Deterministic hot path
Cheap, continuous and reproducible checks.
Claude, Codex and future security models can reason about novel vulnerabilities. CodeMarine supplies continuous deterministic coverage, bounded context and an independent validation gate.
The collaboration workflow is the product direction. Deterministic scanning and graph context exist today. Automated escalation and patch validation are planned.Reachable from two external entry points.
Novel impact, exploit path and proposed remediation.
Pattern quantity does not replace semantic reasoning. Model intelligence does not replace reproducible policy. CodeMarine keeps those roles separate and connects them through evidence.
Find novel, context-dependent vulnerabilities
Check known risk continuously and deterministically
Reason across business logic and intent
Track dependencies, agent tools and policy state
Explain impact and propose contextual fixes
Validate patches against revision, rules and tests
Investigate selected high-value cases
Control when code, data and budget may be shared
The frontier model operates inside a defined workflow. It can add evidence, challenge a finding and propose a patch. It cannot silently erase deterministic policy.
CodeMarine scans the workspace, dependency graph and AI configuration.
Policy decides whether the case deserves local specialist or frontier investigation.
A bounded packet includes relevant files, call paths, evidence and sharing scope.
An approved provider returns a verified, rejected, uncertain or incomplete result.
CodeMarine rescans an isolated patch and checks policy, provenance and tests.
A verified discovery can become a tested deterministic regression rule.
CodeMarine already knows parts of the call graph, finding evidence and dependency state. A model should not waste time rediscovering them or receive unrelated source by default.
Provider, model, budget and data policy are attached before transmission.
Cheap, continuous and reproducible checks.
Compact security models narrow candidate files inside a constrained sandbox.
Deep reasoning for selected novel or high-impact cases.
Small open-weight security models may reduce the search space before a frontier call. Their output remains a candidate, not proof. CodeMarine will benchmark this tier before claiming support or performance.
Remediation should happen in an isolated worktree and return through CodeMarine before it reaches the developer’s checkout or merge path.
The patch must apply to the finding’s exact code revision.
The original issue is rescanned or explicitly adjudicated.
Code, dependency and protected-file checks run again.
Applicable project and policy tests complete successfully.
The decision, provider and validation results remain attributable.
Use local deterministic checks on every relevant event. Buy frontier reasoning only for the cases where semantic depth changes the decision.
CONTINUOUS PATHLocal deterministic
High-frequency checks. No model required.SELECTIVE PATHFrontier investigation
Policy-controlled cases only. Scope and budget recorded.Bars illustrate workflow frequency, not measured customer volume.
Keep deterministic policy independent. Use the best model for the cases that need it.