Developer & AppSec Documentation

Developer Reference Guide: Running & Managing Audits

Explore four ways to run autonomous vulnerability audits with Cyfendo: direct Web Folder Uploads, continuous Git Repositories, lightweight Cloud-Synchronized CLI, and the 100% Cyfendo Private Scan (Zero Source Code Egress).

Four Ways to Run Vulnerability Audits

Choose the workflow that best fits your security posture, data custody requirements, and development lifecycle.

Web UI Folder Drag & Drop

Fastest for ad-hoc audits. Drag any local project folder directly into your browser. In-browser AST filtering computes Protected LOC in milliseconds without sending binaries or dependencies.

Git Repository Integration

Ideal for automated branch tracking. Link your GitHub, GitLab, or Bitbucket repository URL. Cyfendo automatically identifies branch and commit SHAs to deliver incremental diff audits.

Lightweight Cloud CLI (cyfendo scan .)

Standard cloud-synchronized scanning for terminal users and CI/CD pipelines. Packages code locally, uploads to ephemeral cloud sandboxes, streams live telemetry, and exports unified .patch diffs.

Cyfendo Private Scan (cyfendo scan --private .)

Zero Egress

100% Local Machine • Zero Source Code Egress. Executes entire multi-agent security pipeline on your local hardware using your own LLM API keys (OpenAI, Anthropic, Gemini, Vertex, Azure) or air-gapped local models (Ollama/vLLM). Code, ASTs, finding proofs, and patches never leave your machine.

Method 1: Web UI Folder Upload

Run ad-hoc security reviews directly from your browser with zero local software requirements.

Open Dashboard & Click "Start New Scan"

Navigate to /dashboard and click the Start New Scan button. Ensure the Upload Folder tab is selected.

Select or Drag Your Local Project Folder

Select your local project root. Cyfendo’s in-browser scanner automatically applies exclusion rules:

  • Respects custom .gitignore and .cyfendoignore files.
  • Automatically ignores node_modules/, vendor/, .git/, dist/, build/, virtual environments (venv/), and binary assets.
  • Computes precise Protected LOC and displays an instant quota check before uploading.

Watch Live Multi-Agent Telemetry

Once submitted, live Server-Sent Events (SSE) stream the real-time execution across distributed analysis stages: AST Parsing → Taint Propagation → Ephemeral Sandbox PoC Verification → AI Remediation Patch Synthesis.

Review in the Interactive Vulnerability IDE

Inspect findings categorized by CWE and CVSS scores. View line-level taint vectors, run sandbox exploit proofs-of-concept, and download synthesized unified .patch diffs or SARIF reports.

Method 2: Git Repository Integration & Automated Scheduling

Connect remote Git repositories for continuous branch monitoring, monorepo subdirectory scoping, and automated periodic security audits.

Select "Git Repository" in Scan Modal

In the Start New Scan modal on your Dashboard, switch to the Git Repository tab. Provide your repository URL (e.g. https://github.com/org/repo.git) and specify the branch to inspect (e.g. main, develop, or release/v2).

Monorepo Subdirectory Scoping (Optional)

If your repository contains multiple microservices or packages, specify a relative path in Subdirectory (Optional) (e.g., apps/api or packages/backend). Cyfendo packages and audits only source files inside that subpath, preventing unnecessary LOC consumption from unrelated projects.

Private Repository Authentication

For private repositories, provide a Personal Access Token (PAT) with read-only repository permissions (e.g. GitHub fine-grained PAT with Contents: Read-only, GitLab Project Access Token, or Bitbucket App Password). Tokens are encrypted at rest with AES-256 (Fernet), decrypted in-memory only during ephemeral sandbox fetches, and never stored in plaintext.

Incremental Continuity & Churn Tracking

Cyfendo links each repository to an active Protected Project. When rescanning code, Cyfendo evaluates semantic AST continuity against previous snapshots—charging your quota only for newly added or modified lines of code.

Automated Periodic Scanning & Smart Change Detection

Keep your production code continuously protected without manual intervention. Cyfendo allows you to attach an automated periodic scanning schedule to any connected Git project directly from your dashboard.

Git automated periodic scanning configuration parameters and scheduling behaviors
Schedule Parameter Options / Behavior Description
Scan Frequency daily, weekly, monthly Runs every 24 hours, every 7 days, or every 30 days automatically.
Branch / Ref String (e.g. main, staging) The remote Git branch continuously monitored for upstream commits.
Subdirectory Optional relative path (e.g. apps/api) Restricts periodic audits strictly to a designated microservice or monorepo package.
Smart Change Detection 0-Credit Skip Enabled Checks the remote commit SHA via git ls-remote before scanning. If code is unchanged, the run completes in milliseconds with 0 scan credits used.
Remediation Patches Toggle (Enabled by default) Automatically synthesizes surgical, sandbox-verified unified diff patches for every vulnerability found.

Automated Notifications & Alerts

When a scheduled scan finishes, Cyfendo dispatches instant alerts across multiple channels:

  • In-App Notification Center: Real-time unread badge and dropdown with direct links to view finding triage and patches.
  • Email Notification Delivery: Branded security report sent from noreply@cyfendo.com detailing total findings, severity breakdown (Critical, High, Medium, Low), risk score, and patch synthesis status.
  • Automatic Safety States: If monthly scan quota is reached, the schedule automatically pauses (paused_quota) without dropping your project configuration. If Git credentials expire, an alert prompts you to update your access token (paused_auth_error).

