# Cyfendo — Comprehensive Platform Architecture & Reference Manual > Version: 2026.10 | Updated: October 2026 | Authority: Cyfendo Inc. (https://cyfendo.com) ## Table of Contents 1. Company & Mission 2. Core Architecture: Detection, Verification, Remediation 3. Empirical Benchmark Results & Limitations 4. Language & Framework Coverage Matrix 5. Deployment Modes & Data Custody Architecture 6. Subscription Plans, Allowances & Pricing 7. Product Availability: Released Products vs. Upcoming Services 8. Developer CLI Reference & CI/CD Integrations 9. Contact & Official References --- ## 1. Company & Mission - **Company**: Cyfendo Inc. - **Website**: https://cyfendo.com - **Founder & CEO**: Bryan Vuong — former engineering leader at Google and Meta. - **Founder Profile**: https://cyfendo.com/about/bryan-vuong (also known as Ba-Quy Vuong; PhD from UW–Madison) - **Selected Patents**: Inventor on granted US patents in search query understanding, attribute extraction, and data organization (assigned to Wal-Mart Stores, Inc.). Verified details at https://cyfendo.com/about/bryan-vuong#patents. - **Headquarters**: 530 Showers Dr, Suite 236, Mountain View, CA 94040. - **Mission**: Bringing autonomous, high-signal application security and review-ready remediation patches to every software development team without requiring a dedicated internal security department. - **Contact**: contact@cyfendo.com --- ## 2. Core Architecture: Detection, Verification, Remediation Cyfendo operates across three coordinated stages designed to treat potential security findings as hypotheses requiring empirical validation: ### Stage 1: Abstract Syntax Tree (AST) Taint Analysis - Parses application source code into high-fidelity Abstract Syntax Trees across supported languages. - Builds cross-function and cross-file control-flow and data-flow symbol graphs. - Traces untrusted sources (HTTP parameters, request headers, request bodies, message queues, environment variables) to dangerous sinks (SQL execution, OS shell commands, file path operations, SSRF endpoints, template evaluation). ### Stage 2: Dual-Oracle Ephemeral Sandbox (PoC Exploit Verifier) - Where container toolchains and runtimes are present, Cyfendo executes automated verification in an isolated, read-only ephemeral sandbox: 1. **Oracle 1 (Vulnerability Trigger)**: Executes a synthesized minimal Proof of Concept (PoC) trigger payload to test whether the dangerous sink is reachable and exploitable. 2. **Oracle 2 (Functional Baseline)**: Executes benign inputs to confirm expected standard application functionality. - Findings where upstream sanitization or framework defenses prevent reachability are flagged as hardened/unexploitable rather than noisy alerts. ### Stage 3: Surgical Patch Synthesizer & Regression Verification - Synthesizes targeted, minimal diffs (e.g. parameterized queries, safe subprocess argument arrays, strict regex allowlists, path canonicalization). - Re-tests the proposed patch in the sandbox: 1. The trigger payload must be blocked or neutralized. 2. The functional baseline and test suite must continue to execute without regressions. - Developer Approval: Proposed patches are delivered as review-ready diffs or Git branches. Developers retain full control over review and merging. --- ## 3. Empirical Benchmark Results & Limitations ### OWASP Benchmark Evaluation (Evaluated September 2026) Cyfendo was evaluated against the standardized OWASP Benchmark suites across 3,970 total test cases: #### OWASP Benchmark Java v1.2 (2,740 Tests) - Vulnerable cases: 1,415 | Safe controls: 1,325 - True Positives (TP): 1,331 - False Positives (FP): 50 - False Negatives (FN): 84 - True Negatives (TN): 1,275 - Recall (Sensitivity): 94.06% (1,331 / 1,415) - Precision: 96.38% (1,331 / 1,381) - False Positive Rate (FPR): 3.77% (50 / 1,325) - Specificity (TNR): 96.23% (1,275 / 1,325) - Youden's Index (J): 90.29% (Recall − FPR) - Balanced F1 Score: 95.21% #### OWASP Benchmark Python v0.1 (1,230 Tests) - Vulnerable cases: 452 | Safe controls: 778 - True Positives (TP): 407 - False Positives (FP): 27 - False Negatives (FN): 45 - True Negatives (TN): 751 - Recall (Sensitivity): 90.04% (407 / 452) - Precision: 93.78% (407 / 434) - False Positive Rate (FPR): 3.47% (27 / 778) - Specificity (TNR): 96.53% (751 / 778) - Youden's Index (J): 86.57% (Recall − FPR) - Balanced F1 Score: 91.87% ### Evaluation Scope & Limitations - These benchmark results measure detection sensitivity and discrimination accuracy on standardized synthetic benchmark suites. - They do not measure sandbox exploitability validation or patch synthesis quality. - For complete methodology, category-level confusion matrices, and scoring notes, see https://cyfendo.com/benchmarks and https://cyfendo.com/whitepaper. - Machine-readable dataset download: https://cyfendo.com/data/owasp_benchmark_evaluation_summary.json --- ## 4. Language & Framework Coverage Matrix Cyfendo evaluates code across 5 distinct capability dimensions: 1. **Basic scanning**: Pattern and sensitive sink detection across supported files. 2. **Production cross-file analysis**: Full interprocedural symbol graphs and cross-module taint tracing. 3. **Sandbox validation**: Ephemeral sandbox PoC exploit verification where runtime toolchains are present. 4. **Patch generation**: Surgical remediation diff synthesis with pre-flight AST structure and lint verification. 5. **Beta / roadmap support**: Emerging ecosystems with basic syntax parsing while cross-file graphs and runtimes are developed. | Language | Basic Scanning | Production Cross-File Analysis | Frameworks | Sandbox PoC Validation | Patch Generation | Published Benchmark | Status | |---|---|---|---|---|---|---|---| | Python | Supported | Full cross-file & inter-module call graph | Django, Flask, FastAPI, Tornado | Supported (python3 sandbox) | Review-ready patches | OWASP Python v0.1 (90.04% Recall, 3.47% FPR) | Production | | Java | Supported | Class hierarchy & package method calls | Spring Boot, Jakarta EE, Servlets | Supported (javac / java sandbox) | Review-ready patches | OWASP Java v1.2 (94.06% Recall, 3.77% FPR) | Production | | JavaScript / TypeScript | Supported | ES modules, CommonJS require, routes | Node.js, Express, Next.js, Fastify | Supported (node & tsx sandbox) | Review-ready patches | Internal test suites | Production | | Go | Supported | Package-level symbol graphs & calls | net/http, Gin, Echo, Fiber | Supported (go toolchain) | Review-ready patches | Internal test suites | Production | | C / C++ | Supported | Header & translation unit references | POSIX APIs, sockets, memory buffers | Supported (gcc / clang) | Review-ready patches | Internal CWE test suites | Production | | Rust | Supported | Crate-level symbol indexing | Actix-web, Axum, stdlib | Supported (rustc / cargo) | Review-ready patches | Internal test suites | Production | | PHP | Supported | File inclusion & function definitions | Vanilla PHP, Laravel, Symfony | Supported (php CLI) | Review-ready patches | Internal CWE test suites | Production | | Ruby | Supported | Module & require indexing | Rails, Sinatra | Supported (ruby runtime) | Review-ready patches | Internal test suites | Production | | Shell / Bash | Supported | Sourced scripts | POSIX Shell, Bash | Supported (bash/sh) | Review-ready patches | Internal injection tests | Production | | Kotlin / Android | Supported | JVM call graph & decompiled bytecode | Android SDK, Ktor, Spring Boot, Gradle KTS | Supported (Gradle/JVM & Dalvik/JADX) | Review-ready patches | Internal Android CWE test suites | Production | | C#, Swift, Scala | Supported | Roadmap / In Development | ASP.NET Core, Swift stdlib, sbt | Roadmap | Roadmap / Limited | None published | Beta / Roadmap | --- ## 5. Deployment Modes & Data Custody Architecture ### Mode 1: Managed Cloud - **Analysis Environment**: Cyfendo Google Cloud Platform & AWS secure cloud infrastructure in ephemeral RAM containers. - **Data Sent to Cyfendo**: Source code uploaded via TLS 1.3 for duration of scan. - **Where Code Snippets Go**: Ephemeral container RAM in Cyfendo cloud; destroyed immediately upon scan completion. - **Where Telemetry Goes**: Scan findings, issue metadata, and aggregate LOC counts stored in Cyfendo platform