Frequently Asked Questions
Direct, technical, and transparent answers to questions about autonomous scanning, code privacy, AI zero-training, accuracy, remediation patches, and protected LOC pricing.
About Cyfendo
Core positioning, vision, and how Cyfendo compares to traditional static analysis tooling.
Cyfendo is an autonomous application-security platform that continuously scans source code for vulnerabilities and generates review-ready fixes. It is designed to reduce the manual AppSec work required from security and engineering teams by automating detection, triage, and patch synthesis.
Cyfendo supports both cloud-managed audits and Cyfendo Private Scan mode—allowing enterprise teams to run 100% of the analysis locally on their own machines with zero source code egress, using their own LLM accounts or air-gapped on-premise models (Ollama/vLLM).
Traditional SAST scanners rely on rigid syntax patterns and require extensive manual rule tuning, resulting in high false-positive rates and alert fatigue. Cyfendo is designed around autonomous execution: it analyzes semantic code context and control-flow reachability to filter out unreachable noise, delivering actionable findings paired with optional, review-ready unified diff patches.
No. Cyfendo automates repetitive AppSec tasks such as routine scanning, initial triage, noise reduction, and remediation drafting. Security leads and engineering teams remain in full control of security architecture, risk policies, and final code approval.
No. Cyfendo works out of the box with zero complex configuration or custom query language requirements. Developers and engineering teams can connect their repositories and start securing code immediately without prior security specialization.
Yes. Cyfendo operates non-intrusively and can be evaluated alongside existing tools such as Snyk, Semgrep, Checkmarx, Veracode, SonarQube, or proprietary internal security tooling without modifying your existing CI/CD setup.
Scanning & Coverage
Code analysis mechanics, vulnerability scopes, supported languages, and scan triggers.
Cyfendo performs deep semantic static analysis and data-flow reachability analysis on application source code and configuration files. It focuses on identifying application-layer weaknesses, insecure API usage, input validation flaws, and cryptographic misconfigurations.
Cyfendo detects a broad spectrum of application-layer vulnerabilities across the OWASP Top 10, the CWE Top 25 Most Dangerous Software Weaknesses, and specialized cloud/mobile security standards. By combining inter-procedural AST taint tracking, data-flow reachability analysis, and dual-oracle sandbox validation, Cyfendo flags high-confidence flaws across six primary vulnerability domains:
-
Injection Flaws & Dynamic Code Execution: SQL Injection (CWE-89, CWE-564, CWE-943 across raw SQL, cursor calls, and NoSQL APIs), OS Command Injection (CWE-78, CWE-77, CWE-88), Dynamic Code Execution & Unsafe Eval (CWE-94, CWE-95, CWE-96), Cross-Site Scripting / XSS (CWE-79, CWE-80, React
dangerouslySetInnerHTML), Server-Side Template Injection / SSTI (CWE-1336 across Jinja2, Mako, Tornado, EJS, Handlebars, Pug, Nunjucks, Velocity), XPath Injection (CWE-643), LDAP Injection (CWE-90), and XML External Entity / XXE (CWE-611, CWE-827). - Filesystem, Upload & Archive Security: Path & Directory Traversal (CWE-22, CWE-23, CWE-36, CWE-73), Insecure Archive Extraction / Zip Slip (CWE-29 via unvalidated archive decompression), and Unrestricted File Uploads (CWE-434).
-
Application Logic & Modern Framework Weaknesses: Server-Side Request Forgery / SSRF (CWE-918), Insecure Deserialization (CWE-502 across Python
pickle/PyYAML, PHPunserialize, JavaObjectInputStream), Prototype Pollution (CWE-1321), Unsafe Mass Assignment & Entity Over-Posting (CWE-915), Cross-Site Request Forgery / CSRF (CWE-352), Open URL Redirection (CWE-601), and Trust Boundary Violations (CWE-501). -
Authentication, Authorization & Secrets Management: Broken Authentication & Missing Authorization (CWE-287, CWE-306, CWE-862, CWE-863 / BOLA / IDOR), Insecure JWT Verification & Signature Flaws (CWE-347, CWE-345 with
nonealgorithm or missing signature checks), Hardcoded Secrets & C2 Bot Tokens (CWE-798), and Insecure Cookie Configurations (CWE-614, CWE-1004). - Cryptography, TLS & Data Protection: Broken Ciphers & Insecure Modes (CWE-327, such as ECB mode, DES, RC4), Static / Hardcoded Cryptographic IVs & Nonce Reuse (CWE-329), Broken/Weak Cryptographic Hashes (CWE-328, CWE-326 with MD5, SHA-1), Insecure Randomness & Weak PRNG (CWE-330, CWE-338), and Insecure TLS / Disabled Certificate Verification (CWE-295).
