Five capability areas, in production.
Verified against real code and git history. Only shipped features listed here; unbuilt items are in the roadmap.
AI / LLM security testing is its own area here, not a footnote under exploitation: prompt injection and jailbreak testing against LLM and agent endpoints, MITRE ATLAS mapped. A confirmed agent-permission escape needs the target to expose its own tool-call trace; without one, a result is a triage signal, not a filed finding.
Every AI-security run also produces a coverage report across the ten OWASP LLM Top 10 risks: what was tested, what wasn't, and why, not just what was found. See the homepage for what that report says.
Everything below runs yourself, free, forever, with no account needed for the CLI. Some of it Ryvx will also run for you on our own hardware, billed in credits: web-application scans and AI/LLM agent red-teaming. The GitHub remediation-PR bot is also real and hosted, but it's arranged directly with us rather than a self-serve credit purchase. Reverse engineering and hash/IOC lookups are local only, and for malware work that is the point: the sample never leaves your hardware. Each group is tagged below with where it stands. See pricing for how hosted credits work.
- ✓Fingerprinting
- ✓Dependency/SCA scanningneeds a repo URL as the target, not a live URL. Runs the same locally or hosted
- ✓Static rule analysis: Terraform, IAM, Dockerfileneeds a repo URL as the target, not a live URL. Runs the same locally or hosted
- ✓Skills library (22 tech stacks + protocols)
- ✓HTTP traffic log and replayscoped; not full MITM proxy
- ✓Multi-step browser automation (approval-gated)
- ✓API security graph mapping: endpoint surface plus an auth-boundary graph showing who reached what, and which endpoints were never probed as a second identitycoverage gaps are an absent probe, not a safety verdict; BOLA candidates are leads (a same-shaped endpoint answered both identities), not confirmed findings. Neither is ever filed by itself
- ✓Scripted pre-scan checks: headers, cookie flags, well-known paths, JS-bundle secret scan, backend fingerprint, transport, host header injectiondeterministic, zero LLM cost; observations only: it never files a finding on its own
- ✓Core agent graph with PoC-verification gate on every finding
- ✓Per-agent Docker sandbox isolation, secrets-at-rest redactionhosted scans have no Docker CLI in the worker container, so isolation there degrades to a shell denylist, not this
- ✓Kubernetes attack-path analysisneeds a repo URL as the target, not a live URL. Runs the same locally or hosted
- ✓Autonomous remediation PRs: real GitHub round-triphosted; arranged with us rather than a self-serve toggle or a plan inclusion. Email us and we'll connect your repository
- ✓Unattended remediation PRs after a hosted scan finishesoff unless arranged per repository; opens a draft PR only, never pushes to a default or protected branch
- ✓Scan-on-deploy: a verified git push queues a hosted scan automaticallyregister a repo yourself under Monitoring > Deploy Triggers: it generates the webhook secret and shows the payload URL to paste into GitHub or GitLab
- ✓Domain-control challenge for target authorisation
- ~Encryption at rest for scan findingsopt-in; report.md and findings.sarif stay plain text by design
- ✓LLM prompt injection testing: encoding-bypass variants (base64 / rot13 / leetspeak), MITRE ATLAS mapped
- ✓AI agent red-teaming: can your agent be talked past its own permissionsconfirmed escapes when the target exposes its tool calls (--agent-tool-call-field); against a closed target the strongest verdict toward an escape is boundary_probing, never a confirmed escape. A declared canary is the one exception, confirming a disclosure (not an escape) even closed
- ✓Adaptive multi-turn jailbreak strategies: PAIR, TAP, and Crescendo, driven by the scan's own modelthe judge's score is advisory, not proof. Only an instrumented run with a real tool-call trace can return a confirmed escape; a black-box target gets triage toward an escape, never confirmation, except a declared canary echoed back verbatim, which black-box confirms as a disclosure directly
- ✓Resource-exhaustion and output-handling probes: measured amplification and active-payload echo detectionunbounded_consumption measures a real size/latency amplification against a baseline, confirmable even black-box since it's a measurement, not an inference; improper_output_handling flags a verbatim active-payload echo, always triage-only here since confirming it needs a downstream sink this tool can't see. That confirmation lives in the web engine's own XSS confirmation
- ✓OWASP LLM Top 10 coverage report: every risk gets tested_fail, tested_pass, or not_tested, with a stated reason for every gaptested_pass means only "attempted, nothing filed," not secure or absent. 8 of 10 risks are exercised by the current attack battery; the other 2 have a stated reason, both structural rather than "not built yet": supply chain needs model/dependency provenance no black-box probe reaches (covered instead by dependency scanning), and data/model poisoning needs training-pipeline access no remote probe can reach either
Its own entry point: `ryvx aiscan --target <endpoint> --policy <preset>`. No separate account or key beyond the LLM you already configured.