Git Credential Management & Per-Project Isolation

To follow the principle of least privilege, Personal Access Tokens (PATs) can be strictly scoped to a specific project (project_id). This guarantees that repository-level fine-grained tokens (e.g., GitHub Fine-Grained PATs) will never bleed into or trigger scans on other repositories in your workspace.

$ curl -X POST https://cyfendo.com/api/v1/integrations/git/credentials \
    -H "Authorization: Bearer cy_live_..." \
    -H "Content-Type: application/json" \
    -d '{"project_id": "<PROJECT_ID>", "name": "Repo Scoped Token", "token": "github_pat_...", "provider": "github"}'

REST API Scheduling Automation

You can configure or trigger schedules programmatically using Cyfendo's authenticated REST API:

$ curl -X POST https://cyfendo.com/api/v1/projects/<PROJECT_ID>/schedule \
    -H "Authorization: Bearer cy_live_..." \
    -H "Content-Type: application/json" \
    -d '{"frequency": "daily", "git_branch": "main", "git_subdir": "apps/api", "only_scan_on_changes": true, "generate_patches": true}'

Method 3: Cyfendo Local CLI Scanner

Zero-dependency, high-speed CLI scanner designed for developer terminals, headless SSH servers, and CI/CD pipelines.

1. Installation

Choose your preferred installation method below:

Option A: Python Package Manager (pip / pipx)
$ pip install --upgrade cyfendo

2. Authentication

Generate an API Key from Top-Right User Menu → Developer & CLI Access and authenticate your CLI:

# Option A: Interactive login command
$ cyfendo login --key cy_live_xxxxxxxxxxxxxxxxxxxxxxxx

# Option B: Set as environment variable
$ export CYFENDO_API_KEY=cy_live_xxxxxxxxxxxxxxxxxxxxxxxx

3. Running Scans on Cyfendo Server

When running standard scans without the --private flag, your codebase is uploaded and analyzed on the Cyfendo Server (Cloud or on-premises). Analysis, sandbox verification, and patch synthesis execute remotely on the server fleet—no local commercial model keys or GPU dependencies required.

# 1. Standard fast PoC scan on Cyfendo server:
$ cyfendo scan .

# 2. Server-side scan with automated AI remediation patch generation (no --private flag needed):
$ cyfendo scan . --generate-patch

# 3. Server scan with patch generation, custom bundle export, and SARIF report:
$ cyfendo scan . \
    --generate-patch \
    --patch-bundle fixes.patch \
    --sarif cyfendo-results.sarif

# 4. Target a specific existing project in your workspace:
$ cyfendo scan /path/to/source --project "payment-gateway" --generate-patch

# 5. Connect to a custom or self-hosted Cyfendo server endpoint:
$ cyfendo scan --server https://cyfendo.internal:5001 . --generate-patch

# 6. CI/CD or headless execution with auto-confirm:
$ cyfendo scan . --generate-patch --yes --no-interactive

4. Multi-Account & Organization Workspaces

If your account is linked to an organization or multiple business accounts, your single API key grants access to all of them. You can switch active workspace contexts locally or specify target workspaces on the fly:

# 1. List all accessible personal and business workspaces:
$ cyfendo workspaces

# 2. Switch default active workspace (persisted to ~/.cyfendo/config.json):
$ cyfendo workspace switch ws_acme_corp_8f3a

# 3. Execute a scan under a specific organization without switching default:
$ cyfendo scan . --workspace ws_acme_corp_8f3a --generate-patch

# 4. In CI/CD runners, set CYFENDO_WORKSPACE_ID to attribute scans to your organization:
$ export CYFENDO_WORKSPACE_ID=ws_acme_corp_8f3a
$ cyfendo scan . --generate-patch

Method 4: Cyfendo Private Scan

100% Local Machine • Zero Source Code Egress

Execute autonomous multi-agent security audits directly on your local workstation or private runner using your own LLM provider keys or self-hosted models, with complete data sovereignty.

Private Data Custody & Zero Source Code Egress Guarantee

Cyfendo Private Scan is engineered for defense, healthcare, fintech, and enterprise teams with stringent zero-trust data custody requirements:

100% Local Pipeline Execution
AST parsing, cross-file taint analysis, call graphs, exploit verification, and patch synthesis execute directly in your local environment.
Direct LLM Connection
Your machine communicates directly with OpenAI, Anthropic, Gemini, Vertex, Azure, or local Ollama. Cyfendo servers never proxy your code or model prompts.
Local Storage in .cyfendo/
All findings, exploit traces, Markdown reports, SARIF files, and individual .patch diffs are stored exclusively in your local workspace.
Minimal Entitlement Sync
Only aggregate LOC count and high-level finding counters (e.g. 2 critical, 1 high, risk score) sync to Cyfendo to meter plan quota and trigger alerts.