-
Mobile & Android Bytecode Security (APK / Dalvik): Malicious Dynamic Droppers & Arbitrary Code Loading (CWE-506, CWE-494 via
DexClassLoader/PathClassLoader), Android FileProvider Root Path Exposures (CWE-22), Network Traffic Interception (CWE-250 viaVpnService), and Cleartext Storage of Sensitive Information (CWE-312, CWE-922).
Every confirmed vulnerability is presented in an interactive finding dossier with complete source-to-sink taint traces, CWE definitions, CVSS scoring, and optional review-ready patch diffs.
Cyfendo's coverage matrix defines our single source of truth across 5 operational dimensions and multiple language tiers:
- Production Support (10 Core Language Families): Comprehensive cross-file taint analysis, ephemeral sandbox exploit validation, and review-ready patch generation across Python, Java, JavaScript/TypeScript, Go, C/C++, Rust, PHP, Ruby, Shell/Bash, and Kotlin / Android.
- Beta & Roadmap Support (3 Languages): Early-access parsing and basic vulnerability scanning are available for C#, Swift, and Scala (advanced cross-file taint tracking and autonomous patch synthesis are on the active roadmap).
-
5 Operational Capability Dimensions:
- 1) Basic scanning: AST parsing and single-file lexical pattern matching.
- 2) Production cross-file taint analysis: Whole-codebase inter-procedural data-flow tracking from untrusted inputs to sensitive sinks.
- 3) Ephemeral sandbox exploit validation: Dual-oracle dynamic reachability verification using trigger payloads and benign functional baselines.
- 4) Review-ready patch generation: Contextual unified diffs ready for developer review and merge.
- 5) Beta / roadmap support: Preview syntax analysis and ongoing engine expansion.
Detailed breakdown is documented in our Language Coverage Matrix.
Application penetration testing is currently in private Beta for select businesses only. It is separately scoped and available by arrangement (not included in self-serve plans). Organizations can contact sales to discuss assessment requirements and timeline.
No. Cyfendo works out of the box with built-in semantic models and industry standard vulnerability definitions. You do not need to write custom rules or tune regex filters to get started.
Yes. Cyfendo performs whole-codebase indexing to build comprehensive inter-procedural call graphs and trace data flows across modules. On subsequent pull requests and incremental commits, it performs fast differential analysis on modified paths and their callers.
Yes. Through GitHub App and CI/CD integrations, Cyfendo can trigger differential scans automatically on pull requests and commits, returning inline comments and security status checks before code is merged.
Every Cyfendo plan includes a predictable monthly security scan allowance tailored for CI/CD pipelines (5 scans/month on Free, 10/month on Starter, 30/month on Growth, and 100/month on Scale). Identical re-scans of unchanged snapshots consume 0 scan credits, allowing developers to re-verify status without expending scan credits.
No. Cyfendo analyzes source code directly using Abstract Syntax Trees (AST) and semantic symbol tables without requiring a full build environment, compiled binaries, or container images from the customer.
Accuracy & Findings
Factual metrics, benchmark evaluations, false positive handling, and finding dossiers.
No automated security scanner achieves complete perfection across all arbitrary code patterns. Cyfendo is engineered to combine broad vulnerability detection with high precision by verifying data-flow reachability from untrusted sources to sensitive sinks before reporting an issue.
Yes, false positives are possible with any automated security tool. Cyfendo is designed to minimize them by validating semantic reachability and execution context. Every finding includes complete evidence and trace graphs so developers can quickly evaluate validity.
Yes. Automated security scanning cannot guarantee that every vulnerability or complex business-logic flaw will be detected. Cyfendo should be used as a key component of a comprehensive, defense-in-depth security program alongside secure code review and testing.
Each finding includes the vulnerability type and CWE ID, severity classification, affected file and line numbers, complete source-to-sink data-flow trace, an explanation of exploitability, actionable remediation advice, and a review-ready unified diff patch where applicable.
The OWASP Benchmark is a standardized test suite for measuring vulnerability-detection performance across 2,740 test cases. Cyfendo's published results demonstrate performance on that benchmark and should not be interpreted as a guarantee of equivalent detection rates on every real-world application.
Sensitivity (recall) measures how many known vulnerable benchmark cases Cyfendo correctly identified (1,331 out of 1,415 true vulnerability test cases). It is a measure of vulnerability detection completeness, not precision or overall real-world accuracy.
