Developer Reference Guide: Running & Managing Audits
Explore four ways to run autonomous vulnerability audits with Cyfendo: direct Web Folder Uploads, continuous Git Repositories, lightweight Cloud-Synchronized CLI, and the 100% Cyfendo Private Scan (Zero Source Code Egress).
Four Ways to Run Vulnerability Audits
Choose the workflow that best fits your security posture, data custody requirements, and development lifecycle.
Web UI Folder Drag & Drop
Fastest for ad-hoc audits. Drag any local project folder directly into your browser. In-browser AST filtering computes Protected LOC in milliseconds without sending binaries or dependencies.
Git Repository Integration
Ideal for automated branch tracking. Link your GitHub, GitLab, or Bitbucket repository URL. Cyfendo automatically identifies branch and commit SHAs to deliver incremental diff audits.
Lightweight Cloud CLI (cyfendo scan .)
Standard cloud-synchronized scanning for terminal users and CI/CD pipelines. Packages
code locally, uploads to ephemeral cloud sandboxes, streams live telemetry, and exports unified
.patch diffs.
Cyfendo Private Scan
(cyfendo scan --private .)
Zero
Egress
100% Local Machine • Zero Source Code Egress. Executes entire multi-agent security pipeline on your local hardware using your own LLM API keys (OpenAI, Anthropic, Gemini, Vertex, Azure) or air-gapped local models (Ollama/vLLM). Code, ASTs, finding proofs, and patches never leave your machine.
Method 1: Web UI Folder Upload
Run ad-hoc security reviews directly from your browser with zero local software requirements.
Open Dashboard & Click "Start New Scan"
Navigate to /dashboard and click the Start New Scan button. Ensure the Upload Folder tab is selected.
Select or Drag Your Local Project Folder
Select your local project root. Cyfendo’s in-browser scanner automatically applies exclusion rules:
- Respects custom
.gitignoreand.cyfendoignorefiles. - Automatically ignores
node_modules/,vendor/,.git/,dist/,build/, virtual environments (venv/), and binary assets. - Computes precise Protected LOC and displays an instant quota check before uploading.
Watch Live Multi-Agent Telemetry
Once submitted, live Server-Sent Events (SSE) stream the real-time execution across distributed analysis stages: AST Parsing → Taint Propagation → Ephemeral Sandbox PoC Verification → AI Remediation Patch Synthesis.
Review in the Interactive Vulnerability IDE
Inspect findings categorized by CWE and CVSS scores. View line-level taint vectors,
run sandbox exploit proofs-of-concept, and download synthesized unified .patch diffs or
SARIF reports.
Method 2: Git Repository Integration & Automated Scheduling
Connect remote Git repositories for continuous branch monitoring, monorepo subdirectory scoping, and automated periodic security audits.
Select "Git Repository" in Scan Modal
In the Start New Scan modal on your Dashboard, switch to the
Git Repository tab. Provide your repository URL (e.g.
https://github.com/org/repo.git) and specify the branch to inspect (e.g. main,
develop, or release/v2).
Monorepo Subdirectory Scoping (Optional)
If your repository contains multiple microservices or packages, specify a relative
path in Subdirectory (Optional) (e.g., apps/api or
packages/backend). Cyfendo packages and audits only source files inside that subpath,
preventing unnecessary LOC consumption from unrelated projects.
Private Repository Authentication
For private repositories, provide a Personal Access Token (PAT) with read-only
repository permissions (e.g. GitHub fine-grained PAT with Contents: Read-only, GitLab
Project Access Token, or Bitbucket App Password). Tokens are encrypted at rest with AES-256
(Fernet), decrypted in-memory only during ephemeral sandbox fetches, and never stored in
plaintext.
Incremental Continuity & Churn Tracking
Cyfendo links each repository to an active Protected Project. When rescanning code, Cyfendo evaluates semantic AST continuity against previous snapshots—charging your quota only for newly added or modified lines of code.
Automated Periodic Scanning & Smart Change Detection
Keep your production code continuously protected without manual intervention. Cyfendo allows you to attach an automated periodic scanning schedule to any connected Git project directly from your dashboard.
Automated Notifications & Alerts
When a scheduled scan finishes, Cyfendo dispatches instant alerts across multiple channels:
- In-App Notification Center: Real-time unread badge and dropdown with direct links to view finding triage and patches.
- Email Notification Delivery: Branded security report sent
from
noreply@cyfendo.comdetailing total findings, severity breakdown (Critical, High, Medium, Low), risk score, and patch synthesis status. - Automatic Safety States: If monthly scan quota is reached,
the schedule automatically
pauses (
paused_quota) without dropping your project configuration. If Git credentials expire, an alert prompts you to update your access token (paused_auth_error).
Git Credential Management & Per-Project Isolation
To follow the principle of least privilege, Personal Access Tokens (PATs) can be strictly scoped to a
specific project (project_id). This guarantees that repository-level
fine-grained tokens (e.g., GitHub Fine-Grained PATs) will never bleed into or trigger scans on other
repositories in your workspace.
$ curl -X POST https://cyfendo.com/api/v1/integrations/git/credentials \
-H "Authorization: Bearer cy_live_..." \
-H "Content-Type: application/json" \
-d '{"project_id": "<PROJECT_ID>", "name": "Repo Scoped Token", "token": "github_pat_...", "provider": "github"}'
REST API Scheduling Automation
You can configure or trigger schedules programmatically using Cyfendo's authenticated REST API:
$ curl -X POST https://cyfendo.com/api/v1/projects/<PROJECT_ID>/schedule \
-H "Authorization: Bearer cy_live_..." \
-H "Content-Type: application/json" \
-d '{"frequency": "daily", "git_branch": "main", "git_subdir": "apps/api", "only_scan_on_changes": true, "generate_patches": true}'
Method 3: Cyfendo Local CLI Scanner
Zero-dependency, high-speed CLI scanner designed for developer terminals, headless SSH servers, and CI/CD pipelines.