database. - **External AI Providers**: Cyfendo-managed enterprise AI inference under commercial agreements with zero-data-retention terms. - **Model Training**: Customer source code is never used to train Cyfendo or foundation models. - **Retention Policies**: Cyfendo zero-code-retention policy applies. Source code exists only in ephemeral container RAM and is destroyed post-scan. - **Egress Summary**: Source code uploaded to Cyfendo cloud runners; ephemeral processing with zero persistent code storage. - **Offline Operation**: Not supported (requires active connection to Cyfendo cloud). ### Mode 2: Private Scan (External Model Provider) - **Command**: `cyfendo scan --private [PATH]` - **Analysis Environment**: Customer workstation, laptop, or self-hosted CI runner. - **Data Sent to Cyfendo**: Zero source code or repository files. Only entitlement token validation and aggregate LOC telemetry reach Cyfendo API servers. - **Where Code Snippets Go**: Localized vulnerability AST slices and code snippets are sent directly from the customer runner to the customer's configured third-party AI provider (OpenAI, Anthropic, Gemini, Azure, Vertex) using customer API keys (`CYFENDO_LLM_KEY`). - **Where Telemetry Goes**: Entitlement license token check and aggregate LOC telemetry counters reach Cyfendo API servers. - **External AI Providers**: Customer-configured external model providers (OpenAI, Anthropic, Google Gemini, Azure OpenAI, Vertex AI). - **Retention Policies**: Cyfendo retains zero customer code. Data retention by the third-party AI provider is governed by the customer's own commercial agreement/DPA with that vendor (e.g. OpenAI Zero Data Retention policy). - **Egress Summary**: No source code sent to Cyfendo. Localized vulnerability code slices egress to the configured external AI provider, and license telemetry egresses to Cyfendo. (Not zero egress). - **Offline Operation**: Not supported (requires outbound network connectivity to Cyfendo API and external AI provider endpoint). ### Mode 3: Private Scan (Locally Hosted Model) - **Command**: `cyfendo scan --private --provider ollama [PATH]` - **Analysis Environment**: 100% inside customer environment or private VPC on local hardware. - **Data Sent to Cyfendo**: Zero source code, zero AST data, zero code snippets. - **Where Code Snippets Go**: None. Prompts and code slices remain 100% inside customer perimeter on local runtime. - **Where Telemetry Goes**: Online: Minimal cryptographic license check. Offline/Air-gapped: Zero telemetry. - **External AI Providers**: None. Inference runs on local hardware via Ollama, vLLM, or self-hosted endpoints. - **Retention Policies**: 100% customer-controlled local retention; zero third-party data retention. - **Egress Summary**: Strict Zero Egress. No code, AST, or prompt ever leaves the customer's network boundary. - **Offline Operation**: Supported. Operates 100% offline and air-gapped when configured with local models and offline license validation. ### Certifications & Trust Disclosures - **Cloud Infrastructure**: Hosted on Google Cloud Platform and AWS data center facilities holding independent SOC 2 Type II, ISO 27001, and FedRAMP certifications. - **Platform Security Posture**: Cyfendo's platform architecture, internal access controls, and software development lifecycle are engineered in alignment with SOC 2 Type II and ISO 27001 control frameworks. Cyfendo has not yet completed its own independent corporate audit. - **Assessment Reports & Certificates**: Cyfendo scan reports and assessment certificates document automated software security testing scope and empirical results at the time of evaluation. They reflect empirical test results and do not constitute independent third-party certification, regulatory endorsement, OWASP certification, or a guarantee that an application is vulnerability-free. --- ## 6. Subscription Plans, Allowances & Pricing ### Developer Plans - **Free**: $0/month. 10,000 protected LOC, 5 scans/month, 1 project, limited patch evaluation. Penetration testing not included. - **Starter**: $99/month (or $990/year billed annually, equivalent to $83/month). 