Product

The work that happens after discovery

KinetixZero is organized around analysis, validation and disclosure, so a scan becomes a defensible, reproducible result.

kinetix · acme-web · assessment #7
High

Unsanitized path joins into fs.readFile (path traversal)

KX-1042 · src/routes/files.ts:58 · SAST · taint

Likely realFirm
High

Server-side request forgery in webhook fetch

KX-1039 · src/jobs/webhook.ts:21 · SAST · taint

Likely realFirm
Medium

lodash 4.17.19 — prototype pollution (CVE-2020-8203)

KX-1051 · package-lock.json · Dependency

Needs more contextFirm
Medium

Reflected value in response — possible XSS

KX-1033 · src/views/search.tsx:44 · SAST

Likely false positiveTentative
Low

Hardcoded credential pattern in config loader

KX-1028 · src/config/env.ts:12 · Secrets

Likely false positiveTentative

Illustrative sample data

01 · Analysis

See everything, ranked by confidence

  • Semgrep taint-mode rules trace untrusted input to dangerous sinks across JS/TS and Python.
  • Dependency lockfiles resolve against the OSV database with version and fix mapping.
  • Redacted secret detection flags exposed credential patterns without storing the secret.
  • Every finding is marked Firm (taint-verified or matched CVE) or Tentative (pattern match).
02 · Validation

An AI pass that shows its work

  • Claude assesses whether input is controlled, reaches the sink, and is sanitized.
  • Each answer must cite exact lines; KinetixZero verifies citations against the code shown.
  • The verdict is derived server-side — uncited definitive claims are downgraded to unclear.
  • Batch triage ranks open findings so you work the most promising ones first.
03 · Disclosure

From confirmed finding to filed report

  • Export CVE Record Format 5.1 and OSV JSON generated from real finding fields.
  • Generate a professional PDF report with reproduction, impact, and remediation.
  • Track the vendor timeline to a disclosure deadline with health indicators.
  • A hash-chained audit log and evidence hashes make the whole trail verifiable.

Reachability-aware

Code and dependency findings carry the context needed to judge whether the vulnerable path is actually reachable.

Standards-first

Outputs follow CVE 5.1 and OSV so your findings slot into the ecosystems that consume them.

Managed, metered AI

AI runs on KinetixZero's own Claude integration — no key to manage. Every account includes 10 free Agentic Triage runs, and usage is visible in the app.

Ready to run an assessment?

Get started free