort reviews every change at the agent's pace and keeps the result as evidence.

~45%
of AI-generated code contains a vulnerability (Veracode 2025, 100+ models over 80 tasks)
+37%
more critical flaws after 5 rounds of LLM refinement (IEEE-ISTAS 2025; a single study, read it with that caveat)
0
false positives across 2,740 OWASP Benchmark cases; CodeQL raised 531 in the same test
0 B
of your code sent by the analysis, which runs on the developer's machine; snippets only leave when you send them to the Platform

who it is for

From the founder who codes with an agent to the CIO who answers to the auditor.

founder

You ship fast. codafort checks at the same pace.

You don't need to know what SQL injection is to avoid shipping one. codafort explains the risk in a few lines and the agent applies the fix. When your first big customer asks for security evidence, you already have it.

CTO

The same standard on every change, from every dev and every agent.

The review happens in the editor, in the PR and in CI, with the same result in each. Every verdict says what was checked and what was left out, and you decide what fails the build.

CIO

Evidence ready for audits and vendor due diligence.

The result comes out as a counter-signed declaration that the customer or auditor checks on their own, for free and without installing anything. For financial services, there is a map of the evidence against Brazilian CMN and ANBIMA rules.

how it works

Three steps, inside the agent's work.

01

Connect it to the agent

One command connects codafort to Claude Code, Codex, Cursor, OpenCode and Antigravity. There is no server to host and no dashboard to open.

02

It reviews every change

While the agent writes, codafort checks whether data from outside reaches a dangerous spot, such as the database, and proposes the fix. The agent applies it and you approve.

03

The result becomes proof

Each change's verdict is recorded. When someone asks for evidence, codafort counter-signs the set, and the recipient checks the declaration at /verify.

where it fits

From the first prompt to the customer who asks for proof, without changing tools.

agent and editor

While the code is written

The agent consults codafort on every change and gets back only what was confirmed. In VS Code, Neovim or Helix, the finding shows up on the line itself.

PR · CI

Before it reaches the main branch

The same standard runs in the pipeline and publishes the result to GitHub code scanning. You define what fails the build, on any plan.

customer

When someone asks for proof

The counter-signed declaration goes into the data room or the vendor review. The recipient checks, for free and offline, who issued it and that it has not changed since.

the suite

Four ways to check what your agent wrote.

Start with the code, where finding and fixing flaws will be free. Once the app is live, the other three tools show what really happens to it, and each one tells you what it could not check.

codafort free

In your code

Reads code in 16 languages, Delphi included, and finds where data from outside reaches a dangerous spot. It also flags dependencies with known flaws, secrets left in the code and exposed infrastructure and CI settings.

codatrace paid plan

Running app, from inside

Watches the app in Python, Node or Java while it is used or tested, and shows which of those findings actually happened. It only observes. Anything nobody exercised shows up as "not measured", never as safe.

codaprobe paid plan

Running app, from outside

Tests your API over the network the way an outsider would, and only at the address you authorized. Every request is logged for later review. A route the test did not cover stays unchecked.

codacrash free

When the app crashes

Reads a crash record and tells you what caused it, whether the flaw looks exploitable and which crashes are the same problem. It is for defense only. Analyzing one crash will be free; grouping them across many machines is part of a paid plan.

The suite in detail →

measured precision

False alarms cost the team's time and its trust in the tool.

On the OWASP Benchmark, measured against CodeQL and Semgrep in the same run, codafort raised no false positives across 2,740 cases and found as much as CodeQL. The caveat travels with it: we tuned codafort looking at this test, and the others did not. That is why we also publish per-language results on third-party tests, including where we still lose.

PrecisionRecallFalse positives
codafort1.0000.9720
CodeQL 2.270.7210.972531
Semgrep OSS 1.1770.6930.882552

OWASP Benchmark 1.2 (Java, 2,740 cases), all three tools in the same run, on 2026-09-28. Precision: how many alerts were real. Recall: how many real flaws were found.

plans

Plans and pricing: being defined.

What is already decided: finding and fixing vulnerabilities in code will be free. Paid plans come out at launch, and people on the waitlist hear first.

pre-launch

Be among the first to use it.

Leave your e-mail: we will tell you when codafort opens and invite the first ones to try it.