How it works

Authorized scope in, filed disclosure out

KinetixZero mirrors how careful research actually runs — four stages, with a human in the loop at the decisions that matter.

  1. 01

    Define authorized scope

    Everything starts with permission. You create a project, choose an authorization type, and attest to it.

    • Set in-scope and out-of-scope boundaries for the engagement.
    • The attestation is recorded with who attested and when.
    • Scope travels with every finding and export for that project.
  2. 02

    Analyze code & dependencies

    Point KinetixZero at a Git repository or upload a source archive. It runs the analyzers read-only and records a scan.

    • SAST with taint tracking across JavaScript, TypeScript and Python.
    • Dependency resolution matched against OSV advisories.
    • Redacted secret detection, with results surfaced by confidence.
  3. 03

    Validate with the AI pass

    Triage ranks the open findings. The AI layer assesses each one and shows cited evidence — you keep the verdict.

    • Reachability is broken into controlled / reaches-sink / sanitized.
    • Citations are verified against the exact code the model was shown.
    • You confirm what's real and reproduce it; the AI never claims proof.
  4. 04

    Disclose responsibly

    Confirmed findings become a disclosure package, tracked to a deadline with a verifiable trail.

    • Generate CVE 5.1, OSV, and PDF outputs from the finding's fields.
    • Track vendor notification, acknowledgement, and fix to a deadline.
    • A hash-chained audit log keeps the whole history auditable.

See the workflow on your own repo

Get started free