Secure every code and AI change
CodeStax brings code security, software composition analysis, code quality, pull-request review, compliance evidence, and AI Attack Surface Management into one tenant-scoped platform.
How CodeStax works
What CodeStax does
CodeStax combines multiple security scanning engines with AI-powered analysis to provide comprehensive code security coverage:
Key features
| Feature | Description |
|---|---|
| Smart & Deep Scans | Choose between fast scans for frequent checks or thorough scans for release preparation |
| AI Remediation | Get governed fix suggestions with code examples for eligible vulnerabilities |
| CVSS/EPSS Scoring | Industry-standard vulnerability scoring with real-time exploit prediction |
| Vulnerability Correlation | Automatic deduplication of findings detected by multiple scanners |
| AI Attack Surface Management | Evidence-backed AI inventory, OWASP LLM findings, topology, approvals, policies, waivers, and CSV export |
| Multi-Provider Support | Connect GitHub, GitLab.com, and Bitbucket Cloud when the provider is enabled for your deployment |
| PDF Reports | Generate professional security and supporting compliance-evidence reports |
| Team Management | Role-based access control with organization workspaces |
| Automation | API keys, provider webhooks, general and SCA-specific schedules, CI/CD templates, and an installable CLI |
| Governance | Quality profiles, a rule catalog, policies, waivers, audit logs, privacy controls, and compliance exports |
Analysis coverage
| Scanner | Type | What It Finds |
|---|---|---|
| SAST Analyzer | SAST | OWASP Top 10 and CWE-mapped source-code vulnerabilities |
| Dependency Analyzer | SCA | CVEs, KEV and EPSS signals, licenses, outdated packages, reachability, and SBOM/VEX evidence |
| Secret Detection Engine | Secrets | API keys, passwords, tokens, private keys, and sensitive connection strings |
| IaC Security Analyzer | IaC | Terraform, Kubernetes, Helm, CloudFormation, Docker, Compose, and ARM misconfigurations |
| Container Security Analyzer | Container | Dockerfile and container configuration risks |
| Code Quality Analyzer | Quality | Complexity, maintainability, dead code, duplication, and ingested test coverage |
| AI Attack Surface Analyzer | AI security | AI assets, topology, OWASP LLM risks, and coverage-aware reconciliation |
Quick start
Get started in under 5 minutes:
Need help?
- Browse this documentation for detailed guides
- Check the FAQ for common questions
- Use the API reference for automation
- Contact support at support@codestax.co