The Youden Index (J = Sensitivity + Specificity - 1) combines sensitivity and specificity into a single composite measure that penalizes false positives and false negatives equally. A score of 0.90 demonstrates strong discrimination between vulnerable and non-vulnerable code paths.
Yes. We publish our full methodology, testing configurations, and category-by-category score breakdowns in our public OWASP Benchmark White Paper.
Deduplication groups raw vulnerability traces that share the same underlying root cause or execution flow so engineering teams aren't inundated with redundant alerts. Cyfendo supports three configurable deduplication scopes:
- Root Cause (Default): Multi-factor AST call-graph clustering across functions and routes. Consolidates duplicate alerts into single root-cause findings.
- Per-File Isolation (
file): Confines deduplication within individual files. Findings in different files are never merged. - Raw Traces (
none): Disables clustering completely and outputs every verified candidate trace individually.
Benchmark Mode is specifically optimized for running synthetic vulnerability evaluation suites (such as OWASP Benchmark, Juliet Test Suite, SecBench, or internal test suites).
When enabled via the Web UI toggle or the CLI flag (--benchmark-mode), Cyfendo
automatically locks deduplication to Per-File Isolation (to prevent synthetic test
cases in separate files from merging and creating apparent false negatives) and skips initial AI
patch synthesis for maximum evaluation throughput and direct groundtruth comparison.
Patches & Remediation
Fix generation mechanics, developer approval authority, patch formats, and validation.
Cyfendo can generate proposed code changes (remediation patches) for supported findings. Developers remain responsible for reviewing, testing, and accepting those changes before merging.
No. Patch generation is optional. You can use Cyfendo purely for vulnerability detection, triage, and manual remediation guidance.
No. Patch generation is included in all paid plans at no additional charge and can be enabled or disabled whenever you want.
Yes. Some security fixes require coordinated changes across multiple files (such as updating both a database query and its caller), and one generated patch can include all required modifications.
Patches are provided as standard unified diffs (`.patch` format). They can be reviewed visually in the Cyfendo Web IDE, downloaded, or applied locally using standard Git tools (`git apply`).
No. Cyfendo never automatically merges code into your repositories. Developers retain 100% authority and responsibility over all code approvals and merges.
Generated patches undergo syntax parsing and automated re-scanning in an isolated sandbox to confirm that the taint path is broken and the vulnerability is resolved before presenting the fix to developers.
No automated code change should be treated as guaranteed. Cyfendo is designed to generate high-quality, review-ready fixes while keeping developers in control of final testing and merge approval.
Fast PoC Mode (Default): Executes semantic AST parsing, interprocedural taint propagation, and dynamic gVisor sandbox exploit validation without waiting for LLM code synthesis. Scans complete in seconds with verified proofs-of-concept.
AI Remediation Mode: In addition to detection and PoC verification, synthesizes surgical code diffs and verifies them against a dual-oracle sandbox to confirm vulnerability mitigation without regressing unit tests.
Yes. If you run a fast scan (or a benchmark scan where patches were skipped), you can open any individual finding in the Interactive Vulnerability IDE and click "Synthesize Dual-Oracle Patch". Cyfendo will generate, sandbox-verify, and present a surgical unified diff for that specific finding on demand.
Cyfendo Private Scan & Data Sovereignty
Complete autonomy and privacy: run 100% of the vulnerability analysis locally with zero source code egress, using your own commercial LLM keys or air-gapped on-premise models.
For defense, fintech, healthcare, and enterprise teams requiring absolute data sovereignty: run Cyfendo Private Scan 100% locally with Zero Source Code Egress using your own commercial LLM keys or air-gapped on-premise models (Ollama/vLLM).
Cyfendo Private Scan is an enterprise execution mode where the entire autonomous vulnerability audit runs 100% locally on your machine or private CI/CD runners with Zero Source Code Egress.
Instead of routing source code through cloud sandboxes, the Cyfendo CLI executes AST parsing, semantic taint propagation, exploit verification, and patch synthesis directly on your workstation. You provide your own API credentials for leading foundation models (OpenAI, Anthropic Claude, Google Gemini, Azure OpenAI) or connect to self-hosted local models (Ollama, vLLM).
No. Zero source code, AST tokens, call graph data, or vulnerability finding details ever leave your machine to Cyfendo servers.
The entire analysis pipeline runs locally. All finding dossiers, exploit evidence, Markdown reports,
and unified diff patches remain stored strictly on your local disk in ./.cyfendo/. The
only communication with your Cyfendo workspace is an initial entitlement authorization handshake,
aggregate line-of-code usage (to verify plan allowance), and high-level finding counters (e.g. "2
Critical Flaws, Risk Score 8.8") to update your dashboard session and deliver completion alerts.