1. Installation
Choose your preferred installation method below:
$ pip install --upgrade cyfendo
2. Authentication
Generate an API Key from Top-Right User Menu → Developer & CLI Access and authenticate your CLI:
# Option A: Interactive login command
$ cyfendo login --key cy_live_xxxxxxxxxxxxxxxxxxxxxxxx
# Option B: Set as environment variable
$ export CYFENDO_API_KEY=cy_live_xxxxxxxxxxxxxxxxxxxxxxxx
3. Running Scans on Cyfendo Server
When running standard scans without the --private flag, your codebase is uploaded and analyzed on
the Cyfendo Server (Cloud or on-premises). Analysis, sandbox verification, and patch synthesis execute
remotely on the server fleet—no local commercial model keys or GPU dependencies required.
# 1. Standard fast PoC scan on Cyfendo server:
$ cyfendo scan .
# 2. Server-side scan with automated AI remediation patch generation (no --private flag needed):
$ cyfendo scan . --generate-patch
# 3. Server scan with patch generation, custom bundle export, and SARIF report:
$ cyfendo scan . \
--generate-patch \
--patch-bundle fixes.patch \
--sarif cyfendo-results.sarif
# 4. Target a specific existing project in your workspace:
$ cyfendo scan /path/to/source --project "payment-gateway" --generate-patch
# 5. Connect to a custom or self-hosted Cyfendo server endpoint:
$ cyfendo scan --server https://cyfendo.internal:5001 . --generate-patch
# 6. CI/CD or headless execution with auto-confirm:
$ cyfendo scan . --generate-patch --yes --no-interactive
4. Multi-Account & Organization Workspaces
If your account is linked to an organization or multiple business accounts, your single API key grants access to all of them. You can switch active workspace contexts locally or specify target workspaces on the fly:
# 1. List all accessible personal and business workspaces:
$ cyfendo workspaces
# 2. Switch default active workspace (persisted to ~/.cyfendo/config.json):
$ cyfendo workspace switch ws_acme_corp_8f3a
# 3. Execute a scan under a specific organization without switching default:
$ cyfendo scan . --workspace ws_acme_corp_8f3a --generate-patch
# 4. In CI/CD runners, set CYFENDO_WORKSPACE_ID to attribute scans to your organization:
$ export CYFENDO_WORKSPACE_ID=ws_acme_corp_8f3a
$ cyfendo scan . --generate-patch
Method 4: Cyfendo Private Scan
100% Local Machine • Zero Source Code EgressExecute autonomous multi-agent security audits directly on your local workstation or private runner using your own LLM provider keys or self-hosted models, with complete data sovereignty.
Cyfendo Private Scan is engineered for defense, healthcare, fintech, and enterprise teams with stringent zero-trust data custody requirements:
.cyfendo/
.patch diffs are stored exclusively in your
local workspace.Step-by-Step Customer Instructions
Install or Update the Cyfendo CLI
Install the official Cyfendo Python package (requires Python 3.9+) or use the standalone curl script:
$ pip install --upgrade cyfendo
Authenticate Your Cyfendo Workspace
Generate a Cyfendo API key from User Menu → Developer & CLI Access and authenticate your local machine. This verifies your plan entitlements and Protected LOC balance:
$ cyfendo login --key cy_live_xxxxxxxxxxxxxxxxxxxxxxxx
# Verify workspace balance & active plan:
$ cyfendo status
Select Your Model Provider & Set Credentials
Export your AI provider API key as an environment variable, or supply it directly via
the --llm-key flag at runtime:
# For OpenAI:
$ export OPENAI_API_KEY="sk-proj-xxxxxxxxxxxxxxxxxxxxxxxx"
# For Anthropic Claude:
$ export ANTHROPIC_API_KEY="sk-ant-xxxxxxxxxxxxxxxxxxxxxxxx"
# For Google Gemini / Vertex AI:
$ export GEMINI_API_KEY="AIzaSyxxxxxxxxxxxxxxxxxxxx"
# Or for GCP Vertex: export GCP_PROJECT="my-enterprise-project"
# For Azure OpenAI:
$ export AZURE_OPENAI_ENDPOINT="https://my-resource.openai.azure.com/"
$ export AZURE_OPENAI_KEY="xxxxxxxxxxxxxxxxxxxxxxxx"
$ export AZURE_OPENAI_DEPLOYMENT="gpt-4o"
Configure Persistent Defaults (Optional)
Save your preferred provider and model defaults in
~/.cyfendo/config.json so you never have to pass flags on subsequent scans:
$ cyfendo config --set-provider openai
$ cyfendo config --set-model gpt-4o
$ cyfendo config --set-llm-key sk-proj-xxxxxxxxxxxxxxxxxxxxxxxx
Execute the Cyfendo Private Scan
Run cyfendo scan --private . on your target directory. Add
--generate-patch to synthesize unified remediation diffs:
# 1. Run local scan with OpenAI GPT-4o and patch generation:
$ cyfendo scan --private \
--provider openai \
--model gpt-4o \
--generate-patch \
.
# 2. Run with Anthropic Claude 3.7 Sonnet and extended reasoning:
$ cyfendo scan --private \
--provider anthropic \
--model claude-3-7-sonnet-latest \
--thinking high \
--generate-patch \
.
# 3. Add custom steering directive to guide deep vulnerability search:
$ cyfendo scan --private \
--provider openai \
--model gpt-4o \
--directive "Focus audit on authentication bypass, BOLA, and SSRF" \
.