Step-by-Step Customer Instructions

Install or Update the Cyfendo CLI

Install the official Cyfendo Python package (requires Python 3.9+) or use the standalone curl script:

$ pip install --upgrade cyfendo

Authenticate Your Cyfendo Workspace

Generate a Cyfendo API key from User Menu → Developer & CLI Access and authenticate your local machine. This verifies your plan entitlements and Protected LOC balance:

$ cyfendo login --key cy_live_xxxxxxxxxxxxxxxxxxxxxxxx

# Verify workspace balance & active plan:
$ cyfendo status

Select Your Model Provider & Set Credentials

Export your AI provider API key as an environment variable, or supply it directly via the --llm-key flag at runtime:

# For OpenAI:
$ export OPENAI_API_KEY="sk-proj-xxxxxxxxxxxxxxxxxxxxxxxx"

# For Anthropic Claude:
$ export ANTHROPIC_API_KEY="sk-ant-xxxxxxxxxxxxxxxxxxxxxxxx"

# For Google Gemini / Vertex AI:
$ export GEMINI_API_KEY="AIzaSyxxxxxxxxxxxxxxxxxxxx"
# Or for GCP Vertex: export GCP_PROJECT="my-enterprise-project"

# For Azure OpenAI:
$ export AZURE_OPENAI_ENDPOINT="https://my-resource.openai.azure.com/"
$ export AZURE_OPENAI_KEY="xxxxxxxxxxxxxxxxxxxxxxxx"
$ export AZURE_OPENAI_DEPLOYMENT="gpt-4o"

Configure Persistent Defaults (Optional)

Save your preferred provider and model defaults in ~/.cyfendo/config.json so you never have to pass flags on subsequent scans:

$ cyfendo config --set-provider openai
$ cyfendo config --set-model gpt-4o
$ cyfendo config --set-llm-key sk-proj-xxxxxxxxxxxxxxxxxxxxxxxx

Execute the Cyfendo Private Scan

Run cyfendo scan --private . on your target directory. Add --generate-patch to synthesize unified remediation diffs:

# 1. Run local scan with OpenAI GPT-4o and patch generation:
$ cyfendo scan --private \
    --provider openai \
    --model gpt-4o \
    --generate-patch \
    .

# 2. Run with Anthropic Claude 3.7 Sonnet and extended reasoning:
$ cyfendo scan --private \
    --provider anthropic \
    --model claude-3-7-sonnet-latest \
    --thinking high \
    --generate-patch \
    .

# 3. Add custom steering directive to guide deep vulnerability search:
$ cyfendo scan --private \
    --provider openai \
    --model gpt-4o \
    --directive "Focus audit on authentication bypass, BOLA, and SSRF" \
    .

Review Findings & Apply Patches Locally

All artifacts are saved to .cyfendo/ in your project root. Inspect reports in your terminal and apply patches with a single command:

# List all generated patches:
$ cyfendo patches

# View colorized diff for a specific finding:
$ cyfendo patch fnd_388b --show

# Apply patch directly to source code via git apply:
$ cyfendo patch fnd_388b --apply

# Read full Markdown audit report:
$ cat .cyfendo/report.md

Private Scan Provider Setup & Credentials Guide

Comprehensive setup guide for enterprise AI providers, cloud platforms, and 100% air-gapped self-hosted models.

OpenAI (GPT-4o, GPT-4.5, O3-Mini, O1)

--provider openai

Supports all official OpenAI chat and reasoning models. Also supports custom OpenAI-compatible proxy gateways via --endpoint or OPENAI_BASE_URL.

export OPENAI_API_KEY="sk-proj-..."
$ cyfendo scan --private --provider openai --model gpt-4o --generate-patch .

# With custom OpenAI-compatible endpoint (e.g. corporate proxy / LiteLLM):
$ cyfendo scan --private --provider openai --endpoint "https://ai-proxy.corp.internal/v1" --model gpt-4o .

Anthropic Claude (Claude 3.7 Sonnet, Claude 3.5 Sonnet)

--provider anthropic

Leverages Claude's superior code comprehension and extended thinking capabilities. Use --thinking high for maximum depth during deep taint propagation and patch repair.

export ANTHROPIC_API_KEY="sk-ant-..."
$ cyfendo scan --private \
    --provider anthropic \
    --model claude-3-7-sonnet-latest \
    --thinking high \
    --generate-patch \
    .

Google Gemini & GCP Vertex AI

--provider gemini / vertex

Use the standard Gemini Developer API with an API key, or leverage GCP Vertex AI using enterprise Application Default Credentials (ADC) within your Google Cloud project boundary.

# Option A: Gemini Developer API Key
export GEMINI_API_KEY="AIzaSy..."
$ cyfendo scan --private --provider gemini --model gemini-3.7-flash --generate-patch .

# Option B: GCP Vertex AI with Enterprise ADC
$ gcloud auth application-default login
export GCP_PROJECT="my-enterprise-gcp-project"
export VERTEX_AI_LOCATION="us-central1"
$ cyfendo scan --private --provider vertex --model gemini-3.7-flash .

Microsoft Azure OpenAI Service

--provider azure

Connect to your private Microsoft Azure OpenAI resource with dedicated network security, HIPAA/SOC-2 compliance, and enterprise data boundaries.

export AZURE_OPENAI_ENDPOINT="https://my-resource.openai.azure.com/"
export AZURE_OPENAI_KEY="xxxxxxxxxxxxxxxxxxxxxxxx"
export AZURE_OPENAI_DEPLOYMENT="my-gpt4o-deployment"

$ cyfendo scan --private --provider azure --generate-patch .

