# Cyfendo > Cyfendo is an autonomous application security platform that continuously detects, empirically verifies, and synthesizes review-ready patches for vulnerabilities in source code without requiring a dedicated security team. ## Overview Cyfendo brings autonomous AppSec capacity to software engineering teams. Unlike legacy static analysis tools that flood developers with unverified pattern-match alerts, Cyfendo combines AST taint analysis with a Dual-Oracle Ephemeral Sandbox (trigger payload vs. benign functional baseline) to verify reachability and exploitability where toolchains are supported. When a vulnerability is confirmed, Cyfendo synthesizes surgical, contextual patch diffs for developer review and merge. ## Intended Users Software developers, engineering teams, and tech leads who want continuous, high-signal security scanning and review-ready fixes integrated into their Git and CI/CD workflows without needing an in-house security department. ## Current Products vs. Upcoming Services - **Autonomous Code Security Platform (Released)**: Continuous SAST, AST taint tracking, sandboxed PoC exploit validation where supported, review-ready patch synthesis, CLI, and CI/CD pull request gates. - **In-Browser Code Security Scanner (Released)**: Interactive AST scanner and finding inspection at https://cyfendo.com/code-security-scanner. - **Cyfendo Private Scan (Released)**: Local CLI and CI runner execution (`cyfendo scan --private .`). Repository code is never sent to Cyfendo. Supports external LLM providers (where localized snippets egress to the chosen AI vendor) or 100% local models (Ollama/vLLM) for strict zero-egress environments. - **Application Penetration Testing (Beta — Select Businesses Only)**: Blackbox and whitebox penetration testing currently in Beta for select businesses only. It is separately scoped and scheduled by arrangement via consultation at https://cyfendo.com/contact?interest=penetration-testing (not included in self-serve software subscriptions). ## Subscription Plans & Pricing - **Free**: $0/month. 10,000 protected LOC, 5 scans/month, 1 project, limited patch evaluation. Penetration testing not included. - **Starter**: $99/month (or $990/year billed annually, equivalent to $83/month). 100,000 protected LOC, 10 scans/month, unlimited projects & users, full review-ready patches. Penetration testing not included. - **Growth**: $299/month (or $2,990/year billed annually, equivalent to $249/month). 500,000 protected LOC, 30 scans/month, priority scan queue. Penetration testing not included. - **Scale**: $799/month (or $7,990/year billed annually, equivalent to $666/month). 2,000,000 protected LOC, 100 scans/month, add-ons available (+$200/mo or $2,000/yr for +1M LOC and +500 scans). Penetration testing not included. - **Business**: Custom pricing with guided setup, code security, and application penetration testing (Beta for select businesses; separately scoped & available by arrangement). - **Enterprise**: Custom pricing for multi-million LOC scopes, custom scan allotments, private VPC deployments, and dedicated SLAs. Penetration testing available by arrangement (Beta, separately scoped). ## Language Support Capabilities Cyfendo distinguishes five distinct capability dimensions across languages: 1. **Basic scanning**: Structural syntax parsing and taint source/sink detection across 11 language ecosystems (Python, Java, JS/TS, Go, C/C++, Rust, PHP, Ruby, Shell/Bash, Kotlin/Android, C#/Swift/Scala). 2. **Production cross-file analysis**: Full interprocedural symbol and call-graph analysis for 10 production stacks: Python, Java, JS/TS, Go, C/C++, Rust, PHP, Ruby, Shell/Bash, and Kotlin / Android. 3. **Sandbox validation**: Ephemeral containerized PoC exploit trigger vs. benign functional baseline verification where runtime toolchains are present. 4. **Patch generation**: Automated diff synthesis with pre-flight AST and syntax linting validation. 5. **Beta / roadmap support**: C#, Swift, and Scala currently support basic scanning; cross-file analysis and containerized sandbox execution are in active engineering roadmap. ## Quickstart & CLI Install via POSIX shell: ```bash curl -fsSL https://cyfendo.com/install.sh | bash ``` Install via Python Pip: ```bash pip install cyfendo ``` Run local scan: ```bash cyfendo scan . ``` Run Private Scan with local models (strict zero egress): ```bash cyfendo scan --private --provider ollama . ``` Run Private Scan with external AI provider: ```bash cyfendo scan --private --provider openai . ``` ## Authoritative Documentation & Resource Links - [Homepage](https://cyfendo.com/): Product identity, core principles, and interactive walkthrough. - [Pricing](https://cyfendo.com/#pricing): Subscription plans, protected LOC definitions, and scan allowances. - [Code Security Scanner](https://cyfendo.com/code-security-scanner): Interactive AST scanner and sample vulnerability findings. - [SAST Architecture](https://cyfendo.com/sast): Deep static analysis, taint tracking, and verification architecture. - [Developer Guide & CLI](https://cyfendo.com/docs): CLI flags, CI/CD integrations (GitHub Actions, GitLab CI), and language coverage matrix. - [Security Benchmarks](https://cyfendo.com/benchmarks): OWASP Benchmark v1.2 and v0.1 confusion matrices (3,970 tests: 94.06% Java recall, 90.04% Python recall). - [Benchmark Dataset Summary (JSON)](https://cyfendo.com/data/owasp_benchmark_evaluation_summary.json): Downloadable machine-readable evaluation summary. - [Technical White Paper](https://cyfendo.com/whitepaper): Detailed evaluation methodology and Youden's Index analysis on OWASP Benchmark. - [Frequently Asked Questions](https://cyfendo.com/faq): Technical Q&As on code privacy, LOC calculation, and deployment modes. - [About Us](https://cyfendo.com/about): Company mission and background of founder Bryan Vuong (former engineering leader at Google and Meta). - [Founder Profile](https://cyfendo.com/about/bryan-vuong): Public founder profile of Bryan Vuong (also known as Ba-Quy Vuong), engineering leadership at Google and Meta, and PhD from UW–Madison. - [Contact Us](https://cyfendo.com/contact): Inquiries, enterprise sales, and penetration testing discussions. - [Privacy Policy](https://cyfendo.com/privacy): Data custody, zero training on customer code, and retention policies. - [Security Disclosure](https://cyfendo.com/.well-known/security.txt): RFC 9116 security contact and vulnerability disclosure. - [Comprehensive LLM Reference](https://cyfendo.com/llms-full.txt): Detailed technical context and operational reference.