100,000 protected LOC, 10 scans/month, unlimited projects & users, full review-ready patches. Penetration testing not included. - **Growth**: $299/month (or $2,990/year billed annually, equivalent to $249/month). 500,000 protected LOC, 30 scans/month, unlimited projects & users, review-ready patches, priority scan queue. Penetration testing not included. - **Scale**: $799/month (or $7,990/year billed annually, equivalent to $666/month). 2,000,000 protected LOC, 100 scans/month, unlimited projects & users, review-ready patches, priority technical support. Penetration testing not included. - **Scale Add-on (extra_1m)**: +1,000,000 protected LOC and +500 scans/month for $200/month (or $2,000/year billed annually). Available for Scale and Enterprise. ### Business & Enterprise Plans - **Business**: Custom pricing with guided setup, code security, and application penetration testing (Beta for select businesses; separately scoped & available by arrangement). - **Enterprise**: Custom pricing for multi-million LOC codebases, custom scan allotments, private VPC deployments (Managed or Local Models), custom data retention policies, dedicated SLAs, and penetration testing (Beta for select businesses; separately scoped & available by arrangement). ### Protected LOC Measurement - Only non-generated application source code actively protected by Cyfendo is counted. - Excluded: Blank lines, comments, vendored directories (node_modules, vendor, third_party), build/dist artifacts, lockfiles, minified bundles, documentation, media files, and binaries. --- ## 7. Product Availability: Released Products vs. Upcoming Services - **Autonomous Code Security Platform (Released)**: Available across all self-serve and enterprise plans. - **Cyfendo Private Scan (Released)**: Supported via Cyfendo CLI for local and CI/CD scanning. - **Code Security Scanner (Released)**: In-browser interactive AST scanner at https://cyfendo.com/code-security-scanner. - **Application Penetration Testing (Beta — Select Businesses Only)**: Blackbox and whitebox application penetration testing is currently in Beta for select businesses only. It is not an included self-serve developer subscription feature. Organizations can discuss assessment needs, scoping, and scheduling at https://cyfendo.com/contact?interest=penetration-testing. --- ## 8. Developer CLI Reference & CI/CD Integrations ### Installation POSIX Shell: ```bash curl -fsSL https://cyfendo.com/install.sh | bash ``` Python Pip: ```bash pip install cyfendo ``` ### Verified CLI Commands - `cyfendo scan [PATH]` — Scans directory or file for security vulnerabilities via managed cloud runners. - `cyfendo scan --private [PATH]` — Executes AST taint scan locally; localized slices sent to configured AI provider. - `cyfendo scan --private --provider ollama [PATH]` — Strict Zero Egress: runs 100% locally with local models. - `cyfendo config --set-token [TOKEN]` — Configures Cyfendo CLI authentication token. - `cyfendo config --set-provider [PROVIDER]` — Configures persistent Private Scan provider. ### GitHub Actions Integration Example (Private Scan) ```yaml name: Cyfendo Security Scan on: pull_request: branches: [main] jobs: security: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Install Cyfendo CLI run: curl -fsSL https://cyfendo.com/install.sh | bash - name: Run Cyfendo Private Scan env: CYFENDO_TOKEN: ${{ secrets.CYFENDO_TOKEN }} CYFENDO_LLM_KEY: ${{ secrets.OPENAI_API_KEY }} run: cyfendo scan --private --provider openai . ``` --- ## 9. Contact & Official References - **Website**: https://cyfendo.com - **Pricing & Plans**: https://cyfendo.com/#pricing - **Documentation**: https://cyfendo.com/docs - **Benchmarks**: https://cyfendo.com/benchmarks - **Benchmark Evaluation Dataset (JSON)**: https://cyfendo.com/data/owasp_benchmark_evaluation_summary.json - **Technical White Paper**: https://cyfendo.com/whitepaper - **FAQs**: https://cyfendo.com/faq - **About Us**: https://cyfendo.com/about - **Founder Profile**: https://cyfendo.com/about/bryan-vuong - **Contact**: contact@cyfendo.com - **Security Inquiries**: https://cyfendo.com/.well-known/security.txt