Cyfendo provides native, plug-and-play support for major commercial AI providers and open-weight architectures:
- OpenAI:
gpt-4o,gpt-4o-mini,gpt-4.5,gpt-5.6-luna,o3-mini,o1, and custom OpenAI-compatible proxy gateways. - Anthropic Claude:
claude-3-7-sonnet-latest,claude-3-5-sonnet, with optional extended thinking levels (--thinking high/medium/low). - Google Gemini & GCP Vertex AI:
gemini-3.7-flash,gemini-3.6-flashvia Gemini API Key or enterprise Google Cloud Vertex AI with Application Default Credentials (ADC). - Microsoft Azure OpenAI: Private Azure OpenAI resource endpoints and enterprise deployments.
- Self-Hosted & Air-Gapped (Ollama / vLLM): Open-weight models like
deepseek-r1:32b,llama3.3:70b,qwen2.5-coder:32b, andmistral-largerunning on local GPUs.
Yes. For defense contractors, financial institutions, and air-gapped secure facilities, you can pair the Cyfendo CLI with a local inference engine like Ollama or vLLM:
cyfendo scan --private --provider ollama --model deepseek-r1:32b --generate-patch .
In this configuration, zero model API calls traverse the public internet; all multi-agent deliberations, taint tracing, and code synthesis execute strictly on your internal GPU hardware.
No. When running Cyfendo Private Scan with commercial providers (OpenAI, Anthropic, Gemini, Azure), you supply your direct enterprise API key. Under commercial API terms, customer inputs and outputs are never retained or used to train or fine-tune public foundation models.
When using self-hosted open models (Ollama/vLLM), inference occurs entirely in-memory on your private infrastructure without external data logging.
All security audit deliverables are saved strictly on your local filesystem in the
.cyfendo/ directory at your project root:
.cyfendo/report.md: Complete human-readable Markdown security audit report..cyfendo/findings.json: Structured machine-readable JSON finding dossiers..cyfendo/report.sarif: OASIS SARIF 2.1.0 report for IDEs and GitHub Security..cyfendo/patches/: Review-ready individual.patchunified diff files.
You can inspect colorized diffs in your terminal with cyfendo patch <id> --show
and apply them directly with cyfendo patch <id> --apply.
Getting started with Cyfendo Private Scan takes less than two minutes:
- Install or Update CLI:
pip install --upgrade cyfendo - Authenticate Workspace:
cyfendo login --key cy_live_... - Configure Provider Credentials:
export OPENAI_API_KEY=sk-...(or Anthropic/Gemini/Azure/Ollama) - Execute Scan:
cyfendo scan --private --provider openai --model gpt-4o --generate-patch . - Inspect & Apply Patches:
cyfendo patchesandcyfendo patch <id> --apply
Detailed documentation and configuration examples for every provider are available in our Developer Reference Guide.
Cyfendo Private Scans use your existing Cyfendo workspace Protected LOC allowance (e.g. Starter 100K LOC, Growth 500K LOC, Scale 2M LOC).
Rescanning an existing protected project consumes 0 extra Protected LOC. Cyfendo does not charge per-scan fees, developer seat licenses, or AI token markups for Private Scan runs—you only pay your regular plan fee, plus your direct compute costs with your chosen LLM provider.
Source Code, Privacy & AI
Complete transparency on proprietary source code handling, zero model training, isolation, and AI security.
Yes. Source-code security analysis requires read access to the code being analyzed. Access is granted through your chosen integration method (GitHub App read-only permissions, web folder upload, or the local CLI).
No permanent repository mirror is retained. For cloud scans, code is cloned into an isolated, ephemeral sandbox for the duration of the scan and immediately destroyed post-analysis. Only scan metadata, vulnerability findings, code snippets directly relevant to findings, and generated patches are stored in your encrypted account database.
Cloud scans are processed in isolated compute sandboxes hosted on secure enterprise infrastructure in the United States. Enterprise customers with data residency or private networking requirements can deploy self-hosted private worker agents inside their own VPC.
No. Customer source code is not used to train Cyfendo or third-party foundation models. We operate under strict Zero Data Retention (ZDR) and enterprise zero-training contractual agreements.
When AI reasoning is utilized during advanced analysis, only specific extracted code contexts and AST snippets relevant to the potential vulnerability are transmitted via enterprise zero-data-retention APIs where provider training is contractually disabled.
No. Cyfendo uses deterministic static AST parsing and control-flow slicing to identify suspect taint paths first. Only the minimal code snippets involved in candidate vulnerability paths are evaluated for triage and fix generation.
