Skip to Content
Introduction

Welcome to CodeStax

CodeStax is an AI-powered code security platform that helps development teams find and fix vulnerabilities before they reach production.

How CodeStax Works

What CodeStax Does

CodeStax combines multiple security scanning engines with AI-powered analysis to provide comprehensive code security coverage:

  • SAST (Static Application Security Testing) — Find vulnerabilities in your source code across 30+ languages
  • SCA (Software Composition Analysis) — Detect vulnerable dependencies and license compliance issues
  • Secret Detection — Catch leaked API keys, passwords, and tokens before they’re exposed
  • IaC Scanning — Secure your Terraform, Kubernetes, CloudFormation, and Dockerfiles
  • PR Code Reviews — AI-powered security reviews on every pull request

Key Features

FeatureDescription
Smart & Deep ScansChoose between fast scans for frequent checks or thorough scans for release preparation
AI RemediationGet AI-generated fix suggestions with code examples for every vulnerability
CVSS/EPSS ScoringIndustry-standard vulnerability scoring with real-time exploit prediction
Vulnerability CorrelationAutomatic deduplication and attack chain detection across scanners
Multi-Provider SupportWorks with GitHub, Bitbucket, and GitLab repositories
PDF ReportsGenerate compliance-ready reports (SOC 2, ISO 27001)
Team ManagementRole-based access control with organization workspaces
CI/CD IntegrationAPI keys and webhooks for automated security in your pipeline

Supported Scanners

ScannerTypeWhat It Finds
SemgrepSASTOWASP Top 10, CWE vulnerabilities across 30+ languages
TrivySCAKnown CVEs in dependencies across 9 ecosystems
GitleaksSecretsAPI keys, passwords, tokens, private keys
CheckovIaCMisconfigurations in Terraform, K8s, CloudFormation
HadolintContainerDockerfile best practices and security issues
RuffLintingPython code quality and security
BanditSASTPython-specific security vulnerabilities
ESLintLintingJavaScript/TypeScript security patterns

Quick Start

Get started in under 5 minutes:

  1. Create your account at codestax.co
  2. Connect your repositories from GitHub or Bitbucket
  3. Run your first scan and review results
  4. Set up automated scanning on every push

Need Help?

  • Browse this documentation for detailed guides
  • Check the FAQ for common questions
  • Contact support at support@codestax.co