100% Air-Gapped & On-Premise Models (Ollama, vLLM, Local)

--provider ollama

Run audits in isolated air-gapped environments or restricted defense facilities. By pairing Cyfendo with a local inference engine (such as Ollama or vLLM), zero network packets leave your machine or private LAN for model inference.

# 1. Pull open-weights reasoning model in Ollama:
$ ollama pull deepseek-r1:32b
# (or: ollama pull qwen2.5-coder:32b / llama3.3:70b)

# 2. Execute 100% local, air-gapped scan (default endpoint http://localhost:11434/v1):
$ cyfendo scan --private \
    --provider ollama \
    --model deepseek-r1:32b \
    --generate-patch \
    .

# 3. For custom internal vLLM cluster:
$ cyfendo scan --private \
    --provider ollama \
    --endpoint "http://vllm-cluster.internal:8000/v1" \
    --model deepseek-ai/DeepSeek-R1 \
    .

Scan Settings & Advanced Options

Customize finding deduplication scopes, AI remediation synthesis, and benchmark evaluation modes across Web UI and CLI.

Deduplication Scopes (--dedup-scope)

Controls how raw taint traces and candidate findings across call graphs, AST scopes, and source files are clustered into consolidated security alerts:

  • root_cause (Default): Universal multi-factor AST clustering across functions and routes. Consolidates redundant alerts into single root-cause findings for developer triage.
  • file (Per-File Isolation): Prevents findings in separate files from merging. Crucial for synthetic test suites and granular file-by-file audits.
  • none (Raw Traces): Disables deduplication clustering entirely. Outputs every verified candidate finding trace directly without merging.

Fast PoC Mode vs. AI Remediation Patches (--generate-patch)

By default, Cyfendo runs in Fast PoC Mode—executing full AST taint propagation and gVisor sandbox exploit verification in seconds without blocking on AI patch synthesis.

To generate surgical fix diffs during the scan, enable the toggle in the Web UI or pass --generate-patch in the CLI. You can also generate dual-oracle verified patches on-demand directly inside the Vulnerability IDE for any individual finding.

Benchmark Evaluation Mode (--benchmark-mode)

Designed for automated evaluation benchmarks (such as OWASP Benchmark, Juliet, and custom synthetic suites). When enabled, Cyfendo automatically enforces Per-File Isolation (--dedup-scope=file) to avoid cross-file merging and disables initial patch generation for maximum evaluation throughput and exact groundtruth comparison.

# 1. Run in Benchmark Mode (per-file isolation, fast PoC)
$ cyfendo scan . --benchmark-mode

# 2. Run with per-file deduplication and full AI patch generation
$ cyfendo scan . --dedup-scope=file --generate-patch

# 3. Run raw audit without any deduplication
$ cyfendo scan . --dedup-scope=none

Inspecting & Applying Remediation Patches

Cyfendo generates review-ready unified diffs for verified vulnerabilities. Inspect and apply them manually or via CLI.

# 1. List and export individual .patch files into .cyfendo/patches/
$ cyfendo patches

# 2. Inspect colorized diff for a specific finding in the terminal
$ cyfendo patch fnd_91a4 --show

# 3. Apply patch directly to local source code using git apply
$ cyfendo patch fnd_91a4 --apply

# 4. Or apply manually with standard git tooling
$ git apply .cyfendo/patches/01_sql_injection.patch

# 5. Generate patches via Cyfendo server during scan & export unified bundle (no --private flag):
$ cyfendo scan . --generate-patch --patch-bundle fixes.patch
$ git apply fixes.patch

CI/CD Quality Gates & GitHub Pull Request Protection

Enforce autonomous shift-left security directly on GitHub pull requests. Automatically scan code diffs, publish inline SARIF annotations on the PR Files changed tab, block merging on high/critical vulnerabilities via GitHub Branch Protection, and generate 1-click patch artifacts for instant developer remediation.

1. PR Trigger
PR Event & Concurrency

Triggers on pull request opened, synchronize (new commits), and reopened. Smart concurrency cancellation aborts superseded runs to save runner minutes and AI tokens.

2. Runner-Local Audit
Autonomous Audit

Analyzes PR changes directly on your CI runner VM using Cyfendo Private Scan (or via managed Cloud Workers). Full source code remains on your runner; only code snippets route to your configured AI provider (or stay 100% local if using local models), and minimal LOC telemetry goes to Cyfendo for token verification.

3. SARIF 2.1.0
Inline PR Annotations

Exports standard SARIF 2.1.0 findings and uploads via upload-sarif@v4. Security alerts, CWE links, and taint traces display directly on the PR's Files changed tab.

4. Merge Gate
Branch Protection Gate

The --fail-on=high policy exits with code 1 if vulnerabilities exceed your severity threshold, causing GitHub Branch Protection to disable the Merge pull request button.

1 Configure Repository Secrets on GitHub.com

In your GitHub repository, navigate to Settings → Secrets and variables → Actions → New repository secret. (For organization-wide or monorepo setups, configure under Organization Settings → Secrets and variables → Actions).

CYFENDO_API_KEY

Your workspace token from the Cyfendo Dashboard. Validates Protected LOC quota & entitlement limits without transmitting code.

GEMINI_API_KEY / OPENAI_API_KEY

Your commercial AI model key (Gemini, OpenAI, Anthropic, or Azure). Passed directly to the CLI on the runner with zero intermediate proxies.

