Code Integrity
Local-first scanning, shared rule execution, structural confirmation and graph context across the workspace.
CodeMarine protects the shared environment where agents write code, add dependencies and act with developer authority. Each layer has a clear job and a clear proof boundary.
Current, beta and planned capabilities are labelled throughout this page.The planes share normalized findings, policy and evidence. This lets CodeMarine move from a saved file to a package decision, an agent action or a frontier investigation without losing context.
Local-first scanning, shared rule execution, structural confirmation and graph context across the workspace.
Package identity, provenance, manifests, lockfiles, install behavior and AI tool configuration.
Deterministic action evaluation and provider adapters for defined pre-execution paths.
Governed MCP and API paths with scoped credentials and trusted target context.
Revision-bound proof, action receipts, operational health and explicit coverage gaps.
Focused escalation, model investigation, isolated remediation and deterministic patch validation.
The continuous path does not need frontier tokens. A model call happens only when a finding, policy or user decision justifies deeper investigation.
CodeMarine records the workspace and revision context.
Known policy produces a reproducible result.
Clear findings warn or block. Ambiguous cases can move to an approved model.
A patch must pass the deterministic gate and match the expected revision.
Verified discoveries can become regression fixtures and new controls.
CodeMarine separates local deterministic work from optional managed intelligence and model calls. A team can choose the right privacy and cost boundary for each workspace.
High-frequency code, dependency and policy checks run without sending every change to a model.
Signed updates and service-backed features can extend local checks where configured.
Small local security models can help narrow candidate files. Their output remains probabilistic evidence.
Approved models receive bounded context for novel or high-impact cases.
CodeMarine watches the resulting code and trust boundary across tools. Provider integrations add earlier interception where each host supports it.
Continuous checks stay close to the workspace. High-confidence catastrophe policy can intervene on supported paths without turning every command into a permission ceremony.
Teams can adopt different frontier tools while code, dependency and action evidence converge on one policy model.
The product direction is explicit per-surface status with proof, health and limitation details instead of one global protected state.
Start with continuous deterministic protection. Add provider-specific controls as each surface becomes proof-backed.