Review Findings & Apply Patches Locally
All artifacts are saved to .cyfendo/ in your project root. Inspect
reports in your terminal and apply patches with a single command:
# List all generated patches:
$ cyfendo patches
# View colorized diff for a specific finding:
$ cyfendo patch fnd_388b --show
# Apply patch directly to source code via git apply:
$ cyfendo patch fnd_388b --apply
# Read full Markdown audit report:
$ cat .cyfendo/report.md
Private Scan Provider Setup & Credentials Guide
Comprehensive setup guide for enterprise AI providers, cloud platforms, and 100% air-gapped self-hosted models.
OpenAI (GPT-4o, GPT-4.5, O3-Mini, O1)
--provider openai
Supports all official OpenAI chat and reasoning models. Also supports custom OpenAI-compatible proxy
gateways via --endpoint or OPENAI_BASE_URL.
export OPENAI_API_KEY="sk-proj-..."
$ cyfendo scan --private --provider openai --model gpt-4o --generate-patch .
# With custom OpenAI-compatible endpoint (e.g. corporate proxy / LiteLLM):
$ cyfendo scan --private --provider openai --endpoint "https://ai-proxy.corp.internal/v1" --model gpt-4o .
Anthropic Claude (Claude 3.7 Sonnet, Claude 3.5 Sonnet)
--provider anthropic
Leverages Claude's superior code comprehension and extended thinking capabilities. Use
--thinking high for maximum depth during deep taint propagation and patch repair.
export ANTHROPIC_API_KEY="sk-ant-..."
$ cyfendo scan --private \
--provider anthropic \
--model claude-3-7-sonnet-latest \
--thinking high \
--generate-patch \
.
Google Gemini & GCP Vertex AI
--provider gemini / vertexUse the standard Gemini Developer API with an API key, or leverage GCP Vertex AI using enterprise Application Default Credentials (ADC) within your Google Cloud project boundary.
# Option A: Gemini Developer API Key
export GEMINI_API_KEY="AIzaSy..."
$ cyfendo scan --private --provider gemini --model gemini-3.7-flash --generate-patch .
# Option B: GCP Vertex AI with Enterprise ADC
$ gcloud auth application-default login
export GCP_PROJECT="my-enterprise-gcp-project"
export VERTEX_AI_LOCATION="us-central1"
$ cyfendo scan --private --provider vertex --model gemini-3.7-flash .
Microsoft Azure OpenAI Service
--provider azureConnect to your private Microsoft Azure OpenAI resource with dedicated network security, HIPAA/SOC-2 compliance, and enterprise data boundaries.
export AZURE_OPENAI_ENDPOINT="https://my-resource.openai.azure.com/"
export AZURE_OPENAI_KEY="xxxxxxxxxxxxxxxxxxxxxxxx"
export AZURE_OPENAI_DEPLOYMENT="my-gpt4o-deployment"
$ cyfendo scan --private --provider azure --generate-patch .
100% Air-Gapped & On-Premise Models (Ollama, vLLM, Local)
--provider ollamaRun audits in isolated air-gapped environments or restricted defense facilities. By pairing Cyfendo with a local inference engine (such as Ollama or vLLM), zero network packets leave your machine or private LAN for model inference.
# 1. Pull open-weights reasoning model in Ollama:
$ ollama pull deepseek-r1:32b
# (or: ollama pull qwen2.5-coder:32b / llama3.3:70b)
# 2. Execute 100% local, air-gapped scan (default endpoint http://localhost:11434/v1):
$ cyfendo scan --private \
--provider ollama \
--model deepseek-r1:32b \
--generate-patch \
.
# 3. For custom internal vLLM cluster:
$ cyfendo scan --private \
--provider ollama \
--endpoint "http://vllm-cluster.internal:8000/v1" \
--model deepseek-ai/DeepSeek-R1 \
.
Scan Settings & Advanced Options
Customize finding deduplication scopes, AI remediation synthesis, and benchmark evaluation modes across Web UI and CLI.
Deduplication Scopes (--dedup-scope)
Controls how raw taint traces and candidate findings across call graphs, AST scopes, and source files are clustered into consolidated security alerts:
root_cause(Default): Universal multi-factor AST clustering across functions and routes. Consolidates redundant alerts into single root-cause findings for developer triage.file(Per-File Isolation): Prevents findings in separate files from merging. Crucial for synthetic test suites and granular file-by-file audits.none(Raw Traces): Disables deduplication clustering entirely. Outputs every verified candidate finding trace directly without merging.
Fast PoC Mode vs. AI Remediation Patches (--generate-patch)
By default, Cyfendo runs in Fast PoC Mode—executing full AST taint propagation and gVisor sandbox exploit verification in seconds without blocking on AI patch synthesis.
To generate surgical fix diffs during the scan, enable the
toggle in the Web UI or pass --generate-patch in the CLI. You can also generate dual-oracle
verified patches on-demand directly inside the Vulnerability IDE for any individual finding.
Benchmark Evaluation Mode (--benchmark-mode)
Designed for automated evaluation benchmarks (such as OWASP Benchmark, Juliet, and
custom synthetic suites). When enabled, Cyfendo automatically enforces Per-File
Isolation (--dedup-scope=file) to avoid cross-file merging and disables initial
patch generation for maximum evaluation throughput and exact groundtruth comparison.
# 1. Run in Benchmark Mode (per-file isolation, fast PoC)
$ cyfendo scan . --benchmark-mode
# 2. Run with per-file deduplication and full AI patch generation
$ cyfendo scan . --dedup-scope=file --generate-patch
# 3. Run raw audit without any deduplication
$ cyfendo scan . --dedup-scope=none
Inspecting & Applying Remediation Patches
Cyfendo generates review-ready unified diffs for verified vulnerabilities. Inspect and apply them manually or via CLI.