GITHUB_TOKEN (Automatic)

Built-in GitHub Actions token. Automatically provided by GitHub runner; used by upload-sarif@v4 to publish inline PR annotations.

CYFENDO_WORKSPACE_ID (Optional)

Target Business workspace ID (e.g. ws_acme_corp_8f3a). Scopes CI/CD repository scans to your company's pooled organization quota.

2 Add the Pull Request Workflow File (.github/workflows/cyfendo-pr.yml)

Executes the autonomous vulnerability audit locally on your GitHub Actions runner VM using Cyfendo Private Scan. Full source code files never leave the runner to Cyfendo cloud servers; only minimal code snippets route directly to your approved AI provider, and aggregate LOC telemetry goes to Cyfendo for token verification. (For complete zero-egress offline operation, configure Mode 3 with local models).

name: Cyfendo PR Security Gate

on:
  pull_request:
    branches: [main, master]
    types: [opened, synchronize, reopened]

# Cancel in-progress runs when new commits are pushed to the same pull request
concurrency:
  group: cyfendo-${{ github.workflow }}-${{ github.head_ref || github.ref }}
  cancel-in-progress: true

jobs:
  security-gate:
    name: Cyfendo Private Security Gate
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write  # Required to publish SARIF alerts to GitHub PR Files Changed tab
      actions: read  # Required for upload-sarif to query workflow run metadata

    steps:
      - name: Checkout Pull Request Code
        uses: actions/checkout@v4

      - name: Set up Python
        uses: actions/setup-python@v5
        with:
          python-version: '3.11'

      - name: Install Cyfendo CLI & Model Provider SDK
        run: |
          pip install --upgrade cyfendo google-genai
          # For OpenAI:    pip install --upgrade cyfendo openai
          # For Anthropic: pip install --upgrade cyfendo anthropic

      - name: Run Cyfendo Private Scan
        env:
          CYFENDO_API_KEY: ${{ secrets.CYFENDO_API_KEY }}
          GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}
          # OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
          # ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
        run: >
          cyfendo scan .
          --private
          --provider gemini
          --model gemini-2.5-flash
          --fail-on high
          --sarif cyfendo-results.sarif
          --no-interactive

      # Publish standard SARIF 2.1.0 findings to PR "Files changed" annotations
      - name: Upload SARIF to GitHub PR & Security Tab
        uses: github/codeql-action/upload-sarif@v4
        if: always() && hashFiles('cyfendo-results.sarif') != ''  # Upload whenever SARIF exists (even if quality gate fails)
        continue-on-error: true  # Resilient if GitHub Advanced Security is disabled on private repos
        with:
          sarif_file: cyfendo-results.sarif

      # Archive generated remediation patches so developers can download & apply them
      - name: Archive Remediation Patches & SARIF
        uses: actions/upload-artifact@v4
        if: always()
        continue-on-error: true
        with:
          name: cyfendo-remediation-patches
          path: |
            cyfendo-results.sarif
            .cyfendo/patches/
            .cyfendo/report.md

      # Publish quick audit summary directly into the GitHub Actions run summary
      - name: Publish PR Step Summary
        if: always()
        run: |
          if [ -f .cyfendo/report.md ]; then
            echo "## Cyfendo Security Gate Summary" >> $GITHUB_STEP_SUMMARY
            cat .cyfendo/report.md >> $GITHUB_STEP_SUMMARY
          fi

3 Enforce Status Checks with GitHub Branch Protection Rules

To prevent pull requests with unpatched critical or high vulnerabilities from being merged into production, enforce Cyfendo as a required status check on your protected branches:

Step-by-Step GitHub Branch Protection Setup

  1. Open your repository on github.com and click the Settings tab.
  2. In the left sidebar under Code and automation, click Branches (or Rules → Rulesets).
  3. Click Add branch protection rule (or edit your existing rule for main).
  4. Under Branch name pattern, enter main (or your production branch name).
  5. Check "Require a pull request before merging".
  6. Check "Require status checks to pass before merging".
  7. In the status checks search box, search for and select Cyfendo Private Security Gate (or the job name specified in your YAML).
  8. Check "Require branches to be up to date before merging" to guarantee tests run against the latest target commit.
  9. Click Save changes / Create.

What Developers See on GitHub.com:

Pull Request #42: Refactor user authentication routes
feature/auth-routes → main
Cyfendo Private Security Gate — Failed Completed in 48s • Details

Found 1 High Severity Flaw (CWE-89 SQL Injection in services/auth.py:48). Gate threshold is --fail-on=high.

Unit Tests & Linting Passed in 1m 12s • Details

All 42 test suites passed successfully.

4 Developer Review & 1-Click Patch Remediation

Cyfendo turns security reviews into standard code review workflows. Developers can inspect findings directly in the pull request diff and apply generated patches in seconds:

Inline PR Code Annotations

Because findings are uploaded in standard SARIF 2.1.0 format, GitHub automatically renders alerts directly on the PR’s Files changed view. Each annotation displays the exact vulnerable code line, taint path from untrusted input to sink, CWE definition, and remediation advice.

