Security & trust

Safeguards that are part of the product

Security here isn't a promise on a page — these controls are enforced in the platform itself.

Read-only static analysis

KinetixZero analyzes source code and dependencies. It does not launch exploits or attacks against live systems. A human researcher validates and reproduces findings before anything is treated as real.

Authorization on every project

Each project records an explicit authorization attestation and in/out-of-scope boundaries, captured with the attester and timestamp. The platform is intended only for targets you are permitted to analyze.

Isolation at the database

Workspaces are isolated with PostgreSQL row-level security and a restricted application role that cannot bypass it; each user's plan and usage is isolated the same way. A startup guard refuses to serve in production on a connection that could bypass it.

Hardened target fetch

Git targets are cloned over HTTPS with pinned public IPs, no redirects, hooks, submodules or LFS, and symlinks flattened to plain files — so a target's repository can't execute code on the host.

Modern authentication

Argon2id password hashing, opaque server-stored session tokens in HttpOnly cookies, CSRF double-submit with an origin check, and optional TOTP multi-factor authentication.

Auditable end to end

Sensitive actions — including every AI run — are written to a hash-chained, append-only audit log, and exports carry evidence and chain-of-custody hashes so a reviewer can verify the trail.

Responsible use

The rules of the road

KinetixZero is a tool for authorized vulnerability research. Use it only on code you own, open-source projects, assets within a bug-bounty scope, or targets you have written permission to assess.

The AI layer produces hypotheses with cited evidence. It is explicitly not proof of exploitability — model confidence is never presented as a confirmed vulnerability, and the human researcher is responsible for validation and for following each program's disclosure rules.

Private findings and customer data are never shown on public pages. AI runs on KinetixZero's managed Claude integration: only the minimal context for one finding is sent, only when you ask, and the server's key never reaches your browser. Each workspace admin decides whether AI assistance is allowed at all.

Research you can stand behind

Get started free