# 1. List and export individual .patch files into .cyfendo/patches/
$ cyfendo patches
# 2. Inspect colorized diff for a specific finding in the terminal
$ cyfendo patch fnd_91a4 --show
# 3. Apply patch directly to local source code using git apply
$ cyfendo patch fnd_91a4 --apply
# 4. Or apply manually with standard git tooling
$ git apply .cyfendo/patches/01_sql_injection.patch
# 5. Generate patches via Cyfendo server during scan & export unified bundle (no --private flag):
$ cyfendo scan . --generate-patch --patch-bundle fixes.patch
$ git apply fixes.patch
CI/CD Quality Gates & GitHub Pull Request Protection
Enforce autonomous shift-left security directly on GitHub pull requests. Automatically scan code diffs, publish inline SARIF annotations on the PR Files changed tab, block merging on high/critical vulnerabilities via GitHub Branch Protection, and generate 1-click patch artifacts for instant developer remediation.
Triggers on pull request opened, synchronize (new
commits), and reopened. Smart concurrency cancellation aborts superseded runs to save runner
minutes and AI tokens.
Analyzes PR changes directly on your CI runner VM using Cyfendo Private Scan (or via managed Cloud Workers). Full source code remains on your runner; only code snippets route to your configured AI provider (or stay 100% local if using local models), and minimal LOC telemetry goes to Cyfendo for token verification.
Exports standard SARIF 2.1.0 findings and uploads via
upload-sarif@v4. Security alerts, CWE links, and taint traces display directly on the PR's
Files changed tab.
The --fail-on=high policy exits with code 1 if
vulnerabilities exceed your severity threshold, causing GitHub Branch Protection to disable the
Merge pull request button.
1 Configure Repository Secrets on GitHub.com
In your GitHub repository, navigate to Settings → Secrets and variables → Actions → New repository secret. (For organization-wide or monorepo setups, configure under Organization Settings → Secrets and variables → Actions).
CYFENDO_API_KEYYour workspace token from the Cyfendo Dashboard. Validates Protected LOC quota & entitlement limits without transmitting code.
GEMINI_API_KEY / OPENAI_API_KEYYour commercial AI model key (Gemini, OpenAI, Anthropic, or Azure). Passed directly to the CLI on the runner with zero intermediate proxies.
GITHUB_TOKEN (Automatic)Built-in GitHub Actions token. Automatically provided by GitHub runner; used
by upload-sarif@v4 to publish inline PR annotations.
CYFENDO_WORKSPACE_ID (Optional)Target Business workspace ID (e.g. ws_acme_corp_8f3a). Scopes CI/CD repository scans to your company's pooled organization quota.
2
Add the Pull Request Workflow File (.github/workflows/cyfendo-pr.yml)
Executes the autonomous vulnerability audit locally on your GitHub Actions runner VM using Cyfendo Private Scan. Full source code files never leave the runner to Cyfendo cloud servers; only minimal code snippets route directly to your approved AI provider, and aggregate LOC telemetry goes to Cyfendo for token verification. (For complete zero-egress offline operation, configure Mode 3 with local models).
name: Cyfendo PR Security Gate
on:
pull_request:
branches: [main, master]
types: [opened, synchronize, reopened]
# Cancel in-progress runs when new commits are pushed to the same pull request
concurrency:
group: cyfendo-${{ github.workflow }}-${{ github.head_ref || github.ref }}
cancel-in-progress: true
jobs:
security-gate:
name: Cyfendo Private Security Gate
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write # Required to publish SARIF alerts to GitHub PR Files Changed tab
actions: read # Required for upload-sarif to query workflow run metadata
steps:
- name: Checkout Pull Request Code
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install Cyfendo CLI & Model Provider SDK
run: |
pip install --upgrade cyfendo google-genai
# For OpenAI: pip install --upgrade cyfendo openai
# For Anthropic: pip install --upgrade cyfendo anthropic
- name: Run Cyfendo Private Scan
env:
CYFENDO_API_KEY: ${{ secrets.CYFENDO_API_KEY }}
GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}
# OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
# ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
run: >
cyfendo scan .
--private
--provider gemini
--model gemini-2.5-flash
--fail-on high
--sarif cyfendo-results.sarif
--no-interactive
# Publish standard SARIF 2.1.0 findings to PR "Files changed" annotations
- name: Upload SARIF to GitHub PR & Security Tab
uses: github/codeql-action/upload-sarif@v4
if: always() && hashFiles('cyfendo-results.sarif') != '' # Upload whenever SARIF exists (even if quality gate fails)
continue-on-error: true # Resilient if GitHub Advanced Security is disabled on private repos
with:
sarif_file: cyfendo-results.sarif
# Archive generated remediation patches so developers can download & apply them
- name: Archive Remediation Patches & SARIF
uses: actions/upload-artifact@v4
if: always()
continue-on-error: true
with:
name: cyfendo-remediation-patches
path: |
cyfendo-results.sarif
.cyfendo/patches/
.cyfendo/report.md
# Publish quick audit summary directly into the GitHub Actions run summary
- name: Publish PR Step Summary
if: always()
run: |
if [ -f .cyfendo/report.md ]; then
echo "## Cyfendo Security Gate Summary" >> $GITHUB_STEP_SUMMARY
cat .cyfendo/report.md >> $GITHUB_STEP_SUMMARY
fi
Dispatches pull request code to Cyfendo's managed cloud server or self-hosted cluster (without the --private flag). Multi-agent AST analysis, sandbox exploit verification, and automated AI patch synthesis execute remotely on the server fleet. Requires only your CYFENDO_API_KEY—no commercial LLM provider keys (OpenAI, Gemini, Anthropic) or model SDKs are required on your GitHub runner.