Applying Downloaded Patches

Every PR scan automatically archives autonomous unified diff patches under the GitHub Actions Artifacts panel. Developers can download cyfendo-remediation-patches.zip and apply fixes locally with one command:

# Apply autonomous patch locally
$ git apply .cyfendo/patches/01_sql_injection.patch

# Commit and push back to the pull request
$ git commit -am "fix(security): apply Cyfendo remediation patch"
$ git push origin feature/auth-routes
Automatic Merge Unblocking

Pushing the remediation commit immediately triggers a new Cyfendo PR scan. When no vulnerabilities remain above your policy threshold, the status check turns green (Cyfendo Private Security Gate — Passed), and GitHub Branch Protection automatically enables the Merge pull request button.

Teams & Business Workspaces

Multi-seat organization workspaces, granular 3-tier Role-Based Access Control (RBAC), multi-account linking, pooled team quota, and automated member onboarding.

1. Account Types & Architecture

Cyfendo separates personal development from organizational team collaboration:

Developer Account (Personal Workspace)

Tailored for solo developers, founders, and security consultants. Bound to an individual identity with personal billing plans (Free up to 10K LOC, Starter, Growth, or Scale) and private repositories.

Business Account (Organization Workspace)

Designed for engineering teams and enterprises. Features an organization-named workspace (e.g. Acme Cybersecurity Inc.), pooled Protected LOC capacity and monthly scan quotas shared across all team members, centralized invoicing, and multi-seat management.

One Identity → Multiple Workspaces

A single login (email/password or Google Workspace SSO) can link to a personal developer workspace and multiple business organizations simultaneously. Switch between workspaces on the fly via the top navigation dropdown in the Web UI or via cyfendo workspace switch in the CLI.

2. Role-Based Access Control (RBAC) Matrix

Each member of a Business workspace is assigned one of three canonical roles to enforce least-privilege security:

Cyfendo Business Workspace Role-Based Access Control (RBAC) Permissions Matrix
Capability / Action Workspace Owner Run & View (Engineer) View-Only (Auditor)
Run Security Scans (Web UI & CLI) ✔ Allowed ✔ Allowed ✖ Blocked (403)
Create / Bind Protected Projects ✔ Allowed ✔ Allowed ✖ Blocked
View Vulnerabilities & AI Patches ✔ Full ✔ Full ✔ Read-Only
Export SARIF, PDF & Compliance Reports ✔ Allowed ✔ Allowed ✔ Allowed
Invite & Manage Team Members ✔ Exclusive ✖ No Access ✖ No Access
Manage Billing, Invoices & Plan Upgrades ✔ Exclusive ✖ No Access ✖ No Access
Delete Projects / Workspace ✔ Exclusive ✖ No Access ✖ No Access

3. Team Management & Secure Invitations

Workspace Owners manage collaborators through the dedicated Team Dashboard (/team):

Tokenized Email Invitations

Owners invite teammates by specifying their email address and assigned role (Run & View or View-Only). Cyfendo issues a cryptographically secure tokenized link valid for 7 days.

Frictionless Onboarding

If the invitee already has a Cyfendo account, opening the link immediately attaches the organization to their identity. If they are new to Cyfendo, they complete a streamlined one-step activation (/auth/activate/<token>) without entering credit card details.

Strict Data Isolation & Instant Offboarding

Company repositories, source snapshots, scan telemetry, and remediation patches belong strictly to the Organization Workspace. When an employee is removed, their access to all corporate assets is revoked instantaneously, while their personal developer workspace remains completely intact.

4. Multi-Workspace CLI & CI/CD Context

Developers authenticate once with their personal API key and can direct scans into any accessible workspace:

# View all accessible personal & business workspaces:
$ cyfendo workspaces

# Switch local CLI default workspace context:
$ cyfendo workspace switch ws_acme_corp_8f3a

# Scan directly within an organization context without changing default:
$ cyfendo scan . --workspace ws_acme_corp_8f3a --generate-patch

# Configure CI/CD runners (GitHub Actions / GitLab CI) to use organization quota:
$ export CYFENDO_WORKSPACE_ID=ws_acme_corp_8f3a
$ cyfendo scan . --generate-patch

Protected LOC & Quota Accounting

Understand how Lines of Code are counted, cached, and billed under the Cyfendo Protected LOC model.

Source Code Lines Only

Cyfendo only meters executable source code lines. Blank lines, comment blocks, third-party vendor directories (e.g. node_modules/, vendor/, venv/), minified bundles, and compiled binaries are automatically filtered and never charged.

Zero Double-Billing for Rescans

Within a billing cycle, rescanning an existing Protected Project reuses your registered LOC capacity. If you rescan the same 10,000 LOC codebase 50 times in CI/CD, you consume exactly 10,000 Protected LOC, not 500,000.

Incremental AST Cache

When you push commits or scan feature branches, Cyfendo’s distributed cache instantly identifies unchanged files via cryptographic AST hashes, ensuring sub-second response times and immediate exploit validation.

Complete CLI Command Reference

Quick cheat sheet of all available commands and flags.

