Docs / Install
Install
What works on each platform, and what doesn't yet.
Windows
An NSIS desktop installer, currently release 0.3.19: Ryvx_0.3.19_x64-setup.exe, 365 MB. Runs on Windows 10 and 11, 64-bit only.
The installer isn't Authenticode code-signed yet, so Windows SmartScreen will warn that it is from an "unknown publisher". Check the file before you tell Windows to run it anyway. In PowerShell, in the folder you saved it to:
Get-FileHash .${WINDOWS_INSTALLER_FILENAME} -Algorithm SHA256The hash must be 80dff19f72ed7ff7af86df5c6e438a04517f519900eaeb019de8fbdf0ba2a57c, the same value GitHub lists beside the asset on the release page. If it isn't, delete the file. If it is, choose More info, then Run anyway. Updates after that are signed with the Tauri updater key and checked by the installed app before it applies them.
Linux
CLI only. There is no desktop app, no .deb, and no AppImage published.
pip install https://github.com/harryc295/ryvx-downloads/releases/download/cli-v0.3.12/ryvx-0.3.12-py3-none-any.whl
That command checks nothing about the file itself: pip verifies the download made it over the wire intact, not that it is actually the wheel this page names. To check that too, pin the install to the wheel's published hash. pip's hash-checking mode only reads hashes out of a requirements file, so a single-URL install is two steps instead of one flag:
# requirements.txt, one line https://github.com/harryc295/ryvx-downloads/releases/download/cli-v0.3.12/ryvx-0.3.12-py3-none-any.whl --hash=sha256:686ee44fa98ba7472843dd9ec0eebb24bcf1671219b61f7ad84d37c7b1b6a9e5
pip install --require-hashes -r requirements.txt
See the download page for the sdist's digest too, and for what a matching hash does and doesn't prove.
The wheel is 4.3 MB. Requires Python 3.11 or newer, per pyproject.toml's requires-python.
Check yours first, because the failure if it is too old is not obvious:
python3 --version
Installing a wheel from a direct URL does not enforce requires-python on older versions of pip, so Ryvx will install onto an unsupported interpreter and then fail on a dependency instead. What you see is hundreds of lines of litellm version numbers ending in No matching distribution found, which looks like a broken package and is really just the wrong Python. Observed on a Mac running the built-in 3.9. Upgrading pip first (pip install --upgrade pip) makes the real error visible.
macOS
macOS ships Python 3.9, which is too old. The system python3 will not work, and the error it produces points at a dependency rather than at the Python version. Install a newer one and use it by name when creating the virtualenv:
If you do not have Homebrew, and most people who are not developers do not, download the installer from python.org and run it like any other Mac app. This route needs nothing installed first. Then close Terminal completely and open a new window, or the shell you already have running will not see the new interpreter.
With Homebrew, this is the same thing in one command:
brew install python@3.12
Either way, create the virtualenv with the new interpreter by name. Using a bare python3 here is the mistake that starts the whole problem again, because that still points at the system 3.9.
python3.12 -m venv ~/ryvx source ~/ryvx/bin/activate pip install --upgrade pip
The CLI works today, confirmed on real Apple Silicon hardware on 2026-09-02 rather than inferred: someone installed it on their own Mac from these instructions and got a clean ryvx setup run. It's the same wheel as Linux: py3-none-any, zero native extensions (verified: 808 files, no .so, .dylib, .pyd, or .dll) and no platform-gated dependencies, so the identical pip command above installs on macOS unchanged. The Python version above is the only thing that stood between them and a working install.
pip install https://github.com/harryc295/ryvx-downloads/releases/download/cli-v0.3.12/ryvx-0.3.12-py3-none-any.whl
The Linux section above shows the hash-verifying form of this same command; it applies here unchanged.
There is a desktop app for macOS too, but it is behind Windows: the current .dmg is 0.3.13 (notarized and stapled) while Windows is on 0.3.19. It is published on the same downloads repo as Windows. Auto-update does not reach macOS at the moment: the update manifest carries no macOS entry until a Mac build of the current version is published, so check the download page for a newer .dmg and install it over the top. It's Apple Silicon (aarch64) only so far; an Intel build hasn't been started.
All platforms, after install
ryvx --help python -m ryvx dashboard # http://127.0.0.1:8765
dashboard serves the local UI and JSON API at http://127.0.0.1:8765. The Windows desktop app bundles that same dashboard, so on Windows you get it without running the command yourself.
Getting the prerequisites
ryvx setup is the prerequisite doctor. It checks what each capability needs, says which are missing, and prints the exact command for your platform. Nothing is installed unless you ask.
ryvx setup # report what is missing ryvx setup --fix # attempt the fixes that are safe to automate
--fix asks for confirmation before each change and refuses to run non-interactively, so it will not surprise a CI job. It re-checks afterwards and prints the state it actually ended in, rather than assuming its own fixes worked.
Two things it will not do for you. It cannot set an API key: that is your credential and your spend, so it prints the exact export line and leaves it to you. And it will not offer a fix that cannot work on your machine, for instance installing Docker Desktop on a host with no hardware virtualization.
The security toolbox
Scans run each agent in its own container. Without the tooled image that container is a bare Python interpreter: no nmap, sqlmap, nuclei, ffuf, gobuster, httpx, nikto, dirb, whatweb or masscan. Ryvx still works, it just has far less to work with.
docker pull ghcr.io/harryc295/ryvx-sandbox@sha256:8dfeb4a171a041bb7645383117ff341e12a28f4b561c44b183663af4b554caa8
About 1.75 GB. ryvx setup --fix runs this exact command for you if Docker is available. It is deliberately marked optional: Ryvx does not fail, and ryvx setup does not exit non-zero, just because you have not downloaded it. Nothing is ever pulled implicitly during a scan.
The reference is pinned to a digest, not the mutable :latest tag, because this is the image every scan agent's shell executes inside. Docker refuses the pull if the registry serves anything with a different digest, so the bytes you get are the bytes this page names. The image is not yet signed, so the digest proves it is unchanged, not who built it; the build itself is public, below.
Docker is not needed to install Ryvx, to run ryvx --help, or to open the dashboard. It is needed only to run scans in a sandbox.
The image is built from a public repository you can read: Debian plus open-source security tooling, and nothing else. It carries no Ryvx source code, and the build asserts that on every publish by searching the finished image and failing if any is found. You can build it yourself from that same Dockerfile with no access to anything private.
Next
- Getting started: set a model and run your first scan.
- Download: the release cards this page's links point at.
← Back to Docs