Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and async code. AI-agent ready with deterministic rule replay. Open-source alternative to Semgrep Pro and CodeQL.
Formal taint analysis for application security — finds what AST-pattern matchers miss, lets LLM agents enact rules from vulnerabilities, scales where neither can alone.
English | 简体中文 | 繁體中文 | 한국어 | Deutsch | Español | Français | Italiano | Dansk | 日本語 | Polski | Русский | Bosanski | العربية | Norsk | Svenska | Português (Brasil) | ไทย | Türkçe | Українська | বাংলা | हिन्दी | Ελληνικά | Tiếng Việt | Bahasa Indonesia
Supported technologies and integrations
The most thorough taint analysis engine for Spring apps
Roadmap