Skip to main content

Documentation

Install it, see how the agent graph works, and read exactly what's verified before a finding gets reported.

Ryvx runs autonomous LLM agents that recon a target, hunt for vulnerabilities, validate each one with a working proof-of-concept, CVSS-score it, and suggest a concrete code fix: for source code, local apps, live URLs you're authorized to test, or a whole bug bounty program's scope.

The actual bet isn't "more autonomous than the next tool." It's three things held together: every finding is gated behind a working exploit, not an unconfirmed suspicion; every exploit against a production-tagged target needs a live human to say yes first, unless that specific run was explicitly submitted with auto-approve turned on, a choice recorded against the run itself; and every tool call any agent makes is written to an append-only audit log, so a scan's actions can be defended after the fact. These pages document how each of those works, not just that they exist.

Start here

Getting started

Install, set a model (Claude, OpenAI, Gemini, or a local model via litellm), and run your first source review or live scan.

Install

Per-platform install instructions: the Windows desktop installer, the Linux CLI wheel, and what works on macOS today.

How it works

The agent graph: a root orchestrator that never touches the target itself, the subagents it spawns, the sandboxed tool loop they share, and how a run becomes a report.

Verification

The PoC-or-it-didn't-happen gate, deterministic CVSS scoring, the evidence trail behind each finding, and what differential verification does and doesn't cover yet.

Authorization & approval

The domain-control challenge that verifies you own a target, and the live human sign-off required before an exploit fires against production.

Compliance

The seventeen plain-English PCI DSS and Cyber Essentials Plus questions, which ones Ryvx tests directly against your website, and which ones you answer yourself.

Agent boundary testing

How to run it: finding your own chatbot's real endpoint, why a third party's is refused by design, the policy presets, and how to read the containment_escaped/disclosure_confirmed/limit_exceeded/compliant/boundary_probing/inconclusive verdict it returns.

Reverse engineering

The three tiers (triage, solve, decompile), what each costs and returns, why analysis runs in an isolated microVM rather than a container, and when you need the guest image.

GitHub PR bot

Which findings it can use and why, how the sealed-token connection works, the repo/review caps, and how it's arranged with us rather than switched on yourself.

Public API

Drive Ryvx from a CI/CD pipeline without a browser session: issue an API key, the three /api/v1/ routes, the error shape, and why the scan trigger still can't skip the production approval gate.

What's proven, and what only compiles

A tool built around "PoC or it didn't happen" should hold its own claims to the same standard. Several pieces of Ryvx (the ticket-tracker integrations, one reverse-engineering tier, bug bounty scope mode) are finished and tested but have never been run against anything real yet, and published benchmark recall numbers were withdrawn after an audit found the runs behind them were cut short, and were only republished once an untruncated, harness-scored run existed. See the About page for the full capability audit, and the post on withdrawing those numbers for what that looked like in practice.

STAY IN THE LOOP

Release notes and product updates, by email.

We'll send a confirmation email; you're not on the list until you click the link in it. See our privacy policy.