name: Cyfendo Cloud PR Security Gate
on:
pull_request:
branches: [main, master]
types: [opened, synchronize, reopened]
concurrency:
group: cyfendo-cloud-${{ github.workflow }}-${{ github.head_ref || github.ref }}
cancel-in-progress: true
jobs:
security-gate:
name: Cyfendo Server Security Gate
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write # Required to publish SARIF alerts to GitHub PR Files Changed tab
actions: read # Required for upload-sarif to query workflow run metadata
steps:
- name: Checkout Pull Request Code
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.11'
# Install Cyfendo CLI (no model provider SDKs needed for server scans)
- name: Install Cyfendo CLI
run: pip install --upgrade cyfendo
# Run scan on Cyfendo server with automated AI patch synthesis (no --private flag)
- name: Run Cyfendo Server PR Scan & Patch Generation
env:
CYFENDO_API_KEY: ${{ secrets.CYFENDO_API_KEY }}
# Optional: set custom endpoint if using self-hosted Cyfendo server
# CYFENDO_SERVER_URL: ${{ vars.CYFENDO_SERVER_URL }}
run: >
cyfendo scan .
--fail-on high
--generate-patch
--sarif cyfendo-results.sarif
--no-interactive
--yes
# Publish standard SARIF 2.1.0 findings to PR "Files changed" annotations
- name: Upload SARIF to GitHub PR & Security Tab
uses: github/codeql-action/upload-sarif@v4
if: always() && hashFiles('cyfendo-results.sarif') != '' # Upload whenever SARIF exists
continue-on-error: true # Resilient if GitHub Advanced Security is disabled on private repos
with:
sarif_file: cyfendo-results.sarif
# Archive generated remediation patches and audit reports
- name: Archive Remediation Patches & SARIF
uses: actions/upload-artifact@v4
if: always()
continue-on-error: true
with:
name: cyfendo-remediation-patches
path: |
cyfendo-results.sarif
.cyfendo/patches/
.cyfendo/report.md
# Publish quick audit summary directly into the GitHub Actions run summary
- name: Publish PR Step Summary
if: always()
run: |
if [ -f .cyfendo/report.md ]; then
echo "## Cyfendo Security Gate Summary" >> $GITHUB_STEP_SUMMARY
cat .cyfendo/report.md >> $GITHUB_STEP_SUMMARY
fi
- Zero LLM Setup: Runs with standard
cyfendo scan .(no--private). Cyfendo server orchestrates the multi-agent reasoning, requiring onlyCYFENDO_API_KEY. - Automated AI Patch Synthesis:
--generate-patchinstructs the server to generate and sandbox-verify unified.patchdiffs, downloaded into.cyfendo/patches/and archived as workflow artifacts. - Headless Auto-Confirmation:
--yesautomatically confirms the cloud upload prompt in non-interactive CI environments. - Private Repositories & GitHub Advanced Security:
Uploading SARIF alerts to GitHub PR annotations via
upload-sarifis free for public repositories, but requires GitHub Advanced Security (GHAS) on private repos. Settingcontinue-on-error: trueprevents build failures if GHAS is inactive, while Publish PR Step Summary ensures full audit visibility directly on the PR Actions run summary without requiring GHAS.
High-velocity engineering teams can optimize pull request check times down to sub-60 seconds by leveraging fast heuristic analysis profiles and path scoping in monorepo architectures.
# 1. Monorepo scoping: Trigger only when files in the service directory change
on:
pull_request:
paths:
- 'services/auth-api/**'
- 'packages/shared-security/**'
jobs:
fast-gate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# 2. Scope the scan target to only the modified microservice
- name: Fast Monorepo PR Scan
env:
CYFENDO_API_KEY: ${{ secrets.CYFENDO_API_KEY }}
GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}
run: >
cyfendo scan ./services/auth-api
--private
--provider gemini
--model gemini-2.5-flash
--fail-on high
--sarif cyfendo-results.sarif
--no-interactive
Runs Cyfendo Private Scan inside your GitLab CI/CD runners on merge request pipelines. Findings are packaged into standard SARIF artifacts and natively ingested into GitLab’s Security & Compliance vulnerability dashboard.
stages:
- security
cyfendo-private-gate:
stage: security
image: python:3.11-slim
rules:
- if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
- if: '$CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH'
variables:
CYFENDO_API_KEY: "$CYFENDO_API_KEY"
GEMINI_API_KEY: "$GEMINI_API_KEY"
before_script:
- pip install --no-cache-dir cyfendo google-genai
script:
- >
cyfendo scan .
--private
--provider gemini
--model gemini-2.5-flash
--fail-on high
--sarif cyfendo-results.sarif
--no-interactive
artifacts:
when: always
reports:
sast: cyfendo-results.sarif
paths:
- cyfendo-results.sarif
- .cyfendo/report.md
3 Enforce Status Checks with GitHub Branch Protection Rules
To prevent pull requests with unpatched critical or high vulnerabilities from being merged into production, enforce Cyfendo as a required status check on your protected branches:
Step-by-Step GitHub Branch Protection Setup
- Open your repository on github.com and click the Settings tab.
- In the left sidebar under Code and automation, click Branches (or Rules → Rulesets).
- Click Add branch protection rule (or edit your existing rule for
main). - Under Branch name pattern, enter
main(or your production branch name). - Check "Require a pull request before merging".
- Check "Require status checks to pass before merging".
- In the status checks search box, search for and select
Cyfendo Private Security Gate(or the job name specified in your YAML). - Check "Require branches to be up to date before merging" to guarantee tests run against the latest target commit.
- Click Save changes / Create.
What Developers See on GitHub.com:
Found 1 High Severity Flaw (CWE-89 SQL Injection in
services/auth.py:48). Gate threshold is --fail-on=high.
All 42 test suites passed successfully.