Ephemeral scan sandboxes are purged immediately after scan execution. Finding dossiers, security metrics, and generated patches are retained for the lifetime of your account or until you delete the scan or repository.
Yes. You can delete individual scans, repositories, or your entire organization account at any time from your dashboard or by emailing contact@cyfendo.com. Account deletion triggers a permanent purge across all primary databases.
No. Cyfendo employees do not have access to customer source code or finding snippets. In rare technical support situations, access requires explicit, time-bounded customer authorization.
Every scan executes inside a dedicated, single-tenant container with strict filesystem and process boundaries. Database records and finding dossiers are partitioned with organization-level cryptographic keys.
AI reasoning enables Cyfendo to understand complex semantic relationships, evaluate whether security sanitizers are effective in context, explain findings in plain English, and synthesize context-aware remediation diffs.
Yes. AI models can hallucinate or misinterpret code nuances. That is why Cyfendo never relies on raw model outputs alone: it couples AI reasoning with deterministic AST validation, data-flow reachability analysis, and developer review authority.
Repository & Development Workflow
SCM permissions, CI/CD integrations, CLI usage, and branch protection.
You can connect code via our official GitHub App integration, by uploading a ZIP or folder directly
in the web dashboard, or by running the Cyfendo CLI (cyfendo scan .) in your local
terminal or CI pipeline.
Cyfendo adheres to the principle of least privilege. Read-only repository access is sufficient for scanning. Write permissions are requested only if you explicitly enable automated pull-request creation for remediation diffs.
Yes. When configuring the GitHub integration, you can grant access to selected repositories rather than your entire organization.
You can scan GitLab, Bitbucket, Azure DevOps, or local Git repositories using our standalone CLI
(cyfendo scan .) or by uploading project archives through the web dashboard.
Yes. Your existing SCM or CI system checks out the code into a workspace, and the Cyfendo CLI scans the resulting source tree directly.
Yes. The Cyfendo CLI can be integrated into GitHub Actions, GitLab CI, Jenkins, CircleCI, or custom build pipelines to enforce security gates and export SARIF reports.
Yes. Developers can run cyfendo scan . from their terminal to scan local branches and
review findings before pushing code to upstream repositories.
The Cyfendo CLI accepts granular options matching all Web UI configuration controls:
--dedup-scope=root_cause|file|none: Choose between call-graph clustering, per-file isolation, or raw candidate traces.--generate-patch: Enable automated AI remediation patch synthesis during the scan.--no-patch: Explicitly skip patch generation for fast PoC scanning.--benchmark-mode: Run in benchmark evaluation mode (locks deduplication to per-file isolation and skips patch generation).--patch-bundle=<path>: Export all generated fixes into an aggregated unified.patchbundle.
You can attach an automated periodic scanning schedule to any connected Git project directly from the Dashboard (or via REST API). Choose between Daily (Every 24 Hours), Weekly (Every 7 Days), or Monthly (Every 30 Days) frequencies.
When scheduled, Cyfendo runs in the background, fetches new commits, audits code reachability, synthesizes surgical fixes, and delivers completion notifications to your in-app inbox and email address.
When a periodic scan triggers, Cyfendo performs a lightweight, pre-flight check of the remote branch
HEAD commit SHA using git ls-remote before cloning code. If no new commits
have landed since the previous completed scan, the scheduler instantly finishes with status
skipped_unchanged.
0 scan credits are deducted, and no compute or LOC quota is consumed, preserving your full monthly scan budget for genuine codebase changes.
Yes. Cyfendo fully supports monorepo architectures. In both manual and scheduled scans, you can
specify an optional relative subdirectory (e.g. apps/api,
services/billing, or packages/core).
Cyfendo isolates and packages only the files within that subfolder. Your Protected LOC accounting and security vulnerability triage will reflect only that specific service.
Personal Access Tokens for private repositories are encrypted at rest using authenticated AES-256 (Fernet) cryptography.
Tokens are decrypted in-memory strictly during ephemeral sandbox fetch operations, are never written
to disk in plaintext, and are masked in all API responses. All Git subprocesses enforce
-c credential.helper= sandbox isolation so ambient local OS credentials cannot be
accessed.
Yes. Cyfendo strictly isolates Git credentials per project (project_id). When you
configure or update a Git token in your project schedule modal, it is scoped exclusively to that
repository.
This allows you to generate repository-scoped, fine-grained tokens adhering to least privilege. Updating or rotating credentials for one repository will never leak into or trigger scans on other repositories in your workspace.
Scale & Performance
Large repository indexing, scan durations, and differential performance.
