Deterministic hot path
Cheap, continuous and reproducible checks.
Claude, Codex and approved security models can reason about novel vulnerabilities. CodeMarine supplies continuous deterministic coverage, bounded context and an independent validation gate.
Reachable from two external entry points.
Novel impact, exploit path and proposed remediation.
Models handle novel reasoning. CodeMarine handles continuous policy, evidence and validation.
Find novel, context-dependent vulnerabilities
Check known risk continuously and deterministically
Reason across business logic and intent
Track dependencies, agent tools and policy state
Explain impact and propose contextual fixes
Validate patches against revision, rules and tests
Investigate selected high-value cases
Control when code, data and budget may be shared
The model investigates and proposes. CodeMarine validates the result against policy.
CodeMarine scans the workspace, dependency graph and AI configuration.
Policy decides whether the case deserves local specialist or frontier investigation.
A bounded packet includes relevant files, call paths, evidence and sharing scope.
An approved provider returns a verified, rejected, uncertain or incomplete result.
CodeMarine rescans an isolated patch and checks policy, provenance and tests.
A verified discovery can become a tested deterministic regression rule.
Give the model relevant files, call paths, evidence and policy instead of the whole repository.
Provider, model, budget and data policy are attached before transmission.
Cheap, continuous and reproducible checks.
Compact security models narrow candidate files inside a constrained sandbox.
Deep reasoning for selected novel or high-impact cases.
Small local models can narrow candidate files before a frontier call. Their output remains evidence, not proof.
Build it in isolation, then rescan it before merge.
The patch must apply to the finding’s exact code revision.
The original issue is rescanned or explicitly adjudicated.
Code, dependency and protected-file checks run again.
Applicable project and policy tests complete successfully.
The decision, provider and validation results remain attributable.
Run local checks on every change. Buy frontier reasoning only when semantic depth changes the decision.
Run on every relevant change without a model call.
Runs only when policy escalates a case. Scope and budget are recorded.
Escalate the cases that need deep reasoning, then validate every result against independent policy.