4 Developer Review & 1-Click Patch Remediation
Cyfendo turns security reviews into standard code review workflows. Developers can inspect findings directly in the pull request diff and apply generated patches in seconds:
Because findings are uploaded in standard SARIF 2.1.0 format, GitHub automatically renders alerts directly on the PR’s Files changed view. Each annotation displays the exact vulnerable code line, taint path from untrusted input to sink, CWE definition, and remediation advice.
Every PR scan automatically archives autonomous unified diff patches under the GitHub Actions
Artifacts panel. Developers can download cyfendo-remediation-patches.zip
and apply fixes locally with one command:
# Apply autonomous patch locally
$ git apply .cyfendo/patches/01_sql_injection.patch
# Commit and push back to the pull request
$ git commit -am "fix(security): apply Cyfendo remediation patch"
$ git push origin feature/auth-routes
Pushing the remediation commit immediately triggers a new Cyfendo PR scan. When no vulnerabilities
remain above your policy threshold, the status check turns green
(Cyfendo Private Security Gate — Passed), and GitHub Branch Protection automatically
enables the Merge pull request button.
Teams & Business Workspaces
Multi-seat organization workspaces, granular 3-tier Role-Based Access Control (RBAC), multi-account linking, pooled team quota, and automated member onboarding.
1. Account Types & Architecture
Cyfendo separates personal development from organizational team collaboration:
Developer Account (Personal Workspace)
Tailored for solo developers, founders, and security consultants. Bound to an individual identity with personal billing plans (Free up to 10K LOC, Starter, Growth, or Scale) and private repositories.
Business Account (Organization Workspace)
Designed for engineering teams and enterprises. Features an organization-named workspace (e.g. Acme Cybersecurity Inc.), pooled Protected LOC capacity and monthly scan quotas shared across all team members, centralized invoicing, and multi-seat management.
One Identity → Multiple Workspaces
A single login (email/password or Google Workspace SSO) can link to a personal developer workspace and multiple business organizations simultaneously. Switch between workspaces on the fly via the top navigation dropdown in the Web UI or via cyfendo workspace switch in the CLI.
2. Role-Based Access Control (RBAC) Matrix
Each member of a Business workspace is assigned one of three canonical roles to enforce least-privilege security:
| Capability / Action | Workspace Owner | Run & View (Engineer) | View-Only (Auditor) |
|---|---|---|---|
| Run Security Scans (Web UI & CLI) | ✔ Allowed | ✔ Allowed | ✖ Blocked (403) |
| Create / Bind Protected Projects | ✔ Allowed | ✔ Allowed | ✖ Blocked |
| View Vulnerabilities & AI Patches | ✔ Full | ✔ Full | ✔ Read-Only |
| Export SARIF, PDF & Compliance Reports | ✔ Allowed | ✔ Allowed | ✔ Allowed |
| Invite & Manage Team Members | ✔ Exclusive | ✖ No Access | ✖ No Access |
| Manage Billing, Invoices & Plan Upgrades | ✔ Exclusive | ✖ No Access | ✖ No Access |
| Delete Projects / Workspace | ✔ Exclusive | ✖ No Access | ✖ No Access |
3. Team Management & Secure Invitations
Workspace Owners manage collaborators through the dedicated Team Dashboard (/team):
Tokenized Email Invitations
Owners invite teammates by specifying their email address and assigned role (Run & View or View-Only). Cyfendo issues a cryptographically secure tokenized link valid for 7 days.
Frictionless Onboarding
If the invitee already has a Cyfendo account, opening the link immediately attaches the organization to their identity. If they are new to Cyfendo, they complete a streamlined one-step activation (/auth/activate/<token>) without entering credit card details.
Strict Data Isolation & Instant Offboarding
Company repositories, source snapshots, scan telemetry, and remediation patches belong strictly to the Organization Workspace. When an employee is removed, their access to all corporate assets is revoked instantaneously, while their personal developer workspace remains completely intact.
4. Multi-Workspace CLI & CI/CD Context
Developers authenticate once with their personal API key and can direct scans into any accessible workspace:
# View all accessible personal & business workspaces:
$ cyfendo workspaces
# Switch local CLI default workspace context:
$ cyfendo workspace switch ws_acme_corp_8f3a
# Scan directly within an organization context without changing default:
$ cyfendo scan . --workspace ws_acme_corp_8f3a --generate-patch
# Configure CI/CD runners (GitHub Actions / GitLab CI) to use organization quota:
$ export CYFENDO_WORKSPACE_ID=ws_acme_corp_8f3a
$ cyfendo scan . --generate-patch
Protected LOC & Quota Accounting
Understand how Lines of Code are counted, cached, and billed under the Cyfendo Protected LOC model.
Source Code Lines Only
Cyfendo only meters executable source code lines. Blank lines, comment blocks,
third-party vendor directories (e.g. node_modules/, vendor/,
venv/), minified bundles, and compiled binaries are automatically filtered and never
charged.
Zero Double-Billing for Rescans
Within a billing cycle, rescanning an existing Protected Project reuses your registered LOC capacity. If you rescan the same 10,000 LOC codebase 50 times in CI/CD, you consume exactly 10,000 Protected LOC, not 500,000.
Incremental AST Cache
When you push commits or scan feature branches, Cyfendo’s distributed cache instantly identifies unchanged files via cryptographic AST hashes, ensuring sub-second response times and immediate exploit validation.