Cyfendo is designed to work with substantial production codebases, including multi-million-line repositories, utilizing sub-linear indexing and distributed AST analysis.
Scan duration depends on codebase size, language complexity, and whether differential scanning is enabled. Small-to-medium repos typically complete in under 2 minutes, while large enterprise repositories complete in 5 to 15 minutes during full scheduled audits.
No. On pull requests and incremental commits, Cyfendo performs fast differential analysis on modified files and their dependency call graphs, reserving full-codebase audits for initial onboarding and scheduled runs.
Every Cyfendo plan includes a predictable monthly security scan allowance (5/mo on Free, 10/mo on Starter, 30/mo on Growth, 100/mo on Scale). Re-scanning an unchanged codebase snapshot consumes 0 scan credits.
Cyfendo pricing is predictable and based on active protected codebase size with fixed monthly scan allowances. Re-scans of unchanged snapshots cost 0 extra LOC and 0 scan credits. If you need higher scan volumes or larger codebase capacity, modular add-ons and plan upgrades are available.
Security & Trust
Infrastructure hardening, encryption, sandboxing, and compliance standards.
Cyfendo implements defense-in-depth security: all network communication is encrypted with TLS 1.3, stored data and finding dossiers are encrypted at rest with AES-256, compute workloads operate in isolated ephemeral containers, and access is governed by strict role-based access control.
Standard static analysis does not execute your code. When dynamic Proof-of-Concept (PoC) validation is performed, generated test snippets run exclusively inside hardened, air-gapped ephemeral sandboxes with network access disabled.
Sandbox execution occurs inside ephemeral Linux micro-containers configured with non-root execution, restricted seccomp syscall profiles, strict memory/CPU quotas, and complete network egress isolation.
No. No production-system access is required for normal source-code analysis. Cyfendo operates entirely within your development and CI/CD lifecycle.
Infrastructure: Cyfendo cloud services run on Google Cloud Platform and AWS data center infrastructure that maintains independent SOC 2 Type II, ISO 27001, and FedRAMP certifications.
Security Architecture: Cyfendo's platform architecture, access controls, and software development practices are built in strict alignment with SOC 2 Type II and ISO 27001 control frameworks. Cyfendo has not yet completed its own independent corporate audit. Infrastructure certifications attest to provider facilities, not Cyfendo itself.
Customer Scan Reports: Cyfendo automated assessment reports and certificates reflect testing at the time of evaluation. They do not constitute external regulatory certification, OWASP endorsement, or an absolute guarantee that software is vulnerability-free.
Cyfendo helps engineering teams identify and remediate security vulnerabilities mandated by compliance frameworks such as PCI DSS (Req 6.5), HIPAA Security Rule, and NIST SP 800-53. Using Cyfendo does not automatically certify your application.
Visit our dedicated Privacy Policy & Code Protection Architecture and our RFC 9116 Security Disclosure Specification, or contact contact@cyfendo.com.
Pricing & Billing
Protected LOC pricing architecture, monthly scan allowances, tiers, and code add-ons.
Charging purely per scan creates a perverse incentive: engineering teams scan less frequently to conserve budget, leaving critical vulnerabilities undetected until late in release cycles.
Cyfendo's commercial promise is: Predictable pricing based on the code you protect. By pairing protected codebase capacity with generous monthly scan allowances and 0-credit re-scans for unchanged code, your developers can maintain continuous security coverage without unexpected budget spikes.
Protected LOC is an active standing capacity ceiling (similar to disk storage or server RAM), whereas your Monthly Scan allowance is a consumable budget that replenishes each month:
- Standing Capacity (Protected LOC): As long as a repository is actively protected in Cyfendo, it continuously occupies its LOC against your plan's allowance (e.g. actively protecting an 80K LOC repository on a 100K Starter plan leaves 20K LOC available). You do not get a fresh 100K added to your balance next month to protect more repositories simultaneously.
- Continuous Updates are Free (0 Extra LOC): Updating, modifying, refactoring, and fixing code in your active project consumes 0 extra LOC.
- Replenishing Scan Budget: Your monthly security scan allotment (e.g. 10 scans on Starter, 30 on Growth, 100 on Scale) resets automatically at the start of each 30-day billing cycle.
Deleting a project stops active scanning immediately. To maintain fair monthly capacity limits and prevent deletion-rotation abuse (e.g. deleting repository A to scan repository B on the same monthly quota), capacity is accounted across your monthly quota period.
Your full allowance resets at the start of your next monthly billing cycle. When updating an existing project over time, normal version updates and refactors are tracked as continuous versions of the same project.
