Deterministic AI application security. Air-gapped.

Find, prove, and close the vulnerabilities in your code — with your source, findings, and models never leaving your network.

Proven Air-gapped Governed
ModexAI · air-gapped console
ModexAI security-posture dashboard

Proven, not guessed

Every finding is backed by a reachability proof — the exact path from input to sink.

Air-gapped by design

Your code, findings, and models stay on your hardware. No egress, ever.

Governed

Human and AI changes — attributed, gated, and revalidated before they land.

A deterministic layer over a red-team-trained model.

The model reasons like an attacker. The engine proves what's real. The proof — never the model — has the final word.

The model

Red-team-trained

A LoRA-tuned, adversarial base — tuned to surface what an attacker would exploit, and to explain it in plain language.

+
The engine

Deterministic

Inter-procedural taint analysis that proves whether untrusted input can actually reach a dangerous sink.

Checkout to revalidated fix.

Deterministic proof decides what reaches a developer — and nothing is resolved until a re-scan proves the path is closed.

01

Ingest

02

Detect

03

Prove

04

Adjudicate

05

Gate

06

Fix

07

Revalidate

A proof, not a probability.

Every finding carries the exact data-flow — untrusted source, each hop, and the dangerous sink it reaches.

Untrusted sourcerequest.body.target
PropagationbuildUpstreamCall(target)
Dangerous sinkhttp.get(url)
Proven reachable · CWE-918 · SSRF
System map
ModexAI System Map — attack surface, call graph, and taint flows

Your codebase, as a system.

Routes, call graph, and taint flows — see where input enters and everywhere it can reach.

It learns your system — ask it anything.

ModexAI maps your integrations, functions, and business logic, and stays aware of every change. New engineers get answers in plain language, grounded in your actual code.

✦ DexPilot How does checkout talk to billing — and is it safe?
checkout-api calls POST /charge on billing-service (billing.client.ts:24), authenticated with a service token. One taint flow reaches it: a user-supplied note field flows into the request URL — SSRF, unproven. Open the path in the System Map.

Control what AI changes.

Every fix — human or agent — is attributed, gated, and provably closed before it's resolved.

Governance
ModexAI Governance — human vs AI approvals queue
SIEM forwarding
ModexAI SIEM settings — forward events to on-prem collectors

Fits your perimeter.

Air-gapped install. Findings and audit events forward to your SIEM in CEF, LEEF, or Syslog — enforced as CI gates.

See it on your own code — air-gapped, in 30 days.

One system, your Git, your hardware. A go/no-go you can defend.

Request an evaluation
ModexAI — Deterministic, air-gapped application security modexai.co · hello@modexai.co