plans
Plans and pricing: being defined.
codafort is in pre-launch. While we finalise the plans, this page shows how it works. People on the waitlist hear first.
How it works
One command connects codafort to your agent
It works in Claude Code, Codex, Cursor, OpenCode and Antigravity. There is no server to host.
The agent consults codafort on every change
It gets the verdict on the change, an explanation of the risk and the proposed fix, which it applies and checks.
The analysis runs on your machine
The result does not depend on an AI model: the same version always gives the same result. The analysis sends no code; what can leave the machine is listed at /telemetry, and each item can be turned off.
From code to the app in production
On paid plans, other tools confirm what happens with the app running, and the counter-signed declaration takes that evidence to your customer, who checks it at /verify.
What is already decided
- Finding and fixing vulnerabilities will be free.
- The analysis runs on your machine, and your code only leaves it if you send it.
- Accuracy is measured and published, including where we lose: /benchmark.
Questions
When will codafort be available?
No public date yet. People on the waitlist get the notice first and may be invited to the first trials.
Do I need internet to run the analysis?
No. Analysis is local and deterministic: it uploads no code and fetches no dependencies from the cloud. What can leave the machine is a separate matter, and each item can be turned off; the full list is at /telemetry.
Do you see my code or my findings?
Only if you send them. The analysis path sends nothing. If you use codafort Platform, sending the findings (with each one's code snippet) is a command you run, to your own space. Details at /telemetry.
Does verifying a declaration I received cost anything?
No. The /verify page is free and offline: any party checks that the declaration has not changed since it was issued and who issued it. The content is still what the holder declared.