Complete CLI Command Reference
Quick cheat sheet of all available commands and flags.
| Command / Flag | Description | Example |
|---|---|---|
cyfendo login |
Authenticates CLI and stores credentials in ~/.cyfendo/config.json. |
cyfendo login --key cy_live_... |
cyfendo whoami |
Displays active user account, role, organization, and quota usage. | cyfendo whoami |
cyfendo status |
Checks Protected LOC balance, plan limit, and grace period status. | cyfendo status |
cyfendo projects |
Lists active protected projects in your workspace with LOC counts. | cyfendo projects |
cyfendo scan <path> |
Packages directory, uploads to Cyfendo cloud sandbox, and streams live audit telemetry. | cyfendo scan . |
cyfendo scan --private <path> |
Cyfendo Private Scan: 100% local execution with zero source code or finding egress. Uses your own LLM keys or local models. | cyfendo scan --private . |
--provider <name> |
Specifies AI provider for Cyfendo Private Scan: openai, anthropic,
gemini, vertex, azure, or ollama.
|
--provider openai |
--model <name> |
Specifies target LLM model (e.g. gpt-4o, gpt-4o-mini,
claude-3-7-sonnet-latest, gemini-3.6-flash, gemini-3.7-flash,
deepseek-r1:32b).
|
--model gpt-4o |
--llm-key <key> |
Direct API key for chosen LLM provider (or export via OPENAI_API_KEY,
ANTHROPIC_API_KEY, etc.).
|
--llm-key sk-proj-... |
--endpoint <url> |
Custom OpenAI-compatible base URL for corporate proxies, vLLM, or self-hosted Ollama. | --endpoint http://localhost:11434/v1 |
--thinking <level> |
Sets reasoning effort level for thinking-capable models (off / none,
low, medium, high).
|
--thinking high |
--directive <text> |
Developer steering directive to focus vulnerability research on specific areas. | --directive "Focus on BOLA & auth" |
cyfendo config |
Inspects or configures persistent CLI defaults (--set-provider,
--set-model, --set-thinking, --set-llm-key,
--set-endpoint).
|
cyfendo config --set-provider openai |
cyfendo workspaces |
Lists all accessible personal and business workspaces with account types, roles, and status. | cyfendo workspaces |
cyfendo workspace switch <id> |
Switches the local default active workspace context in ~/.cyfendo/config.json. |
cyfendo workspace switch ws_acme_corp |
--workspace, -w <id> |
Global CLI flag to execute any command within a specific organization workspace context. | cyfendo scan . -w ws_acme_corp |
CYFENDO_WORKSPACE_ID |
Environment variable specifying target workspace context (recommended for CI/CD runners). | CYFENDO_WORKSPACE_ID=ws_... |
--project, -p |
Binds scan run to an existing Protected Project name or ID. | --project "backend-api" |
--dedup-scope <scope> |
Sets vulnerability deduplication scope: root_cause (default), file
(per-file isolation), or none (raw traces). |
--dedup-scope=file |
--benchmark-mode |
Runs in benchmark evaluation mode (overrides --dedup-scope=file and disables patch
generation). |
--benchmark-mode |
--generate-patch |
Synthesizes and sandbox-verifies AI remediation patches during scan. | --generate-patch |
--no-patch |
Explicitly skips remediation patch generation (default fast PoC mode). | --no-patch |
--patch-bundle <path> |
Exports aggregated unified remediation diff bundle file. | --patch-bundle fixes.patch |
--fail-on <level> |
Exits with code 1 if findings at or above threshold exist (critical, high,
medium, low).
|
--fail-on=high |
--output, -o <path> |
Custom destination path for export JSON report (defaults to report.json). |
--output results.json |
--sarif <path> |
Exports findings in OASIS SARIF 2.1.0 JSON format for GitHub / IDE integration. | --sarif=results.sarif |
--clean |
Clears all cached analysis stage checkpoints and forces a fresh scan from scratch. | --clean |
--no-interactive |
Disables animated spinners and progress bars for clean CI/CD log output. | --no-interactive |
-v, --verbose |
Enables verbose diagnostic traces and model communication logs. | cyfendo scan --private -v . |
cyfendo patches [id] |
Lists and exports all individual vulnerability .patch diffs. |
cyfendo patches |
cyfendo patch <target> |
Inspects (--show) or applies (--apply) a vulnerability patch to local
files. |
cyfendo patch 01_sql --show |
cyfendo logout |
Clears stored credentials from ~/.cyfendo/config.json. |
cyfendo logout |
Language & Framework Coverage Matrix
Authoritative breakdown of parsing depth, cross-file taint analysis, framework recognition, sandbox PoC validation, and empirical benchmark coverage.