- ✓Tier 1 static triage: strings, radare2, capa, floss, real microVM
- ✓Quick-triage mode + full RE UI in the dashboard
- ~Tier 2 auto-solve (angr) + LLM escalation, PoC-gatedsolved a trivial crackme; not against packed, obfuscated, or genuinely malicious samples
- ✓YARA / IOC generation + MalwareBazaar reputation
- ✓Windows VM backend (QEMU/WHPX-accelerated)
- ~Tier 3: Ghidra headless decompilation84 functions on a trivial PE; not run against real malware
Needs QEMU/KVM (or WHPX on Windows, HVF on macOS) plus an ~8GB guest image, neither bundled in the installer. `ryvx setup` (CLI) or the desktop app's Setup page detects both and names the exact fix.
- ✓Executive view, trend analytics, attack-chain visualization
- ✓Compliance-tag surfacing across 7 frameworks
- ✓PDF export, evidence bundles (HAR + screenshot)
- ✓SARIF, JSON, Markdown export: SARIF ingested natively by GitHub, GitLab and Defender; scan events can also push to Slack, Microsoft Teams, Discord, email, or a generic webhooka finding that wasn't independently confirmed says so in the report rather than being presented as proven
- ✓Triage queue, asset inventory, knowledge graph, one-click re-test
- ✓Public REST API (/api/v1): API-key auth, trigger and list scans from CI without a browser sessionserved by the desktop/CLI sidecar on localhost only; not available for hosted scans
- ✓Per-run token and cost telemetry: input/output/cache breakdown per agent, not just a run total
- ✓Full analytics for hosted scans: compliance mapping, systemic/CWE trends, AI-security findings, asset inventory, knowledge graphfed from Postgres, scoped by your own login; the local triage queue itself still only shows this machine's own scans
- ✓Org-shared finding triage: one verdict per finding, visible to your whole organisationhosted-only, since a local install has no shared state to build this on
- ~Immutable per-org audit trail of every tool call a hosted agent maderetained for successful scans only; a failed scan's trail is still discarded. API only, no dashboard screen yet
- ~Shareable evidence links: one finding's evidence, no account needed to view itexpires within 30 days, revocable; API only, no dashboard screen to create or manage one yet
- ~Hosted scan execution: queue a scan, a worker claims and runs it off your machineone worker process on a personal machine behind NAT, no auto-restart after reboot; its container has no Docker CLI, so per-agent sandbox isolation degrades to a shell denylist
- ✓Continuous monitoring: scheduled scans, delta tracking, regression alerts, Slack/Teams/Discord/email alertshosted scheduling runs on pg_cron, independent of any machine being on; local/CLI scheduling still needs the desktop app's own sidecar
IN THE PRODUCT
What you work in
The screens behind the login. Where each one runs today is listed plainly. Analytics, Asset Inventory, the Knowledge Graph and Compliance now read live from your hosted account too, with the same per-request tenant isolation as the API. The Triage Queue and Hash Lookup still only read the run store on the machine that did the scanning.
Get the desktop app for everything above, or run a hosted scan with no setup.