Comprehensive list of Cyfendo CLI commands, flags, descriptions, and examples
Command / Flag Description Example
cyfendo login Authenticates CLI and stores credentials in ~/.cyfendo/config.json. cyfendo login --key cy_live_...
cyfendo whoami Displays active user account, role, organization, and quota usage. cyfendo whoami
cyfendo status Checks Protected LOC balance, plan limit, and grace period status. cyfendo status
cyfendo projects Lists active protected projects in your workspace with LOC counts. cyfendo projects
cyfendo scan <path> Packages directory, uploads to Cyfendo cloud sandbox, and streams live audit telemetry. cyfendo scan .
cyfendo scan --private <path> Cyfendo Private Scan: 100% local execution with zero source code or finding egress. Uses your own LLM keys or local models. cyfendo scan --private .
--provider <name> Specifies AI provider for Cyfendo Private Scan: openai, anthropic, gemini, vertex, azure, or ollama. --provider openai
--model <name> Specifies target LLM model (e.g. gpt-4o, gpt-4o-mini, claude-3-7-sonnet-latest, gemini-3.6-flash, gemini-3.7-flash, deepseek-r1:32b). --model gpt-4o
--llm-key <key> Direct API key for chosen LLM provider (or export via OPENAI_API_KEY, ANTHROPIC_API_KEY, etc.). --llm-key sk-proj-...
--endpoint <url> Custom OpenAI-compatible base URL for corporate proxies, vLLM, or self-hosted Ollama. --endpoint http://localhost:11434/v1
--thinking <level> Sets reasoning effort level for thinking-capable models (off / none, low, medium, high). --thinking high
--directive <text> Developer steering directive to focus vulnerability research on specific areas. --directive "Focus on BOLA & auth"
cyfendo config Inspects or configures persistent CLI defaults (--set-provider, --set-model, --set-thinking, --set-llm-key, --set-endpoint). cyfendo config --set-provider openai
cyfendo workspaces Lists all accessible personal and business workspaces with account types, roles, and status. cyfendo workspaces
cyfendo workspace switch <id> Switches the local default active workspace context in ~/.cyfendo/config.json. cyfendo workspace switch ws_acme_corp
--workspace, -w <id> Global CLI flag to execute any command within a specific organization workspace context. cyfendo scan . -w ws_acme_corp
CYFENDO_WORKSPACE_ID Environment variable specifying target workspace context (recommended for CI/CD runners). CYFENDO_WORKSPACE_ID=ws_...
--project, -p Binds scan run to an existing Protected Project name or ID. --project "backend-api"
--dedup-scope <scope> Sets vulnerability deduplication scope: root_cause (default), file (per-file isolation), or none (raw traces). --dedup-scope=file
--benchmark-mode Runs in benchmark evaluation mode (overrides --dedup-scope=file and disables patch generation). --benchmark-mode
--generate-patch Synthesizes and sandbox-verifies AI remediation patches during scan. --generate-patch
--no-patch Explicitly skips remediation patch generation (default fast PoC mode). --no-patch
--patch-bundle <path> Exports aggregated unified remediation diff bundle file. --patch-bundle fixes.patch
--fail-on <level> Exits with code 1 if findings at or above threshold exist (critical, high, medium, low). --fail-on=high
--output, -o <path> Custom destination path for export JSON report (defaults to report.json). --output results.json
--sarif <path> Exports findings in OASIS SARIF 2.1.0 JSON format for GitHub / IDE integration. --sarif=results.sarif
--clean Clears all cached analysis stage checkpoints and forces a fresh scan from scratch. --clean
--no-interactive Disables animated spinners and progress bars for clean CI/CD log output. --no-interactive
-v, --verbose Enables verbose diagnostic traces and model communication logs. cyfendo scan --private -v .
cyfendo patches [id] Lists and exports all individual vulnerability .patch diffs. cyfendo patches
cyfendo patch <target> Inspects (--show) or applies (--apply) a vulnerability patch to local files. cyfendo patch 01_sql --show
cyfendo logout Clears stored credentials from ~/.cyfendo/config.json. cyfendo logout

Language & Framework Coverage Matrix

Authoritative breakdown of parsing depth, cross-file taint analysis, framework recognition, sandbox PoC validation, and empirical benchmark coverage.