Every Cyfendo plan includes a generous monthly scan allowance designed for active continuous security and CI/CD pipelines, combined with unlimited user seats:
- Free Plan: Up to 10K protected LOC, 5 security scans / month (1 protected repository).
- Starter Plan ($99/mo): Up to 100K protected LOC, 10 security scans / month (unlimited repositories).
- Growth Plan ($299/mo): Up to 500K protected LOC, 30 security scans / month (unlimited repositories & priority scan queue).
- Scale Plan ($799/mo): Up to 2M protected LOC, 100 security scans / month (modular add-on expansions available).
Identical Re-scans (0 Scan Credits): Scanning an identical commit or snapshot where no code changed does not consume a scan credit. Scan allowances automatically refresh at the start of each 30-day billing cycle.
Cyfendo uses a Period Peak (High-Water Mark) model per 30-day billing cycle to ensure developers are never penalized for frequent scanning or refactoring:
- Continuous Re-scans & Bugfixes (0 Extra LOC): When you modify, refactor, or fix code in your project and the overall codebase size stays within its current monthly peak, the Delta LOC is 0. Re-scans and automated PR checks cost nothing extra.
- Codebase Growth & Feature Expansion (+Delta LOC): When your project expands in size (e.g. from 10,000 LOC to 13,000 LOC), you are only charged for the net new growth (+3,000 LOC Delta), not the entire 13,000 LOC codebase from scratch.
- Code Reduction / Cleanup (0 Extra LOC): If you delete unused code and your project shrinks from 10,000 LOC to 8,500 LOC, the Delta LOC is 0. The previously committed peak (10,000 LOC) is retained for the current 30-day cycle and resets at your next billing renewal.
- Automated Source Continuity Analysis: Cyfendo deterministically matches version lineage between uploads (handling folder name changes, moved files, and incremental edits). Only completely unrelated codebases (<20% overlap) are treated as new project allocations to prevent slot laundering.
Cyfendo counts only genuine first-party application source code.
- Comments & Blank Lines: Automatically stripped and excluded across all supported languages (Python, Java, JS/TS, Go, C/C++, Rust, etc.).
- Vendored Packages & Dependencies: Directories like
node_modules/,vendor/,third_party/, and lockfiles (package-lock.json,poetry.lock) are completely excluded from Protected LOC calculations. - Build Artifacts & Binaries:
dist/,build/, compiled binaries, images, and fonts are automatically ignored. - Minified & Dense Code: Detected automatically; standard readable code is counted normally, while dense or minified single-line assets utilize an effective density floor to prevent quota distortion.
Cyfendo provides an automatic 14-day grace period whenever active protected code exceeds your plan allowance. During this grace period, ongoing scans and CI/CD pipelines continue uninterrupted so your team's workflow is never blocked during an active sprint.
You can easily upgrade your plan tier or adjust your protected projects directly from your Plan & Billing settings. You are never automatically charged or silently upgraded without explicit confirmation.
Additional 1M LOC capacity units (+$200/month or $2,000/year per 1M LOC and +500 scans/month) are exclusively available as modular capacity expansions on the Scale tier (for codebases exceeding 2M LOC).
For codebases under 2M LOC, upgrading between our standard tiers (Starter at 100K LOC, Growth at 500K LOC, Scale at 2M LOC) provides the lowest cost per line and ensures access to all corresponding platform capabilities.
Enterprise & Support
Custom deployments, SLAs, procurement reviews, support tiers, and vulnerability reporting.
Enterprise is designed for organizations with codebases exceeding 2M LOC, specialized private VPC deployment requirements, SSO/SAML integrations, custom data retention policies, or dedicated contractual SLAs.
Contact us if you have private deployment requirements. We work with qualified Enterprise customers to evaluate self-hosted private worker agent deployments inside AWS, Azure, or GCP VPCs.
Yes. Cyfendo includes built-in Google Workspace Single Sign-On (SSO) and granular Role-Based Access Control (Workspace Owner, Run & View, View-Only) across all Business and Enterprise accounts. Workspace owners can invite collaborators, assign roles, and enforce least-privilege scanning from the centralized Team Dashboard. Dedicated SAML 2.0 / Okta integrations are supported on custom enterprise contracts.
Yes. Enterprise agreements support custom data-retention schedules, zero-storage finding policies, and dedicated audit log exports.
Yes. Enterprise contracts include uptime SLAs (up to 99.9%) and priority technical support response commitments.
Yes. Cyfendo can provide available security documentation and work with qualified customers during vendor and security review.
Developers can flag findings directly in the dashboard as "False Positive" or "Accept Risk" with optional notes. This feedback refines reachability analysis on subsequent scans.
