To reproduce one scan you would need three to five tools — each with its own contract and none talking to the others. Here, a security finding crosses with who sustains the code and with the blast radius in the architecture.
EVIDENCE IN EVERY FINDING — FILE AND LINE CITED
Nine live reports — each answers a different question about the same system.
The architecture portrait — core, domains, dependencies, integrations and the real system diagram.
Static-analysis findings, vulnerable dependencies and secrets — with severity and an attack-surface map.
The database from the inside, without production access: schema, indexes, sensitive data by regulatory category and tenant isolation.
Where the code hurts — critical change points, health per dimension and the cut points.
The symptoms of assisted development — without accusing authorship. Generated blocks with no test, style patterns, inherited risks.
The ability to evolve safely — delivery rhythm, coupling and process health.
What to migrate, in which order and where to cut — dispositions, seams and dependencies.
Right domain boundaries and resilient integrations between systems.
Who sustains the system — knowledge concentration, team alignment and delivery rhythm.
Every report can become an executable kit — conclusions turn into stories with criteria and sensors. Meet the SDD Kit →
Detection uses no language model: static analysis with a curated corpus of rules from audited open sources, dependencies against public databases (including known in-the-wild exploitation) and secret scanning. The model comes in later, only to narrate — the finding has the nature of proof.
From the code and the structural snapshot: reconstructed schema, missing indexes, personal data by regulatory category (LGPD/GDPR), tenant isolation and the regulatory matrix — each point with its evidence seal.
Linked to the repository, the report stops being a photograph: the chain of generations becomes tracking.
The real trend across generations — what improved, what degraded, what appeared.
Adoption of recommendations is measured per finding — and the reason for not adopting is asked, never inferred.
Clickable provenance on every comparison; when the scope changes, the report refuses the comparison instead of adding different things.
Tell us what you need to decide and we point to which of the nine to start with — or create the account and generate the first one on your repository, no card.