| Language | Basic Scanning | Cross-File Analysis | Sandbox Validation | Patch Generation | Frameworks & Benchmark | Status |
|---|---|---|---|---|---|---|
|
Python
.py, .pyw
|
Supported (AST syntax & taint sink detection) | Full cross-file & inter-module call graph | Supported (ephemeral sandbox with python3 runtime) | Full review-ready patch generation included |
Django, Flask, FastAPI, Tornado, Standard Library
|
Production |
|
Java
.java
|
Supported (AST syntax & taint sink detection) | Class hierarchy & cross-package method invocation analysis | Supported (ephemeral sandbox with javac / java toolchains) | Full review-ready patch generation included |
Spring Boot, Jakarta EE, Servlet API
|
Production |
|
JavaScript / TypeScript
.js, .jsx, .mjs, .cjs, .ts, .tsx
|
Supported (AST syntax & taint sink detection) | ES module imports, CommonJS require, and route graph tracing | Supported (ephemeral sandbox with node & tsx/ts-node) | Full review-ready patch generation included |
Node.js, Express, Next.js, Fastify, React
Internal synthetic test suites (standardized public suite pending)
|
Production |
|
Go
.go
|
Supported (AST syntax & taint sink detection) | Package-level call graphs and cross-file method invocations | Supported (ephemeral sandbox with go toolchain) | Full review-ready patch generation included |
Standard Library (net/http), Gin, Echo, Fiber
Internal synthetic test suites (standardized public suite pending)
|
Production |
|
C / C++
.c, .h, .cpp, .cc, .cxx, .hpp, .hh
|
Supported (Lexical boundary & buffer sink detection) | Header and translation unit reference indexing | Supported (ephemeral sandbox with gcc / clang compilers) | Full review-ready patch generation included |
POSIX standard APIs, socket APIs, memory buffer handling
Internal CWE-focused test suites
|
Production |
|
Rust
.rs
|
Supported (AST syntax & unsafe block detection) | Crate-level module indexing and unsafe block tracing | Supported (ephemeral sandbox with rustc / cargo) | Full review-ready patch generation included |
Actix-web, Axum, Standard Library
Internal synthetic test suites
|
Production |
|
PHP
.php, .phtml
|
Supported (Symbol & sink extraction) | File inclusion and global function definition indexing | Supported (ephemeral sandbox with php CLI) | Full review-ready patch generation included |
Vanilla PHP, Laravel, Symfony routes
Internal CWE-focused test suites
|
Production |
|
Ruby
.rb
|
Supported (Symbol & method extraction) | Module and require statement indexing | Supported (ephemeral sandbox with ruby runtime) | Full review-ready patch generation included |
Ruby on Rails, Sinatra
Internal CWE-focused test suites
|
Production |
|
Shell / Bash
.sh, .bash, .zsh
|
Supported (Command & argument parsing) | Sourced script analysis | Supported (ephemeral sandbox with bash/sh) | Full review-ready patch generation included |
POSIX Shell, Bash scripting
Internal command injection test cases
|
Production |
|
Kotlin / Android
.kt, .kts, .dex, .apk
|
Supported (.kt source & Dalvik .dex/.apk) | Supported (JVM call graph & decompiled bytecode) | Supported via Gradle/JVM execution & Dalvik bytecode decompilation | Full review-ready patch generation included (AST-verified) |
Android SDK, Ktor, Spring Boot (Kotlin), Gradle KTS
Internal Android CWE test suites (validated in E2E Case 13)
|
Production |
|
C#, Swift, Scala
.cs, .swift, .scala
|
Supported (Syntax pattern & sink detection) | In active engineering development (roadmap) | Not enabled in default sandbox (no dotnet/swift/sbt in worker) | Roadmap / Limited |
ASP.NET Core, Swift standard library, sbt
None currently published
|
Beta / Roadmap |
Coverage Notes:
1. Basic Scanning: Lexical and AST syntax inspection for immediate flaw patterns.
2. Cross-File Analysis: Interprocedural call-graph tracing and inter-module taint propagation across full repositories.
3. Sandbox Validation: Ephemeral Docker container execution verifying exploit reachability under real runtime environments.
4. Patch Generation: Dual-Oracle validated code patches delivered as review-ready diffs.
5. Beta / Roadmap: Parsing and basic syntactic rule checks available; cross-file taint and automated sandboxing are in active engineering.
Deployment Modes & Data Custody Architecture
Comprehensive comparison of source code custody, network boundaries, AI provider integrations, and retention policies.
| Security Dimension | Mode 1: Managed Cloud | Mode 2: Private Scan (External AI) | Mode 3: Private Scan (Local Models) |
|---|---|---|---|
| Execution Location | Google Cloud & AWS RAM containers | Customer workstation, VM, or CI runner | Customer workstation, VM, or on-prem hardware |
| Where Source Code Goes | Uploaded via TLS 1.3 to ephemeral RAM containers | Zero source code or files sent to Cyfendo | Zero source code or files sent to Cyfendo |
| Where Code Snippets Go | Analyzed in ephemeral RAM container; destroyed immediately | Candidate vulnerability snippets sent to customer's AI provider (OpenAI, Anthropic, Gemini) | 100% inside perimeter (routed strictly to localhost Ollama/vLLM) |
| Where Telemetry Goes | Scan metadata, finding titles, CWEs saved in workspace | Aggregate LOC count & scan timestamp sent to Cyfendo for token verification | Aggregate LOC count & scan timestamp sent to Cyfendo for token verification |
| External AI Provider | Cyfendo-managed enterprise inference | Customer's chosen API (OpenAI, Anthropic, Gemini) | None (Ollama, vLLM, self-hosted models) |
| Data Egress Classification | Cloud RAM processing with ephemeral destruction | Egress to customer's AI provider API + quota telemetry to Cyfendo | Strict Zero Egress (100% inside customer perimeter) |
| Governing Retention Policy | Cyfendo ephemeral RAM policy; destroyed upon scan completion | Governed entirely by customer's agreement & retention terms with AI provider | Customer's internal machine/hardware policy; zero cloud retention |
| Model Training Policy | Never used to train foundation models | Governed by customer's agreement with their chosen AI provider | Zero data shared with any third party |
| Offline / Air-Gapped Operation | No (requires internet connection to Cyfendo cloud) | No (requires internet connection to external AI provider & Cyfendo token verification) | Supported (fully offline or air-gapped on local hardware) |
| CLI Command | cyfendo scan [PATH] |
cyfendo scan --private . |
cyfendo scan --private --provider ollama . |
| Customer Controls | Workspace management, scan schedule, role RBAC | Customer controls API keys, provider, and model | Customer controls hardware, network, and model weights |
Certifications & Trust Disclosures
- Cloud Infrastructure: Cyfendo cloud services run on Google Cloud Platform and AWS data center facilities holding independent SOC 2 Type II, ISO 27001, and FedRAMP certifications.
- Platform Security Posture: Cyfendo's platform architecture, internal development lifecycles, and access policies are engineered in strict alignment with SOC 2 Type II and ISO 27001 control frameworks. Cyfendo has not yet completed its own independent corporate audit.
- Assessment Reports Disclaimer: Cyfendo scan reports and certificates document automated static and sandbox analysis results at the time of evaluation. They reflect empirical test results and do not constitute independent regulatory certification, OWASP endorsement, or an absolute guarantee that an application is vulnerability-free.