Do not merge it. Developers remain in control. Report the patch through the product or support channel so our engineering team can investigate.
We maintain an RFC 9116 security disclosure policy. Please email vulnerability details to contact@cyfendo.com. Full security contact details are available at /.well-known/security.txt.
Free users have access to technical documentation and standard email support. Paid plans include priority ticketing, and Scale/Enterprise plans include dedicated technical account management and Slack/Teams channels.
Teams & Business Accounts
Multi-seat organizations, Role-Based Access Control (RBAC), multi-account linking, pooled team quota, and CLI workspace switching.
Developer Accounts are tailored for solo developers, open-source maintainers, and security researchers. They provide a personal private workspace with individual billing plans (Free up to 10K LOC, Starter, Growth, or Scale) and a personal CLI API key.
Business Accounts are designed for engineering teams and growing companies. They feature an organization-named workspace (e.g., Acme Cybersecurity Inc.), pooled Protected LOC capacity and monthly scan quotas shared across the entire team, centralized billing with consolidated corporate invoices, multi-seat member management, granular 3-tier RBAC, and secure tokenized team invitations.
Yes! Cyfendo provides true multi-account and multi-workspace linking under a single unified identity. You can authenticate once (using email/password or Google Workspace SSO) and seamlessly access both your personal Developer workspace and any number of company or client Business workspaces.
In the Web Dashboard, you can switch between active workspace contexts instantly using the workspace switcher dropdown in the top navigation bar. In the Cyfendo CLI, you can list all accessible accounts with cyfendo workspaces, switch default context with cyfendo workspace switch <id>, or target an ad-hoc workspace on any command with the global --workspace <id> (or -w <id>) flag.
Cyfendo enforces 3 canonical roles to ensure security and least-privilege governance:
- Workspace Owner: Full workspace authority. Can manage billing and subscriptions, update organization details, invite or remove team members, assign or change member roles, transfer ownership, delete projects, and execute all security scans.
- Run & View (Engineer): Standard engineering workflows. Can run scans via Web UI or CLI, attach protected projects, view vulnerability findings, export SARIF, and download/apply automated AI remediation patches. Cannot manage billing or modify team membership.
- View-Only (Auditor): Read-only governance. Can view scan dashboards, inspect findings, review security scorecards, and export compliance reports. Blocked from initiating scans or consuming organizational quota.
Workspace Owners can invite team members from the centralized Team Dashboard (/team) by providing the teammate's corporate email address and choosing an assigned role (Run & View or View-Only).
Cyfendo automatically generates a secure tokenized invitation link valid for 7 days and sends an invitation email. Existing Cyfendo users join the organization immediately upon opening the link. New colleagues activate their account in a streamlined one-step form with their name and password—no corporate credit cards or payment details required.
In a Business workspace, all active team members draw from the organization's pooled standing Protected LOC capacity and pooled monthly scan allowance. Individual team members never need their own subscriptions or payment methods to audit company code.
The /team and /billing dashboards display real-time visibility into organization-wide capacity utilization, active project breakdown, and remaining monthly scan budgets. Additional capacity units (+100K LOC and +10 scans per unit) can be added by the workspace Owner at any time.
A developer's single API key automatically grants access to all their linked workspaces. The CLI provides full multi-workspace ergonomics:
cyfendo workspaces: Lists all linked personal and business workspaces with their IDs, organization names, account types, and your active role.cyfendo workspace switch <id>: Sets your default active workspace context in~/.cyfendo/config.json.cyfendo scan . --workspace <id>(or-w <id>): Executes a scan within a specific organization workspace context on the fly.- CI/CD Pipelines: Set the
CYFENDO_WORKSPACE_IDenvironment variable in your GitHub Actions or GitLab CI secrets to automatically attribute scans to the organization's quota.
Cyfendo guarantees strict data isolation between workspaces. All protected projects, source snapshots, scan records, vulnerability findings, and remediation patches belong strictly to the Organization Workspace, not to the individual team member who initiated them.
When an employee is removed from the organization via the Team Dashboard (/team), their access to all company repositories, findings, and billing details is revoked immediately. However, their personal Developer account and personal projects remain completely intact and unaffected.
Yes! Any developer can upgrade their workspace to a Business account directly from the Billing & Plans page (/billing) or their profile.
During upgrade, you can enter your organization or company name, choose your pooled capacity tier, and immediately invite colleagues to your new organization workspace. Your existing projects and scan histories can be seamlessly retained under your organization.
Put Your Application Security on Autopilot
Start with up to 10K protected LOC and 5 scans per month. No credit card required.