Language Basic Scanning Cross-File Analysis Sandbox Validation Patch Generation Frameworks & Benchmark Status
Python
.py, .pyw
Supported (AST syntax & taint sink detection) Full cross-file & inter-module call graph Supported (ephemeral sandbox with python3 runtime) Full review-ready patch generation included
Django, Flask, FastAPI, Tornado, Standard Library
Production
Java
.java
Supported (AST syntax & taint sink detection) Class hierarchy & cross-package method invocation analysis Supported (ephemeral sandbox with javac / java toolchains) Full review-ready patch generation included
Spring Boot, Jakarta EE, Servlet API
Production
JavaScript / TypeScript
.js, .jsx, .mjs, .cjs, .ts, .tsx
Supported (AST syntax & taint sink detection) ES module imports, CommonJS require, and route graph tracing Supported (ephemeral sandbox with node & tsx/ts-node) Full review-ready patch generation included
Node.js, Express, Next.js, Fastify, React
Internal synthetic test suites (standardized public suite pending)
Production
Go
.go
Supported (AST syntax & taint sink detection) Package-level call graphs and cross-file method invocations Supported (ephemeral sandbox with go toolchain) Full review-ready patch generation included
Standard Library (net/http), Gin, Echo, Fiber
Internal synthetic test suites (standardized public suite pending)
Production
C / C++
.c, .h, .cpp, .cc, .cxx, .hpp, .hh
Supported (Lexical boundary & buffer sink detection) Header and translation unit reference indexing Supported (ephemeral sandbox with gcc / clang compilers) Full review-ready patch generation included
POSIX standard APIs, socket APIs, memory buffer handling
Internal CWE-focused test suites
Production
Rust
.rs
Supported (AST syntax & unsafe block detection) Crate-level module indexing and unsafe block tracing Supported (ephemeral sandbox with rustc / cargo) Full review-ready patch generation included
Actix-web, Axum, Standard Library
Internal synthetic test suites
Production
PHP
.php, .phtml
Supported (Symbol & sink extraction) File inclusion and global function definition indexing Supported (ephemeral sandbox with php CLI) Full review-ready patch generation included
Vanilla PHP, Laravel, Symfony routes
Internal CWE-focused test suites
Production
Ruby
.rb
Supported (Symbol & method extraction) Module and require statement indexing Supported (ephemeral sandbox with ruby runtime) Full review-ready patch generation included
Ruby on Rails, Sinatra
Internal CWE-focused test suites
Production
Shell / Bash
.sh, .bash, .zsh
Supported (Command & argument parsing) Sourced script analysis Supported (ephemeral sandbox with bash/sh) Full review-ready patch generation included
POSIX Shell, Bash scripting
Internal command injection test cases
Production
Kotlin / Android
.kt, .kts, .dex, .apk
Supported (.kt source & Dalvik .dex/.apk) Supported (JVM call graph & decompiled bytecode) Supported via Gradle/JVM execution & Dalvik bytecode decompilation Full review-ready patch generation included (AST-verified)
Android SDK, Ktor, Spring Boot (Kotlin), Gradle KTS
Internal Android CWE test suites (validated in E2E Case 13)
Production
C#, Swift, Scala
.cs, .swift, .scala
Supported (Syntax pattern & sink detection) In active engineering development (roadmap) Not enabled in default sandbox (no dotnet/swift/sbt in worker) Roadmap / Limited
ASP.NET Core, Swift standard library, sbt
None currently published
Beta / Roadmap

Coverage Notes: 1. Basic Scanning: Lexical and AST syntax inspection for immediate flaw patterns.
2. Cross-File Analysis: Interprocedural call-graph tracing and inter-module taint propagation across full repositories.
3. Sandbox Validation: Ephemeral Docker container execution verifying exploit reachability under real runtime environments.
4. Patch Generation: Dual-Oracle validated code patches delivered as review-ready diffs.
5. Beta / Roadmap: Parsing and basic syntactic rule checks available; cross-file taint and automated sandboxing are in active engineering.

Deployment Modes & Data Custody Architecture

Comprehensive comparison of source code custody, network boundaries, AI provider integrations, and retention policies.

Security Dimension Mode 1: Managed Cloud Mode 2: Private Scan (External AI) Mode 3: Private Scan (Local Models)
Execution Location Google Cloud & AWS RAM containers Customer workstation, VM, or CI runner Customer workstation, VM, or on-prem hardware
Where Source Code Goes Uploaded via TLS 1.3 to ephemeral RAM containers Zero source code or files sent to Cyfendo Zero source code or files sent to Cyfendo
Where Code Snippets Go Analyzed in ephemeral RAM container; destroyed immediately Candidate vulnerability snippets sent to customer's AI provider (OpenAI, Anthropic, Gemini) 100% inside perimeter (routed strictly to localhost Ollama/vLLM)
Where Telemetry Goes Scan metadata, finding titles, CWEs saved in workspace Aggregate LOC count & scan timestamp sent to Cyfendo for token verification Aggregate LOC count & scan timestamp sent to Cyfendo for token verification
External AI Provider Cyfendo-managed enterprise inference Customer's chosen API (OpenAI, Anthropic, Gemini) None (Ollama, vLLM, self-hosted models)
Data Egress Classification Cloud RAM processing with ephemeral destruction Egress to customer's AI provider API + quota telemetry to Cyfendo Strict Zero Egress (100% inside customer perimeter)
Governing Retention Policy Cyfendo ephemeral RAM policy; destroyed upon scan completion Governed entirely by customer's agreement & retention terms with AI provider Customer's internal machine/hardware policy; zero cloud retention
Model Training Policy Never used to train foundation models Governed by customer's agreement with their chosen AI provider Zero data shared with any third party
Offline / Air-Gapped Operation No (requires internet connection to Cyfendo cloud) No (requires internet connection to external AI provider & Cyfendo token verification) Supported (fully offline or air-gapped on local hardware)
CLI Command cyfendo scan [PATH] cyfendo scan --private . cyfendo scan --private --provider ollama .
Customer Controls Workspace management, scan schedule, role RBAC Customer controls API keys, provider, and model Customer controls hardware, network, and model weights

Certifications & Trust Disclosures

  • Cloud Infrastructure: Cyfendo cloud services run on Google Cloud Platform and AWS data center facilities holding independent SOC 2 Type II, ISO 27001, and FedRAMP certifications.
  • Platform Security Posture: Cyfendo's platform architecture, internal development lifecycles, and access policies are engineered in strict alignment with SOC 2 Type II and ISO 27001 control frameworks. Cyfendo has not yet completed its own independent corporate audit.
  • Assessment Reports Disclaimer: Cyfendo scan reports and certificates document automated static and sandbox analysis results at the time of evaluation. They reflect empirical test results and do not constitute independent regulatory certification, OWASP endorsement, or an absolute guarantee that an application is vulnerability-free.